Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4177


Module Name
AWS Key Management Service HSM
FIPS 140-2
Sunset Date
Overall Level
When installed, initialized and configured as specified in Section 3 of the Security Policy
Security Level Exceptions
  • Cryptographic Module Specification: Level 3
  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Multi-Chip Stand Alone
The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.
Tested Configuration(s)
  • N/A
Approved Algorithms
AES Cert. #4527
CKG vendor affirmed
CVL Certs. #1208 and #1209
DRBG Cert. #1487
ECDSA Cert. #1102
HMAC Cert. #2987
KAS-SSC vendor affirmed
KBKDF Cert. #133
KDA vendor affirmed
KTS AES Cert. #4527
KTS vendor affirmed
RSA Cert. #2464
SHS Cert. #3708
Allowed Algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Hardware Versions
Firmware Versions
1.6.109, 1.6.163 and 1.6.165


Amazon Web Services, Inc.
410 Terry Ave N
Ste 1200
Seattle, WA 98109-5210

Kelvin Yiu
Ken Beer

Validation History

Date Type Lab
3/15/2022 Initial ACUMEN SECURITY, LLC