M9 / Key management and HSMs

HSM validation reality: CAVP vs CMVP

PractitionerAdvisor

After this lesson you can

  • State, in NIST's own words, the difference between CAVP (algorithm validation) and CMVP (module validation) and which is the prerequisite for which
  • Compare a given vendor announcement with a CMVP certificate record and decide which one is really independently validated
  • Name at least two real CMVP-validated modules that support PQC today

Before thisPKCS#11 v3.2 post-quantum mechanisms

Mental model

When a vendor says “we are ready for PQC”, that sentence can hide three different realities: just a roadmap promise, an independent test that the algorithm works mathematically correctly (CAVP), or independent validation of the whole hardware module, physical and logical security included (CMVP). Telling these three apart is at the heart of deciding which module a bank generates its root CA key in.

CAVP and CMVP: NIST’s own definition

NIST’s own CMVP FAQ answers this directly: “Cryptographic algorithms approved for use in the modules must first be validated by the Cryptographic Algorithm Validation Program (CAVP), before submitting the module validation to the CMVP.” So CAVP is the prerequisite for CMVP: first the algorithm itself is validated (mathematical correctness, with test vectors), then the whole module using that algorithm (physical tamper resistance, key management, self-test routines, production process control) is validated through a separate, more comprehensive process. A vendor saying “we got CAVP” is a real and verifiable achievement, but it does not substitute for CMVP; for a root CA key ceremony, CMVP is what is really needed.

Two real examples: validated vs pending

Today (September 2026) two different situations sit side by side on the market, and that difference is exactly what this lesson wants to teach:

CMVP-validated (a real certificate exists):

  • Thales TCT Luna T7, Certificate #5450SOURCED, validated on 29 July 2026, with ML-DSA/ML-KEM/LMS in the algorithm list.
  • Crypto4A QASM Cryptographic Module, Certificate #5497SOURCED, validated on 19 August 2026, with ML-DSA/ML-KEM/LMS/SLH-DSA in the algorithm list.

CAVP only (algorithm tests passed, no module certificate):

  • Entrust nShield: CAVP validated, CMVP pendingSOURCED.
  • Utimaco Quantum Protect: CAVP only, no CMVP claimSOURCED.

Note that all four vendors have made real, verifiable progress on PQC algorithms; this is not a “good vendor, bad vendor” comparison, just a difference in validation stage. But that difference matters when making a production decision: generating a root CA key today in Thales’s or Crypto4A’s CMVP-certified module has a different risk profile from generating it in Entrust’s or Utimaco’s (not yet CMVP-certified) module.

Methodology note: in the initial research, the CAVP-only status of Entrust and Utimaco rested on trade press reports about a year old. To follow this lesson’s own discipline (check the live database, don’t rely on secondary news), the claim was re-checked by querying the CMVP database directly: Entrust’s most recent certificate (#5329, nShield 5s, validated 15 June 2026) still lists no PQC algorithm. The conclusion did not change, but the verification method was corrected; an example that a finding being right does not mean you stop questioning how you verified it.

The exact count is uncertain, honestly: CMVP’s search interface cannot be queried automatically, so we do not claim the exact number of PQC-capable, CMVP-validated modules; we know there are at least two (the two above), and there may be more. Claiming “there is only one” or “this is a comprehensive list” would violate the very discipline this lesson teaches.

How to read a CMVP certificate

When you open a certificate record (like the two examples above), check these fields in order: Module Name (exactly which product and firmware version), Vendor, Validation Date (when it was validated; an old date may not cover current firmware), Overall Level (a security level from 1 to 4; a bank’s root CA usually calls for Level 3), and Algorithm List (which algorithms are really within the certificate’s scope; there is a difference between a module saying “we support PQC” in general and actually seeing ML-DSA/ML-KEM in the list; if the list is empty or contains only classical algorithms, the PQC claim is not within that certificate’s scope). This five-minute reading habit is, as the original brief also stresses, one of the skills that separates people who can check a vendor claim from those who cannot.

Numbers to know

  • CAVP: is the algorithm's math right (a prerequisite for CMVP). CMVP: has the whole module (physical and logical security included) been validated
  • Today (September 2026) at least two CMVP-validated modules support PQC: Thales TCT Luna T7 (#5450) and Crypto4A QASM (#5497); Entrust nShield and Utimaco Quantum Protect are CAVP-only, CMVP pending

Lab: Check a vendor claim in the CMVP database

Requires: internet access. Check your setup

shell
# Open csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5450
Recorded output
Module: Luna T7, Vendor: Thales Trusted Cyber Technologies, Validation Date: 7/29/2026, Overall Level: 3; you will see ML-DSA/ML-KEM/LMS in the algorithm list
shell
# Open csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5497
Recorded output
Module: QASM Cryptographic Module, Vendor: Crypto4A Technologies Inc., Validation Date: 8/19/2026; you will see ML-DSA/ML-KEM/LMS/SLH-DSA in the algorithm list
shell
# Compare the Quantum Protect press release on utimaco.com with the CMVP search page
Recorded output
The press release says 'CAVP testing' and makes no CMVP certificate claim; on the CMVP search page you will not find a certificate with PQC algorithms for Utimaco (as of September 2026)

At the table

How to say this in a bank meeting.

To an executive
The difference between a vendor saying 'we are PQC ready' and an independent laboratory validating it is the kind of difference that can leave us exposed in an audit. Today we know which vendors are really validated and which are still at the roadmap stage.
To an architect
CAVP validates that the algorithm is implemented correctly (with test vectors); CMVP validates the whole module (physical security, key management, self-tests) and takes CAVP as a prerequisite. An HSM saying 'we support PQC' may not even be at CAVP level; generating a root CA key in that module without a CMVP certificate means taking on that risk.
Objection
“"Vendor X says 'we are ready for PQC'. Isn't that enough?"”
Answer
No, and we can show it with concrete examples: Entrust nShield and Utimaco Quantum Protect both received CAVP validation for PQC algorithms but have no CMVP certificate yet; it is pending. By contrast, Thales TCT Luna T7 (#5450) and Crypto4A QASM (#5497) really are CMVP certified. The difference between the two is the answer to which one is defensible today for a production root CA.

Sources

  • NIST CSRC, 2026. NIST's primary, official statement that CAVP is a prerequisite for CMVP (item P-13)

    item P-13 / 5 min

  • NIST CSRC, 2026. A second real, CMVP-validated, PQC-capable module besides Thales; refutes the assumption that 'there is only one'

    certificate record, algorithm list / 5 min

  • Utimaco, 2025. A real example of a CAVP-only vendor announcement with no CMVP claim, needed for comparison

    whole text, a short press release / 5 min

    Commercial stake: Utimaco is announcing its own product's success; stating openly that it is CAVP-only (not claiming CMVP) is honest, but it is still sales material

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    What does each of CAVP and CMVP validate, and which is the prerequisite for which?

  2. 02Recall

    As of today, which two HSM modules are really CMVP certified for PQC algorithms?

  3. 03Scenario

    A vendor tells you 'our ML-DSA algorithm has been tested by NIST'. Does that sentence imply CAVP or CMVP, and how do you resolve the ambiguity?

  4. 04Hostile

    An auditor asks 'How did you verify your vendor's PQC claim?' Which database and which certificate number do you point to?

Project linkContributes directly to the vendor assessment section of Project 4 (capstone); a concrete example of how to apply the CAVP/CMVP distinction when selecting an HSM vendor.