HID® iCLASS® SE
HID's second-generation AES-secured smart card and the platform most large sites migrate through — a facility-operations guide to deploying, issuing, and expanding iCLASS SE.
Can you buy third-party HID iCLASS SE cards?
HID iCLASS SE is an AES-secured 13.56 MHz smart credential built on HID's Secure Identity Object model, where credential data is encrypted and cryptographically bound to the card's secure element. Because SE credentials are provisioned with your organization's HID keys, they're ordered through HID or an authorized integrator — an independent supplier cannot produce a working iCLASS SE card.
- 13.56 MHz
- Frequency
- 13.56 MHz Contactless Smart Card — AES-secured, Secure Identity Object model
- Technology
- 2
- Bit formats
- 6+
- OEM part nos.
- Brand channel
- Order from
This is the operational rundown for facilities running HID iCLASS SE: what the platform does, how credentials are issued and replaced, how it sits alongside your legacy readers during a migration, and where an independent supplier like us can genuinely help versus where you need HID's channel. We don't sell iCLASS SE, and we'd rather map the terrain clearly than overstate what we do.
What iCLASS SE brought to the table
iCLASS SE is the generation where HID moved its smart-card platform onto the Secure Identity Object model and AES-based mutual authentication. Each credential's access data lives inside an SIO — an encrypted, digitally signed container bound to that specific chip — so the payload can't be lifted off one card and dropped onto another. For a facility, that's the whole point: the credential is trustworthy because it's cryptographically anchored, not just because it holds the right number.
SE also introduced genuine multi-application capability. The same card can carry access control plus logical login, cashless vending, or transit under separately keyed SIOs, which is why corporate campuses and universities standardized on it for one-card programs. And because SE readers are software-configurable, a single reader can be provisioned to accept SE while still reading an older format during a transition.
Issuing and replacing SE credentials
SE credentials are created under HID's Trusted Identity Platform using keys specific to your organization. When your system was commissioned, those keys were provisioned into your readers and your credential orders; every subsequent card is minted against them. That key management is what an outside vendor fundamentally cannot replicate, which is why compatible SE cards don't exist.
Replacing a lost SE card follows the issuance channel: your integrator orders a new credential to your keys, and you revoke the lost one in your access software so it's dead on the next reader attempt. Bulk reissuance — onboarding waves, site consolidations — runs the same way, batched through your integrator against your key set.
If your organization holds an Elite key (a per-organization master key program layered on SE), reissuance specifically requires that key, so the administrator who holds it has to be in the loop. See the iCLASS Elite page for how that program changes the ordering picture.
Migration reality: SE alongside what you already have
Most SE deployments don't happen overnight. A facility with hundreds of doors and thousands of credentials migrates in phases, and multiCLASS SE readers are the tool that makes it survivable — a reader can be configured to accept SE credentials for migrated users while still reading a legacy format for those not yet reissued.
The operational discipline that matters: the security benefit of SE only fully lands once the legacy technology is switched off at the reader. A reader left permanently in mixed mode keeps the door only as strong as its weakest accepted credential. Plan the migration with an end date for legacy acceptance, not an indefinite overlap.
This is also where an independent supplier is genuinely useful. During the overlap, you still need working legacy credentials for the un-migrated population and the secondary doors, and that's stock we can supply while the SE rollout proceeds through HID's channel.
Where American Key Cards fits
We don't supply iCLASS SE — those come from HID or your integrator, provisioned to your keys. What we supply is the open 125 kHz proximity side of your building: the parking gates, outbuildings, and legacy doors that almost every SE site still runs, plus the interim proximity credentials that keep a migration moving.
If you're standing in a building trying to work out which doors are SE and which are still on a proximity format we can supply, send photos of the readers and a working credential. We'll identify what's what, supply the parts we legitimately can, and point you to the right channel for the SE credentials — no guesswork, no overselling.
HID iCLASS SE specifications
- System brand
- HID Global / ASSA ABLOY
- Technology
- 13.56 MHz Contactless Smart Card — AES-secured, Secure Identity Object model
- Frequency
- 13.56 MHz
- Credential platform
- HID iCLASS SE secure element (high-assurance certified) with AES co-processor; credentials carried as digitally signed, device-bound Secure Identity Objects
- Bit formats
- Any standard HID access format carried inside an encrypted SIO (26-bit H10301, 37-bit H10302/H10304, Corporate 1000), Field-programmable under HID issuance
- OEM part numbers
- 3000 / 3002 / 3003 / 3004 (iCLASS SE card, various memory), 3050 (SE composite card), 3100 / 3150 (SE + Prox card), 3250 (SE key fob), 3300 (SE tag), 3350 (SE clamshell)
Specifications reviewed August 2026
How to order HID iCLASS SE credentials
iCLASS SE credentials are issued through HID's Trusted Identity Platform against your organization's keys, so they come from HID or an authorized HID integrator — typically the company that services your access system. American Key Cards does not supply iCLASS SE credentials; a third party cannot provision one that enrolls.
Editorial reference page. American Key Cards is an independent credential supplier and is not affiliated with, endorsed by, or sponsored by HID. We do not sell HID's secured credentials; brand and product names appear only to identify the technology discussed, and all trademarks remain the property of their respective owners.
Readers in this ecosystem
Related formats
You might also need
HID Seos
HID's flagship AES-secured smart credential, built so that the credential is inseparable from its chip — a facility-operations guide to how Seos is deployed, issued, and expanded.
How it worksHID iCLASS SR
The bridge issuance between legacy iCLASS and the SE platform — a facility guide to where SR fits, how it's ordered, and when to plan past it toward SE or Seos.
How it worksHID iCLASS (Legacy)
HID's first-generation 13.56 MHz smart card — a facility guide to where legacy iCLASS came from, how it's ordered, and why planning a migration to SE or Seos is the smart operational move.
How it worksHID iCLASS SE — FAQ
Can I get iCLASS SE cards from a third-party supplier?
No. SE credentials must be provisioned with your organization's HID keys under HID's Trusted Identity Platform, which only HID and authorized integrators can do. We don't sell them and won't claim to — a compatible SE card that actually enrolls isn't something an outside vendor can make.
How do I replace a lost iCLASS SE card?
Through your access-control integrator, who orders a new credential provisioned to your keys; then revoke the lost card in your management software so it stops working immediately. If your credentials are Elite-keyed, the administrator holding your Elite key must be involved.
Is iCLASS SE the same as Seos?
They share the Secure Identity Object model and AES security, but Seos is the device-independent, highest-assurance end-state (cards, phones, wearables) while SE is the card-platform generation many sites migrate through. For new reader deployments, Signo readers running Seos are typically the target.
Can you help during our SE migration?
Yes — with the legacy side. We supply the open 125 kHz proximity credentials for un-migrated users and secondary doors so you're never short during the overlap, while the SE credentials themselves come through HID's channel.