What is the Luna 8 Network HSM?
Luna 8 Network HSM is the next generation of Luna HSM technology, built on the new Thales HSM platform. Designed to protect cryptographic keys, identities, applications, and digital transactions, Luna 8 combines quantum-ready security, crypto agility, operational efficiency, and scalable performance to help organizations prepare for future cryptographic challenges.
Integration, automation and scalability are increasingly important considerations for organizations modernizing their cryptographic infrastructure. Luna 8 combines support for post-quantum cryptography with the flexibility organizations need to adapt as security requirements continue to evolve.”
Luna 8 Network HSM Features & Benefits
The HSM for the Post-Quantum Era
Built on decades of Thales cryptographic expertise, Luna 8 is designed to meet the world's highest security certification standards while delivering industry-leading performance, including accelerated support for post-quantum cryptography.
Quantum-safe and future-ready by design
Luna 8 combines native PQC support, quantum-safe protections, and a scalable, crypto-agile architecture to deliver a quantum-safe root of trust ready for what’s next.
- Native PQC support with high throughput and low latency
- Quantum-safe updates, protocols, and internal security mechanisms
- Upgradeable architecture designed to adopt new algorithms, standards, and capabilities as requirements evolve
- 20x more energy efficient per transaction compared to previous generation HSMs
Our fastest HSM ever
Accelerate traditional and post-quantum workloads with the custom-designed Thales cryptographic processor built for high-volume use cases.
- Optimized for high-performance ML-DSA and ML-KEM operations in PQC infrastructure
- Scale high-throughput traditional crypto operations
- Built for high-volume operations and transactions including SSL/TLS key protection, code signing, digital IDs and more
Scalable, multi-tenant architecture
Scale securely across enterprise and hyperscale environments with isolated HSM instances and predictable performance.
- Each Thales HSM can contain one or two crypto modules
- Each crypto module is independent providing double the density for the same rack space
- Each crypto module can host up to 15x HSM instances allowing a maximum of 30x HSM instances per appliance when configured with two crypto modules
High-assurance key protection in hardware
Protect cryptographic keys throughout their lifecycle inside tamper-evident, high-assurance hardware.
- Keys remain protected inside the HSM
- Side-channel protection for the Thales custom-designed crypto processor
- Secure audit logging, device attestation, quorum authorization, and multi-factor authentication
Compliance-ready trust
Help meet demanding regulatory and audit requirements with high-assurance controls and a hardware platform designed for leading security certifications.
- Designed for FIPS 140-3 Level 3 and Common Criteria certification
- Supports compliance needs for GDPR, eIDAS, HIPAA, PCI DSS, and more
- Strengthens governance with flexible security policies, separation of duties, quorum authorization, and MFA
Contact a specialist about Thales Luna HSMs
Connect Luna HSMs across your application ecosystem
Support multiple use cases with one of the industry's broadest ecosystems of third-party applications and integrations. Quickly secure a large number of standard applications with our broad partner ecosystem – documented, out-of-the-box integrations with Thales Luna Network HSMs.
Migrate to Luna 8 with confidence
If you’re using Luna 7 today, moving to Luna 8 is designed to be straightforward and low risk. Luna 8 is backwards compatible, so your existing applications and use cases can continue to work through the Luna HSM Universal Client — helping you upgrade with confidence while minimizing disruption.
Looking for Luna 7?
Luna 7 Network HSM remains available for existing customers who need it. For product details, visit the Luna 7 product page.
Technology evolves. Dependability remains.
Luna Network HSM customers can rely on more than industry-leading hardware. They also benefit from Thales technical expertise, product support resources, firmware access, documentation, knowledge articles, and customer case management services.
Recommended resources
Featured resource
HSM Buyer’s Guide
Learn what to consider when choosing an HSM vendor, including certifications, deployment flexibility, integrations, scalability, operational control, and post-quantum readiness.
Frequently asked questions
What are the Luna Network HSM 8 specifications?
Superior Performance:
- Deliver high-speed PQC cryptographic operations with ML-DSA-65 and ML-KEM-768
- Scale high-throughput traditional crypto operations
Highest Security & Compliance:
- Keys always remain in tamper-evident hardware
- Meet compliance needs for GDPR, eIDAS, HIPAA, PCI-DSS, and more
- Multiple roles for strong separation of duties
- Quorum authorization with MofN and multi-factor authentication for increased security
- Side-channel protection
- High-assurance delivery with device attestation
- On-board dual entropy source including QRNG
- Support for external entropy source
- Securely backup keys in hardware with Luna Backup HSM for redundancy, reliability and disaster recovery
Easily Scale and Optimize Operational Cost:
- Each Thales HSM can contain one or two crypto modules; each crypto module is independent providing double the density for the same rack space
- Each crypto module can host up to 15x HSM instances, allowing a max of 30x HSM instances per appliance when configured with two crypto modules
- Run multiple Luna 8 firmware versions within secure containers on the same hardware
- Automate HSM administration and operational processes through APIs and CLI tools
- Integrate with existing IT infrastructure tools for monitoring, logging and metrics
- Out of band diagnostics and hardware utilization metrics
- Flexible security policies to meet your key management and compliance needs
- Increased portability, greater efficiency and less overhead using Luna Client in a container
Security Certifications:
- FIPS 140-3 Level 3*
- Common Criteria*
- Qualified Signature or Seal Creation Device (QSCD) listing for eIDAS 2 compliance*
- Brazil INMETRO Approved (Formerly ITI)*
- Singapore NITES Common Criteria Scheme*
- NATO approved for NATO SECRET*
* In Process
For a full list of technical specifications, please download the Luna 8 Network HSM Product Brief
What are the common use cases for Thales Luna hardware security modules?
