808bits

NITROXIII CNN35XX-NFBE HSM Family

FIPS 140-3 certificate #5219 · JISA Softech Private Limited · data as of 2026-09-08

NITROXIII CNN35XX-NFBE HSM Family, from JISA Softech Private Limited, holds FIPS 140-3 certificate #5219 at overall level 3. The validation is active, with a sunset date of 2029-05-29. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2029-05-29, 992 days away.
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates SSPs whose strengths are modified by available entropy

Certificate

Certificate number5219
StandardFIPS 140-3
Statusactive
Sunset date2029-05-29
Overall level3
Module typeHardware
EmbodimentMultiChipEmbed
VendorJISA Softech Private Limited · website
Hardware versionsHW-1.0 (CNL3510-NFBE-G; CNL3510P-NFBE-G; CNL3530-NFBE-G; CNL3560-NFBE-G; CNL3560P-NFBE-G; CNN3510-NFBE-G; CNN3530-NFBE-G; CNN3560-NFBE-G; CNN3560P-NFBE-G); HW-2.0 (CNL3510-NFBE-2.0-G; CNL3510B-NFBE-2.0-G; CNL3510P-NFBE-2.0-G; CNL3510PB-NFBE-2.0-G; CNL3530-NFBE-2.0-G; CNL3530B-NFBE-2.0-G; CNL3560-NFBE-2.0-G; CNL3560B-NFBE-2.0-G; CNL3560P-NFBE-2.0-G; CNL3560PB-NFBE-2.0-G; CNN3505LP-NFBE-2.0-G; CNN3510-NFBE-2.0-G; CNN3510LP-NFBE-2.0-G; CNN3510LPB-NFBE-2.0-G; CNN3530-NFBE-2.0-G; CNN3560-NFBE-2.0-G; CNN3560P-NFBE-2.0-G); HW-3.0 (CNL3510-NFBE-3.0-G; CNL3510A-NFBE-3.0-G; CNL3510C-NFBE-3.0-G; CNL3510D-NFBE-3.0-G; CNL3510E-NFBE-3.0-G; CNL3510F-NFBE-3.0-G; CNL3510I-NFBE-3.0-G; CNL3510P-NFBE-3.0-G; CNL3530-NFBE-3.0-G; CNL3530A-NFBE-3.0-G; CNL3530B-NFBE-3.0-G; CNL3530C-NFBE-3.0-G; CNL3530D-NFBE-3.0-G; CNL3530E-NFBE-3.0-G; CNL3530F-NFBE-3.0-G; CNL3560-NFBE-3.0-G; CNL3560A-NFBE-3.0-G; CNL3560B-NFBE-3.0-G; CNL3560B-NFBE-3.0-G-FB; CNL3560C-NFBE-3.0-G; CNL3560D-NFBE-3.0-G; CNL3560E-NFBE-3.0-G; CNL3560F-NFBE-3.0-G; CNL3560P-NFBE-3.0-G; CNN3505LP-NFBE-3.0-G; CNN3505LPA-NFBE-3.0-G; CNN3505LPC-NFBE-3.0-G; CNN3505LPD-NFBE-3.0-G; CNN3505LPE-NFBE-3.0-G; CNN3505LPF-NFBE-3.0-G; CNN3510-NFBE-3.0-G; CNN3510A-NFBE-3.0-G; CNN3510C-NFBE-3.0-G; CNN3510D-NFBE-3.0-G; CNN3510E-NFBE-3.0-G; CNN3510F-NFBE-3.0-G; CNN3510LP-NFBE-3.0-G; CNN3510LPA-NFBE-3.0-G; CNN3510LPB-NFBE-3.0-G; CNN3510LPC-NFBE-3.0-G; CNN3510LPD-NFBE-3.0-G; CNN3510LPE-NFBE-3.0-G; CNN3510LPF-NFBE-3.0-G; CNN3530-NFBE-3.0-G; CNN3530A-NFBE-3.0-G; CNN3530C-NFBE-3.0-G; CNN3530D-NFBE-3.0-G; CNN3530E-NFBE-3.0-G; CNN3530F-NFBE-3.0-G; CNN3560-NFBE-3.0-G; CNN3560A-NFBE-3.0-G; CNN3560C-NFBE-3.0-G; CNN3560D-NFBE-3.0-G; CNN3560E-NFBE-3.0-G; CNN3560F-NFBE-3.0-G; CNN3560P-NFBE-3.0-G)
Firmware versionsCNN35XX-NFBE-FW-2.09-0702, CNN35XX-NFBE-SMW-2.09-0702, CNN35XX-UBOOT-4.03-03
EntropyENT (P)

Module description

Quoted from the NIST CMVP entry for this certificate.

