FIPS 140-3 LEVEL 3 VALIDATED HARDWARE · NIST CMVP #5331

Discover, migrate and operate a Quantum Safe digital trust platform.

Mobile-ID brings together cryptographic discovery, validated hardware, providers and SDKs, PKI, remote signing, data protection, verification and managed crypto-agility for a controlled transition from RSA/ECC to hybrid and PQC target states.

Overall level
3
Module type
Hardware
Status
Active
Initial validation
16 Jun 2026
Validation scope

Certificate #5331 validates the listed hardware and firmware module plus the approved services in its NIST Security Policy. PQC capability and algorithm-validation status are disclosed separately.

Trusted Key Token hardware trust anchor
NIST CMVP #5331FIPS 140-3 Level 3
Quantum-safe & crypto-agility control plane
  • Discover / CBOM
  • Trusted Key / HSM
  • CNG / PKCS#11 / Java
  • CA / TSA / Remote Signing
  • Documents / TLS / API
  • Interop / Evidence / Operations

NAMED PRODUCTS

From discovery to protected data, QKD, evidence, certificates and Web3 migration.

Pilot product

QuantumSafe Discovery Studio

Discover cryptographic exposure from packet captures, certificates, software dependencies and declared CBOM data—then turn findings into an owned migration backlog.

Explore →
Controlled pilot

QuantumSafe Evidence Shield

Augment existing PDF, CMS, XML and software artifacts with versioned quantum-safe evidence while preserving the original business object and verification history.

Explore →
Research / partner pilot

QuantumSafe QKD Bridge

Present QKD-derived keys through governed enterprise interfaces, synchronize approved key material with HSM/KMS controls and support PPK-based protected tunnels.

Explore →
Research preview

QuantumSafe Circuit Studio

Build and execute small quantum circuits in the browser, inspect amplitudes and probabilities, and connect quantum-computing concepts to PQC migration decisions.

Explore →
Controlled pilot

QuantumSafe Data Shield

Protect selected fields, files, messages and API payloads before they cross shared infrastructure, using versioned hybrid/PQC envelope profiles and protected backend key services.

Explore →
Solution preview

QuantumSafe Asset Assurance

Support auditors in validating wallet formats, challenge signatures, activity evidence, counterparty exposure and proof-of-control records across approved blockchain connectors.

Explore →
Research lab

QuantumSafe Web3 Migration Lab

Model the impact of post-quantum signatures on wallets, transactions, smart contracts, consensus interfaces and verification costs before committing to a chain migration design.

Explore →
Pilot platform

QuantumSafe Certificate Fabric

Design, issue, validate and migrate classical, hybrid and PQC certificate profiles across CA, RA, VA, TSA, HSM and relying-party ecosystems.

Explore →

WHY ACT NOW

Quantum-safe migration is an ecosystem program—not a single algorithm upgrade.

Long-lived confidentiality, signatures and trust services depend on cryptography embedded across infrastructure, policy, software and operational evidence.

01

Long-lived confidentiality

Information collected today may remain valuable long enough for future cryptanalytic advances to matter.

02

Long-lived signatures

Contracts, certificates and legal evidence must remain verifiable across algorithm and certificate lifecycles.

03

Hidden dependencies

Public-key cryptography is embedded in CA, HSM, middleware, APIs, applications, devices and operational procedures.

04

Auditable change

Algorithm changes require policy, interoperability testing, version control, monitoring and an evidence trail.

QUANTUMSAFE PRODUCT ECOSYSTEM

One governed ecosystem—from cryptographic discovery to trusted operation.

Seven product pillars connect visibility, protected keys, application integration, trust services, data protection, verification and continuous crypto-agility. Every capability is labeled by evidence-backed maturity.

Public maturity modelValidatedAvailablePilotSolution architectureRoadmapResearch / partner track

TRUSTED KEY TOKEN

A validated hardware root of trust for high-assurance identity and signing.

The Trusted Key Token is a portable smart-card-based cryptographic module designed for strong authentication, digital signatures, secure online transactions and protection of sensitive data.

Trusted Key Token portable hardware cryptographic module

Designed for controlled deployment

  • Generate and use private keys inside the hardware boundary
  • Support strong authentication, identity and digital-signature workflows
  • Integrate through middleware instead of exposing cryptographic secrets
  • Provide a familiar trust anchor for phased RSA/ECC-to-PQC migration
01

PQC status—stated with an explicit boundary

FIPS 140-3

Validated boundary

The NIST record covers the identified module configurations and approved cryptographic services listed in the public Security Policy.

