808bits

Aegis Secure Key 3Z and Aegis Secure Key 3NX Cryptographic Module

FIPS 140-2 certificate #4420 · Apricorn · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: The module generates cryptographic keys whose strengths are modified by available entropy.

Certificate

Certificate number4420
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorApricorn · website
Hardware versionsP/Ns ASK3Z-16GB [2.0], ASK3Z-32GB [2.0], ASK3Z-64GB [2.0], ASK3Z-128GB [2.0], ASK3-NX-2GB [2.0], ASK3-NX-4GB [2.0], ASK3-NX-8GB [2.0], ASK3-NX-16GB [2.0], ASK3-NX-32GB [2.0], ASK3-NX-64GB [2.0], ASK3-NX-128GB [2.0], ASK3-NX-256GB [2.0], ASK3-NXC-4GB [2.0], ASK3-NXC-8GB [2.0], ASK3-NXC-16GB [2.0], ASK3-NXC-32GB [2.0], ASK3-NXC-64GB [2.0], ASK3-NXC-128GB [2.0] ASK3-NXC-256GB [2.0]; Hardware Version: Rev A; P/Ns ASK3-NXC-4GB [2.1], ASK3-NXC-8GB [2.1], ASK3-NXC-16GB [2.1], ASK3-NXC-32GB [2.1], ASK3-NXC-64GB [2.1], ASK3-NXC-128GB [2.1], ASK3-NXC-256GB [2.1], ASK3-NXC-512GB [2.1]; Hardware Version: Rev B; P/Ns ASK3Z-16GB [2.1], ASK3Z-32GB [2.1], ASK3Z-64GB [2.1], ASK3Z-128GB [2.1], ASK3-NX-2GB [2.1], ASK3-NX-4GB [2.1], ASK3-NX-8GB [2.1], ASK3-NX-16GB [2.1], ASK3-NX-32GB [2.1], ASK3-NX-64GB [2.1], ASK3-NX-128GB [2.1], ASK3-NX-256GB [2.1], ASK3-NX-512GB [2.1]; Hardware Version: Rev C
Firmware versions2.0 and 2.1

Module description

The Apricorn Aegis Secure Key 3z and Apricorn Aegis Secure Key 3NX are hardware encrypted USB 3.1 memory keys.The software free design allows interface to any host that supports USB and mass storage.Authentication is performed via the embedded keypad and all critical security parameters (PINs, encryption keys, etc) never leave the device boundary for improved security. The device supports 1 administrator and 1 user and offers a variety of features including programmable brute force, recovery PINs, 7-16 digit PINs, auto lock, read only modes, and is compatible with our Aegis Configurator.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA1909, C967
CKGvendor affirmed
DRBGC1032
ECDSAC1033
ENT
KAS
KAS-SSCA1913
KDAA1913
SHSC1029

Tested configurations

  • N/A

Validation history

DateTypeLab
2023-01-20InitialAEGISOLVE, Inc.
2023-02-14UpdateAEGISOLVE, Inc.
2024-11-27UpdateAEGISOLVE, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-01-20, 2023-02-14, 2024-11-27

Source documents