808bits

nShield F2 500+ & nShield F2 1500+ & nShield F2 6000+

FIPS 140-2 certificate #3726 · Entrust · data as of 2026-09-03

nShield F2 500+ & nShield F2 1500+ & nShield F2 6000+, from Entrust, holds FIPS 140-2 certificate #3726 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized to Overall Level 2 per Security Policy. The protocol TLS shall not be used when operated in FIPS mode

Certificate

Certificate number3726
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorEntrust · website
Hardware versionsnC3423E-500, nC3423E-1K5 and nC3423E-6K0, Build Standard N
Firmware versions12.50.8

Module description

Quoted from the NIST CMVP entry for this certificate.

The nShield modules: nShield F2 500+ & nShield F2 1500+ & nShield F2 6000+ family of secure e-commerce HSMs are multi-tasking hardware modules that are optimized for performing modular arithmetic on very large integers. The nShield modules are FIPS 140-2 level 2 embedded devices. The units are identical in operation and only vary in the processing speed.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (12)

AlgorithmCAVP certificates
AESC754
CKGvendor affirmed
CVLC754
DRBGC754
DSAC754
ECDSAC754
HMACC754
KBKDFC754
KTSvendor affirmed
RSAC754
SHSC754
Triple-DESC754

Allowed algorithms

Diffie-Hellman (CVL Cert. #C754, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C754, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); EC MQV (CVL Cert. #C754, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2020-10-19InitialLightship Security, Inc.
2022-02-09UpdateLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-10-19, 2022-02-09

Source documents