FIPS 203 / 204 / 205

Quantum-safe standards track

ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) are the principal NIST PQC standards referenced by the solution architecture.

Scope note

Deployment disclosure

PQC availability, parameter sets, firmware, performance and validation evidence must be confirmed for each deployment. Certificate #5331 is not represented here as PQC algorithm validation.

PQC ECOSYSTEM

Quantum Safe is a cross-cutting capability—not another isolated subsystem.

The migration affects how identities are enrolled, certificates are issued, keys are protected, signatures are created, time is trusted, status is validated and evidence is preserved.

  1. RA Identity & enrollment RA / TMS-RA
  2. CA Certificate issuance Root / Issuing CA
  3. KEY Key protection Token / HSM / QSCD
  4. SIGN Signing services Local / remote / eSeal
  5. TSA Trusted time Timestamp / LTV
  6. VA Validation VA / OCSP / CRL
  7. EVID Evidence & apps PAdES / DMS / eGov
Quantum-safe & crypto-agility control planeInventory · Algorithm policy · Hybrid profiles · Key lifecycle · Monitoring · Evidence

What changes inside each subsystem

CA · RA · VA · TSA · HSM · QSCD · Remote Signing · PAdES · Evidence

CA Root CA / Issuing CATrust chains, certificate profiles and lifecycle policy.
Role
Builds and signs trust chains, issues certificates and enforces certificate-policy controls.
PQC impact
New algorithm identifiers, larger keys and signatures, hybrid chains, CP/CPS updates and relying-party compatibility.
Mobile-ID delivery
Target architecture, algorithm policy, certificate profiles, HSM readiness, pilot and controlled cutover.
Evidence
Crypto inventory, profile matrix, policy OIDs, issuance and path-validation test reports.
RA RA / TMS-RAIdentity proofing, enrollment, renewal and revocation initiation.
Role
Links a verified identity to a key and certificate request through governed enrollment workflows.
PQC impact
PQC key enrollment, proof of possession, device binding, larger request objects and re-key procedures.
Mobile-ID delivery
TMS-RA integration, enrollment-policy design, device lifecycle and recovery or re-enrollment workflows.
Evidence
Identity-to-key traceability, enrollment test cases, approval logs and exception handling.
VA VA / OCSP / CRLCertificate-status distribution and relying-party validation.
Role
Publishes revocation status and helps applications determine whether certificates remain trustworthy.
PQC impact
Response-signing algorithms, payload growth, cache behaviour, dual validation and backward compatibility.
Mobile-ID delivery
Dual-stack OCSP/CRL design, responder profiles, performance testing and relying-party integration.
Evidence
Latency and load results, signed-response samples, revocation scenarios and verifier matrix.
TSA TSA / Timestamp / LTVTrusted time and long-term validation of signed evidence.
Role
Binds trusted time to data and supports preservation of signature evidence beyond certificate expiry.
PQC impact
Timestamp-token algorithms, archive timestamps, evidence renewal, larger containers and validation policy.
Mobile-ID delivery
Timestamp profiles, LTV architecture, renewal policy, TSA key protection and verifier integration.
Evidence
Timestamp samples, LTV validation reports, time-source controls and renewal test cases.
KEY Trusted Key / HSM / SAM / QSCDHardware-backed key custody, use policy and cryptographic agility.
Role
Protects CA, service or end-user keys and constrains how cryptographic operations are authorized.
PQC impact
Algorithm support, object size, memory, backup and recovery, rotation, firmware and hardware boundaries.
Mobile-ID delivery
Trusted Key Token, HSM/SAM/QSCD integration, key ceremonies, lifecycle controls and capability matrix.
Evidence
Module version, configuration baseline, key-ceremony record, access policy and validation references.
RSSP Remote SigningCentralized signing with strong signer authentication and controlled key use.
Role
Orchestrates signer authentication, signature activation, key use and evidence around a protected signing service.
PQC impact
PQC key custody, signature activation data, API payloads, transaction binding and hybrid signatures.
Mobile-ID delivery
Remote-signing architecture, SAM/QSCD controls, API integration, policy and transaction-confirmation flows.
Evidence
Authentication logs, signature-activation records, API test suite and end-to-end signing evidence.
DOC PAdES / CAdES / XAdES / ASiCSignature containers, business documents and interoperability.
Role
Packages signatures, certificates, timestamps and validation material into durable business evidence.
PQC impact
Algorithm OIDs, container size, library support, verifier behaviour and archival profiles.
Mobile-ID delivery
Format profiles, signing and validation libraries, middleware integration and test-corpus design.
Evidence
Signed sample corpus, cross-verifier results, version matrix and LTV or archival validation.
EVID Audit, evidence & operationsPolicy traceability, monitoring and proof that controls operated as designed.
Role
Connects architecture and cryptographic changes to approved policy, logs, monitoring and accountable ownership.
PQC impact
Crypto-inventory versioning, policy transitions, signed logs, evidence retention and exception management.
Mobile-ID delivery
Control catalogue, evidence model, monitoring design, operating procedures and review cadence.
Evidence
Readiness report, risk decisions, change approvals, validation reports and audit-ready package.

