FIPS 140-3 · HSM · PKI

YubiHSM 2 FIPS

YubiHSM 2 FIPS hardware security module

The YubiHSM 2, FIPS 140-3 validated, for PKI that has to satisfy an auditor.

Not a traditional HSM

A nano-format HSM, FIPS 140-3 validated, protecting infrastructure for which a rack-mounted appliance would be disproportionate.

Enhanced protection for cryptographic keys

Secure generation, storage and management of digital keys, performed in hardware.

Rapid integration with hardware-backed security

A comprehensive open-source cryptographic toolbox, with support for PKCS#11.

Simplified deployment for organisations of all sizes

An ultra-portable form factor at a price that suits both long-standing and emerging use cases.

Overview

The same device and the same integration path as the YubiHSM 2, validated to FIPS 140-3. Where a certificate authority underpins regulated services, auditors and procurement frameworks frequently require the key-protection hardware itself to be validated rather than merely equivalent. This is the variant that answers that requirement.

Specifications

Protocols
  • PKCS#11
  • YubiHSM KSP (Windows)
  • Native libraries
  • Direct USB
Form factors
  • Nano
  • USB-A
  • USB-C
Certification
FIPS 140-3 validated.
Durability
IP68 rated, crush resistant, no batteries, no moving parts

Key protection

Integration

Deployment

A YubiHSM 2 module beside the front USB ports of a rack server
The module occupies a front USB port — no rack unit, no separate appliance.

Best for

Regulated PKI — financial services, government, and critical infrastructure — where the HSM protecting the root must itself carry validation.

Typical uses

FIPS-validated certificate authority, regulated code signing, compliance-driven key management.

Request a quote Delivered from stock in Baku. Formal e-invoice for business buyers.