Standards & programs
What is FIPS 140-3?
NIST standard for cryptographic MODULE validation (CMVP). Distinct from FIPS 203/204/205, which standardize ALGORITHMS. 8 connector implementations - 6 via PKCS#11 (AWS CloudHSM · Azure Dedicated HSM · Thales Luna · Entrust nShield · Utimaco CryptoServer · Marvell LiquidSecurity) and 2 via REST API (HashiCorp Vault Transit · Fortanix DSM). The generic PKCS#11 path is verified with SoftHSM, the Vault REST path is verified with a live Vault backend, and QNSI's shipped provider plus HSPK custody path are proven on AWS CloudHSM hsm2m.medium in FIPS mode. Named hardware is enabled only after per-deployment qualification. AWS CloudHSM can provide FIPS 140-3 Level 3 custody under Marvell Semiconductor, Inc.'s certificate #4703 only after the customer provisions and QNSI qualifies that service for the deployment. Native-PQC HSM and cloud-KMS products now exist; their algorithms, firmware, and validation scope vary. QNSI's current HSPK API supports ML-DSA-44/65/87 as a software signing compatibility path rooted in qualified HSM custody, while QNSI's 87-algorithm catalog is a broader software migration and interoperability surface.
Decision context
Why FIPS 140-3 matters
FIPS 140-3 evaluates cryptographic modules and their security boundaries, roles, services and operational requirements. It answers a different question from FIPS 203, 204 and 205, which specify post-quantum algorithms. Buyers need both scopes stated precisely to avoid implying nonexistent certification.
How to evaluate FIPS 140-3
Request the CMVP certificate number, module name, version, validated operational environment, security policy and algorithm certificates. Confirm that the deployed binary and mode fall within that boundary. A cloud provider, HSM family or library name is insufficient when the selected version or configuration differs.
Standards & programs
Standards & programs evidence boundary
Standards define algorithms, testing methods, transition expectations, or regulatory obligations; they do not automatically certify a product or deployment. Confirm the exact publication, version, scope, implementation evidence, and accountable assessment route before describing a system as compliant or validated.
FAQ
Common questions
What is FIPS 140-3?
NIST standard for cryptographic MODULE validation (CMVP). Distinct from FIPS 203/204/205, which standardize ALGORITHMS. 8 connector implementations - 6 via PKCS#11 (AWS CloudHSM · Azure Dedicated HSM · Thales Luna · Entrust nShield · Utimaco CryptoServer · Marvell LiquidSecurity) and 2 via REST API (HashiCorp Vault Transit · Fortanix DSM). The generic PKCS#11 path is verified with SoftHSM, the Vault REST path is verified with a live Vault backend, and QNSI's shipped provider plus HSPK custody path are proven on AWS CloudHSM hsm2m.medium in FIPS mode. Named hardware is enabled only after per-deployment qualification. AWS CloudHSM can provide FIPS 140-3 Level 3 custody under Marvell Semiconductor, Inc.'s certificate #4703 only after the customer provisions and QNSI qualifies that service for the deployment. Native-PQC HSM and cloud-KMS products now exist; their algorithms, firmware, and validation scope vary. QNSI's current HSPK API supports ML-DSA-44/65/87 as a software signing compatibility path rooted in qualified HSM custody, while QNSI's 87-algorithm catalog is a broader software migration and interoperability surface.
Why does FIPS 140-3 matter?
FIPS 140-3 evaluates cryptographic modules and their security boundaries, roles, services and operational requirements. It answers a different question from FIPS 203, 204 and 205, which specify post-quantum algorithms. Buyers need both scopes stated precisely to avoid implying nonexistent certification.
How should FIPS 140-3 be evaluated?
Request the CMVP certificate number, module name, version, validated operational environment, security policy and algorithm certificates. Confirm that the deployed binary and mode fall within that boundary. A cloud provider, HSM family or library name is insufficient when the selected version or configuration differs.
More