TRUSTED PQC SERVICES

A controlled, evidence-based transformation from discovery to operation.

Each phase produces auditable deliverables and a decision gate. The goal is to reduce migration risk without promising a zero-risk or universal big-bang replacement.

01ASSESS

PQC readiness assessment

Find where vulnerable public-key cryptography, long-lived data and operational dependencies exist.

Key outputs
  • Cryptographic inventory
  • Dependency and data-lifetime map
  • Quantum-risk priorities
02DESIGN

Architecture & policy

Define target states, algorithm policy, trust-service profiles and governance for crypto-agility.

Key outputs
  • Target architecture
  • Algorithm and certificate policy
  • Control and evidence model
03PILOT

Hybrid proof and interoperability

Test priority use cases with real middleware, devices, formats, verifiers and operational constraints.

Key outputs
  • Pilot implementation
  • Interoperability matrix
  • Performance and issue report
04MIGRATE

Integration & controlled rollout

Integrate CA, VA, TSA, key protection, signing, middleware, APIs and business applications in phases.

Key outputs
  • Implementation baseline
  • Cutover and rollback plan
  • Updated operating procedures
05VALIDATE

Validation & evidence

Verify functional, security, policy, compatibility and long-term evidence requirements before scale.

Key outputs
  • Validation report
  • Signed test corpus
  • Audit-ready evidence package
06OPERATE

Operate, monitor & improve

Manage algorithm, key, certificate, firmware and policy lifecycles as standards and products evolve.

Key outputs
  • Monitoring and review cadence
  • Lifecycle and exception process
  • Continuous-improvement backlog

STANDARDS & EVIDENCE

Claims that security, procurement and audit teams can verify.

FIPS 140-3 module validation and NIST post-quantum algorithm standards answer different questions. The site keeps those claims separate and links to primary evidence.

FIPS 140-3

Cryptographic module security

Defines security requirements for cryptographic modules. Certificate #5331 records Trusted Key Token at Overall Level 3 for the identified configurations.

Verify #5331
FIPS 203

ML-KEM key establishment

Specifies ML-KEM for establishing shared secret keys over a public channel in post-quantum deployments.

Read FIPS 203
FIPS 204

ML-DSA digital signatures

Specifies ML-DSA for generating and verifying post-quantum digital signatures.

Read FIPS 204
FIPS 205

SLH-DSA hash-based signatures

Specifies the stateless hash-based SLH-DSA signature scheme for post-quantum use cases.

Read FIPS 205

Claim and evidence matrix

Public wording, status and evidence for the principal product and service claims.

Evidence reviewed on 19 July 2026. Re-check the NIST record before publishing future revisions.
Public wording, status and evidence for the principal product and service claims.
ClaimStatusPublic evidenceApproved wording
Trusted Key module security boundary Validated NIST CMVP #5331 and Security Policy FIPS 140-3 Level 3 validated hardware module
Certificate status Active at review date NIST certificate record, reviewed 16 July 2026 Active at the last evidence review
Approved algorithms inside #5331 boundary Listed in public policy AES, ECDSA, RSA, SHA, HMAC, KAS/KDF under CAVP A4980 Approved services are those listed in the NIST Security Policy
ML-KEM / ML-DSA / SLH-DSA Confirm per deployment Product capability matrix, firmware and project validation evidence PQC engineering track; not claimed as covered by #5331
Application and middleware interoperability Version-specific Pilot test report and supported-version matrix Supported combinations are listed in the project matrix
Hybrid migration Service architecture Architecture, pilot, validation and migration deliverables Controlled transition designed to reduce disruption—not a zero-risk guarantee
Certificate caveat

The NIST record notes that generated sensitive security parameters depend on available entropy, and it does not assure the strength of externally loaded parameters. Review the complete record and Security Policy for procurement decisions.

CONTROLLED MIGRATION ROADMAP

Move from existing RSA/ECC to hybrid operation and, where justified, a PQC target state.

