808bits

AWS Key Management Service HSM

FIPS 140-2 certificate #4177 · Amazon Web Services, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When installed, initialized and configured as specified in Section 3 of the Security Policy

Certificate

Certificate number4177
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAmazon Web Services, Inc. · website
Hardware versions2.0
Firmware versions1.6.109, 1.6.163 and 1.6.165

Module description

The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.

Security level exceptions

  • Cryptographic Module Specification: Level 3
  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4527
CKGvendor affirmed
CVL1208, 1209
DRBG1487
ECDSA1102
HMAC2987
KAS-SSCvendor affirmed
KBKDF133
KDAvendor affirmed
KTS
KTSvendor affirmed
RSA2464
SHS3708

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2022-03-15InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-03-15

Source documents