Navigation

Get in touch
Logo
News

IBM HSM: Keys in the mainframe and in the cloud

IBM builds Crypto Express cards for IBM Z, Power and x86 servers and adds key services in the IBM Cloud. We pick the right card or the right service with you and check the required validation level. We connect the CCA and EP11 modes to your applications. We plan the announced end dates in the cloud from the start.

Try product
  • FIPS 140-2 Level 4, CMVP 4558
  • FIPS 140-3 Level 3 in progress
  • PCI HSM with CCA 8.x
  • CRYSTALS-Dilithium and Kyber
IBM 4769 PCIe cryptographic coprocessor
Product photo: IBM

IBM at a glance

A hardware security module generates and stores cryptographic keys inside a certified device that never releases the key in plaintext. At IBM this device is the Crypto Express card with three operating modes. CCA covers payments, EP11 delivers Enterprise PKCS#11 for general applications, and the third mode only accelerates. The card sits in mainframes of the IBM Z line and in Power systems. As model 4770-001 it also runs in an x86 server under RHEL.

Cryptography and hardware security modules are our core competence. We know the CCA and EP11 modes, the connection through ICSF under z/OS and the announced end dates in the IBM Cloud. We run your project from the selection through the integration into daily operations.

Crypto Express cards, cloud services, key management
FIPS 140-2 Level 4, CMVP 4558
CRYSTALS-Dilithium and Kyber in hardware, hybrid ECDH with Kyber
PCIe card in IBM Z, Power and x86, plus IBM Cloud

The series in detail

IBM 4770 and Crypto Express 8S

The 4770 is the current card from IBM and carries the name Crypto Express 8S on IBM Z. It sits in z16 and z17, in Power11 systems and as model 4770-001 in x86 servers under RHEL. The card responds to tampering and is the only IBM card that also runs in x86 servers. It serves the z/OS operating system through the key service ICSF. It also serves Linux on Z, AIX, IBM i and Linux on Power.

Models

IBM 4770 and Crypto Express 8S: Models
Crypto Express 8S for IBM z16Feature code 0851
Crypto Express 8S for IBM z17Feature codes 0908 and 0909
4770 for Power11Feature codes EPG4, EPG5 and EPG6
4770-001x86 server under RHEL
Form factors
PCIe card
Operation
Your own data center, IBM Z from z16, Power11 systems, x86 servers under RHEL

Certifications

  • FIPS 140-2 Level 4, CMVP 4558, valid until September 21, 2026
  • FIPS 140-3 Level 3 in progress, hardware at Level 4
  • PCI HSM with CCA 8.x, on IBM Z still pending per the overview page

Features

  • Three operating modes: CCA for payments, EP11 for PKCS#11, plain accelerator
  • CRYSTALS-Dilithium and Kyber in hardware, plus hybrid ECDH with Kyber
  • Quantum-safe code load and quantum-safe attestation
  • RSA up to 4096 bit, ECC up to P-521 and Brainpool 512, Curve25519, Curve448, EdDSA and SHA-3
  • Format preserving encryption FF1 and FF2, plus TR-31, X9.143 and TR-34
  • More than 23,000 PIN operations per second, custom code through UDX

Vendor information

IBM 4769 and Crypto Express 7S

The 4769 is the card of the prior generation and runs as Crypto Express 7S. It sits in IBM z15 as well as in Power9 and Power10. For servers without IBM Z there is the 4769-001 variant. The card carries FIPS 140-2 Level 4 with certificate number 4079 and the PCI HSM validation from CCA 7.x. The older 4768 card also carries Level 4 with certificate number 3410, and the 4767 and 4765 cards are no longer sold.

