Summary
- NIST certificate 5517 lists the Aegis Secure Key 3.0 cryptographic module as FIPS 140-3 Level 3 and active.
- The module was initially validated on 9 September 2026.
- The certification independently covers the cryptographic module; Apricorn's performance, capacity, and quantum-resistance claims are separate vendor assertions.
The US National Institute of Standards and Technology has validated Apricorn‘s Aegis Secure Key 3.0 at FIPS 140-3 Level 3, giving the hardware-encrypted USB device independent certification under the latest generation of the US federal cryptographic standard.
NIST’s Cryptographic Module Validation Program lists certificate 5517 as active, with an initial validation date of 9 September 2026. The certificate covers the Aegis Secure Key 3.0 Cryptographic Module and records an overall security level of 3, subject to the trusted-channel caveat specified in its security policy.
Apricorn announced the validation on 10 September. It is the first product in the company’s portfolio to complete FIPS 140-3 validation after eight earlier products were validated against the previous FIPS 140-2 regime.
The distinction between validation and product marketing is important. NIST’s certificate establishes that the specified cryptographic module was tested through the CMVP process against the applicable FIPS requirements. It does not independently validate all of Apricorn’s wider product claims, including comparative speed, capacity leadership, or its description of its portfolio as quantum-resistant.
The certified module supports approved algorithms including AES-XTS, AES-CBC, AES-ECB, SHA-256, HMAC, ECDSA, and other mechanisms listed on the NIST certificate. Authentication is carried out through the device’s embedded keypad, keeping PIN entry separate from the host computer.
That architecture is intended to reduce reliance on endpoint software. The storage device handles encryption internally and can therefore be used across compatible operating systems without installing a software encryption client.
FIPS 140-3 Level 3 also covers requirements beyond the selection of cryptographic algorithms. The standard addresses areas including physical security, identity-based authentication, cryptographic key management, and mechanisms for responding to environmental conditions.
For Apricorn, the certification is primarily significant in procurement environments where validated cryptography is a formal requirement rather than a desirable security feature. US federal agencies, defence contractors, and organisations operating under government security requirements frequently specify FIPS-validated modules.
The implications are not limited entirely to the US. European defence organisations, multinational contractors, regulated businesses, and digital-forensics teams often encounter FIPS requirements through customers, cross-border programmes, or internal assurance policies.
Portable storage remains a relatively old technology category but continues to present a specific security problem. Removable media can move data into environments that are deliberately isolated from networks, including industrial, defence, laboratory, and forensic systems. That makes it useful operationally while bypassing many cloud-based data controls.
Hardware encryption reduces one class of exposure by protecting data on a lost or stolen drive. It does not remove risks around authorised users copying information incorrectly, compromised endpoints accessing an unlocked device, or removable media introducing malware into isolated systems.
The FIPS validation therefore provides assurance about a defined cryptographic boundary rather than the entire operational workflow in which the drive is used.
Apricorn has said it is moving its wider portfolio from FIPS 140-2 to FIPS 140-3. That transition reflects a broader procurement cycle under which older validated cryptographic modules are gradually being replaced as government and regulated environments update requirements.
Certificate 5517 gives buyers an independently verifiable basis for one part of that decision. The security value of the device in deployment will still depend on how removable media is authorised, handled, inventoried, and connected to sensitive systems.




