Our Security Certifications
Our commitment to delivering secure, reliable, and quality Hardware Security Modules (HSM) is reflected in our compliance with the industry's most stringent certifications.
FIPS Validation
FIPS 140-3 is the latest iteration for validating the effectiveness of cryptographic hardware. It aligns with international ISO/IEC 19790. This certification indicates that our HSMs have strong physical security, controlled access, and robust key management practices, making it suitable for protecting sensitive information in various applications. Learn more on the NIST website.
- FIPS 140-2 Level 3: Certificate 4583 | Certificate 3430
- FIPS 140-3 Level 3 (certification in process) - view the implementation under test list.
Securosys obtained its FIPS140-2 L3 certification in April 2019. The current certification was renewed in December 2019 and is currently sunsetting due to the transition to FIPS140-3, which is under process since May 2023. The certificate remains valid but has not been updated to reflect the latest guidance and standards. Learn more.
Cryptographic Algorithm Validation Program (CAVP)
This certification confirms that cryptographic algorithms and helper functions are implemented correctly according to stringent standards set by NIST and U.S. federal regulations. By validating aspects like key scheduling and function compliance, CAVP ensures that algorithms can securely manage encryption, key handling, and cryptographic operations, supporting high security standards for sensitive data.
- Explore the detailed algorithm certificates.
Common Criteria EAL4+ Certification
The Common Criteria (CC) certification refers to Protection Profiles (PP) for IT products, which specify generic security requirements for a product category. These profiles are implementation-independent but can be tailored to a specific Target of Evaluation (TOE) by the security target that can be derived from the product.
- Certification EAL4+ in conformance to PP EN 419221-5
- QSCD conformance to Regulation EU No: 910/2014 (eIDAS )
- Certification CC EN419221-5 - this certification is re-evaluated and QSCD evaluation according to EN 419 241-2
Our current certification is valid until April 14, 2026.
ISO/IEC 27001
Securosys CloudHSM service has achieved ISO/IEC 27001 certification, confirming that the team managing the service adheres to strict information-security practices. Additionally, all data centers hosting CloudHSM instances meet or exceed Tier-3 standards, providing high levels of physical security and infrastructure resilience.
About CloudHSM
CloudHSM is built upon Securosys' Primus HSM devices, which are rigorously tested and certified to meet the highest security standards. Primus HSMs comply with FIPS 140-2 Level 3, and are Common Criteria EAL4+ certified.
As mentioned above, Securosys CloudHSM uses real Hardware Security Modules which are also Common Criteria EAL4+ certified and comply with EN 419 221-5. This ensures compliance with the strict requirements for Qualified Electronic Signature (QSCD) and Seal Creation Device (QSealCD) as well as SCAL2 compliance according to EU regulation 910/2014, normed in EN 419-241-2. To read more about CloudHSM certification, click here.