The private key is generated and used inside the device and is designed to never be exportable — that is the entire security proposition.
What an HSM actually does
A hardware security module (HSM) is a tamper-resistant computing device — physical appliance or cloud instance — that generates, stores, and uses cryptographic keys without ever exposing the private key material to the outside. Signing happens inside the device; the key never leaves it. If your organisation issues certificates, runs a CA, or must prove that signing keys could not have been copied, the HSM is the machine that makes that claim credible. If you only buy e-signature seats from a provider, the provider's HSMs are already part of what you are paying for.
At a glance
Five facts that cover most HSM questions in vendor conversations.
Certification matters more than hardware: FIPS 140-3 (US) and Common Criteria are what auditors and regulators actually check.
Cloud HSM from AWS, Azure, or Google is now the default choice — no shipping, racking, or HSM admin team required.
Under eIDAS, a QTSP's qualified seal/signature keys must live in a QSCD — a certified secure device, usually an HSM.
Most enterprises buying e-signatures never touch an HSM directly; they inherit one through their platform's trust infrastructure.
On-premise HSM vs cloud HSM vs managed signing platform
Three realistic ways a signing workload ends up protected by an HSM, compared on what a buyer actually cares about.
| On-premise HSM | Cloud HSM | Managed e-signature platform | |
|---|---|---|---|
| Who operates it | Your security team | Your cloud team, in your account | The provider, as part of the service |
| Typical fit | Own CA, banking core, strict data residency | Self-built signing infrastructure in cloud | Contract, procurement, HR, sales workflows |
| Cost model | Capex per appliance + support contracts | Hourly per instance, 24/7 clusters add up monthly | Per-user or per-envelope subscription |
| Compliance proof | FIPS 140-3 / CC certificates you present yourself | Same certificates, cloud attestation added | Provider publishes certification and audit reports |
| Time to production | Weeks to months (procurement, racking, config) | Days once networking is sorted | Same day for standard signing workflows |
The standards that matter in 2026
Hardware without a certificate is just hardware. These are the marks regulators and enterprise security teams look for.
FIPS 140-3
The current US and de facto global benchmark for cryptographic modules, administered by NIST. New procurements should expect FIPS 140-3 validation rather than the legacy 140-2, which has moved to its maintenance-only historical phase. Validation is per module and level (1-4); level 3 is the common requirement for signing keys.
Common Criteria (EAL)
An international certification scheme, frequently demanded alongside FIPS in banking, government, and APAC tenders. HSM vendors such as Thales, Entrust, and Utimaco maintain both certifications for their flagship lines.
QSCD under eIDAS
In the EU, a Qualified Trust Service Provider must protect qualified signature and seal keys in a Qualified Electronic Signature/Seal Creation Device. In practice that means a certified HSM (physical or remote). With eIDAS 2.0 and the EU Digital Identity Wallet rolling out, qualified keys keep this requirement — the wallet changes how users authenticate, not how QTSPs protect keys.
Cloud attestation
AWS CloudHSM, Azure Dedicated HSM / Azure Cloud HSM, and Google Cloud HSM all publish FIPS 140-3 validated configurations. Your responsibility shifts from buying certificates to proving your cluster is configured in a validated way and logging key usage.
When you need your own HSM — and when you don't
The honest decision test, because owning HSMs is an operating burden that most signing workloads can avoid.
You probably need one
You run a CA or issue your own certificates, you are a regulated financial institution with in-house key management obligations, or a regulator/contract requires keys under your exclusive control with hardware-level proof.
You probably don't
You are signing contracts, NDAs, offers, and approvals with an e-signature platform. The platform's trust infrastructure — including its HSMs — is exactly what a SOC 2 report, certificate policy, and trust-service documentation cover. Ask the vendor for those instead of buying hardware.
The cost reality check
A dedicated cloud HSM cluster runs in the hundreds of US dollars per month before engineering time; on-premise appliances carry five-figure capex plus support. For a full cost breakdown of cloud HSM options and what a managed platform includes instead, see our HSM pricing and deployment analysis.
The middle path
Platforms that expose API-driven signing with bring-your-own-key or dedicated key isolation give enterprises hardware-level separation without operating the module. If your requirement is 'keys not shared with other tenants', ask for that capability by name.
Common questions
For advanced and qualified signatures, yes — the platform's keys are protected in certified hardware as part of its trust infrastructure. For simple electronic signatures, signing may rely on platform-level cryptography where an HSM is one layer of the overall key protection design, not a per-document guarantee. Ask the provider which signature level your plan uses.







