808bits

NITROXIII CNN35XX-NFBE HSM Family

FIPS 140-2 certificate #3254 · Marvell Semiconductor, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized and configured per Section 10 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3254
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorMarvell Semiconductor, Inc. · website
Hardware versionsP/Ns CNL3560P-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNL3560P-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3560P-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3560B-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3560B-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3560-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNL3560-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3560-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3560A-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3560C-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3560D-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3560E-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3560F-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3530-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNL3530-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3530-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3530B-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3530B-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3530A-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3530C-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3530D-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3530E-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3530F-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3510-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNL3510-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3510-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3510B-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3510P-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNL3510P-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3510P-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3510PB-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3560PB-NFBE-2.0-G [1, 2, 3, 4, 7], CNL3510A-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3510C-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3510D-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3510E-NFBE-3.0-G [1, 2, 3, 4, 7], CNL3510F-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3560P-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNN3560P-NFBE-2.0-G [1, 2, 3, 4, 7], CNN3560P-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3560-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNN3560-NFBE-2.0-G [1, 2, 3, 4, 7], CNN3560-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3560A-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3560C-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3560D-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3560E-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3560F-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3530-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNN3530-NFBE-2.0-G [1, 2, 3, 4, 7], CNN3530-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3530A-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3530C-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3530D-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3530E-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3530F-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510-NFBE-G [1, 2, 3, 4, 5, 6, 7], CNN3510-NFBE-2.0-G [1, 2, 3, 4, 7], CNN3510-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510A-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510C-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510D-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510E-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510F-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510LP-NFBE-2.0-G [1, 2, 3, 4, 7], CNN3510LP-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510LPB-NFBE-2.0-G [1, 2, 3, 4, 7], CNN3510LPB-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510LPA-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510LPC-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510LPD-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510LPE-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3510LPF-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3505LP-NFBE-2.0-G [1, 2, 3, 4, 7], CNN3505LP-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3505LPA-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3505LPC-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3505LPD-NFBE-3.0-G [1, 2, 3, 4, 7], CNN3505LPE-NFBE-3.0-G [1, 2, 3, 4, 7] and CNN3505LPF-NFBE-3.0-G [1, 2, 3, 4, 7]
Firmware versionsCNN35XX-NFBE-FW-2.04 build 48 [1], CNN35XX-NFBE-FW-2.04 build 49 [2], CNN35XX-NFBE-FW-2.04 build 50 [3], CNN35XX-NFBE-FW-2.04 build 52 [4], CNN35XX-NFBE-FW-2.05 build 15 [5], CNN35XX-NFBE-FW-2.05 build 18 [6] and CNN35XX-NFBE-FW-2.05 build 16 [7]

Module description

CNN35XX-NFBE HSM Family is a high performance purpose built solution for key management and crypto acceleration compliance to FIPS 140-2. The module supports flexible key store that can be partitioned up to 32 individually managed and isolated partitions. This is a SRIOV capable PCIe adapter and can be used in a virtualization environment to extend services like virtual key management, crypto and TLS offloads to VMs in dedicated I/O channels. This product is suitable for PKI vendors, SSL servers/load balancers.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2033, 2034, 2035, 3205, 3206, 4104
CKGvendor affirmed
CVL167, 563
DRBG680
DSA916
ECDSA589
HMAC1233, 2019
KAS53
KASvendor affirmed
KBKDF65
KTS
KTS
KTS
KTS
RSA1634, 2218
RSA1634
SHS1780, 2652
Triple-DES1311, 2242

Allowed algorithms

EC Curve Secp256k1; EC Diffie-Hellman (CVL Certs. #167 and #563, key agreement; key establishment methodology provides 128 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-08-02InitialUL Verification Services, Inc.
2018-08-17UpdateUL Verification Services, Inc.
2018-10-09UpdateUL Verification Services, Inc.
2019-01-30UpdateUL Verification Services, Inc.
2019-04-02UpdateUL Verification Services, Inc.
2019-06-13UpdateUL Verification Services, Inc.
2019-07-15UpdateUL Verification Services, Inc.
2019-07-18UpdateUL Verification Services, Inc.
2019-08-12UpdateUL Verification Services, Inc.
2019-11-18UpdateUL Verification Services, Inc.
2020-07-01UpdateUL Verification Services, Inc.
2020-07-10UpdateUL Verification Services, Inc.
2020-12-01UpdateUL Verification Services, Inc.
2021-07-06UpdateUL Verification Services, Inc.
2021-07-09UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-08-02, 2018-08-17, 2018-10-09, 2019-01-30, 2019-04-02, 2019-06-13, 2019-07-15, 2019-07-18, 2019-08-12, 2019-11-18, 2020-07-01, 2020-07-10, 2020-12-01, 2021-07-06, 2021-07-09

Source documents