View device illustration

Models

IBM 4769 and Crypto Express 7S: Models
Crypto Express 7S for IBM z15FIPS 140-2 Level 4 with CMVP 4079
4769 for Power9 and Power10The same card in the Power system
4769-001Variant for servers of the x64 line
4768 and Crypto Express 6SOlder card with CMVP 3410 and PCI HSM from CCA 6.0
Form factors
PCIe card
Operation
Your own data center, IBM z15, Power9 and Power10, Servers of the x64 line
Lifecycle
Prior generation of the 4770, still listed in the portfolio, while the older 4767 and 4765 cards are no longer sold

Certifications

  • FIPS 140-2 Level 4, CMVP 4079
  • PCI HSM from CCA 7.x
  • FIPS 140-2 Level 4, CMVP 3410 for the 4768

Features

  • Use in IBM z15 as well as in Power9 and Power10
  • Variant 4769-001 for servers of the x64 line
  • PCI HSM validation from CCA 7.x for payments
  • The 4768 carries PCI HSM from CCA 6.0
  • The 4767 and 4765 cards are no longer sold

Vendor information

IBM Cloud HSM 7.0 and 6.0

IBM Cloud HSM provides a dedicated appliance per customer in IBM Cloud Classic, technically a Thales Luna. Version 7.0 uses the Luna a750 with FIPS 140-2 Level 3, version 6.0 the Luna SA 7000 with Level 2. The service is deprecated and is supported until August 11, 2027. IBM recommends the Utimaco HSM service on IBM Cloud as the replacement.

Appliance of the IBM Cloud hardware security module
Product photo: IBM

Models

IBM Cloud HSM 7.0 and 6.0: Models
IBM Cloud HSM 7.0Thales Luna a750 with FIPS 140-2 Level 3
IBM Cloud HSM 6.0Thales Luna SA 7000 with FIPS 140-2 Level 2
Form factors
Dedicated appliance in IBM Cloud
Operation
IBM Cloud Classic
Lifecycle
Deprecated, supported until August 11, 2027, with the Utimaco HSM service on IBM Cloud as the recommended replacement

Certifications

  • FIPS 140-2 Level 3 for the Luna a750
  • FIPS 140-2 Level 2 for the Luna SA 7000

Features

  • One dedicated appliance per customer in IBM Cloud Classic
  • Support until August 11, 2027
  • Utimaco Payment HSM as a Service has been in the IBM Cloud catalog since August 22, 2025
  • The deprecation is described only in the IBM documentation

Vendor information

Hyper Protect Crypto Services and Key Protect Dedicated

Hyper Protect Crypto Services combines a single tenant key service with a cloud HSM on LinuxONE and Crypto Express. The service is deprecated, and the successor is IBM Cloud Key Protect Dedicated with a single tenant, KYOK and KMIP. IBM announced that successor on March 19, 2026. Its modules aim at FIPS 140-3 Level 4, and that validation is in progress. As hardware in the back end IBM names Utimaco, Thales and Marvell.

Models

Hyper Protect Crypto Services and Key Protect Dedicated: Models
Hyper Protect Crypto ServicesOne tenant per instance, HSM on LinuxONE
IBM Cloud Key Protect DedicatedSuccessor, announced on March 19, 2026
Key ProtectSeveral tenants, FIPS 140-2 Level 3, BYOK
Unified Key OrchestratorAlso for containers, z/OS and LinuxONE in your own data center
Form factors
Cloud service
Operation
IBM Cloud, Your own data center for the Unified Key Orchestrator
Lifecycle
Hyper Protect Crypto Services is deprecated, end of marketing on March 28, 2026, end of service on March 20, 2027, while the overview page names March 28, 2027

Certifications

  • FIPS 140-2 Level 4 for Hyper Protect Crypto Services
  • Common Criteria EAL4
  • FIPS 140-3 Level 4 for Key Protect Dedicated in progress
  • FIPS 140-2 Level 3 for Key Protect

Features

  • Keep Your Own Key, control over the key stays with you
  • PKCS#11 and GREP11 for applications, KMIP for key management systems
  • Unified Key Orchestrator drives AWS KMS, Azure Key Vault, Google Cloud KMS and Key Protect
  • Key Protect Dedicated names Utimaco, Thales and Marvell as hardware in the back end
  • A variant with PKCS#11 is announced

Vendor information

Guardium Key Lifecycle Manager

The Guardium Key Lifecycle Manager in version 4 is a key server and speaks KMIP, IPP and REST. It runs on bare metal, in a virtual machine or in a container. For the keys you can optionally attach a hardware security module at FIPS 140-3 Level 3. That way it separates the administration of keys from the applications that use them.

