JaCarta-2 PKI/GOST by Aladdin-RD is designed for electronic signature and authentication using modern Russian and foreign cryptographic algorithms. It includes certified USB tokens and smart cards supporting both foreign cryptographic algorithms and domestic algorithms GOST R 34.10-2012 and GOST R 34.11-2012 for enhanced qualified electronic signatures and strict two-factor user authentication. JaCarta-2 PKI/GOST ensures the integrity and confidentiality of transmitted data through encryption and message authentication according to GOST 28147-89. It securely stores user data and objects (passwords, digital certificates, key containers of popular software cryptographic tools) in proprietary secure non-volatile memory (EEPROM). The devices are available in two form factors: USB token (in Nano and XL cases) and smart card (black plastic, chip with palladium contacts). The XL USB token and smart cards can integrate passive RFID tags for physical access control, allowing use with access control systems, contactless electronic turnstiles, and personnel time tracking systems that support RFID tags. JaCarta-2 PKI/GOST is designed for use in various automated systems (EGAIS, ASU TP, etc.), including M2M, IoT, and others, and has an increased resource for the number of write cycles in EEPROM memory and electronic signature operations. Specifically, the number of electronic signature generation operations is at least 10 million. The signing speed for large documents is significantly improved, as the hash function computation is performed by the software library on the host side at the main processor's speed, rather than on the device's microcontroller. The computed value of the hash function for generating the electronic signature is transmitted to the device via a secure channel. JaCarta-2 PKI/GOST provides new recovery mechanisms: self-unlocking (PUK code) and remote unlocking by the Administrator. It also includes new protection mechanisms against attacks and blocking, with the Administrator PIN code replaced by a security administrator key. The devices are certified according to new requirements of the FSB of Russia, making them functionally complete and cryptographically secure. The certified cryptographic protection means (electronic signature tool) is intended for legitimate and secure integration into application, system, and embedded software and hardware. The devices are designed as secure and are built on the basis of secure smart card chips (Secure Element). Encryption keys are not stored in the device's memory, making it useless to hack. The use of Java Card technology allows for the addition of necessary functionality to JaCarta-2 PKI/GOST devices without the need for re-certification of the cryptographic module with the FSB of Russia.