Crypto4A Technologies has received a key U.S. government security validation for the cryptographic module underpinning its next-generation hardware security module, adding another piece of infrastructure for organizations preparing for the transition to post-quantum cryptography.
The Canadian cybersecurity company said its QASM cryptographic module has achieved Federal Information Processing Standard 140-3 Level 3 validation through the National Institute of Standards and Technology’s Cryptographic Module Validation Program. QASM is designed to support the post-quantum cryptography algorithms standardized by NIST.
The validation is significant because hardware security modules, or HSMs, sit at the foundation of many security systems. The specialized devices generate, protect and manage cryptographic keys used to secure financial transactions, government networks, critical infrastructure and other sensitive systems.
FIPS 140-3 establishes security requirements for cryptographic modules used by U.S. federal agencies and is also widely used as a security benchmark outside government. Level 3 requirements include protections against physical tampering, identity-based authentication and safeguards around sensitive cryptographic keys and other security parameters.
The validation applies to Crypto4A’s QASM module rather than serving as a general certification of every product or system using the technology.
The company said QASM supports all of the post-quantum algorithms standardized by NIST, allowing organizations to combine validated hardware security with cryptography designed to withstand attacks from future quantum computers. That capability is intended to help organizations replace vulnerable cryptographic systems without abandoning the hardware-based protections already used for sensitive keys.
“Trust in the digital economy depends on independently validated cryptographic foundations. Crypto4A’s achievement of NIST FIPS 140-3 Level 3 provides the highest level of assurance that cryptographic keys are protected against both today’s threats and the realities of a post-quantum future. This level of certification matters because it gives organizations confidence that their trust anchors are built on rigor, resilience, and verifiable security,” said Amit Sinha, CEO and Board Member, DigiCert.
The validation comes as governments and businesses begin moving toward post-quantum cryptography following NIST’s publication of its first three finalized PQC standards in 2024. The transition is expected to take years because cryptographic technology is embedded throughout software, hardware, communications networks and other infrastructure.
Large-scale, fault-tolerant quantum computers capable of breaking widely used public-key cryptography do not yet exist, and their arrival remains uncertain. The security concern is that sufficiently powerful quantum computers could eventually undermine algorithms such as RSA and elliptic-curve cryptography that are widely used for encryption, digital signatures and identity verification.
That has prompted organizations to begin inventorying cryptographic systems and adopting crypto-agile infrastructure capable of supporting new algorithms as standards and threats change.
“Quantum computing is moving at an ever-faster pace towards being able to hack into today’s networks faster than you can snap your fingers ‐ and most of the systems we rely on aren’t ready for it. That’s why we set out to build the world’s first fully quantum-safe hardware security module. This certification represents years of an uncompromising commitment to engineering and strong security foundations that can guard against the cybersecurity threats of the future. Being the first company in the world to achieve NIST FIPS 140-3 Level 3 for quantum-safe technology underscores Crypto4A’s leadership in building the hardware needed to rekey the global economy,” said Bruno Couillard, CEO and Co-Founder of Crypto4A.
Crypto4A describes the module as the first quantum-safe HSM technology supporting all NIST-standardized PQC algorithms to achieve FIPS 140-3 Level 3 validation. The validation provides an independently tested security foundation for organizations beginning migrations to post-quantum systems, although broader deployment will depend on how the module is integrated into applications and existing security infrastructure.



