Skip to main content
Cloud / Azure / Products / Azure Cloud HSM - Hardware Security Module

Azure Cloud HSM - Hardware Security Module

Azure Cloud HSM provides FIPS 140-3 Level 3 validated hardware security modules for cryptographic keys.

security
Pricing Model Usage-based per HSM cluster hour, pricing on request via Azure pricing calculator or sales
Availability Selected Azure regions
Data Sovereignty EU regions available
Reliability SLA as published by the provider SLA

What is Azure Cloud HSM?

Azure Cloud HSM is Microsoft Azure’s current hardware security module service for cryptographic keys with the highest security requirements. It is FIPS 140-3 Level 3 validated and provides each customer with a dedicated, single-tenant HSM cluster with full administrative control. Cloud HSM is the successor to Azure Dedicated HSM: Dedicated HSM has stopped accepting new customers since 2025 and will remain supported for existing customers until July 31, 2028. Microsoft recommends that new customers, and existing customers looking to migrate, move to Azure Cloud HSM or alternatively to Managed HSM or Azure Key Vault, depending on requirements.

Core Features

  • FIPS 140-3 Level 3 validated, single-tenant HSM clusters with a customer-specific security domain
  • High availability through clusters of multiple HSM nodes with automatic synchronization and failover
  • Full administrative control over keys and policies for the customer, with patching and maintenance handled by Microsoft
  • Support for PKCS#11, OpenSSL, JCA/JCE, CNG/KSP, and TDE for SQL Server and Oracle
  • Secure, dedicated access from your own virtual network

Typical Use Cases

  • Lift-and-shift of applications with dedicated HSM requirements from on-premises or from Azure Dedicated HSM
  • PKI and certificate authority hosting (e.g., Active Directory Certificate Services)
  • Database encryption (TDE) for SQL Server or Oracle
  • SSL/TLS offloading as well as document and code signing

Benefits

  • Highest available security level for cryptographic keys in Azure
  • Full control over the HSM combined with a managed operational model (high availability, patching)
  • Supports compliance requirements such as eIDAS and PCI 3DS
  • Migration path for existing Dedicated HSM or on-premises HSM applications

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you with Azure Cloud HSM: architecture, PKI design, migration from Azure Dedicated HSM or on-premises HSMs, and compliance consulting.

Frequently Asked Questions

What is Azure Cloud HSM?

Azure Cloud HSM is a FIPS 140-3 Level 3 validated, highly available single-tenant hardware security module service. It is the successor to Azure Dedicated HSM, which stopped accepting new customers in 2025 and will be supported for existing customers until July 31, 2028.

What is the difference from Azure Key Vault and Managed HSM?

Azure Key Vault is multi-tenant and uses hardware validated to a lower FIPS level. Managed HSM is a PaaS offering that integrates with other Azure services. Cloud HSM is pure IaaS, giving full administrative control over a dedicated, customer-specific HSM cluster without integration into other PaaS/SaaS services.

How does high availability work?

A Cloud HSM cluster consists of multiple HSM nodes, three by default. Keys and policies are automatically synchronized across nodes, and if a node fails, member nodes are automatically migrated to healthy ones. Microsoft handles patching and maintenance, while the customer retains administrative control over the keys.

What does Azure Cloud HSM cost?

Billing is usage-based per hour for the HSM cluster. Specific pricing must be requested through the Azure pricing calculator or sales, as it can vary by program or contract.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

STACKIT

STACKIT CSPM - Cloud Security Posture Management

STACKIT CSPM (Public Preview): assess cloud security posture with a compliance dashboard, BSI C5/ISO 27000 benchmarks, …

Pricing Pricing as published in the STACKIT …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Key Management Service - Key Management

STACKIT KMS: centralized cryptographic key management from German data centers, BYOK, rotation, GDPR-compliant.

Pricing Consumption-based, billed per key …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Secrets Manager - Secure Credential Management

STACKIT Secrets Manager: Secure management of API keys, passwords, certificates. Versioning, audit logs, GDPR compliant.

Pricing Hourly billing based on capacity tier …
SLA SLA as published by the provider
Compare →
Google Cloud

Access Context Manager - Attribute-Based Access Control

Access Context Manager defines access levels and service perimeters for fine-grained, attribute-based access control in …

Pricing Free: according to the official pricing …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Advisory Notifications - Security and Privacy Communications

Advisory Notifications delivers communications about critical security and privacy events in the Google Cloud console.

Pricing Google does not publish a dedicated …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Artifact Analysis - Vulnerability Scanning for Artifacts

Artifact Analysis scans container images and packages for vulnerabilities and stores the associated metadata. The …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →

83 comparable products found across other clouds.

Ready to start with Azure Cloud HSM - Hardware Security Module?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation