RFID Cards

MIFARE Plus S 2K Cards

MIFARE Plus S 2K cards—also searched as MIFARE Plus S2K—for installed systems that specify the original S generation. Match the exact chip, UID option and required security level before sample approval.

NXP identifies MIFARE Plus S as discontinued. Ask us to confirm current availability for your specified part and quantity; any alternative generation requires approval from your system integrator.

The product photo shows a MIFARE Plus S 4K card as a family reference. It is not a photo of the S 2K version; confirm the chip and memory in the offered sample.

Free standard samples · Quotation within one business day

Download datasheet (PDF)

Product details

Specify MIFARE Plus S 2K precisely

Ordering from an existing specification? Keep the variant name: MIFARE Plus SE, S, X, EV1 and EV2 identify different chips. This page prioritises S 2K enquiries and compares the family below. An SE requirement must not be replaced with S 2K simply because both are called MIFARE Plus. Send the approved part or card specification when checking availability.

Order detailS 2K selection requirement
GenerationOriginal MIFARE Plus S; S is not an abbreviation for Plus EV1 or EV2.
Memory2 kB; confirm the actual offered part rather than identifying memory from the artwork.
UID optionSpecify the UID type required by the installed system. The S family includes different UID/NUID variants.
Delivery stateAgree SL0 for personalisation, or the required configured state for issuance.
Reader integrationSpecify the required security level, reader firmware and application configuration.
SupplyConfirm the exact available part, quantity and batch before agreeing the order.

The MIFARE Plus family: SE, S, X, EV1 and EV2

MIFARE Plus is a family, not a single chip. The variants share the ISO/IEC 14443 Type A air interface and open-standard AES-128 cryptography, but differ in memory and in which security levels they support. Memory and security levels below are from NXP; the exact part must still be named and approved for your order.

MIFARE Plus variantMemorySecurity levels (NXP)Notes
MIFARE Plus SE1 kBSL1, SL3Entry-level AES upgrade for MIFARE Classic 1K; AES-128; Common Criteria EAL4+
MIFARE Plus S2 kB / 4 kBSL1, SL3Original “standard” Plus; AES-128; now discontinued by NXP
MIFARE Plus X2 kB / 4 kBSL1, SL2, SL3Original “expert” Plus; adds SL2, virtual-card support and proximity check; AES-128; EAL4+
MIFARE Plus EV12 kB / 4 kBSL1, SL3Second-generation Plus; SL2 not offered; proximity check; EAL5+
MIFARE Plus EV22 kB / 4 kBSL0, SL1, SL3Current Plus; SL1SL3MixMode, Transaction MAC, Proximity Check, Transaction Timer; AES-128; EAL5+

SL0 is the initial delivery configuration used for personalisation. SL2 — AES authentication combined with MIFARE Classic Crypto1 data confidentiality — is specific to MIFARE Plus X; the SE, S, EV1 and EV2 products move directly between SL1 and SL3. Every generation is offered with a 7-byte UID or a 4-byte NUID. Because an order for S 2K should not silently become an EV2 order, the offered part is named and approved before the order is agreed.

S 2K, S 4K and later Plus generations

VariantPurchasing distinction
MIFARE Plus S 2KThe priority model on this page for systems explicitly specifying S 2K. Confirm remaining supply.
MIFARE Plus S 4KA different memory option in the original S family; the existing product photo shows this version.
MIFARE Plus XA separate original variant with a different feature set; do not substitute it solely because the memory matches.
MIFARE Plus EV1 / EV2Later generations. EV2 adds functions such as sector-level migration and Transaction MAC; these are not S 2K specifications.

For a new project or a supply alternative, ask the integrator to evaluate the current Plus generation. The offered part must be named and approved; an order for S 2K should not silently become an EV2 order. Compare MIFARE DESFire cards if the project instead requires an application/file model.

What to send for an S 2K quotation

  • The required S 2K part or existing approved card specification, quantity and whether alternatives are acceptable.
  • Reader and software details, UID requirement and intended delivery security level.
  • Blank or personalised delivery, with an agreed separate process for sensitive key handling.
  • Card size, material, artwork and numbering; delivery destination and target date.

S 2K sample approval

  1. Confirm that the offered sample is the approved S-generation chip and 2 kB memory option.
  2. Verify the UID and delivery state expected by your issuing software.
  3. Complete enrolment, authentication and the intended transaction with the installed reader.
  4. If a migration is planned, test it on dedicated samples under the integrator’s procedure before applying it to an order.
  5. Approve the print and physical specification, and record the accepted part for repeat orders.

