Utimaco has achieved FIPS 140-3 Level 3 validation for its multi-tenant u.trust General Purpose HSM Se-Series, aligning with the latest standard for cryptographic modules defined by NIST. This certification confirms that the platform meets stringent requirements for physical security, authentication, and the protection of cryptographic keys within a validated boundary.
The u.trust General Purpose HSM Se-Series has achieved FIPS 140-3 Level 3 validation from the NIST Cryptographic Module Validation Program. The validation extends Utimaco's FIPS 140-3 coverage across its HSM portfolio and gives customers a certified platform for new FIPS 140-3 deployments, including those governed by U.S. federal procurement requirements taking effect September 21, 2026, when FIPS 140-2 certificates move to historical status.
With this milestone, Utimaco offers FIPS 140-3 Level 3 validated platforms across both general purpose and payment portfolios, joining the Atalla AT1000 Payment HSM, which was the first payment HSM achieving FIPS 140-3 certification, marking an early benchmark for payment security aligned with the latest NIST standard.
In-Field Activation, Not a Migration Project
Investment protection is a defining design principle of the u.trust General Purpose HSM Se-Series, and this certification reflects that principle.
Organizations already deploying the platform need to simply upgrade the firmware on site – no hardware replacement or RMA needed.
In-field performance upgrades remain available within the two model tiers — Se100 → Se2k → Se5k and Se15k → Se40k — allowing customers to scale throughput without re-certifying their platform. The multitenancy upgrades are available on the Se5k and Se40k models where the option lies between 8 – 16 – 31 cHSMs.
Certifications Held by the u.trust General Purpose HSM Se-Series
With this announcement, the platform carries:
- FIPS 140-3 Level 3 (NIST validated — new)
- FIPS 140-2 Level 3 (NIST validated)
- Common Criteria, included in the STIC CCN Product and Service Catalog of Spain's National Cryptologic Centre in its highest qualified ICT security product category
- PCI PTS HSM v3 for operational and technical security requirements in payment environments
The u.trust General Purpose HSM Se-Series delivers this compliance coverage on a container-based multi-tenant architecture supporting up to 31 fully isolated containers and performance up to 40,000 RSA 2K signatures per second.
Specialized Compliance Across the Utimaco Portfolio
Customers with requirements beyond the scope of the u.trust General Purpose HSM Se-Series can draw on Utimaco's broader HSM portfolio:
- For eIDAS-qualified signatures and seals, the Utimaco CryptoServer CP5 is Common Criteria certified against Protection Profile EN 419 221-5 — the first HSM in the market to achieve this certification, purpose-built for Trust Service Providers.
- For classified environments, the Utimaco CryptoServer General Purpose HSM is available in a version approved for VS-NfD, RESTREINT UE/EU RESTRICTED, and NATO RESTRICTED.
- For the highest physical security tier, the u.trust General Purpose HSM CSe-Series, announced in October 2025, is the tamper-active platform designed to meet FIPS 140-3 Level 4 physical protection, with certification work already in progress.
Availability
Existing deployments can achieve FIPS 140-3 Level by upgrading to the validated firmware version.
Learn more: u.trust General Purpose HSM Se-Series · GP HSM Simulator · Contact Sales
Ready to Secure Your Digital Future?
Join over 500 global enterprises and government institutions who trust Utimaco for their critical security infrastructure.
Contact SalesYour download request(s):

Your download request(s):

About Utimaco's Downloads
Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).
For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.
A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.