Navigation

Get in touch
Logo
News

IDEMIA Sphere HSM: Secure Elements instead of one processor

IDEMIA Secure Transactions entered the market for hardware security modules with the Sphere HSM in September 2025 and builds it from a matrix of Secure Elements. We sort the vendor statements from the documented facts, check the fit for your applications and support installation and operations.

Try product
  • Matrix of Secure Elements
  • 32SE to 128SE
  • About 50 watts
  • FIPS 140-3 Level 3 as a vendor statement
IDEMIA Sphere HSM
Product photo: IDEMIA

IDEMIA at a glance

The Sphere HSM spreads the cryptography across many Secure Elements, which are tamper resistant microcontrollers, and works without a central main processor. Whoever needs more throughput adds further Secure Elements, while the device draws about 50 watts and runs without fans. IDEMIA designs and pre-configures the devices in France and aims them at post-quantum algorithms.

Cryptography and hardware security modules are our core competence. On a young product we separate the documented facts from the vendor statements, check the fit against your applications and run your project from the first selection to daily operations.

Matrix of Secure Elements without a central main processor
Desktop and rack, 32SE to 128SE
About 50 watts, no fans, no battery replacement
FIPS 140-3 Level 3 as a vendor statement, no CMVP entry

The series in detail

IDEMIA Sphere HSM

The Sphere HSM has been on the market since September 2025 and spreads keys and computing work across a matrix of Secure Elements. Without a central main processor the throughput grows with every added element, and several tenants work in separate security domains.

View device illustration

Models

IDEMIA Sphere HSM: Models
Matrix of Secure ElementsMany protected microcontrollers instead of one main processor
Growth with further Secure ElementsMore throughput through added elements in the device
Security domainsSeparated tenants on one device
Cluster with failoverActive devices take over operations for each other
Form factors
Desktop device, Rack device
Operation
Your own data center, Cloud

Certifications

  • FIPS 140-3 Level 3 as a vendor statement from the press release
  • No entry found in the CMVP validation list
  • No statement found on PCI PTS, Common Criteria or ANSSI

Features

  • About 50 watts of power draw in operation
  • No fans and no battery replacement
  • Designed for post-quantum algorithms
  • Designed in France and pre-configured there
  • Security domains separate several tenants

Vendor information

Sphere HSM sizes from 32SE to 128SE

The line reaches from the desktop device to the rack device and from 32 Secure Elements up to 128 Secure Elements. You pay for the size you need and add further elements later without exchanging the device.

View device illustration

Models

Sphere HSM sizes from 32SE to 128SE: Models
32SESmallest stated build with 32 Secure Elements
128SELargest stated build with 128 Secure Elements
Form factors
Desktop device, Rack device
Operation
Your own data center, Cloud

Certifications

  • FIPS 140-3 Level 3 as a vendor statement, no CMVP entry

Features

  • Desktop device for small environments
  • Rack device for the server cabinet
  • Growth in steps from 32SE to 128SE
  • Cold storage of keys as an option
  • Active cluster with failover

Vendor information

IDEMIA Sphere Cryptographic Library

The Sphere Cryptographic Library bundles classical algorithms and post-quantum algorithms in one library and was published in July 2025. Its algorithms are validated in the CAVP program, and IDEMIA offers an advisory service for the move to post-quantum algorithms.

View device illustration

Models

IDEMIA Sphere Cryptographic Library: Models
Classical algorithmsCovered by the CAVP validation
Post-quantum algorithmsCovered by the CAVP validation
Form factors
Software library
Operation
Your own data center, Cloud

Certifications

  • Algorithms validated in the CAVP program, published in July 2025

Features

  • Classical algorithms and post-quantum algorithms in one library
  • Algorithms validated in the CAVP program
  • Published in July 2025
  • Vendor advisory for the move to post-quantum algorithms

Vendor information

How you find the right size

Four questions decide the choice: the size, the required proof of validation, the applications with their interfaces and the operating model. We clear them in a workshop and record for every figure whether it is documented or a vendor statement.

Size

The build ranges from 32 Secure Elements to 128 Secure Elements, and you raise it later with further elements. We translate your load from signing, key generation and encryption into a size and plan the later growth into it.

Proof of validation

IDEMIA names FIPS 140-3 Level 3 in the press release, and no entry in the CMVP validation list can be found for it. No statement on PCI PTS, Common Criteria or ANSSI is available, so we check up front what your regulator accepts as proof.

Applications and interfaces

IDEMIA names as applications PKI and certificate authorities, code signing, identity and access management, payment processing, data encryption, cloud key management and digital identity. The list of programming interfaces is not published so far, so we clear it with the vendor before every connection.

Operating model

You run the device in your own data center or in the cloud, with cold storage for rarely used keys and an active cluster with failover. The entire solution runs in German data centers.

What we deliver around IDEMIA

We deliver the work around the device: checking the statements, sizing the build, connecting the applications, the key ceremony and monitoring. One team accompanies you from consulting to operations.

  • HSM consulting and integration

    We size the number of Secure Elements to your load, cut the security domains to your tenants, clear the interfaces with the vendor and document the key ceremony in an audit proof form.

    HSM & Key Management

  • PQC readiness

    We record which keys and protocols rest on RSA and ECC, because quantum computers threaten both algorithms. We then check which post-quantum algorithms the Sphere Cryptographic Library covers for your use case.

    Post-Quantum Cryptography

  • Cybersecurity

    We monitor the devices in operation, separate administration from application, review roles and logs regularly and feed the events into your SIEM, the system that collects and rates security messages.

    Cybersecurity

Standards and evidence

Five rules decide the selection and the documentation on IDEMIA projects. We tell you which statement the vendor makes and which proof exists for it today.

Requirement / Demands / OTOKO® delivers
RequirementDemandsOTOKO® delivers
FIPS 140-3Validated crypto modules with a defined physical protection levelLevel 3 as a vendor statement from the press release, no CMVP entry to be found
eIDAS 2.0Certified signature creation device at the trust service providerIDEMIA aims the Sphere HSM at it, a confirmation as a QSCD is not available
NIS2Risk management and evidence for important and essential entitiesSphere HSM as the key store, we produce the evidence in the project
DORAResilient IT in the financial sector with evidence about service providersCluster with failover, we document operations and logs along with it
Cyber Resilience ActSecure products with digital elements across the life cycleIDEMIA names the alignment with the regulation, we check the proof per version

Frequently asked questions about IDEMIA

Related topics

You would like to learn more about

IDEMIA

IDEMIA Secure Transactions entered the market for hardware security modules with the Sphere HSM in September 2025 and builds it from a matrix of Secure Elements. We sort the vendor statements from the documented facts, check the fit for your applications and support installation and operations.

Our clients

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.