Back to DashboardHardware InfrastructurePhase 6 · Infrastructure & Performanceadvanced60 min

HSM & PQC Operations

Deep dive into Hardware Security Modules: PKCS#11 v3.2 PQC mechanisms, vendor comparison, firmware migration, and FIPS 140-3 validation.

Why this matters: Your keys are only as safe as the hardware holding them — HSMs are where PQC migration meets the physical root of trust.

Start here: Step through the 8 PKCS#11 operations in order: each shows the API call and detail, and Execute Operation reveals the expected output — or live output from the in-browser HSM in Live WASM mode.

For your role

Security Architect
Step through eight PKCS#11 PQC operations with the on-prem versus cloud comparison, then the nine-vendor comparison by PQC maturity, algorithms and FIPS validation, and the fleet sizing for ten enterprise use cases.
Researcher / Academic
Track CMVP and CAVP PQC validation status across HSM vendors in Step 4: it is the current record of which modules have validated ML-KEM and ML-DSA implementations.
Certification & Validation Engineer
Step 4 tracks CMVP and CAVP PQC validation status across HSM vendors — read it by stage: a CAVP validation of ML-KEM or ML-DSA is the prerequisite, not a module certificate.
IT Ops / DevOps
Plan the firmware migration from classical to PQC with dual partitions in Step 3 and size the fleet in Step 5: the two operations a PQC rollout adds to an HSM estate.
Practice in the Simulation

A Hardware Security Module (HSM) is a tamper-resistant physical device that performs cryptographic operations and protects keys within a certified security boundary. The defines four increasing, qualitative security levels. A module's certificate states one overall level; its Security Policy lists the level reached in each requirement area.

Level 1

Lowest level: basic requirements, production-grade components, no specific physical-security mechanisms required. Not software-only: a Level 1 module can be hardware, software, firmware or hybrid, though many software libraries are validated here.

Level 2

Tamper-evidence (seals, coatings). Role-based authentication. Minimum OS requirements.

Level 3

Tamper-resistant. Identity-based authentication. Physical/logical separation of interfaces. Keys zeroed on tamper detection.

Level 4

Tamper-responsive envelope. Environmental failure protection (voltage, temperature). Complete physical penetration protection.

HSM Integration Architecture

Application (TLS Server, CA, Key Manager)
PKCS#11 API (v3.2 with PQC mechanisms)
Provider Library (vendor-specific)
HSM Firmware (PQC algorithm engine)
Hardware Crypto Accelerator + DRBG + Tamper Protection

On-Prem vs Cloud HSM

On-Prem HSMs
  • • Thales Luna 7 (Network HSM, FIPS 140-3 L3)
  • • Entrust nShield 5 (Network HSM, FIPS 140-3 L3)
  • • Utimaco SecurityServer (PCIe, FIPS 140-3 L3)

Full PQC firmware support available today

Cloud HSMs
  • • AWS CloudHSM (ML-DSA preview via SDK)
  • • Azure Dedicated HSM (Thales backend, upgrade pending)
  • • Google Cloud HSM (PQC on roadmap)

Cloud HSMs currently lack firmware-level PQC support

Ready to explore HSM operations?

Step through PKCS#11 PQC operations, compare vendors, and plan firmware migrations in the interactive workshop.

Related Resources

Products shown here are a representative selection — not an exhaustive list. For the full vendor landscape with PQC readiness status, visit the Tools & Products tab in this module or browse the Migrate catalog →

Check off all sections and mark this reading done.

In the Industry Landscape

Check your understanding

15 questions on HSM & PQC Operations, each with its answer and the reason.

Take the quiz

Next step

Produce the artifact: Infrastructure Modernization Planner

This module belongs to phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase in the Command Center.

Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.