QNSI

Standards & programs

What is FIPS 140-3?

NIST standard for cryptographic MODULE validation (CMVP). Distinct from FIPS 203/204/205, which standardize ALGORITHMS. 8 connector implementations - 6 via PKCS#11 (AWS CloudHSM · Azure Dedicated HSM · Thales Luna · Entrust nShield · Utimaco CryptoServer · Marvell LiquidSecurity) and 2 via REST API (HashiCorp Vault Transit · Fortanix DSM). The generic PKCS#11 path is verified with SoftHSM, the Vault REST path is verified with a live Vault backend, and QNSI's shipped provider plus HSPK custody path are proven on AWS CloudHSM hsm2m.medium in FIPS mode. Named hardware is enabled only after per-deployment qualification. AWS CloudHSM can provide FIPS 140-3 Level 3 custody under Marvell Semiconductor, Inc.'s certificate #4703 only after the customer provisions and QNSI qualifies that service for the deployment. Native-PQC HSM and cloud-KMS products now exist; their algorithms, firmware, and validation scope vary. QNSI's current HSPK API supports ML-DSA-44/65/87 as a software signing compatibility path rooted in qualified HSM custody, while QNSI's 90-algorithm catalog is a broader software migration and interoperability surface.

Decision context

Why FIPS 140-3 matters

FIPS 140-3 evaluates cryptographic modules and their security boundaries, roles, services and operational requirements. It answers a different question from FIPS 203, 204 and 205, which specify post-quantum algorithms. Buyers need both scopes stated precisely to avoid implying nonexistent certification.

How to evaluate FIPS 140-3

Request the CMVP certificate number, module name, version, validated operational environment, security policy and algorithm certificates. Confirm that the deployed binary and mode fall within that boundary. A cloud provider, HSM family or library name is insufficient when the selected version or configuration differs.

Standards & programs

Standards & programs evidence boundary

Standards define algorithms, testing methods, transition expectations, or regulatory obligations; they do not automatically certify a product or deployment. Confirm the exact publication, version, scope, implementation evidence, and accountable assessment route before describing a system as compliant or validated.

FAQ

Common questions

What is FIPS 140-3?

NIST standard for cryptographic MODULE validation (CMVP). Distinct from FIPS 203/204/205, which standardize ALGORITHMS. 8 connector implementations - 6 via PKCS#11 (AWS CloudHSM · Azure Dedicated HSM · Thales Luna · Entrust nShield · Utimaco CryptoServer · Marvell LiquidSecurity) and 2 via REST API (HashiCorp Vault Transit · Fortanix DSM). The generic PKCS#11 path is verified with SoftHSM, the Vault REST path is verified with a live Vault backend, and QNSI's shipped provider plus HSPK custody path are proven on AWS CloudHSM hsm2m.medium in FIPS mode. Named hardware is enabled only after per-deployment qualification. AWS CloudHSM can provide FIPS 140-3 Level 3 custody under Marvell Semiconductor, Inc.'s certificate #4703 only after the customer provisions and QNSI qualifies that service for the deployment. Native-PQC HSM and cloud-KMS products now exist; their algorithms, firmware, and validation scope vary. QNSI's current HSPK API supports ML-DSA-44/65/87 as a software signing compatibility path rooted in qualified HSM custody, while QNSI's 90-algorithm catalog is a broader software migration and interoperability surface.

Why does FIPS 140-3 matter?

FIPS 140-3 evaluates cryptographic modules and their security boundaries, roles, services and operational requirements. It answers a different question from FIPS 203, 204 and 205, which specify post-quantum algorithms. Buyers need both scopes stated precisely to avoid implying nonexistent certification.

How should FIPS 140-3 be evaluated?

Request the CMVP certificate number, module name, version, validated operational environment, security policy and algorithm certificates. Confirm that the deployed binary and mode fall within that boundary. A cloud provider, HSM family or library name is insufficient when the selected version or configuration differs.

More

Keep exploring

QNSI privacy choices

Necessary storage keeps the site secure. With your permission, privacy-bounded analytics help HEOSSI understand pages, journeys, and campaign outcomes. No advertising profiles are created.

Cookie policy