808bits

nShield F2 500+, nShield F2 1500+ and nShield F2 6000+

FIPS 140-2 certificate #2643 · nCipher Security Limited · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized to Overall Level 2 per Security Policy. The protocol TLS shall not be used when operated in FIPS mode

Certificate

Certificate number2643
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
VendornCipher Security Limited · website
Hardware versionsnC3423E-500, nC3423E-1K5 and nC3423E-6K0, Build Standard N
Firmware versions2.61.2-2 and 2.62.1-2

Module description

The nShield modules: nShield F2 500+, nShield F2 1500+, nShield F2 6000+ are tamper evident and tamper responsive Hardware Security Modules which provide support for the widest range of cryptographic algorithms, application programming interfaces (APIs) and host operating systems, enabling the devices to be used with virtually any business application. The units are identical in operation and only vary in the processing speed.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3420, 3446
CVL516, 532
DRBG825
DSA964
ECDSA695
HMAC2178
KBKDF56
KTS
RSA1752
SHS2826
Triple-DES1931
Triple-DES MACvendor affirmed

Other algorithms

ARC4; Aria; Camellia; CAST-256; DES; Diffie-Hellman (CVL Cert. #516, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #532, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); ECMQV (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); El-Gamal; HAS-160; HMAC-MD5; HMAC-RIPEMD160; HMAC-Tiger; KCDSA; MD5; NDRNG; RIPEMD-160; RSA (encrypt/decrypt); RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); SEED; Tiger; TLS KDF (non-compliant); Triple-DES (key wrapping; non-compliant)

Tested configurations

  • N/A

Validation history

DateTypeLab
2016-05-13InitialDXC Technology
2018-06-20UpdateDXC Technology
2018-07-27UpdateDXC Technology
2019-06-03UpdateDXC Technology

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-05-13, 2018-06-20, 2018-07-27, 2019-06-03

Source documents