Models

Guardium Key Lifecycle Manager: Models
Guardium Key Lifecycle Manager v4Key server with KMIP, IPP and REST
Optional back end HSMAttachment of a module at FIPS 140-3 Level 3
Form factors
Bare metal, Virtual machine, Container
Operation
Your own data center, Virtualization, Container platform

Certifications

  • FIPS 140-3 Level 3 for the optional back end HSM

Features

  • KMIP for third party systems, plus IPP and REST
  • Operation on bare metal, in a virtual machine or in a container
  • Optional attachment of a module at FIPS 140-3 Level 3
  • Separates key administration from the application

Vendor information

How you pick the right model

Four points decide the choice at IBM: the platform, the operating mode of the card, the required validation level and the life cycle of the service. We clear them in a workshop and record the result in a decision paper.

Platform

The card follows the server: z16 and z17 take the Crypto Express 8S, while z15 takes the Crypto Express 7S. For Power11 there is the 4770, for Power9 and Power10 the 4769. In x86 servers only the 4770-001 runs, under RHEL.

Operating mode

CCA is the operating mode for payments and carries the PCI HSM validation there, while EP11 delivers Enterprise PKCS#11 for general applications. The plain accelerator computes without holding keys and suits pure compute load. We set the operating mode per card and application and document the decision.

Validation level and evidence

The 4770 carries FIPS 140-2 Level 4 with certificate number 4558, valid until September 21, 2026. The review against FIPS 140-3 Level 3 is still running, while the hardware meets Level 4. The PCI HSM validation applies from CCA 8.x, and for IBM Z the overview page names the status as pending.

Life cycle and operations

IBM Cloud HSM runs until August 11, 2027, and Hyper Protect Crypto Services ends as a service on March 20, 2027. Whoever plans in the cloud today picks Key Protect Dedicated. The entire solution runs in German data centers.

Our work around IBM

We do not only supply the card, we supply the work before and after it: selection, connection to ICSF and the applications, key ceremony, monitoring and operations. We document the key ceremony so that auditors can follow it later. One team accompanies you from consulting to operations.

  • HSM consulting and integration

    We select the card and the operating mode, set up CCA and EP11 and connect z/OS through ICSF. Linux and AIX follow, and we document the key ceremony in an audit proof form.

    HSM & Key Management

  • PQC readiness

    We record which keys and protocols rest on RSA and ECC today, because quantum computers threaten both algorithms. We then plan the path to CRYSTALS-Dilithium and Kyber in the card, plus the hybrid ECDH with Kyber. The quantum-safe code load and the attestation go into the same plan.

    Post-Quantum Cryptography

  • Cybersecurity

    We separate administration from application, review roles and logs and monitor the cards in daily operations. We feed the events into your SIEM, the system that collects and rates security messages.

    Cybersecurity

Standards and evidence

These five rules decide the choice of the card and the documentation in an IBM project. We tell you which card or service carries each one today and which proof is still in progress.

Requirement / Demands / OTOKO® delivers
RequirementDemandsOTOKO® delivers
FIPS 140-2Validated crypto modules with a defined physical protection level4770 at Level 4 with CMVP 4558, 4769 at Level 4 with CMVP 4079
FIPS 140-3Validation against the current standard for crypto modules4770 at Level 3 in progress, Key Protect Dedicated at Level 4 in progress
PCI HSMCertified hardware for PINs and card keys4770 from CCA 8.x, 4769 from CCA 7.x, on IBM Z pending per the overview page
Common Criteria EAL4Certified implementation of the key protectionHyper Protect Crypto Services on LinuxONE and Crypto Express
KMIP and X9.143Vendor neutral key management and protected key exchangeKMIP in the Guardium Key Lifecycle Manager, TR-31, X9.143 and TR-34 on the 4770

Frequently asked questions about IBM

Related topics

You would like to learn more about

IBM

IBM builds Crypto Express cards for IBM Z, Power and x86 servers and adds key services in the IBM Cloud. We pick the right card or the right service with you and check the required validation level. We connect the CCA and EP11 modes to your applications. We plan the announced end dates in the cloud from the start.

Our clients

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.