HID 13.56 MHz credential family

HID iCLASS SE, SR & Seos: The Credential Family Explained

HID iCLASS SE, iCLASS SR and Seos are three tiers of HID Global's modern 13.56 MHz credential family, all built on the Secure Identity Object (SIO) data model and AES-128 cryptography. iCLASS SE is the platform, iCLASS SR is the dual-technology migration card, and Seos is the highest-assurance credential that also runs on phones.

Last updated 2026-07-29

What is the HID iCLASS SE / SR / Seos family?

The HID iCLASS SE, iCLASS SR, and Seos family is HID Global's set of modern 13.56 MHz credentials that replaced the original iCLASS generation. They are not three unrelated products — they are tiers of one architecture, all built on the Secure Identity Object (SIO) data model and protected by AES-128 cryptography rather than the proprietary cipher used by legacy iCLASS.

Read them as a ladder. iCLASS SE is the platform and the workhorse card. iCLASS SR is the dual-technology card that bridges a legacy-to-SE migration. Seos sits at the top as the device-independent, highest-assurance credential that runs identically on a card, a fob, or a smartphone. Choosing between them is mostly a question of how far along a migration a site is and whether phone-based access is needed.

How do iCLASS SE, iCLASS SR and Seos differ?

The three members of the HID iCLASS SE / SR / Seos family share a data model but play different roles. This map compares each by its job, its cryptography, the form factors it runs on, and whether any third party can supply a compatible card.

Family memberPrimary roleCryptographyRuns onThird-party card?
iCLASS SECurrent platform cardAES-128, SIO, diversified keysCard, fobNo — integrator only
iCLASS SRLegacy-to-SE migration bridgeLegacy iCLASS + AES-128 SIOCardNo — via HID
SeosHighest-assurance, mobile-readyAES-128, device-independentCard, fob, phoneNo — HID channel

What ties the family together — the SIO data model?

The common thread across the HID iCLASS SE / SR / Seos family is the Secure Identity Object (SIO): an encrypted, digitally-signed data container that holds the credential and is bound to a site's keys. Because identity lives in the SIO rather than in a fixed chip serial, the same protected object can be issued to a card, a fob, or a phone without weakening it.

HID's Seos credential datasheet describes this model as securing data with "a wrapper that provides key diversification, authentication signatures, and AES-128 based encryption," using a "mutual authentication protocol with generation of diversified session key" and defaulting to a random 4-byte identifier so a card cannot be tracked by a fixed number. That SIO layer is what every member of the family has in common, and it is why none of them is copyable like a proximity card.

How do I tell which HID credential my site uses?

Most sites cannot tell an iCLASS SE card from a legacy iCLASS or Seos card by looking — the plastic is usually identical. The reliable answer comes from the credential-management records or the integrator who programmed the system, because the difference is in the keys and data model, not the printing. If the site was deployed or upgraded after the mid-2010s and uses HID Signo or multiCLASS SE readers, it is likely on iCLASS SE or Seos.

This matters for ordering: legacy iCLASS, iCLASS SE, iCLASS SR, and Seos are not interchangeable at the credential level, and none of the modern members can be duplicated by a third party. Confirming which credential a site runs — through HID or your integrator — before ordering avoids buying cards that will not enroll.

Which readers run the whole family?

HID Signo and multiCLASS SE readers are the hardware that ties the HID iCLASS SE / SR / Seos family together at the door. Both read iCLASS SE, iCLASS SR, and Seos, and multi-technology versions also read legacy iCLASS and 125 kHz proximity at the same reader. That is what makes a phased migration possible: a site can install Signo or multiCLASS SE readers, keep every existing credential working, then move users up the family tier by tier.

The typical end-state is Seos, because it moves security from any fixed number to an AES-128 credential that also works as a phone-based mobile credential. The readers do not need to change again once they are Signo or multiCLASS SE, only the credentials do.

Where legacy 125 kHz proximity still fits during migration

Across the HID iCLASS SE / SR / Seos family, one thing does not change: none of these modern credentials can be sourced from a third-party card maker, so additional iCLASS SE, SR, or Seos cards come from HID or your integrator. What Security ID Systems can supply is the open 125 kHz proximity formats that most sites still run somewhere during an HID migration — on gates, parking, or older doors that have not been cut over yet.

Those open proximity formats we encode as fully compatible credentials that read identically on your existing readers. They are the practical companion to an HID upgrade, covering the doors that are still on proximity while the secure 13.56 MHz rollout finishes.

Compatible formats we do supply

None of the HID iCLASS SE / SR / Seos family can be sourced from a third party — but the 125 kHz proximity formats most sites still run during a migration are ones we encode as fully compatible credentials.

Sources & references

HID Global and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

HID iCLASS SE / SR / Seos family — common questions

Is iCLASS SE the same as Seos?

No. Both belong to HID's modern family and both use the Secure Identity Object (SIO) model and AES-128, but iCLASS SE is the platform-generation card that replaced legacy iCLASS, while Seos is the highest-assurance, device-independent credential that also runs on phones and wearables. Seos is usually the end-state of an HID migration.

Which is more secure, iCLASS SE or Seos?

Both use AES-128 and the SIO data model, and neither has a publicly documented cryptographic break. Seos is positioned as the highest-assurance tier because it is device-independent and mobile-ready, but for a physical card at a door, iCLASS SE and Seos both defeat the copy-the-number attack that breaks 125 kHz proximity cards.

How do I know if my cards are iCLASS SE, SR or Seos?

Usually you cannot tell by looking, because the plastic is identical. Check your credential-management records or ask the integrator who programmed the system — the difference is in the keys and data model, not the printing. Sites on HID Signo or multiCLASS SE readers are typically running iCLASS SE or Seos.

Can any of the HID family be cloned?

No third party can clone iCLASS SE, iCLASS SR, or Seos. All three store identity in an encrypted, signed Secure Identity Object bound to site keys and use AES-128 mutual authentication, with no published break. Only the legacy iCLASS generation, whose proprietary cipher was published in 2012, is considered clone-vulnerable.

Do I need new readers to move from iCLASS SE to Seos?

Usually no. HID Signo and multiCLASS SE readers already support iCLASS SE, iCLASS SR, and Seos, so a site on those readers can move users up to Seos by re-issuing credentials rather than swapping hardware. Confirm your specific reader model and firmware with HID or your integrator.