Related product: MIFARE Classic cards. Browse all RFID cards for other credential technologies.

Primary references: NXP MIFARE Plus family, MIFARE Plus S lifecycle information, the MIFARE Plus X fact sheet, MIFARE Plus SE, and MIFARE Plus EV2 with its fact sheet. Chip documentation describes IC capabilities; it does not establish stock or a finished card's compatibility with your system.

SL1 and SL3: what the system must support

For MIFARE Plus S, SL1 provides a MIFARE Classic-compatible operating mode. SL3 uses AES-based authentication and protected communication over ISO/IEC 14443-4. Moving to SL3 requires a reader and application that implement the required commands and key handling. The security-level change proceeds to a higher level and cannot be reversed.

Compatibility mode does not prove that an installed reader will accept every S 2K card. UID handling, reader timing, data layout and personalisation must be checked with the actual system. Approve the sample in the delivery state intended for your order.

Migration path: MIFARE Classic to Plus SL1 to SL3

MIFARE Plus is designed as the upgrade path from MIFARE Classic. A card is delivered in SL0, the personalisation state, then committed to a working security level. In SL1 it behaves like a MIFARE Classic 1K or 4K card using the Crypto1 command set, which can support a staged migration after the exact chip, UID handling, data layout and reader firmware have been qualified. Issuing a different chip alone does not establish compatibility. When the readers and application are ready, the card is switched to SL3, where AES-128 is mandatory for authentication, communication confidentiality and integrity over ISO/IEC 14443-4. The security-level change only ever moves upward and cannot be reversed, so agree the delivery state before personalisation.

On MIFARE Plus EV2 the SL1SL3MixMode lets sectors migrate from Crypto1 to AES individually, at sector or chip level, so a system can move one application at a time rather than all at once. Whichever generation you specify, treat the move from SL1 to SL3 as a change to the approved configuration and test it on dedicated samples with the production readers first. For the Classic starting point, see the MIFARE Classic card; for a new AES-only system, compare MIFARE DESFire cards.

MIFARE Plus or MIFARE DESFire: choosing the card family

MIFARE Plus and MIFARE DESFire are NXP's two mid- to high-security 13.56 MHz families. Both use the ISO/IEC 14443 Type A air interface and AES-128, but they are built around different memory architectures and solve different problems. Plus is the sector-based upgrade path from MIFARE Classic; DESFire is a file-system chip designed for credentials that carry several independent applications. Choose the family by architecture first, then name the exact part. The table below sets the two families side by side on the dimensions that usually decide the specification.

DimensionMIFARE Plus (S / X / EV1 / EV2)MIFARE DESFire (EV1 / EV2 / EV3)
Memory modelSector/block layout inherited from MIFARE Classic: 16-byte blocks grouped into sectors — 16 sectors on 1K, 32 sectors on 2K, and 40 sectors on 4K (the last 8 sectors on 4K holding 16 blocks each)Application/file system: applications addressed by a 3-byte AID, each holding several files with their own sizes and access rights
Security modelSecurity-level ladder SL0 → SL1 → SL3 (SL2 on Plus X only). SL1 runs Crypto1; SL3 uses AES-128 over ISO/IEC 14443-4Application/file access rights and configured key types, including AES-128. Agree authenticated operations and delivery configuration with the integrator
Multi-application supportApplications can use assigned sectors, with on-chip sector keys and access conditions; agree the allocation and key ownershipChip-enforced silos: up to 28 applications on EV1, memory-bound on EV2/EV3, each with its own keys
MIFARE Classic reader compatibilitySL1 provides a Classic-compatible mode; qualify UID handling, data layout, configuration and reader firmware on the actual systemNo — requires ISO/IEC 14443-4 (T=CL) and the DESFire command set
Reader requirementsClassic readers for SL1; SL3 needs readers and firmware that implement Plus AES authenticationReaders and firmware that implement the DESFire AES command set
UID options7-byte UID or 4-byte NUID, offered on each generation7-byte UID; random ID supported
Typical useMigrating an installed MIFARE Classic estate to AES; single-application deployments at volumeNew builds whose credential must carry several independent applications under separate key control
Quotation basisExact Plus part, memory, security state, card construction and quantityExact DESFire generation, memory, personalisation, card construction and quantity

Which family to choose usually follows from the reader estate, the number of applications, the volume and any certification requirement:

  • Choose MIFARE Plus when there is a meaningful MIFARE Classic reader estate to migrate. SL1 lets you reissue cards first and move readers to SL3 AES afterwards, one device at a time, rather than a single-step cutover.
  • For volume deployments, compare quotations for the approved chip, construction and personalisation on the same basis. The family name alone does not determine the finished-card price.
  • Choose MIFARE DESFire for a new build whose credential must carry several independent applications — for example badge, canteen and print quota — under chip-enforced key separation.
  • Choose MIFARE DESFire where the information-security requirements call for the file-level access model or a specific hardware certification; confirm the required certification from the buyer's own specification, not from assumption.
  • Where both patterns exist, a reader fleet that implements both command sets can carry Plus and DESFire cards together; confirm the reader firmware supports both before mixing them.

