808bits

nShield Connect 6000 [1], nShield Connect 1500 [2] and nShield Connect 500 [3]

FIPS 140-2 certificate #1571 · Thales - nCipher · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with nShield PCIe validated to FIPS 140-2 under Cert. #1063

Certificate

Certificate number1571
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-chip standalone
VendorThales - nCipher · website
Hardware versionsNH2047 [1], NH2040 [2] and NH2033 [3], Build Standard N
Firmware versionsV11.30

Module description

The Thales nShield Connect is a network-attached hardware security module for business continuity of always-on, mission-critical systems in shared infrastructures, providing high availability, scalability and remote management for cryptographic infrastructures. Part of the nCipher product line, nShield Connect is the world's first HSM with redundant, hot-swappable power supplies, and enables organizations to build reliable, large-scale cryptographic services for their infrastructures.

Approved algorithms

AlgorithmCAVP certificate
AES397, 754, 1227
AES GCM754
DSA280, 407
ECDSA81, 145
HMAC410, 717
RNG436, 681
RSA356
SHS764, 1127
Triple-DES435, 666, 883
Triple-DES MACvendor affirmed

Other algorithms

Aria; Arc Four; Camellia; CAST 6; DES; MD5; SEED; HMAC-MD5, HMAC-Tiger, HMAC-RIPEMD160; RIPEMD 160; Tiger; El-Gamal; KCDSA; HAS 160; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 192 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); ECMQV (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2011-07-13InitialCYGNACOM SOLUTIONS INC

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2011-07-13

Source documents