808bits

DocuSign Signature Appliance

FIPS 140-2 certificate #3518 · DocuSign, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. This module contains the embedded module eToken 5105 validated to FIPS 140-2 under Cert. #1883 operating in FIPS mode. No assurance of the minimum strength of generated keys

Certificate

Certificate number3518
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorDocuSign, Inc. · website
Hardware versions8.0
Firmware versions9.0.9.10

Module description

The DocuSign Signature Appliance is a digital signature appliance that is connected to the organizational network and manages all signature keys and certificates of organization's end-users. End-users will connect securely to the appliance from their PC for the purpose of signing documents and data. The DocuSign Signature Appliance also enables organization using AES based encryption keys for encrypting/decrypting data.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC85, C86
CKGvendor affirmed
CVLC86
DRBG98, C85
HMACC85, C86
KTS
KTS
PBKDFvendor affirmed
RSAC85, C86
SHS1465, C85, C86
Triple-DESC85
Triple-DES MACvendor affirmed

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength); Triple-DES (Cert. #C85, key unwrapping)

Tested configurations

  • N/A

Validation history

DateTypeLab
2019-09-05InitialCYGNACOM SOLUTIONS INC

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-09-05

Source documents