- Key Takeaways
- Key Custody: Where the Private Key Actually Lives
- Firmware Support vs. Validation: The Gap That Matters
- The FIPS 140-2 Sunset Complicates the Timing
- Performance, Backup, and High Availability
- A Procurement Checklist
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- A Compliance Question, Not an Algorithm Question
- Frequently Asked Questions
Quick answer: A post-quantum certificate does not strictly require a hardware security module the way FIPS-regulated environments require one for classical keys, but for any production certificate authority, the practical answer is yes: CA/Browser Forum requirements already mandate FIPS-validated hardware for code-signing and CA private keys, and that requirement carries forward unchanged into ML-KEM and ML-DSA. The complication is validation status, not the requirement itself. As of this guide’s publication, PQC algorithms validate only under FIPS 140-3, not FIPS 140-2, and no HSM vendor has yet completed a combined FIPS 140-3 Level 3 validation with PQC algorithm support; the furthest-along submissions sit in CMVP’s Modules in Process or Implementation Under Test queues, with final approvals expected through 2026 and 2027. This guide covers what actually determines whether you need new hardware, and what to check before assuming a vendor’s PQC claim is backed by a completed validation.
“Do we need new HSMs for post-quantum” gets asked as a yes-or-no question when it is really five separate questions: where does the private key actually live, does your current hardware’s firmware support the algorithm at all, is that firmware validated or just capable, what does your compliance framework actually require, and what does the performance profile look like under real signing volume. This guide walks through each one.
Key Takeaways
- PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) validate only under FIPS 140-3; there is no FIPS 140-2 validation path for them, which matters given FIPS 140-2 certificates move to CMVP’s Historical list on September 21, 2026.
- As of this guide’s publication, no HSM vendor has completed a combined FIPS 140-3 Level 3 validation with PQC algorithm support; the furthest submissions remain in CMVP’s Modules in Process or Implementation Under Test stages.
- CMVP validation submissions have historically taken more than two years on average from lab submission to certification, a timeline worth planning around rather than assuming will accelerate.
- Algorithm support and algorithm validation are two different claims; some vendors have CAVP algorithm-level certification for PQC without a completed FIPS 140-3 module validation covering it.
- Whether hardware key custody is strictly required depends on your compliance framework, not the algorithm; CA/Browser Forum requirements for code-signing and CA private keys apply the same way to PQC keys as classical ones.
Key Custody: Where the Private Key Actually Lives
The core question is not whether ML-DSA can run in software, it can, but whether your specific use case requires the private key to be generated and held inside a hardware boundary that never exposes it in plaintext. For CA private keys and code-signing keys specifically, CA/Browser Forum Baseline Requirements already mandate this for classical algorithms, and nothing in that requirement changes for post-quantum algorithms; a root or issuing CA moving to ML-DSA still needs its private key inside FIPS-validated hardware to meet the same baseline requirements it met under RSA or ECDSA. For lower-stakes use cases outside that regulatory scope, software-based key storage remains a legitimate option, the same trade-off that applied before PQC entered the picture.
Firmware Support vs. Validation: The Gap That Matters
This is where vendor claims and actual procurement-ready status diverge, and it is worth checking carefully rather than accepting “we support PQC” at face value. Three distinct claims get conflated:
- Algorithm capability: the HSM’s firmware can technically execute ML-KEM or ML-DSA operations.
- CAVP algorithm validation: NIST’s Cryptographic Algorithm Validation Program has independently confirmed the specific algorithm implementation is correct, a narrower, faster validation than a full module validation.
- FIPS 140-3 module validation: CMVP has validated the complete hardware module, including the PQC algorithm implementation, against the full FIPS 140-3 standard, the validation that actually satisfies federal procurement and most regulated-industry compliance requirements.
A vendor can genuinely have the first two without the third. As of this guide’s publication, that is the state of the market broadly: individual algorithm validations exist, but a combined FIPS 140-3 Level 3 module validation covering PQC algorithms had not yet completed for any vendor, with the furthest submissions in CMVP’s Modules in Process or Implementation Under Test queues. Ask specifically which of the three claims a vendor is making, and ask for the actual CMVP certificate number or queue status, not a roadmap statement.
The FIPS 140-2 Sunset Complicates the Timing
September 21, 2026 is when CMVP moves all remaining FIPS 140-2 certificates to its Historical list. Modules on that list can still be purchased and used for existing systems, but new federal procurement is expected to specify FIPS 140-3. That timing interacts awkwardly with PQC readiness: since PQC algorithms have no FIPS 140-2 path at all, any organization needing both an immediate FIPS 140-3 procurement and PQC algorithm support is procuring into a market where that exact combination may not yet have a completed validation, forcing a choice between validated classical-only hardware today or capable-but-not-yet-validated PQC hardware.
