A self-contained unit that is capable of storing at least one plaintext or encrypted cryptographic key or key component that can be transferred, upon request, into a cryptographic module.
Sources:
CNSSI 4009-2015
from
FIPS 140-2