If you do it right (store the cert in a TPM) the device itself actually is a second factor so you don't need anything other than the device.
Wouldn't that require a browser plugin to login with?
You can have a SSO server that requires a TLS client certificate signed by your own internal CA, or you could put it behind a VPN authenticated with the certificate. Either way, with no custom software, you get device and use authentication.