Thales Luna HSMs are commonly used to protect PKI and certificate authority keys, secure TLS private keys, protect software-signing credentials, secure encryption keys used by databases and applications, support digital signatures and transaction signing, and provide centralized cryptographic services across on-premises and cloud environments. Additional use cases include post-quantum cryptography readiness, digital assets, telecommunications security, and IoT device security.
How does an HSM enhance cybersecurity for businesses?
A hardware security module, or HSM, strengthens cybersecurity by protecting cryptographic keys inside tamper-resistant hardware rather than exposing them in software or external trusted layers. By keeping keys protected in a dedicated hardware environment, HSMs help secure the cryptographic operations that protect data, applications, identities, transactions, and digital services.
HSMs also support stronger governance over key management by enforcing access controls, separation of duties, secure audit logging, quorum authorization, and multi-factor authentication. For organizations operating in regulated or high-risk environments, an HSM provides a high-assurance root of trust for encryption, signing, authentication, certificate protection, and other critical security functions.
What are the latest advancements in hardware security modules?
The latest HSM advancements are focused on helping organizations prepare for post-quantum cryptography, scale cryptographic services more efficiently, and simplify operations across complex IT environments. Modern HSMs are evolving beyond isolated key storage appliances into crypto-agile platforms that support emerging algorithms, secure multi-tenancy, automation, monitoring, and centralized cryptographic services.
Luna 8 brings these advancements together with native PQC support, a quantum-safe operating model, secure multi-tenant isolation, Quality of Service controls, APIs and CLI tools for automation, monitoring and logging integrations, and improved hardware utilization. It is also powered by a custom-designed Thales cryptographic processor engineered for high-volume operations, crypto agility, side-channel protection, and long-term roadmap control.
How do Thales Luna HSMs compare to other hardware security modules?
Thales Luna HSMs are designed to provide high-assurance, hardware-based key protection for enterprise, cloud, and hybrid environments. Recognized as the #1 General Purpose HSMs on PeerSpot, Luna HSMs combine strong security controls, broad application integration support, scalable deployment options, and long-standing cryptographic expertise to help organizations protect sensitive keys and secure critical digital infrastructure.
With Luna 8, Thales extends the Luna portfolio with quantum-ready security, high-performance cryptographic processing, multi-tenant scalability, crypto-agile architecture, and operational flexibility. Luna 8 is built on the new Thales HSM platform and powered by a custom-designed Thales cryptographic processor, supporting high throughput for both traditional and post-quantum algorithms. ABI Research has also identified Thales as the leader in total global HSM shipments.
Can Thales Luna HSMs be integrated with cloud security solutions?
Yes. Thales Luna HSMs can support cloud, hybrid-cloud, and multi-cloud security architectures by helping organizations protect and control the cryptographic keys used across cloud applications and services. This enables businesses to take advantage of cloud flexibility while maintaining strong governance over key ownership, access, and usage.
Luna HSMs can be used to support use cases such as bring your own key, hold your own key, database encryption, digital identity, code signing, SSL/TLS key protection, and application security. Luna 8 also supports modern operational models through APIs, CLI tools, monitoring and logging integrations, and Luna Client in a container, helping teams deploy and manage HSM-backed security across distributed environments.
How can existing Luna 7 customers migrate to Luna 8?
Luna 8 is designed to help existing Luna customers migrate with continuity and minimal disruption. The platform supports compatibility-focused migration through familiar interfaces, established Luna workflows, Universal Client support, and migration capabilities for existing key material.
For Luna 7 customers, Luna 8 is intended to support existing applications and use cases while adding greater performance, scalability, and quantum-ready capabilities. Customers can continue working with familiar operational models while preparing for new cryptographic requirements, higher throughput, and more scalable deployment architectures.
Is Luna 8 suitable for post-quantum cryptography initiatives?
Yes. Luna 8 is designed to help organizations prepare for post-quantum cryptography initiatives with a quantum-safe foundation of trust, native PQC support, and crypto-agile architecture. It supports high-throughput PQC operations, including ML-DSA and ML-KEM, helping organizations begin planning and testing PQC migration while maintaining support for traditional cryptographic workloads.
Luna 8 also supports quantum-safe updates, protocols, and internal security mechanisms, along with entropy options including QRNG and support for external entropy sources. Its upgradeable architecture is designed to help organizations adapt as PQC standards, algorithms, and security requirements continue to evolve.
Explore the Luna HSM portfolio
Flexible deployment for every need across Luna HSM products and related services.






















