808bits

CryptoServer CSe-Series

FIPS 140-2 certificate #3886 · Utimaco IS GmbH · data as of 2026-09-03

CryptoServer CSe-Series, from Utimaco IS GmbH, holds FIPS 140-2 certificate #3886 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3886
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorUtimaco IS GmbH · website
Hardware versionsCryptoServer CSe-Series 4.00.5.0 and CryptoServer CSe-Series 4.00.5.1
Firmware versionsSecurityServer-CSe-Series-4.32.0.3-FIPS

Module description

Quoted from the NIST CMVP entry for this certificate.

The CryptoServer CSe-Series is an encapsulated, protected security module realized as a multi-chip embedded cryptographic module per FIPS 140-2. Its realization meets overall FIPS 140-2 Level 3 requirements, with Level 4 "Physical Security". The module's primary purpose is to provide secure cryptographic services such as encryption or decryption (for various algorithms like AES and Triple-DES), hashing, signing and verification of data (RSA, ECDSA, DSA), random number generation, on-board secure key generation, key storage and further key management functions in a tamper-protected environment.

Security level exceptions

  • Physical Security: Level 4

Approved algorithms (18)

AlgorithmCAVP certificates
AESC1122, C1137, C1138, C1140, C1246
CKGvendor affirmed
CVLA1016, C1141, C1165
DRBGA1068
DSAC1195
ECDSAC1196, A2367
ENT
HMACC1142
KAS
KAS-SSCA2368, A2369, A2227
KBKDFC1164
KDAA1016, A2417
KTS
KTS-RSA
RSAC1197
SHA-3C1125
SHSA1067, C1124, C1126
Triple-DESC1128

Allowed algorithms

EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); EC Diffie-Hellman (shared secret computation provides between 112 and 256 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-04-07InitialPenumbra Security, Inc.
2023-08-23UpdatePenumbra Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-04-07, 2023-08-23

Source documents