HSM & PQC Operations
Deep dive into Hardware Security Modules: PKCS#11 v3.2 PQC mechanisms, vendor comparison, firmware migration, and FIPS 140-3 validation.
Why this matters: Your keys are only as safe as the hardware holding them — HSMs are where PQC migration meets the physical root of trust.
Start here: Step through the 8 PKCS#11 operations in order: each shows the API call and detail, and Execute Operation reveals the expected output — or live output from the in-browser HSM in Live WASM mode.
For your role
- Security Architect
- Step through eight PKCS#11 PQC operations with the on-prem versus cloud comparison, then the nine-vendor comparison by PQC maturity, algorithms and FIPS validation, and the fleet sizing for ten enterprise use cases.
- Researcher / Academic
- Track CMVP and CAVP PQC validation status across HSM vendors in Step 4: it is the current record of which modules have validated ML-KEM and ML-DSA implementations.
- Certification & Validation Engineer
- Step 4 tracks CMVP and CAVP PQC validation status across HSM vendors — read it by stage: a CAVP validation of ML-KEM or ML-DSA is the prerequisite, not a module certificate.
- IT Ops / DevOps
- Plan the firmware migration from classical to PQC with dual partitions in Step 3 and size the fleet in Step 5: the two operations a PQC rollout adds to an HSM estate.
A Hardware Security Module (HSM) is a tamper-resistant physical device that performs cryptographic operations and protects keys within a certified security boundary. The defines four increasing, qualitative security levels. A module's certificate states one overall level; its Security Policy lists the level reached in each requirement area.
Lowest level: basic requirements, production-grade components, no specific physical-security mechanisms required. Not software-only: a Level 1 module can be hardware, software, firmware or hybrid, though many software libraries are validated here.
Tamper-evidence (seals, coatings). Role-based authentication. Minimum OS requirements.
Tamper-resistant. Identity-based authentication. Physical/logical separation of interfaces. Keys zeroed on tamper detection.
Tamper-responsive envelope. Environmental failure protection (voltage, temperature). Complete physical penetration protection.
HSM Integration Architecture
On-Prem vs Cloud HSM
- • Thales Luna 7 (Network HSM, FIPS 140-3 L3)
- • Entrust nShield 5 (Network HSM, FIPS 140-3 L3)
- • Utimaco SecurityServer (PCIe, FIPS 140-3 L3)
Full PQC firmware support available today
- • AWS CloudHSM (ML-DSA preview via SDK)
- • Azure Dedicated HSM (Thales backend, upgrade pending)
- • Google Cloud HSM (PQC on roadmap)
Cloud HSMs currently lack firmware-level PQC support
Ready to explore HSM operations?
Step through PKCS#11 PQC operations, compare vendors, and plan firmware migrations in the interactive workshop.
Related Resources
Products shown here are a representative selection — not an exhaustive list. For the full vendor landscape with PQC readiness status, visit the Tools & Products tab in this module or browse the Migrate catalog →
Check off all sections and mark this reading done.
Related modules
- ACVP Lab Workflow: From Vector Set to EvidenceSame migration phase · Shares ML-KEM, ML-DSA, PKCS#11
- Homomorphic Encryption (FHE) & HSM Key CustodySame track · Hardware Infrastructure · Same migration phase · Shares ML-DSA, ML-KEM
- Confidential Computing & TEEsSame track · Hardware Infrastructure · Same migration phase · Shares ML-DSA, ML-KEM
- Secure Boot & Firmware PQCSame track · Hardware Infrastructure · Same migration phase · Shares ML-DSA, ML-KEM
In the Industry Landscape
- Hardware Security ModulesPQC key generation & side-channel hardening · PKCS#11 / KMIP interface migration · Root-of-trust & firmware signing · +1 more
- Cloud Computing / Data CentersBy protocol · Cloud KMS / BYOK key wrapping · Cloud HSM root keys & FIPS modules
- Cryptocurrency / BlockchainBy protocol · Exchange & custody key management
- Finance & BankingBy protocol · HSM key management & wrapping
Check your understanding
15 questions on HSM & PQC Operations, each with its answer and the reason.
Take the quizNext step
Produce the artifact: Infrastructure Modernization PlannerThis module belongs to phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase in the Command Center.
Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.