Supported Hardware Security Modules (HSMs)

The following table lists HSM support for each SignServer deployment option. Integration methods include PKCS #11 standard and REST APIs. SignServer additionally supports software-based keys for lower security requirements or development.

PQC : Indicates PQC algorithm support.

HSM Type

Software stack

Cloud

Software Appliance

Hardware Appliance

Container Set

Network HSMs integrated with REST APIs

Azure Key Vault / MS Managed HSM​

check mark

check mark
Doc link

check mark
Doc link

Fortanix Data Security Manager (DSM)​ PQC

check mark


check mark

Doc link

Securosys Primus HSM and CloudHSM Service



check mark

Doc link



Network HSMs integrated with PKCS#11

AWS CloudHSM​

check mark

check mark

Doc link

Bull TrustWay Proteccio​

check mark


check mark

Doc link


CloudHSM Service




check mark

Doc link



Entrust nShield Connect​/5c PQC

check mark


check mark

Doc link


Securosys Primus




check mark

Doc link



SoftHSMv2

check mark





check mark

Doc link

Thales DPoD​

check mark


check mark
Doc link


Thales Luna 7 PQC

check mark


check mark
Doc link


check mark
Doc link

Thales USB HSM




check mark

Doc link



Thales TCT​

check mark


check mark

Doc link


Utimaco CryptoServer​

check mark



check mark
Doc link


check mark

Doc link

Utimaco u.trust Anchor​ PQC


check mark


check mark

Doc link


Internal Hardware Appliance PCIe HSMs integrated with PKCS#11

Thales Luna PCIe

check mark



check mark

Doc link


Utimaco PCIe

check mark



check mark

Doc link