The NITROXIII CNN35XX-NFBE HSM Family module is a high-performance purpose-built security solution for crypto acceleration. The module provides a FIPS 140-3 overall Level 3 security solution. The module is deployed inside CryptoBind HSM and CryptoBind DSS to provide crypto and TLS 1.0/1.1/1.2 acceleration in a secure manner to the system host. It is typically deployed in a CryptoBind HSM & CryptoBind DSS network appliance to provide cryptographic operations. The module’s functions are accessed over the PCIe interface via an API defined by the module inside CryptoBind HSM and CryptoBind DSS.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (56)

AlgorithmCAVP certificates
AES-CBCC819, C839
AES-CCMC839
AES-CMACA1190, A1195, C839
AES-CTRC839
AES-ECBC819, C839
AES-GCMA1203, C839
AES-GMACC839
AES-KWC1263
AES-KWPC1263
Counter DRBGC821
DSA KeyGen (FIPS186-4)C823
DSA PQGGen (FIPS186-4)C823
DSA PQGVer (FIPS186-4)C823
DSA SigGen (FIPS186-4)C823
DSA SigVer (FIPS186-4)C823
ECDSA KeyGen (FIPS186-4)C825
ECDSA KeyVer (FIPS186-4)C825
ECDSA SigGen (FIPS186-4)C825, C829
ECDSA SigVer (FIPS186-4)C825, C829
Hash DRBGC830
HMAC-SHA-1C822, C839
HMAC-SHA2-224C822, C839
HMAC-SHA2-256C822, C839
HMAC-SHA2-384C822, C839
HMAC-SHA2-512C822, C839
KAS-ECC CDH-ComponentC829
KAS-ECC Sp800-56Ar3A1219
KAS-ECC-SSC Sp800-56Ar3A1220, A2161
KAS-IFC-SSCA1193
KDA HKDF Sp800-56Cr1A1192
KDA OneStep Sp800-56Cr1A1192
KDA TwoStep Sp800-56Cr1A1192
KDF ANS 9.63C825
KDF SP800-108A1191, C826, C839
KDF TLSC840
KTS-IFCA1194
PBKDFA1196
RSA Decryption PrimitiveA1200, C839
RSA KeyGen (FIPS186-4)A1199, C824
RSA SigGen (FIPS186-2)C824
RSA SigGen (FIPS186-4)A1199
RSA Signature PrimitiveC839
RSA SigVer (FIPS186-4)A1199, A1201, C824
SHA-1C820, SHS 1780
SHA2-224C820, SHS 1780
SHA2-256A1202, C820, SHS 1780
SHA2-384C820, SHS 1780
SHA2-512C820, SHS 1780
SHA3-224A1197
SHA3-256A1197
SHA3-512A1197
SHAKE-128A1197
SHAKE-256A1197
TDES-CBCTDES 1311
TDES-ECBC1169, TDES 1311
TDES-KWC1263

Allowed algorithms

AES (Cert. #C819, key unwrapping provides 128, 192 or 256 bits of encryption strength. Per IG D.G.; Key unwrap only N3FIPS-OpenSSL-1.1.1-AES ECB mode: Decrypt; 128, 192 and 256 bits CBC mode: Decrypt: 128, 192 and 256 bits *Legacy use only);EC Diffie-Hellman with non-NIST recommended curves (Cert. #C829, provides 112, 128, 160, 192 or 256 bits of encryption strength. Per IG C.A. ; EC-DH Secp224k1(112 bits), Secp256K1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 brainpoolP224r1(112 bits), brainpoolP256r1(128 bits), brainpoolP320r1(160 bits), brainpoolP384r1(192 bits), brainpoolP512r1(256 bits) FRP256v1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 (SHA-1*, SHA2-224, SHA2-256, SHA2-384, SHA2-512));ECDSA with non-NIST recommended curves (Cert. #C825, provides 112, 128, 160, 192 or 256 bits of encryption strength. Per IG C.A. ; EC Key generation, sign, verify Secp224k1(112 bits), Secp256K1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 brainpoolP224r1(112 bits), brainpoolP256r1(128 bits), brainpoolP320r1(160 bits), brainpoolP384r1(192 bits), brainpoolP512r1(256 bits) FRP256v1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 (SHA-1*, SHA2-224, SHA2-256, SHA2-384, SHA2-512))

Tested configurations

  • N/A

Validation history

DateTypeLab
2026-03-31InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2026-03-31

Source documents