Performance, Backup, and High Availability
ML-KEM and ML-DSA operations run efficiently on current HSM hardware generally, but confirm signing throughput specifically under your actual certificate issuance volume rather than a vendor’s synthetic benchmark, since larger key and signature sizes do add real computational and storage overhead per operation compared to classical algorithms. Backup and high-availability procedures for PQC keys follow the same principles as classical HSM key backup, encrypted key export between HSMs of the same security domain, dual control, split-knowledge ceremonies, but confirm your specific HSM platform’s backup and clustering features have been extended to cover PQC key types, since not every platform feature ships simultaneously with new algorithm support.
A Procurement Checklist
- Which specific PQC algorithms and parameter sets does the firmware support today, by version number, not a general roadmap claim.
- What is the actual CMVP validation status, active, Modules in Process, Implementation Under Test, or not yet submitted, for the exact firmware version you would deploy.
- Does your compliance framework require FIPS 140-3 module validation specifically, or does CAVP algorithm validation satisfy your requirements, since the answer changes what “ready” means for your procurement.
- What is the firmware upgrade path for hardware you already own, versus what requires a new hardware purchase.
- Are backup, HA, and clustering features confirmed for PQC key types on your specific platform and firmware version, not assumed from classical-algorithm feature parity.
What We’d Actually Recommend
Confirm your regulatory and compliance framework’s actual HSM requirement before assuming new hardware is mandatory; the requirement comes from your compliance posture, not the algorithm itself. For any procurement, verify CMVP validation status directly against the CMVP database rather than a vendor’s marketing claim, and separate algorithm capability from module validation explicitly when evaluating readiness. Plan around the current, longer FIPS 140-3 PQC validation timeline rather than assuming an accelerated schedule, and confirm backup, HA, and firmware upgrade paths for your specific platform before committing to a hardware refresh.
How Encryption Consulting Can Help
Understanding whether your specific compliance framework and use case actually require new HSM hardware, versus a firmware update or continued software-based key storage, is exactly the kind of assessment our PQC Advisory Services provide, mapped against your actual certificate types and regulatory obligations rather than a blanket hardware refresh recommendation.
CBOM Secure builds the inventory that any HSM procurement decision should start from, mapping which of your keys currently require hardware custody and which do not, so the hardware refresh scope is based on actual requirements rather than a uniform assumption. Where the HSM decision is made, our HSM Services assess current firmware validation status against your specific compliance requirements before any purchase.
A Compliance Question, Not an Algorithm Question
Whether PQC certificates require quantum-safe HSMs is fundamentally the same question it was for classical algorithms: does your specific compliance framework and use case require hardware key custody. What has changed is validation timing, since PQC algorithms validate only under FIPS 140-3, and that combined validation had not yet completed for any vendor as of this guide’s publication. Separating algorithm capability from module validation, and checking the actual CMVP status rather than a roadmap claim, is what turns an HSM procurement decision from a guess into an informed one.
Frequently Asked Questions
Can ML-DSA run without a hardware security module?
Technically yes, in software. Whether that is acceptable depends on your specific compliance requirements. CA private keys and code-signing keys are typically required to be hardware-protected under existing baseline requirements, a requirement that carries forward unchanged for PQC algorithms.
Has any HSM vendor completed FIPS 140-3 validation with PQC algorithm support?
As of this guide’s publication, no vendor had completed a combined FIPS 140-3 Level 3 module validation covering PQC algorithms; the furthest submissions were in CMVP’s Modules in Process or Implementation Under Test stages, with completions expected through 2026 and 2027. Check current CMVP status directly before assuming this has changed.
What is the difference between algorithm support and algorithm validation?
Algorithm support means the HSM firmware can technically execute the operation. Validation means an independent body, CAVP for the algorithm implementation or CMVP for the full module, has confirmed it meets the standard. A vendor can have support without a completed module validation.
Does the FIPS 140-2 sunset on September 21, 2026 affect PQC HSM procurement?
Indirectly. PQC algorithms have no FIPS 140-2 validation path at all, so an organization needing both immediate FIPS 140-3 compliance and PQC support is procuring into a market where that specific combination may not yet have a completed validation.
How long does FIPS 140-3 validation typically take?
Historically more than two years on average from lab submission to certification. This is a realistic planning assumption for any organization tracking a specific vendor’s PQC validation timeline rather than expecting near-term completion.
- Key Takeaways
- Key Custody: Where the Private Key Actually Lives
- Firmware Support vs. Validation: The Gap That Matters
- The FIPS 140-2 Sunset Complicates the Timing
- Performance, Backup, and High Availability
- A Procurement Checklist
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- A Compliance Question, Not an Algorithm Question
- Frequently Asked Questions
