Thales Achieves First U.S. FIPS 140-3 Validation for Hardware Security Modules

    Thales Trusted Cyber Technologies has secured the first U.S.-manufactured FIPS 140-3 Level 3 validation for its Luna T-Series hardware security modules, paving the way for robust federal cybersecurity. The upcoming release will facilitate the adoption of post-quantum cryptography, aligning with federal standards and enhancing data protection measures across agencies.

    National Institute of Standards and Technology, National Security Agency

    Key Signals

    • Thales awarded first U.S. FIPS 140-3 Level 3 validation for Luna T-Series HSMs
    • Upcoming Luna T-Series version 7.15.1 to support post-quantum cryptography
    • Growing demand for compliant cybersecurity hardware presents opportunities for vendors

    "The certification supports federal agencies as they adapt to changing cybersecurity standards and prepare for the adoption of post-quantum cryptography."

    Bill Becker, Chief Technology Officer, Thales Trusted Cyber Technologies

    In a significant milestone for federal cybersecurity, Thales Trusted Cyber Technologies has been awarded the first Federal Information Processing Standards (FIPS) 140-3 Level 3 validation for its Luna T-Series hardware security modules (HSMs). This certification positions Thales as a leading technology partner for federal agencies, enabling them to align their operations with evolving cybersecurity mandates. The Luna T-Series, specifically the upcoming version 7.15.1, will support post-quantum cryptography algorithms, an essential requirement as agencies prepare for the anticipated transition to quantum-resistant security measures.

    Historically, compliance with stringent security protocols has been crucial for protecting sensitive federal information and applications. The FIPS 140-3 Level 3 certification ensures that the Luna T-Series HSMs are equipped to withstand physical tampering while managing cryptographic keys, thus reinforcing the integrity of federal cybersecurity frameworks. Bill Becker, Chief Technology Officer at Thales TCT, emphasized the importance of this certification: "The certification supports federal agencies as they adapt to changing cybersecurity standards and prepare for the adoption of post-quantum cryptography."

    The announcement underscores the urgency for federal agencies to upgrade their encryption and key management systems, particularly as quantum computing capabilities emerge as a potential risk to traditional cryptographic systems. With Thales leading the charge by integrating the latest National Institute of Standards and Technology (NIST) and National Security Agency (NSA) standards into their products, procurement professionals must evaluate these innovative HSMs as part of their secure infrastructure strategies.

    As IT modernization continues to be a priority for the government, the demand for advanced cybersecurity hardware is likely to increase significantly. The Luna T-Series modules not only fulfill compliance requirements but also present opportunities for agencies to enhance their data protection frameworks. Given the emerging landscape of cybersecurity threats, validated HSMs like Thales' offering are critical in maintaining operational continuity and securing sensitive federal operations.

    The Luna T-Series line, entirely developed and manufactured in the U.S., adheres to government supply chain mandates, which further establishes Thales as a trusted provider for federal procurement. The forthcoming version 7.15.1 of the Luna T-Series is set to include support for groundbreaking algorithms such as ML-DSA and ML-KEM, aligning with NSA’s Commercial National Security Algorithm Suite 2.0 for post-quantum cryptography.

    Organizations involved in federal IT procurements should prioritize acquiring FIPS 140-3 validated HSMs to facilitate secure key management and cryptographic operations. Thales has also engaged in partnerships, such as with Virtru, to integrate its HSMs into more comprehensive cybersecurity solutions, further highlighting the importance of collaboration in addressing modern security challenges.

    The progressive stance of Thales in response to the shifting cryptographic landscape reveals a growing trend toward prioritizing advanced security mechanisms within federal contracts. As more agencies recognize the need to secure their operations against future threats posed by quantum computing, the potential for increased procurement within this niche market appears robust.

    • Thales’ Luna T-Series is the first U.S.-manufactured HSM with FIPS 140-3 Level 3 validation.
    • Scheduled release of version 7.15.1 will support post-quantum cryptography algorithms.
    • The certification means enhanced security for federal agencies adapting to new cybersecurity standards.
    • Procurement professionals are encouraged to consider validated HSMs for secure key management operations.
    • The Luna T-Series HSMs protect cryptographic keys for sensitive federal data.
    • Thales' certification corresponds to developments by NIST and NSA, reinforcing their standing as a trusted vendor.
    • Increased compliance requirements will drive demand for advanced cybersecurity hardware in federal agencies.
    • Thales’ collaboration with Virtru supports broader federal cybersecurity initiatives.

    Agencies

    • National Institute of Standards and Technology
    • National Security Agency

    Vendors

    • Thales Trusted Cyber Technologies