The target state is selected per use case, relying-party compatibility, product maturity, legal requirements and validated evidence—not by marketing deadline.

  1. 01
    Discover

    Inventory cryptography, data lifetimes, systems, owners and obligations.

  2. 02
    Design

    Select target states, policies, controls and pilot decision criteria.

  3. 03
    Pilot hybrid

    Test priority use cases with real products, versions and relying parties.

  4. 04
    Migrate

    Roll out by trust service, application group and evidence requirement.

  5. 05
    Validate

    Confirm security, policy, interoperability, performance and recovery.

  6. 06
    Operate

    Monitor standards, certificates, algorithms, firmware and exceptions.

ExistingRSA / ECC
TransitionalHybrid
TargetPQC where justified

PRIORITY USE CASES

Start with information and transactions that stay valuable the longest.

Prioritization should combine confidentiality lifetime, signature-verification lifetime, business value, regulatory exposure and cryptographic dependency.

TSP

Trust service providers

CA, VA, TSA, remote signing, certificate policy and long-term evidence.

FIN

Banking & financial services

High-value transactions, customer identity, contracts and regulated records.

GOV

Government & public services

Citizen records, digital identity, e-government workflows and archives.

CNI

Critical infrastructure

Operational technology, infrastructure identity, code signing and protected communications.

ENT

Enterprise records

eSeal, ERP/DMS approvals, legal documents, workflows and archival evidence.

TECHNICAL WORKSHOP

Turn Quantum Safe from a broad objective into an executable program.

A focused workshop aligns security, PKI, compliance, architecture and application owners around a shared scope and evidence plan.

Request a technical PoC
Workshop outputs
  • Cryptographic inventory and dependency hypotheses
  • Priority systems and long-lived data classes
  • Target architecture for CA, VA, TSA, key protection and signing
  • Hybrid pilot scope, interoperability matrix and decision gates
  • Evidence package, ownership model and migration roadmap

FAQ

Questions procurement, security and architecture teams usually ask.

What does “Quantum Safe” mean in this architecture?

It is a cross-cutting capability covering cryptographic inventory, algorithm policy, key protection, PKI, signing, validation, evidence and controlled migration. It is not treated as a standalone box beside CA or VA.

What exactly does NIST CMVP Certificate #5331 validate?

It records the Trusted Key Token Cryptographic Module as a FIPS 140-3 hardware module at Overall Level 3 for the configurations and services identified in the NIST record and Security Policy.

Are ML-KEM, ML-DSA or SLH-DSA validated under Certificate #5331?

The public Security Policy for #5331 lists approved classical services such as AES, ECDSA, RSA, SHA, HMAC, KAS and KDF. This site therefore does not claim that #5331 validates PQC algorithms. PQC capability and validation evidence must be confirmed separately for the target product and firmware.

Why use a hybrid migration stage?

A hybrid stage can preserve compatibility while organizations test PQC algorithms, products, policies, relying parties and operational evidence. The design must still be validated per use case; hybrid is not automatically the correct answer everywhere.

How do CA, VA, TSA and remote signing change with PQC?

They may require new algorithm identifiers, certificate and timestamp profiles, larger objects, updated HSM or token support, revised APIs, verifier changes, performance testing and updated policy or evidence packages.

Can Trusted Key Token integrate with current desktop and signing applications?

The architecture supports middleware-based integration. Actual support depends on the specific token model, firmware, operating system, middleware and application version, so the supported combination should be confirmed in an interoperability pilot.

What deliverables should a PQC readiness project produce?

At minimum: a cryptographic inventory, dependency and data-lifetime map, risk priorities, target architecture, algorithm policy, pilot plan, interoperability matrix, validation report and an owned migration roadmap.

How should an organization start?

Start with a scoped workshop and cryptographic inventory. Prioritize data and signatures with long protection lifetimes, then pilot one or two high-value trust-service paths before broad rollout.

CONTACT MOBILE-ID

Plan a QuantumSafe technical PoC.

Share the systems, compliance obligations and long-lived data you need to protect. A Mobile-ID specialist will review the request and propose the appropriate next step.

Office
Level 9, Thuy Loi 4 Building
286–288 Nguyen Xi Street
Binh Loi Trung Ward, Ho Chi Minh City, Vietnam
Contact-data notice

This supplied build includes no third-party analytics or marketing cookies. Contact-form data is sent only to the configured Mobile-ID endpoint. Confirm the final retention and privacy wording with Mobile-ID legal and security teams before production.

Email info@mobile-id.vn