Skip to main content

IT security

What is an HSM (Hardware Security Module)?

An HSM is a physical device that protects cryptographic keys and performs encryption in secured hardware. See when an HSM is required, e.g. under eIDAS.

In short

An HSM (Hardware Security Module) is a physical, hardened device that stores cryptographic keys and performs encryption, signing and key generation inside secured hardware.

The point is that the private keys never leave the module: even an attacker with full access to the server cannot copy them. HSMs are certified against standards such as FIPS 140 and Common Criteria and are used where keys are business-critical, for example for root certificates in a PKI, qualified signatures under eIDAS, payment infrastructure and code signing.

The alternative for many businesses is a cloud HSM or a managed key service, where the hardware is rented as a service. The HSM requirement typically surfaces in audits, eIDAS approvals and supplier requirements in finance and pharma. MI Support IT advises Danish businesses on secure key management and enterprise PKI, all the way from choosing the right HSM model through implementation to ongoing operations and certificate lifecycle.

Back to the glossary

What is an HSM?

An HSM (Hardware Security Module) is a dedicated physical device whose sole task is to protect cryptographic keys. All key generation, encryption and signing takes place inside the module, and the private keys can never be exported in plain text. If someone physically tampers with the device, it typically erases its own keys.

HSM vs. software keys

Keys stored as files on a server can be copied unnoticed by anyone with sufficient access, and a leak is often never discovered. Keys in an HSM, on the other hand, can only be used, not handed over: the module performs the operation and never releases the key itself. That is the difference auditors and standards such as FIPS 140 look for when the keys are business-critical.

When does compliance require an HSM?

The requirement typically arises in three places:

  1. Regulation and certification: qualified electronic signatures under eIDAS require the keys to be protected in certified hardware. See ENISA, the EU's cybersecurity agency, for the framework around trust services.
  2. PKI root keys: root and issuing certificates in a PKI are the foundation of the entire chain of trust. If they are compromised, everything issued from them is worthless.
  3. Supplier and industry requirements: finance, pharma and payment solutions often impose contractual requirements for FIPS 140-certified key protection, and code signing of software increasingly requires hardware-protected keys too.

HSM in your own rack or as a cloud service?

A physical HSM gives full control but requires redundancy, backup ceremonies and specialist knowledge. Cloud services such as Azure Key Vault with HSM protection (see Microsoft Learn) deliver the same certified protection as a service and are often a better fit for Danish SMBs. The choice depends on compliance requirements, integrations and who will operate the solution day to day.

The HSM and the rest of key management

An HSM solves the storage, but not the lifecycle: certificates still have to be issued, renewed and monitored, otherwise expiry means downtime. If you want the full picture, we have collected it in the e-book PKI and HSM in practice with a checklist for assessing your own maturity.

How MI Support IT can help

We have many years of specialist experience with enterprise PKI and key management, from designing certificate hierarchies to selecting and operating HSM solutions. Read more under PKI Management, or contact us for a concrete assessment of your needs.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.