A hardware security module (HSM) is a dedicated cryptographic processor that generates, protects, stores, and uses cryptographic keys inside a hardened, tamper-resistant hardware boundary. HSMs act as trust anchors for encryption, signing, authentication, and other critical operations that support secure applications, transactions, identities, and digital services.
Thales HSMs are trusted by enterprises, financial institutions, governments, and cloud providers to protect cryptographic keys, secure high-value workloads, support compliance, and establish a hardware root of trust for digital operations across on-premises, cloud, hybrid, and payment environments.
Protect cryptographic keys and sensitive operations inside tamper-resistant, FIPS-validated hardware, where keys never leave the secure boundary.
Support security and regulatory requirements with certified HSMs designed for rigorous validation, auditability, and standards such as FIPS, Common Criteria, PCI DSS, eIDAS, GDPR, and more.
Support high-volume cryptographic workloads across on-premises, cloud, and hybrid environments with flexible deployment models and broad integration support.
Advance crypto agility and post-quantum readiness with HSM strategies designed to help organizations adapt to emerging standards and long-term security requirements.
Use centralized management, reporting, monitoring, and resource partitioning to simplify deployment and reduce complexity across cryptographic environments.
Introducing a new Thales Luna HSM built to help organizations establish a quantum-safe root of trust. Luna HSM 8 combines crypto agility, native post-quantum cryptography support, stronger security isolation, multi-tenant scalability, and management APIs designed to simplify automation, monitoring, and operational integration.
Transition to quantum-safe cryptography with PQC algorithms and quantum-safe root of trust
Optimized for high-volume PQC operations
Automate administration & integrate IT infrastructure tools for easy deployment & scalability
Modern Architecture for faster updates and new crypto mechanisms
Easy migration from Luna 7 with compatible APIs and key migration solution
Thales has an extensive HSM portfolio to help meet diverse business and security needs across environments, while staying ready for emerging technologies and future security requirements:
Luna HSMs have led the general-purpose HSM market for over 30 years, delivering a crypto-agile, quantum-safe foundation of trust for securing keys, identities, data, and applications. Built for high performance, scalability, and compliance, with FIPS 140-3 and Common Criteria certifications, helping meet the most stringent security and regulatory requirements.
Secure every payment card transaction with Thales payShield, that protects 80% of global POS transactions. Prevent fraud, accelerate time-to-market, ensure PCI DSS and EMV compliance, and scales confidently with high-performance cryptography built for today and tomorrow’s payment ecosystems.
Luna Cloud HSM and payShield Cloud HSM deliver HSM-as-a-Service capabilities for protecting cryptographic keys, applications, sensitive data, and payment transactions in cloud and hybrid environments. Available through the Thales Data Protection on Demand marketplace, they provide dedicated, FIPS-certified hardware security with rapid deployment, elastic scalability, and simplified operations.
As digital services expand across cloud, hybrid, and complex environments, organizations need trusted cryptographic infrastructure for PKI, payment security, code signing, key protection, and post-quantum readiness.
Thales helps build a stronger hardware root of trust with the control, flexibility, compliance support, and crypto agility needed to protect critical operations today and adapt as requirements evolve.
Build crypto agility into key protection strategies so organizations can adapt as PQC standards and requirements evolve.
Protect CA keys and signing operations that establish trusted identities for users, devices, applications, and services while supporting audit and compliance requirements.
Secure payment credentials, PINs, EMV processes, card issuance, and high-volume transaction workflows while supporting PCI DSS, EMV, and other payment security requirements.
Safeguard signing keys used to verify software, firmware, containers, and DevOps release pipelines.
Maintain control of cryptographic keys across cloud, on-premises, and hybrid environments to support security, sovereignty, and regulatory requirements.
Discuss the right HSM approach for your environment, compliance goals, and strategy.
Learn what to consider when choosing an HSM vendor, including certifications, deployment flexibility, integrations, scalability, operational control, and post-quantum readiness.
A hardware security module is a dedicated cryptographic processor that protects cryptographic keys inside tamper-resistant hardware and performs critical operations such as encryption, signing, and authentication within a secure boundary.
Enterprises buy hardware security modules to protect transactions, identities, and applications, as HSMs excel at securing cryptographic keys and provisioning encryption, decryption, authentication, and digital signing services for a wide range of applications.
Organizations typically use an HSM when they need a high-assurance hardware root of trust to protect cryptographic keys, secure critical operations such as PKI or code signing, and support stringent compliance or audit requirements.
HSMs help organizations protect cryptographic keys inside tamper-resistant hardware, reduce exposure from software-only key storage, support compliance, simplify secure key operations, integrate with enterprise applications, and establish a hardware root of trust for current and future cryptographic needs.
Luna HSMs play a critical role in protecting applications using emerging technologies:
General-purpose HSMs support broad enterprise cryptographic use cases such as PKI, TLS, code signing, database encryption, and digital identity. Payment HSMs are purpose-built for payment workflows such as PIN processing, card issuance, EMV, and transaction security.
Cloud HSM services provide on-demand access to HSM capabilities through cloud delivery models, while on-premises HSMs are dedicated appliances managed within customer environments. Many organizations use a mix of both to support hybrid strategies.
An HSM provides hardware-based key protection and secure cryptographic operations, while a key management system typically manages key lifecycle, policy, and orchestration functions. Organizations often use HSMs when they need stronger hardware-backed protection for key material.
Post-quantum cryptography matters because organizations need cryptographic infrastructure that can adapt to new algorithms and protect long-lived data and trust systems against emerging threats, including harvest now, decrypt later risks.
Hardware Security Modules (HSMs) are available in several form factors and deployment models to support different security, performance, and operational requirements. Thales offers network-attached HSMs (Luna Network HSM) for centralized enterprise deployments, embedded PCIe HSMs (Luna PCIe HSM) for low-latency application integration, USB-connected HSMs (Luna USB HSM) for portability and development use cases, cloud-based HSM-as-a-Service offerings (Luna Cloud HSM and payShield Cloud HSM), and dedicated backup HSMs (Luna Backup HSM) for key backup and disaster recovery.
The cost of a hardware security module (HSM) depends on factors such as the deployment model, licensing, performance and capacity requirements, integration effort, scalability, staffing, support, and ongoing administration. Buyers should evaluate total cost of ownership, including whether the HSM can support additional use cases and evolving requirements—such as post-quantum cryptography—without costly re-architecture or premature replacement.