# rsa-securid

Source: https://startwithidentity.com/vendors/mfa/rsa-securid/
Last updated: 2026-06-19
License: content by Start with Identity. Cite the source URL.

---

## Overview

RSA SecurID is the original hardware-token MFA, dating to the 1980s, and the hard token with its rotating code is still an icon of two-factor authentication. RSA is now owned by Symphony Technology Group and sells SecurID as a broader access-management suite spanning hardware and software OTP, mobile push, and risk-based authentication. It remains deeply entrenched in government, defense, and banking, where long procurement cycles and on-premises requirements keep legacy deployments running.

## What it is good at

Reliability, maturity, and trust in regulated environments are the strengths. The platform has decades of hardening, deep on-premises and air-gapped deployment options, strong compliance and audit posture, and integrations with the legacy enterprise applications and VPNs that newer vendors often ignore. For organizations that must run authentication inside their own data centers, it is a known, supportable quantity.

## Where it falls short

The heritage is also the weakness. Time-based codes are a shared-secret scheme and are [phishable](https://startwithidentity.com/glossary/phishing-resistant-mfa/); hardware tokens are costly to distribute, replace, and manage. The modern best practice is to migrate from OTP toward [FIDO2/passkey](https://startwithidentity.com/standards/webauthn-fido2/) authenticators. Developer experience and self-service UX trail the modern specialists, and pricing is quote-based and enterprise-weighted.

## Pricing

Quote-based enterprise licensing, with hardware token costs on top of per-user subscription. Model token replacement and seat costs with the [TCO calculator](https://startwithidentity.com/tools/tco-calculator/).

## Best for, and who should look elsewhere

Choose it for federal, defense, and banking environments still standardized on hard tokens or requiring on-premises authentication. Organizations building modern, phishing-resistant access should look at [Yubico](https://startwithidentity.com/vendors/mfa/yubico/) hardware keys, [HYPR](https://startwithidentity.com/vendors/mfa/hypr/) for workforce passwordless, or [Duo](https://startwithidentity.com/vendors/mfa/duo/) for managed cloud MFA. See the [MFA directory](https://startwithidentity.com/vendors/mfa/) and the [how-to-choose guide](https://startwithidentity.com/guides/buyer-guides/how-to-choose-an-mfa-solution/).

## Bottom line

The legacy standard for token-based MFA in regulated, on-premises environments. Plan a migration path to phishing-resistant authenticators.
