808bits

DocuSign HSM Appliance

FIPS 140-2 certificate #2860 · DocuSign, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #1883. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. This module contains the embedded module eToken 5105 validated to FIPS 140-2 under Cert. #1883 operating in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2860
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorDocuSign, Inc. · website
Hardware versions5.0
Firmware versions5.0.0, 5.0.2 and 5.0.3

Module description

DocuSign HSM Appliance is a high-performance cryptographic service provider. It performs high-speed cryptographic operations while protecting sensitive data. Its features include Triple-DES, AES, Triple-DES MAC, CCM, HMAC, RSA, ECDSA, SHA-1, SHA-256, SHA-384, SHA-512, public key database and certificate support, authenticated and encrypted communication with the module, secure storage of secret/private keys, software key medium and smartcard support, tamper-responsive enclosure, high level API requiring no cryptographic expertise, in-depth logging and auditing, and secure backup capabilities.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4029, 4031, 4640, 4641, 5283, 5284
CVL857, 1039, 1296, 1297, 1745, 1746
DRBG98, 1205, 1565, 2030
ECDSA900, 1143, 1378
HMAC2630, 2632, 3073, 3074, 3490, 3491
KTS
RSA2069, 2533, 2822
SHS1465, 3325, 3326, 3804, 3805, 4242, 4243
Triple-DES2207, 2469, 2669
Triple-DES MACvendor affirmed

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-03-08InitialCYGNACOM SOLUTIONS INC
2017-10-03UpdateCYGNACOM SOLUTIONS INC
2018-04-10UpdateCYGNACOM SOLUTIONS INC

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-03-08, 2017-10-03, 2018-04-10

Source documents