808bits

NITROXIII CNN35XX-NFBE HSM Family

FIPS 140-2 certificate #2495 · Marvell Semiconductor, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2495
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorMarvell Semiconductor, Inc. · website
Hardware versionsP/Ns CNL3560P-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNL3560P-NFBE-2.0-G [6, 7, 8], CNL3560P-NFBE-3.0-G [6, 7, 8], CNL3560B-NFBE-2.0-G [6, 7, 8], CNL3560B-NFBE-3.0-G [6, 7, 8], CNL3560-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNL3560-NFBE-2.0-G [6, 7, 8], CNL3560-NFBE-3.0-G [6, 7, 8], CNL3560A-NFBE-3.0-G [6, 7, 8], CNL3560C-NFBE-3.0-G [6, 7, 8], CNL3560D-NFBE-3.0-G [6, 7, 8], CNL3560E-NFBE-3.0-G [6, 7, 8], CNL3560F-NFBE-3.0-G [6, 7, 8], CNL3530-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNL3530-NFBE-2.0-G [6, 7, 8], CNL3530-NFBE-3.0-G [6, 7, 8], CNL3530B-NFBE-2.0-G [6, 7, 8], CNL3530B-NFBE-3.0-G [6, 7, 8], CNL3530A-NFBE-3.0-G [6, 7, 8], CNL3530C-NFBE-3.0-G [6, 7, 8], CNL3530D-NFBE-3.0-G [6, 7, 8], CNL3530E-NFBE-3.0-G [6, 7, 8], CNL3530F-NFBE-3.0-G [6, 7, 8], CNL3510-NFBE-G [1, 2, 3, 4, 5, 6, 7, 8], CNL3510-NFBE-2.0-G [6, 7, 8], CNL3510-NFBE-3.0-G [6, 7, 8], CNL3510P-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNL3510P-NFBE-2.0-G [6, 7, 8], CNL3510P-NFBE-3.0-G [6, 7, 8], CNL3510A-NFBE-3.0-G [6, 7, 8], CNL3510C-NFBE-3.0-G [6, 7, 8], CNL3510D-NFBE-3.0-G [6, 7, 8], CNL3510E-NFBE-3.0-G [6, 7, 8], CNL3510F-NFBE-3.0-G [6, 7, 8], CNN3560P-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNN3560P-NFBE-2.0-G [6, 7, 8], CNN3560P-NFBE-3.0-G [6, 7, 8], CNN3560-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNN3560-NFBE-2.0-G [6, 7, 8], CNN3560-NFBE-3.0-G [6, 7, 8], CNN3560A-NFBE-3.0-G [6, 7, 8], CNN3560C-NFBE-3.0-G [6, 7, 8], CNN3560D-NFBE-3.0-G [6, 7, 8], CNN3560E-NFBE-3.0-G [6, 7, 8], CNN3560F-NFBE-3.0-G [6, 7, 8], CNN3530-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNN3530-NFBE-2.0-G [6, 7, 8], CNN3530-NFBE-3.0-G [6, 7, 8], CNN3530A-NFBE-3.0-G [6, 7, 8], CNN3530C-NFBE-3.0-G [6, 7, 8], CNN3530D-NFBE-3.0-G [6, 7, 8], CNN3530E-NFBE-3.0-G [6, 7, 8], CNN3530F-NFBE-3.0-G [6, 7, 8], CNN3510-NFBE-G [1 ,2, 3, 4, 5, 6, 7, 8], CNN3510-NFBE-2.0-G [6, 7, 8], CNN3510-NFBE-3.0-G [6, 7, 8], CNN3510A-NFBE-3.0-G [6, 7, 8], CNN3510C-NFBE-3.0-G [6, 7, 8], CNN3510D-NFBE-3.0-G [6, 7, 8], CNN3510E-NFBE-3.0-G [6, 7, 8], CNN3510F-NFBE-3.0-G [6, 7, 8], CNN3510LP-NFBE-2.0-G [6, 7, 8], CNN3510LP-NFBE-3.0-G [6, 7, 8], CNN3510LPB-NFBE-2.0-G [6, 7, 8], CNN3510LPB-NFBE-3.0-G [6, 7, 8], CNN3510LPA-NFBE-3.0-G [6, 7, 8], CNN3510LPC-NFBE-3.0-G [6, 7, 8], CNN3510LPD-NFBE-3.0-G [6, 7, 8], CNN3510LPE-NFBE-3.0-G [6, 7, 8], CNN3510LPF-NFBE-3.0-G [6, 7, 8], CNN3505LP-NFBE-2.0-G [6, 7, 8], CNN3505LP-NFBE-3.0-G [6, 7, 8], CNN3505LPA-NFBE-3.0-G [6, 7, 8],CNN3505LPC-NFBE-3.0-G [6, 7, 8], CNN3505LPD-NFBE-3.0-G [6, 7, 8], CNN3505LPE-NFBE-3.0-G [6, 7, 8] and CNN3505LPF-NFBE-3.0-G [6, 7, 8]
Firmware versionsCNN35XX-NFBE-FW-1.0 build 35 [1], CNN35XX-NFBE-FW-1.0 build 38 [2], CNN35XX-NFBE-FW-1.0 build 39 [3], CNN35XX-NFBE-FW-1.0 build 44 [4], CNN35XX-NFBE-FW-1.0 build 48 [5], CNN35XX-NFBE-FW-1.0 build 51 [6], CNN35XX-NFBE-FW-1.0 build 52 [7] or CNN35XX-NFBE-FW-1.0 build 58 [8]

Module description

CNN35XX-NFBE HSM Family is a high performance purpose built solution for key management and crypto acceleration compliance to FIPS 140-2. The module supports flexible key store that can be partitioned up to 32 individually managed and isolated partitions. This is a SRIOV capable PCIe adapter and can be used in virtualization environment to extend services like virtual key management, crypto and TLS offloads to VMs in dedicated I/O channels. This product is suitable for PKI vendors, SSL servers/load balancers.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2033, 2034, 2035, 3205, 3206
CVL167, 563
DRBG680
DSA916
ECDSA589
HMAC1233, 2019
KAS53
KASvendor affirmed
KBKDF65
KTS
RSA1634
SHS1780, 2652
Triple-DES1311

Other algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength); MD5; RC4; PBE

Tested configurations

  • N/A

Validation history

DateTypeLab
2015-12-15InitialUL Verification Services, Inc.
2016-02-23UpdateUL Verification Services, Inc.
2016-06-03UpdateUL Verification Services, Inc.
2016-08-19UpdateUL Verification Services, Inc.
2017-09-15UpdateUL Verification Services, Inc.
2017-11-09UpdateUL Verification Services, Inc.
2017-11-17UpdateUL Verification Services, Inc.
2017-12-11UpdateUL Verification Services, Inc.
2019-04-02UpdateUL Verification Services, Inc.
2020-09-30UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2015-12-15, 2016-02-23, 2016-06-03, 2016-08-19, 2017-09-15, 2017-11-09, 2017-11-17, 2017-12-11, 2019-04-02, 2020-09-30

Source documents