M9 / Key management and HSMs

The cost of an HSM fleet refresh

PractitionerAdvisor

After this lesson you can

  • Explain, component by component, that the real bottleneck of an HSM fleet refresh is not hardware cost but the certification, procurement and ceremony timeline
  • Acknowledge that no reliable, measured timeline estimate exists publicly in this area today, and argue that this itself is a risk signal

Before thisPQC and smart cards

Mental model

The question “how long will it take to move our HSM fleet to PQC” is often confused with hardware procurement time: “we order the new devices and they arrive in a few weeks.” That completely misses the real bottleneck. Every step you saw in the previous four lessons of this module (CMVP certification, the key ceremony, KMIP integration, the smart card and token inventory) is a timeline item, and none of them is measured by “buy the hardware”.

The real timeline items

Putting together the earlier M9 lessons, the real components of an HSM fleet refresh are:

  1. Waiting for CMVP certification (hsm-validation-reality lesson): if the vendor’s chosen model is not yet CMVP certified (as is the case today for CAVP-only vendors such as Entrust and Utimaco), waiting for the certificate is a period you do not control.
  2. Procurement and delivery: the order-to-delivery time of the hardware itself, usually the shortest item.
  3. Integration and KMIP/PKCS#11 compatibility testing (pkcs11-pq-mechanisms, key-ceremony-and-kmip lessons): verifying that the new HSM really talks to the existing key management infrastructure (KMIP server, PKCS#11 clients).
  4. Key ceremony planning and execution (key-ceremony-and-kmip lesson): witness coordination, script update, rehearsal, the real ceremony.
  5. A separate approval process for payment HSMs: separately from general-purpose FIPS 140-3 certification, payment HSMs need a PCI-specific approval process that runs on a different schedule (you will go into detail in M10).

An honest gap: there is no reliable total figure

While preparing this lesson, we searched for a reliable, measured source with an open methodology for “how long does a bank take to refresh its HSM fleet” (Encryption Consulting’s financial sector analyses, NIST’s CMVP program page, and HSM vendors’ own public materials were checked) and found none. All that turned up were qualitative observations (“hardware replacement times are among the longest items”, with no figure) and unverifiable, indirect claims about the average duration of the CMVP process itself. Some single-analyst estimates circulating in the industry were found (for example claims that a migration program involves “thousands of tasks”), but these are figures with no stated methodology and no independent verification, and they are not repeated in this lesson.

The gap itself is what this lesson teaches: even practitioners have no real figure on this, and that is a risk signal in itself. Giving a board a single, unsourced number like “it takes X months” would be the kind of false certainty you try to avoid throughout this course. The right approach: present the five components above separately, each with its own uncertainty, and fill them in for your own bank with real assumptions (tagged ESTIMATED, assumptions open) using the cost model tool you will see in M13.

Why the gap is a finding in itself

Saying “we don’t know, nobody knows” in front of a hostile architect or an auditor may look weak; but this lesson argues the opposite. If an area is this active (vendors getting CAVP, CMVP certificates being issued, standards like PKCS#11 v3.2 being completed) and still nobody has a measured answer to “how long does a fleet refresh take”, that is a sign the area is not yet mature enough and that first movers will have to produce their own measurements. For a bank this means not “let’s wait and see” but “our own pilot program’s measurements will become the industry’s reference point”; the rollover runbook in your Project 2 (PQC PKI) should be the first concrete data point that fills exactly this gap.

Numbers to know

  • The 5 independent timeline items of an HSM fleet refresh: waiting for CMVP certification, procurement and delivery, integration testing, the key ceremony, and separate PCI approval for payment HSMs; none can be reduced to a single number

Lab: List the five items for your own bank

[not run] This is a planning exercise; real durations depend on your own vendor and current certification status

Requires: . Check your setup

shell
# For your own organization: which validation status is your current HSM vendor in (repeat the CAVP/CMVP check from the M9 lesson hsm-validation-reality), and for each of the five items mark who controls it (you, the vendor, or the certification authority)
Recorded output
A table: item, estimated duration range (ESTIMATED, assumptions written down), who controls it

At the table

How to say this in a bank meeting.

To an executive
The cost of an HSM fleet refresh is not the hardware invoice but the process: certification waits and ceremony coordination should appear as separate lines in budget planning.
To an architect
The five timeline items (CMVP wait, procurement, integration testing, ceremony, separate PCI approval for payment HSMs) are independent of each other; some can run in parallel (procurement and integration test preparation can move at the same time), but the CMVP wait and the ceremony sequence usually cannot.
Objection
“"How long did other banks take to do this? Do you have a reference point?"”
Answer
Honestly: no, there is no public, reliable reference, and that is a finding in itself (see below). Our own pilot program's measurements will be one of the first concrete reference points in this area.

Sources

  • Encryption Consulting (Tushar Sharma), 2026. An unmeasured but qualitatively accurate practitioner observation that hardware replacement times are among the longest items in a financial institution's PQC timeline; it also notes that payment HSMs need a PCI approval process separate from general-purpose FIPS 140-3

    hardware replacement times section / 10 min

    Commercial stake: Encryption Consulting is a PQC consultancy

  • NIST CSRC, 2026. The official program page on how long the CMVP process itself takes (from lab testing to certificate); the source of part of the timeline cost, though it gives no direct 'it takes X months' figure

    program overview, modernization updates / 10 min

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    What is usually the real bottleneck in an HSM fleet refresh: hardware cost, or process and timeline?

  2. 02Recall

    What additional steps lie between an HSM getting a CMVP certificate and that HSM going into production at a bank?

  3. 03Scenario

    A CFO says 'Let's buy the new HSMs and be done', thinking the cost is just the hardware price. Which additional timeline items (from the earlier M9 lessons) do you remind them of?

  4. 04Hostile

    A board member says 'How long will it take to move our HSM fleet to PQC? Give me one number.' Give an honest answer: explain why you cannot give one number, and which components you will list instead.

Project linkContributes to the HSM fleet row of Project 4's (capstone) migration roadmap, as a realistic component list and a note on timeline uncertainty.