808bits

AWS Nitro Card Security Engine

FIPS 140-2 certificate #3739 · Amazon Web Services, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3739
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeFirmware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorAmazon Web Services, Inc. · website
Hardware versionsAL5+
Firmware versionsHAL-rel-3.2-uemu-fips

Module description

The AWS Nitro Card Security Engine is a multi-chip standalone firmware-hybrid module. The Approved cryptographic services provided by the module are: - Data encryption / decryption utilizing symmetric ciphers, i.e. AES algorithms. - Computation of hash values, i.e. SHA-256, SHA-512. - Message authentication utilizing HMAC-SHA256, HMAC-SHA512, hashing algorithms.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC997
HMACC2168
SHSC997

Tested configurations

  • Carbon Linux (Linux kernel 4.9.32) running on Cortex ARMv8 with AL5+

Validation history

DateTypeLab
2020-10-29InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-10-29

Source documents