Navigation

Get in touch
Logo
News

Thales HSM: Luna and payShield in operation

Thales runs three hardware lines: Luna for general applications, payShield for card payments and ProtectServer for custom code inside the device. We compare Luna 7 and the new Luna 8 platform with you, connect the modules to your applications and take over operations.

Try product
  • FIPS 140-3 Level 3
  • Common Criteria EAL4+
  • eIDAS QSCD
  • PCI HSM v3
Thales Luna 8 network HSM in a turntable view
Product photo: Thales

Thales in profile

A hardware security module creates and stores keys in certified hardware and never releases them in plaintext. At Thales the portfolio splits by task: Luna serves general applications over PKCS#11, payShield processes PINs and card keys in payments, and ProtectServer runs custom code inside the security boundary through functionality modules.

Cryptography and hardware security modules are our core competence. We know the Universal Client, partition provisioning through Crypto Command Center and the path from Luna 7 to Luna 8, and we plan your project along the certificates your regulator asks for.

Luna, payShield, ProtectServer, Data Protection on Demand
FIPS 140-3 Level 3, NIST certificate 4684
ML-KEM, ML-DSA, LMS, HSS
Appliance, PCIe card, USB device, cloud service

The series in detail

Luna 8 Network HSM

Thales introduced Luna 8 in August 2026 as the first product on a new platform with a crypto processor of its own design. The validations for FIPS 140-3 Level 3 and Common Criteria are still in progress, so whoever needs a valid certificate keeps buying Luna 7.

View device illustration

Models

Luna 8 Network HSM: Models
Luna 100 StandardOne container, 128 MB key storage
Luna 150 EnterpriseUp to 6 containers, 1,024 MB key storage
Luna 190 MaximumUp to 15 containers, 4,096 MB key storage
Form factors
1U appliance with four 10 Gbit ports
Operation
Your own data center, Hosting at a service provider

Certifications

  • FIPS 140-3 Level 3 in progress
  • Common Criteria EAL4+ per EN 419 221-5 in progress
  • QSCD for eIDAS 2 in progress
  • INMETRO, NITES and NATO SECRET in progress

Features

  • Each container is a separate Luna 8 instance with up to 10 partitions
  • One or two crypto modules per 1U, up to 30 instances in total
  • A separate firmware version per container
  • ML-KEM per FIPS 203, ML-DSA per FIPS 204 plus LMS and HSS
  • Entropy from a quantum random number generator
  • Backwards compatible through the Luna HSM Universal Client

Vendor information

Luna 7 Network HSM

The Luna 7 Network HSM carries the certificates that tenders ask for today, among them FIPS 140-3 Level 3 for the K7 module and Common Criteria EAL4+ per EN 419 221-5. The A models log administrators in with a password, the S models also require the PED, a separate input device for the login.

Thales Luna 7 network HSM in a turntable view
Product photo: Thales

Models

Luna 7 Network HSM: Models
A700 and S7001,000 RSA-2048 operations per second, 5 partitions
A750 and S7505,000 RSA-2048 operations per second, 5 to 20 partitions
A790 and S79010,000 RSA-2048 operations per second, 10 to 100 partitions
Form factors
1U network appliance
Operation
Your own data center, Hybrid with Luna Cloud HSM

Certifications

  • FIPS 140-3 Level 3, NIST certificate 4684 for the K7 module
  • FIPS 140-2 Level 3
  • Common Criteria EAL4+ per EN 419 221-5
  • Listed as QSCD

Features

  • ECC P-256 with 2,000, 10,000 or 20,000 operations per second by tier
  • Firmware 7.9 from July 29, 2025 brings ML-KEM and ML-DSA
  • Login with a password or with the PED
  • Key cloning and backup together with Luna Cloud HSM

Vendor information

Luna 7 PCIe HSM and USB HSM

The PCIe card sits in the application server and reaches the same performance tiers as the network device, which keeps the paths short for device makers and latency critical services. The U700 USB device holds one partition with 32 MB of storage and serves the offline root of a PKI.

Thales Luna PCIe HSM as a plug-in card
Product photo: Thales

Models

Luna 7 PCIe HSM and USB HSM: Models
PCIe A700 to A790Same performance tiers as the network devices
PCIe S700 to S790Login through the PED
U700One partition, 32 MB storage, USB 3.0 Type-C
Form factors
PCIe card, USB device
Operation
Application server, Workplace without a network connection

Certifications

  • FIPS 140-2 Level 3
  • FIPS 140-3 for the K7 module, NIST certificate 4684
  • Common Criteria EAL4+ per EN 419 221-5
  • Listed as QSCD
  • U700 at FIPS 140-3 Level 3 per the product page, in review on the compliance page

Features

  • Drivers for Windows and Linux
  • Embedded by manufacturers into their own devices
  • U700 for offline root certificate authorities and for your own keys in the cloud
  • Same performance tiers and throughput as the Luna 7 Network HSM

Vendor information

Luna Cloud HSM on Data Protection on Demand

Data Protection on Demand is the Thales marketplace where you obtain Luna Cloud HSM and ready made services for signing, code signing and databases. The services run on hardware validated to FIPS 140-2 Level 3, and Hybrid Luna connects them to your own devices.

