Thales Ships an HSM Built for Post-Quantum Migration
Thales has launched Luna 8, a hardware security module built to carry enterprises through the shift to post-quantum cryptography (PQC). HSMs are the tamper-resistant boxes that guard the cryptographic keys behind banking, certificates, digital identity, and secure communications, and Luna 8’s pitch is that it runs both today’s algorithms and the new quantum-resistant ones on one appliance. It’s a market leader shipping the infrastructure layer of a migration that’s mostly lived in standards documents until now.
The unglamorous layer of migration
NIST finished its post-quantum encryption standards in 2024, but standards on paper don’t protect anyone until the infrastructure runs them. HSMs are a big part of that infrastructure. They hold and manage the keys behind an organization’s certificates, signing, authentication, and PKI, and if they can’t handle the new algorithms, the migration stalls at the hardware.
Thales is one of the largest HSM vendors, so its move to a post-quantum-ready box signals the transition reaching the deployment stage. Per the August 4 announcement, Luna 8’s selling point is crypto-agility. It runs current and post-quantum algorithms on the same appliance and is upgradeable as standards shift, so enterprises don’t have to replace what they already own.
Todd Moore, who leads Thales’s data-security products, put the logic simply.
“Enterprises need to build post-quantum readiness through cryptographic agility. Powered by our custom-designed cryptographic processor, Luna 8 delivers high-performance support for both current and post-quantum algorithms.”
The urgency Thales leans on is grounded. Its own threat survey puts harvest now decrypt later at the top of the risk list, the attack where an adversary stores encrypted data today to crack once a quantum computer arrives, which is why the migration is already underway rather than a worry for later.
What’s shipping, and what’s pending
Luna 8 is available now as a network appliance, though its high-assurance certifications, FIPS 140-3 Level 3 and EU Common Criteria, are still in assessment. Payment-HSM support is a future release. Also, “quantum safe” here means the box runs the NIST post-quantum algorithms, the strongest current bet, and no guarantee against every future attack.
Even so, the product answers a concrete need. Running PQC in practice means handling the much larger keys and signatures the new algorithms carry, and doing it inside audited hardware. That’s the layer a growing services market is forming around, seen in moves like Keyfactor’s PQC migration channel, and it’s the same shift that has enterprises mapping out how to move their cryptography in the first place. Thales selling a post-quantum HSM is that shift showing up in the product catalog.