808bits

X4i Hardware Security Module (HSM)

FIPS 140-2 certificate #4225 · Pitney Bowes, Inc. · data as of 2026-09-03

X4i Hardware Security Module (HSM), from Pitney Bowes, Inc., holds FIPS 140-2 certificate #4225 at overall level 3. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2026-09-21, 17 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS Mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number4225
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level3
Module typeHardware
EmbodimentSingle Chip
VendorPitney Bowes, Inc. · website
Hardware versionsMAX32590 Secure Microcontroller Revision B4
Firmware versionsPB Bootloader Version 00.00.0016, HSM Application Version 21.04.0008, and Device Abstraction Layer (DAL) Version 01.02.002F

Module description

Quoted from the NIST CMVP entry for this certificate.

The X4i HSM is a single chip cryptographic module using the Maxim MAX32590 hardware. The central purpose of the module is as a physical computing device that safeguards and manages cryptographic keys and provides cryptographic services to connected host devices.

Approved algorithms (11)

AlgorithmCAVP certificates
AES5954
CKGvendor affirmed
DRBGC472
ECDSAC476
HMACC464
KAS
KAS-SSCA1869
KDAA1869
KTS
RSAC477
SHSC295

Tested configurations

  • N/A

Validation history

DateTypeLab
2022-05-12InitialPenumbra Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-05-12

Source documents