tech · quantum risk
Is HSM program Quantum Proof? Cyber Program & PQC
Verdict
An HSM program protects keys from extraction but does not quantum-proof classical algorithms inside the device. Demand vendor PQC support timelines and practice dual-control ceremonies for migration.
Overview
Program-level HSM governance covers ownership, ceremonies, firmware, and algorithm policy—beyond a single network TLS offload box.
See also network-oriented HSM page under Wave 7b for edge TLS context.
Program inventory focus: HSMs holding classical algorithms still issue classical trust. Typical classical surfaces: Root and intermediate CA keys; Code-signing and payment keys. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: Root and intermediate CA keys, Code-signing and payment keys
- Hash: Ceremony documentation
- Public-key exposure: HSMs holding classical algorithms still issue classical trust.
What breaks
- Single person with admin rights
- Classical-only firmware roadmap unknown
Mitigations
- Algorithm inventory per partition
- Vendor PQC questionnaires
- Ceremony runbooks for key migration
FAQ
Cloud HSM vs on-prem?
Same algorithm questions; shared responsibility differs.
FIPS validated means PQC?
No—check which algorithms are approved and implemented.
Key concepts (technical dictionary)
Terms used on this page — open a definition: