808bits

Purity Encryption Module

FIPS 140-2 certificate #4109 · Pure Storage, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: None

Certificate

Certificate number4109
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorPure Storage, Inc. · website
Software versions1.3
Hardware versionsIntel Xeon E5-2698 v4, Intel Xeon 4114, Intel Xeon 6130, Intel Xeon 6230 and Intel Xeon 8368

Module description

Purity Encryption Module is a standalone cryptographic module for the Purity Operating Environment for FlashArray (Purity//FA). Purity//FA powers Pure Storage's FlashArray family of products which provide economical all-flash storage. Purity Encryption Module enables FlashArray to support always-on, inline encryption of data with an internal key management scheme that requires no user intervention.

Security level exceptions

  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AESA727
CKGvendor affirmed
DRBGA727
HMACA727
KTS
SHSA727

Allowed algorithms

NDRNG

Tested configurations

  • Purity OS 5.3 running on C60 with Intel Xeon 6130 with PAA
  • Purity OS 5.3 running on M70R2 with Intel Xeon E5-2698 v4 with PAA
  • Purity OS 5.3 running on X70R3 with Intel Xeon 6230 with PAA
  • Purity OS 6.1 running on C60 with Intel Xeon 6130 with PAA
  • Purity OS 6.1 running on X20R2 with Intel Xeon 4114 with PAA
  • Purity OS 6.1 running on X70R3 with Intel Xeon 6230 with PAA
  • Purity OS 6.2 running on XL170 with Intel Xeon 8368 with PAA
  • Purity OS 6.3 running on XL170 with Intel Xeon 8368 with PAA (single-user mode)

Validation history

DateTypeLab
2021-12-16InitialAcumen Security
2021-12-30UpdateAcumen Security
2022-01-04UpdateAcumen Security
2023-03-01UpdateAcumen Security
2023-04-04UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2021-12-16, 2021-12-30, 2022-01-04, 2023-03-01, 2023-04-04

Known CVEs in this module family (heuristic match)

Name-based association with the module's product family, not a statement about the validated boundary. See methodology.

CVECVSSSeverity
CVE-2023-310427.7HIGH
CVE-2023-366277.7HIGH
CVE-2023-283726.5MEDIUM

Source documents