NIST certificate(s) for HSMs used with Key Vault Managed HSM

Harry, Christopher 20 Reputation points
2024-02-16T14:59:19.0433333+00:00

Per the article here: https://learn.microsoft.com/en-us/azure/key-vault/managed-hsm/overview Managed HSM is using FIPS 140-2 Level 3 HSMs for security. Is it possible to get the NIST certificates for those HSMs? We are in the midst of a project and for audit purposes we need to provide a copy of those certificates stating the hardware is certified for Level 3. Thanks. -Chris

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,455 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Dillon Silzer 57,831 Reputation points Volunteer Moderator
    2024-02-17T20:11:30.8466667+00:00

    Hello Chris,

    I'd recommend to contact fips@microsoft.com with questions.

    Windows FIPS 140 validation

    https://learn.microsoft.com/en-us/windows/security/security-foundations/certification/fips-140-validation#contact

    If this is helpful please accept answer.

    0 comments No comments

  2. Shweta Mathur 30,301 Reputation points Microsoft Employee Moderator
    2024-02-19T07:27:45.4766667+00:00

    Hi @Harry, Christopher , Thanks for reaching out. You can use certificate https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/3718 FIPS 140 Level 3 validated HSMs for safeguarding cryptographic keys for security. Hope this will help.

    Thanks,

    Shweta


    Please remember to "Accept Answer" if answer helped you.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.