NIST FIPS 140 3 Level 3 is the strong tier U.S. validation for tamper responsive hardware that guards encryption keys for banks, governments, and grid operators.
Ottawa-based Crypto4A says its QASM cryptographic module has passed NIST FIPS 140-3 Level 3 validation, which the company claims is the first such validation for a quantum-safe hardware security module (HSM) under the updated U.S. standard.
A hardware security module is the physical appliance that generates and guards the encryption keys protecting banks, governments, telecoms, and power-grid systems. The Level 3 bar requires strong identity-based authentication, logical separation of key-management functions, and immediate key zeroization if the device detects physical tampering.
QASM, the core module inside Crypto4A's QxHSM and QxVault appliances, natively executes the full suite of NIST-standardized post-quantum algorithms: ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), and stateful hash-based LMS signatures. The architecture is crypto-agile, letting customers migrate from classical RSA and ECC keys to post-quantum keys without swapping hardware or disrupting live operations.
DigiCert has partnered with Crypto4A to integrate the validated QASM module into the DigiCert ONE platform, positioning it for high-assurance digital signing, certificate issuance, and automated PKI. The pairing is also pitched as a defense against "harvest now, decrypt later" attacks that stockpile encrypted traffic for future quantum decryption.
The company is targeting governments, defense agencies, and critical-infrastructure operators preparing for mandatory post-quantum migration deadlines. The "first quantum-safe HSM" claim is Crypto4A's; independent verification against the NIST CMVP validation list was not present in the announcement.