Safe your digital cost system within the cloud with Azure Cost HSM—now usually out there | Azure Weblog and Updates


We’re very excited to announce the overall availability of Azure Cost HSM, a BareMetal Infrastructure as a service (IaaS) that allows clients to have native entry to cost HSM within the Azure cloud. With Azure Cost HSM, clients can seamlessly migrate PCI workloads to Azure and meet probably the most stringent safety, audit compliance, low latency, and high-performance necessities wanted by the Cost Card Trade (PCI).

Azure Cost HSM service empowers service suppliers and monetary establishments to speed up their cost system’s digital transformation technique and undertake the general public cloud.

ACI logo “Cost HSM help within the public cloud is likely one of the most important hurdles to beat in transferring cost techniques to the general public cloud.  Whereas there are lots of totally different options, none can meet the stringent necessities required for a cost system. Microsoft, working with Thales, stepped as much as present a cost HSM resolution that might meet the modernization ambitions of ACI Worldwide’s expertise platform. It has been a pleasure working with each groups to convey this resolution to actuality.”

—Timothy White, Chief Architect, Retail Funds and Cloud

Service overview

Azure Cost HSM resolution is delivered utilizing Thales payShield 10K Cost HSM, which gives single-tenant HSMs and full distant administration capabilities. The service is designed to allow complete buyer management with strict position and knowledge separation between Microsoft and the client. HSMs are provisioned and linked on to the client’s digital community, and the HSMs are below the client’s sole administration management. As soon as allotted, Microsoft’s administrative entry is restricted to “Operator” mode and full accountability for configuration and upkeep of the HSM and software program falls upon the client. When the HSM is not required and the system is returned to Microsoft, buyer knowledge is erased to make sure  privateness and safety. The answer comes with Thales payShield premium package deal license and enhanced help Plan, with a direct relationship between the client and Thales.


HSM provisioning service will allocate HSM device to  a customer’s virtual network, customer can fully access and manage HSM remotely with Thales payShield Manager and TMD.

Determine 1: After HSM is provisioned, HSM system is linked on to a buyer’s digital community with full distant HSM administration capabilities via Thales payShield Supervisor and TMD.

The client can shortly add extra HSM capability on demand and subscribe to the very best efficiency degree (as much as 2500 CPS) for mission-critical cost purposes with low latency. The client can improve, or downgrade HSM efficiency degree primarily based on enterprise wants with out interruption of HSM manufacturing utilization. HSMs will be simply provisioned as a pair of units and configured for prime availability.

Azure stays dedicated to serving to clients obtain compliance with the Cost Card Trade’s main compliance certifications. Azure Cost HSM is licensed throughout stringent safety and compliance necessities established by the PCI Safety Requirements Council (PCI SSC) together with PCI DSS, PCI 3DS, and PCI PIN. Thales payShield 10K HSMs are licensed to FIPS 140-2 Degree 3 and PCI HSM v3. Azure Cost HSM clients can considerably cut back their compliance time, efforts, and value by leveraging the shared accountability matrix from Azure’s PCI Attestation of Compliance (AOC).

Typical use instances

Monetary establishments and repair suppliers within the cost ecosystem together with issuers, service suppliers, acquirers, processors, and cost networks will profit from Azure Cost HSM. Azure Cost HSM allows a variety of use instances, akin to cost processing, which permits card and cellular cost authorization and 3D-Safe authentication; cost credential issuing for playing cards, wearables, and linked units; securing keys and authentication knowledge and delicate knowledge safety for point-to-point encryption, safety tokenization, and EMV cost tokenization.

Get began

Azure Cost HSM is on the market at launch within the following areas: East US, West US, South Central US, Central US, North Europe, and West Europe

As Azure Cost HSM is a specialised service, clients ought to ask their Microsoft account supervisor and CSA to ship the request through e-mail.

Study extra about Azure Cost HSM

To obtain PCI certification stories and shared accountability matrices:


Leave a Reply