Marketplace of Thales Data Protection on Demand
Product photo: Thales

Models

Luna Cloud HSM on Data Protection on Demand: Models
Luna Cloud HSMGeneral service for keys and signatures
Digital Signing and Java Code SignerServices for signatures and signed code
Microsoft ADCS and AuthenticodeServices for Windows PKI and code signing
Oracle TDE and SQL ServerKeys for database encryption
Luna Key Broker for Microsoft DKEKey brokering for Double Key Encryption
Hybrid Luna HSMConnection between cloud service and your own device
Form factors
Cloud service
Operation
Cloud service from Thales, Hybrid with your own Luna devices

Certifications

  • Hardware validated to FIPS 140-2 Level 3

Features

  • Further services for CyberArk, Hyperledger and PKI keys
  • Luna HSM Backup secures keys out of the service
  • CipherTrust Key Management Services in the same marketplace
  • payShield Cloud HSM as a hosted device for Azure, AWS and Google Cloud

Vendor information

payShield 10K

The payShield 10K processes PINs, card keys and transactions at issuers, acquirers and networks and carries the PCI HSM v3 approval. Thales states neither a FIPS 140-3 validation nor post-quantum algorithms for this device.

Thales payShield 10K in a turntable view
Product photo: Thales

Models

payShield 10K: Models
PS10-STwo host ports at 1 Gbps
PS10-DHost ports at 10 Gbps
PS10-FConnection over FICON
Form factors
1U appliance
Operation
Your own data center, payShield Cloud HSM as a hosted device

Certifications

  • FIPS 140-2 Level 3 for the TASP
  • PCI HSM v3 including RAP
  • PCI HSM v3 KLD for the Trusted Management Device
  • AusPayNet, CB HSM, GBIC and Bancontact

Features

  • Performance per license: 25, 60, 250, 1,000, 2,500 or 10,000 calls per second
  • Performance tier extendable later by license
  • Up to 20 LMK partitions for separated key sets
  • Managed through payShield Manager and payShield Monitor
  • Key loading through the Trusted Management Device

Vendor information

ProtectServer 3

ProtectServer 3 targets teams that want to run their own logic inside the device, because functionality modules execute within the security boundary. The devices carry FIPS 140-2 Level 3, and the FIPS 140-3 Level 3 validation has been running since firmware 7.03.03 of September 2025.

Thales ProtectServer 3 External HSM
Product photo: Thales

Models

ProtectServer 3: Models
ProtectServer 3+ External1U, two power supplies, four Gigabit ports
ProtectServer 3 ExternalCompact housing for smaller environments
ProtectServer 3 PCIePerformance tiers PL25, PL220 and PL3500
Form factors
1U appliance, Compact desktop device, PCIe card
Operation
Your own data center, Application server with a PCIe card

Certifications

  • FIPS 140-2 Level 3
  • FIPS 140-3 Level 3 in progress, firmware 7.03.03 since September 2025

Features

  • Functionality modules run custom code inside the security boundary
  • Software emulator for development and test
  • Two power supplies and four Gigabit ports on the ProtectServer 3+ External

Vendor information

How you find the right line

Four questions decide the choice at Thales: the required evidence, the load with the number of partitions, the type of application and the operating model. We check the four points together and put the reasons for the choice in writing.

Certificate today or platform for tomorrow

Luna 7 carries FIPS 140-3 Level 3 and Common Criteria EAL4+ and therefore fits tenders that demand proof. At Luna 8 these validations are still running, and in exchange the platform brings more containers and the new post-quantum algorithms.

Load and partitions

The Luna 7 Network HSM ranges from 1,000 to 10,000 RSA-2048 operations per second and from 5 to 100 partitions. Luna 8 counts differently: up to 15 containers per device, each container with up to 10 partitions.

Application or payments

PIN processing and card keys require the payShield 10K with the PCI HSM v3 approval. PKI, code signing and databases run on Luna, and custom logic inside the device belongs on ProtectServer 3.

Operating model

You can run the devices yourself, you can hand operations to us, or you can book Luna Cloud HSM and payShield Cloud HSM as a service. The entire solution runs in German data centers.

What we handle around Thales

The real work sits around the device: selection, connecting the applications, the key ceremony, monitoring and operations. One team accompanies you from consulting to operations.

  • HSM consulting and integration

    We compare the Luna tiers against your load, set up the partitions and connect your applications through the Luna HSM Universal Client. We record the key ceremony for the audit.

    HSM & Key Management

  • PQC readiness

    We record which applications rest on RSA and ECC, because quantum computers can break both, and we plan the move to ML-KEM and ML-DSA. On Luna 7 firmware 7.9 delivers these algorithms, on Luna 8 they belong to the platform.

    Post-Quantum Cryptography

  • Cloud

    We select the right services on Data Protection on Demand, connect them to your applications and keep keys in your own data center through Hybrid Luna. payShield Cloud HSM can run with Azure, AWS and Google Cloud.

    Cloud

Standards and evidence

Five rules decide selection and documentation on Thales projects. We assign each rule the line that carries it today and name the validations that are still running.

Requirement / Demands / OTOKO® delivers
RequirementDemandsOTOKO® delivers
FIPS 140-3Validated crypto modules with a defined physical protection levelLuna 7 at Level 3 with NIST certificate 4684, Luna 8 and ProtectServer 3 in progress
Common Criteria EN 419 221-5Certified signing module for trust servicesLuna 7 as a network device and PCIe card with EAL4+, Luna 8 in progress
eIDASQualified signature creation device at the trust service providerLuna 7 is listed as QSCD, the QSCD review for eIDAS 2 runs at Luna 8
PCI HSMCertified hardware for PINs and card keyspayShield 10K per v3 with RAP, plus the KLD review of the Trusted Management Device
National card approvalsApprovals of the national payment schemespayShield 10K with AusPayNet, CB HSM, GBIC and Bancontact, a vendor statement without a certificate number

Frequently asked questions about Thales

Related topics

You would like to learn more about

Thales

Thales runs three hardware lines: Luna for general applications, payShield for card payments and ProtectServer for custom code inside the device. We compare Luna 7 and the new Luna 8 platform with you, connect the modules to your applications and take over operations.

Our clients

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.