808bits

AWS Key Management Service HSM

FIPS 140-2 certificate #4523 · Amazon Web Services, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When installed, initialized and configured as specified in Section 3 of the Security Policy

Certificate

Certificate number4523
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAmazon Web Services, Inc. · website
Hardware versions3.0
Firmware versions1.7.100, 1.7.102 and 1.7.103

Module description

The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA1791, A1908
CKGvendor affirmed
CVLA1908
DRBGA1791, A1908
ECDSAA1908
ENT
HMACA1908
KASA1908
KBKDFA1910
KDAA1908
KTS
KTS-RSA
RSAA1908
SHSA1908

Allowed algorithms

RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2023-05-19InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-05-19

Source documents