808bits

Unbound Tech EKM Cryptographic Module

FIPS 140-2 certificate #3453 · Unbound Tech · data as of 2026-09-03

Unbound Tech EKM Cryptographic Module, from Unbound Tech, holds FIPS 140-2 certificate #3453 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with two additional Unbound Tech EKM Cryptographic Modules with each EKM Cryptographic Module running in Entry mode, Pair mode, and Auxiliary mode as specified in Section 3.1 of the Security Policy
This caveat mentions binding. A bound module inherits the earliest sunset of the modules it binds to, so the sunset date above can be optimistic.

Certificate

Certificate number3453
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorUnbound Tech · website
Software versions2.0

Module description

Quoted from the NIST CMVP entry for this certificate.

Unbound's Enterprise Key Management (EKM) lets you manage and control keys working with any application. This pure-software solution is easy to deploy and maintain, while giving you unmatched levels of security and control for your crypto keys in the cloud. Based on Unbound vHSM technology, the keys are guaranteed to never appear in the clear, not even when generated or while at use - ensuring your most sensitive keys are kept private at all times.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3

Approved algorithms (10)

AlgorithmCAVP certificates
AES5443, 5444
CKGvendor affirmed
CVL1884, 1885, 1886, 1887, 1888, 1889
DRBG2126
ECDSA1447, 1448
HMAC3600, 3601
KASvendor affirmed
KTSvendor affirmed
RSA2918, 2919
SHS4362

Allowed algorithms

EC Diffie-Hellman (key agreement; key establishment methodology provides 128 bits of encryption strength); NDRNG; RSA (key unwrapping; key establishment methodology provides 128 bits of encryption strength)

Tested configurations

  • Windows Server version 1803 (2016 version 10.0.17134) running on Intel® i3 on Gigabyte GA-6ISL with PAA (single-user mode)
  • Windows Server version 1803 (2016 version 10.0.17134) running on Intel® i3 on Gigabyte GA-6ISL without PAA

Validation history

DateTypeLab
2019-05-07InitialUL Verification Services, Inc.
2020-04-24UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-05-07, 2020-04-24

Source documents