u.trust Anchor
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Certificate
| Certificate number | 5223 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-03-31 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | MultiChipEmbed |
| Vendor | Utimaco IS GmbH · website |
Module description
u.trust Anchor is a new generation of HSM, comprising all traditional hardware security features and introducing containerized HSMs (cHSMs). Each cHSM provides secure cryptographic services such as signing and verification of data, encryption or decryption, hashing, on-board random number generation and secure key generation, key storage and key management functions in a tamper-protected multi-tenant environment. The HSM delivers a highly elastic HSM architecture that scales rapidly on demand and enables service providers to deliver HSM as a Service (HSMaaS) in multiple use cases.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-04-01 | Initial | Penumbra Security, Inc. |
| 2026-04-22 | Update | Penumbra Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-04-01