QNSI

Standards & programs

What is FIPS 140-3?

NIST standard for cryptographic MODULE validation (CMVP). Distinct from FIPS 203/204/205, which standardize ALGORITHMS. 8 connector implementations - 6 via PKCS#11 (AWS CloudHSM · Azure Dedicated HSM · Thales Luna · Entrust nShield · Utimaco CryptoServer · Marvell LiquidSecurity) and 2 via REST API (HashiCorp Vault Transit · Fortanix DSM). The generic PKCS#11 path is verified with SoftHSM, the Vault REST path is verified with a live Vault backend, and QNSI's shipped provider plus HSPK custody path are proven on AWS CloudHSM hsm2m.medium in FIPS mode. Named hardware is enabled only after per-deployment qualification. AWS CloudHSM can provide FIPS 140-3 Level 3 custody under Marvell Semiconductor, Inc.'s certificate #4703 only after the customer provisions and QNSI qualifies that service for the deployment. Native-PQC HSM and cloud-KMS products now exist; their algorithms, firmware, and validation scope vary. QNSI's current HSPK API supports ML-DSA-44/65/87 as a software signing compatibility path rooted in qualified HSM custody, while QNSI's 87-algorithm catalog is a broader software migration and interoperability surface.

Decision context

Why FIPS 140-3 matters

FIPS 140-3 evaluates cryptographic modules and their security boundaries, roles, services and operational requirements. It answers a different question from FIPS 203, 204 and 205, which specify post-quantum algorithms. Buyers need both scopes stated precisely to avoid implying nonexistent certification.

How to evaluate FIPS 140-3

Request the CMVP certificate number, module name, version, validated operational environment, security policy and algorithm certificates. Confirm that the deployed binary and mode fall within that boundary. A cloud provider, HSM family or library name is insufficient when the selected version or configuration differs.

Standards & programs

Standards & programs evidence boundary

Standards define algorithms, testing methods, transition expectations, or regulatory obligations; they do not automatically certify a product or deployment. Confirm the exact publication, version, scope, implementation evidence, and accountable assessment route before describing a system as compliant or validated.

FAQ

Common questions

What is FIPS 140-3?

NIST standard for cryptographic MODULE validation (CMVP). Distinct from FIPS 203/204/205, which standardize ALGORITHMS. 8 connector implementations - 6 via PKCS#11 (AWS CloudHSM · Azure Dedicated HSM · Thales Luna · Entrust nShield · Utimaco CryptoServer · Marvell LiquidSecurity) and 2 via REST API (HashiCorp Vault Transit · Fortanix DSM). The generic PKCS#11 path is verified with SoftHSM, the Vault REST path is verified with a live Vault backend, and QNSI's shipped provider plus HSPK custody path are proven on AWS CloudHSM hsm2m.medium in FIPS mode. Named hardware is enabled only after per-deployment qualification. AWS CloudHSM can provide FIPS 140-3 Level 3 custody under Marvell Semiconductor, Inc.'s certificate #4703 only after the customer provisions and QNSI qualifies that service for the deployment. Native-PQC HSM and cloud-KMS products now exist; their algorithms, firmware, and validation scope vary. QNSI's current HSPK API supports ML-DSA-44/65/87 as a software signing compatibility path rooted in qualified HSM custody, while QNSI's 87-algorithm catalog is a broader software migration and interoperability surface.

Why does FIPS 140-3 matter?

FIPS 140-3 evaluates cryptographic modules and their security boundaries, roles, services and operational requirements. It answers a different question from FIPS 203, 204 and 205, which specify post-quantum algorithms. Buyers need both scopes stated precisely to avoid implying nonexistent certification.

How should FIPS 140-3 be evaluated?

Request the CMVP certificate number, module name, version, validated operational environment, security policy and algorithm certificates. Confirm that the deployed binary and mode fall within that boundary. A cloud provider, HSM family or library name is insufficient when the selected version or configuration differs.

More

Keep exploring