Skip to main content
Cloud / AWS / Products / AWS Payment Cryptography - Managed Payment HSM

AWS Payment Cryptography - Managed Payment HSM

AWS Payment Cryptography provides payment cryptographic operations and key management as a managed service, without operating your own payment HSMs.

Security, Identity & Compliance
Pricing Model Per active key per month plus per API call
Availability Multiple Regions worldwide, including Frankfurt, Ireland, London and Paris
Data Sovereignty EU regions available (Frankfurt, Ireland, London, Paris)
Reliability As stated by the provider; see official documentation SLA

What is AWS Payment Cryptography?

AWS Payment Cryptography is a fully managed service that enables payment applications to perform cryptographic operations without running dedicated hardware security modules (HSMs). AWS describes three areas of use: payment card processing, payment key exchange and storage in accordance with Payment Card Industry (PCI) standards, and simplified integration through native AWS APIs instead of legacy socket-based calls.

The service is regional and provides separate endpoints for the control plane (key management) and the data plane (cryptographic operations). In Europe, Frankfurt, Ireland, London and Paris are available, among others.

Core capabilities

  • Payment card processing: Translate, decrypt and validate sensitive data and verify cryptograms through elastic APIs
  • Key exchange and management: Key generation, exchange and storage in accordance with PCI standards
  • No HSM hardware: Capacity is provided elastically, so you do not procure and operate hardware instances
  • Native AWS integration: Access through AWS APIs, SDKs and the console instead of proprietary socket interfaces
  • Physical key exchange: AWS operates secure facilities in the United States for exchanging physical keys

Typical use cases

Payment processing for acquirers and issuers: PIN translation, cryptogram verification and validation of sensitive card data through API calls rather than your own HSM estate.

Replacing on-premises HSMs: Existing payment HSM environments can be migrated to the managed service step by step, without procuring replacement hardware.

Key management under PCI requirements: Generation, exchange and storage of payment keys in line with PCI standards, managed through the AWS console and API.

Benefits

  • No procurement, maintenance or capacity planning for HSM hardware
  • Elastic capacity for cryptographic functions with high throughput and low latency
  • Billing based on active keys and actual API calls, with no upfront investment
  • EU regions keep processing and key material within Europe

Integration with innFactory

As an AWS Reseller, innFactory supports you with AWS Payment Cryptography: assessing your existing HSM landscape, designing key hierarchies and key exchange processes, connecting your payment applications, and running and monitoring the service in EU regions.

Typical Use Cases

Payment card processing
PIN translation and cryptogram verification
Payment key exchange in line with PCI standards
Replacing on-premises payment HSMs

Technical Specifications

Endpoints Separate control plane and data plane endpoints per Region
Key exchange Physical key exchange through AWS-operated secure facilities in the United States
Keys Default quota of 2,000 keys and 2,000 aliases per account and Region
Throughput Default quota of 500 data plane requests/s (symmetric), 20/s (asymmetric)

Frequently Asked Questions

What is AWS Payment Cryptography?

AWS Payment Cryptography is a fully managed service that lets payment applications perform cryptographic operations without requiring dedicated hardware security modules (HSMs). Sensitive data can be translated, decrypted and validated through elastic APIs, and cryptograms can be verified.

Do I still need my own payment HSMs?

AWS positions the service explicitly as a way to remove the dependency on your own HSM hardware. You do not provision hardware instances; capacity is provided elastically. For physical key exchange, AWS operates secure facilities in the United States.

How is the service billed?

Billing has two components: a monthly charge per active key, prorated hourly, and a tiered charge per 10,000 API calls. Current amounts are listed on the official pricing page.

Is the service available in the EU?

Yes. AWS Payment Cryptography provides control plane and data plane endpoints in Europe (Frankfurt), Europe (Ireland), Europe (London) and Europe (Paris), among others. Keys and calls stay in the Region you select.

Which quotas apply?

By default, 2,000 keys and 2,000 aliases are available per account and Region. Data plane defaults are 500 requests per second with symmetric keys and 20 requests per second with asymmetric keys. These values can be adjusted through Service Quotas.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of AWS (official documentation). This page does not represent an offer by AWS.

AWS Cloud Expertise

innFactory is an AWS Reseller with certified cloud architects. We provide consulting, implementation, and managed services for AWS.

Ready to start with AWS Payment Cryptography - Managed Payment HSM?

Our certified AWS experts help you with architecture, integration, and optimization.

Schedule Consultation