By RFID MFG Editorial Team · Updated September 1, 2026 · 2 min read
Same family, different security era
Both are NXP chips on 13.56 MHz ISO/IEC 14443 A, and both fit the same CR80 card body — the difference is the security design. MIFARE Classic dates from the 1990s and protects data with the proprietary CRYPTO1 cipher, which has had publicly documented attacks since 2008; it survives in huge numbers because readers, locks and closed-loop systems already speak it. DESFire EV2/EV3 uses open AES-128 with mutual authentication and holds Common Criteria EAL5+ certification — the level banks and transit authorities specify.
MIFARE Classic vs DESFire
| Chip | Memory | Security | Typical use | Relative cost |
|---|---|---|---|---|
| MIFARE Classic 1K | 1 KB (16 sectors) | CRYPTO1 — legacy, known attacks | Door access, membership, closed loops | Lowest |
| MIFARE Classic 4K | 4 KB (40 sectors) | CRYPTO1 — legacy, known attacks | Multi-application legacy systems | Low |
| DESFire EV2 | 2 / 4 / 8 KB | AES-128, mutual authentication | Payment, transit, campus ID | Higher |
| DESFire EV3 | 2 / 4 / 8 KB | AES-128, EAL5+ certified | New high-security deployments | Highest |
When Classic is still a reasonable choice
Replacement and expansion cards for an existing Classic-based system, low-stakes membership and loyalty, and closed loops where a cloned card cannot extract real money. The chip is cheap, every access platform reads it, and re-issuing an entire estate has its own cost. What it is not for: new systems protecting money, identity or restricted areas.
When to specify DESFire
Anything touching payment or stored value, campus and corporate ID, government use, and any new access system you expect to run for a decade. AES-128 with mutual authentication resists the cloning attacks that broke CRYPTO1, and per-application keys let one card carry access, payment and identity without the applications seeing each other.
Migrating an existing system
The usual path is phased: issue DESFire cards encoded with both your new AES keys and, where the platform allows, legacy sector data, upgrade readers to multi-protocol firmware, then retire Classic acceptance once the fleet is replaced. We encode both chips per system spec under NDA and supply free pre-production samples so you can verify against your readers before committing either way.
Related reading
Frequently asked questions
Is MIFARE Classic still secure enough to use?
For new high-security systems, no — CRYPTO1 attacks are public and cloning tools are cheap. For replacement cards in an existing closed-loop or low-stakes system, it remains a pragmatic, low-cost choice while a migration is planned.
Do I have to replace readers to move to DESFire?
Often not — many access readers accept both with a firmware setting or multi-protocol mode. Confirm with your platform vendor, then validate with encoded samples before a bulk order.
How much more does DESFire cost than Classic?
DESFire sits well above Classic per chip, and EV3 above EV2 — but at volume the gap narrows, and for payment or identity the security is the point. Exact pricing is stated on a written quotation.
Can one card run both Classic and DESFire?
Not on a single chip. A dual-chip card is possible for special migrations, but the cleaner route is DESFire with per-application keys, which carries multiple applications on one secure chip.