Within the Plus family, EV1 dropped the SL2 mode and retained the proximity check that Plus X had introduced; EV2 added SL1SL3MixMode for per-sector migration, Transaction MAC and a Transaction Timer. Both EV1 and EV2 hold Common Criteria EAL5+. Whichever family and generation you specify, name the exact part and approve it on samples with the production readers before the order — an S 2K requirement should not become an EV2 or a DESFire order without your integrator's approval. For the file-model alternative see MIFARE DESFire cards; for a hospitality deployment weighing Classic, Plus and DESFire locks see hotel key cards.

Confirm the MIFARE Plus S 2K batch

  1. Send with your enquiry

    State that your system requires Plus S 2K, with the chip identifier option, security level and encoding layout. Include the reader and application details.

  2. Approve a sample

    Validate a sample from the proposed supply against the installed system, including authentication and data operations. Test any proposed replacement separately.

  3. Confirm the quotation

    The S series is discontinued by NXP. Confirm current batch availability, exact chip and delivery schedule; do not assume another Plus generation is a direct replacement.

Discuss your specification →

Frequently asked questions

Is MIFARE Plus S2K the same as MIFARE Plus S 2K?

S2K is commonly used as a compact product description. The specification should name MIFARE Plus S, 2 kB, with the required UID option and delivery state. Confirm the exact offered part before approval.

Is MIFARE Plus S 2K still manufactured?

NXP’s MIFARE Plus S product page says the product is discontinued. Ask us to confirm current availability for the required part and quantity. Do not assume regular stock or approve a different Plus generation without your integrator’s review.

Why does the photograph show a Plus S 4K card?

It is an existing family-reference photo of the S 4K version. The page prioritises S 2K enquiries, but the photograph does not establish the memory being quoted. The quotation and approved sample must identify the exact chip and capacity.

Will an S 2K card work in my MIFARE Classic readers?

Check the required security level, UID handling, data layout and reader support with the integrator. Test enrolment and the real application transaction on a sample; compatibility mode alone is not acceptance evidence for your installation.

Can I change an S 2K card from SL3 back to SL1?

No. The S-generation security level can move to a higher level, not back to a lower one. Agree the delivery state before personalisation or sample testing so the cards suit your issuing workflow.

Can you substitute MIFARE Plus EV2 for S 2K?

An alternative must be expressly approved for the project. EV2 is a different generation with additional functions. Confirm the offered part and configuration, then test it with the installed readers and software before accepting a substitution.

MIFARE Plus vs DESFire: which family should I specify?

Choose by architecture. MIFARE Plus keeps the MIFARE Classic sector/block layout and is Classic-reader compatible in SL1, which makes it the migration path for an existing Classic estate and for single-application deployments at volume. MIFARE DESFire uses an application/file system with per-file access rights linked to application keys, which suits a new build carrying several independent applications. See our MIFARE DESFire cards page once the family is chosen.

Is MIFARE Plus SL3 as secure as DESFire for AES?

Both use AES-128 authentication with protected communication over ISO/IEC 14443-4. The differences are structural — Plus uses sector-based memory with per-sector keys, while DESFire uses a file system with per-application key sets — and in the specific hardware certification each generation carries (current Plus EV1/EV2 and DESFire EV2/EV3 both reach Common Criteria EAL5+). Confirm the specific certification your procurement requires from the buyer's own information-security document rather than assuming a level.

Can MIFARE Plus and DESFire cards run on the same readers?

Yes, with readers whose firmware implements both command sets. Plus SL1 needs Classic-compatible readers, while Plus SL3 and DESFire both need ISO/IEC 14443-4 (T=CL) with the relevant AES command set. Confirm the reader firmware supports both families before issuing a mixed fleet, and test enrolment and a full transaction on samples.

Buyer guides

Ready to specify your order?

Send the product, quantity and application so we can confirm the options and pricing for your project.

Prefer to message us? WhatsApp or email about this product.

Get a quote WhatsApp
WhatsApp