Apricorn has secured FIPS 140-3 Level 3 validation for the cryptographic module in its Aegis Secure Key 3.0, moving the hardware-encrypted USB drive from submitted status into formal certification under the latest generation of the US federal cryptographic standard.
The National Institute of Standards and Technology lists certificate 5517 as active, with an initial validation date of 9 September 2026 and an overall security level of 3. The certificate identifies the ASK3 as a hardware cryptographic module and currently gives it a sunset date of 8 September 2031.
The result makes the ASK3 the first Apricorn product to complete validation under FIPS 140-3. The company previously built much of its encrypted-storage portfolio around FIPS 140-2 certification and says eight earlier validations cover the majority of that product range.
FIPS validation is important where buyers require more than a manufacturer’s assertion that an encryption product is secure. The Cryptographic Module Validation Program uses accredited laboratories and formal technical review to assess an implementation against defined security requirements, giving government and regulated customers a recognised basis for procurement.
NIST’s certificate describes the ASK3 as a hardware-encrypted USB 3.1 memory key with authentication performed through an embedded keypad. Critical security parameters, including PINs and encryption keys, remain inside the defined device boundary rather than being passed to software running on the host computer.
Jeanclaude Toma, chief executive of Apricorn, said: “The result is a portable drive that gives federal agencies, defence contractors and regulated organisations independent assurance that its core security controls perform as intended.”
The current product uses 256-bit AES-XTS hardware encryption and operates without host-installed authentication software. Users unlock the device through its physical keypad before the computer can access the encrypted storage, separating the primary authentication mechanism from the operating system connected to the drive.
That model is relevant to industrial, defence, forensic, and other controlled environments where removable media continues to be used between systems that cannot simply rely on cloud storage or permanent network connections. Air-gapped equipment, isolated production systems, field computers, test rigs, and legacy platforms can all require a physical method of moving data.
Removable media also creates an obvious security risk. Encryption can protect information if a drive is lost or stolen, but organisations still need policies controlling who can use removable devices, what can be copied, which machines they may connect to, and how media is sanitised or retired.
FIPS validation does not solve those operating problems. It verifies a defined cryptographic implementation and security boundary, providing a technical control that sits underneath the organisation’s wider access, data-handling, endpoint, and physical-security procedures.
The ASK3 combines a USB flash-drive form factor with a mini solid-state-drive architecture and is offered in capacities up to 4TB. Apricorn substantially revised the product earlier this year, increasing capacity and adding environmental protection while the updated cryptographic module was progressing through the validation programme.
The company says write performance is nearly 20% higher than the preceding version. That is a manufacturer performance claim rather than part of NIST certificate 5517, just as Apricorn’s description of its storage portfolio as “quantum-resistant” should not be confused with the scope of the federal validation.
The NIST record validates the identified FIPS 140-3 module and its approved cryptographic functions. It does not certify a broad marketing statement that the drive is resistant to every future quantum-computing threat.
That distinction matters because security certifications are often stretched in product marketing beyond what has actually been tested. Certificate 5517 identifies approved AES, hashing, key-agreement, key-derivation, random-number-generation, and digital-signature functions and records the product’s overall security level; those are more useful claims than attaching unrelated conclusions to the badge.
Physical protection forms another part of the design. Apricorn encloses the drive against tampering and incorporates an environmental protection circuit that shuts the device down when temperature or voltage moves outside safe limits. Once acceptable operating conditions return, the product can be brought back into use.
The mechanism is intended both to protect the hardware and to address environmental-failure requirements within FIPS 140-3. Portable devices can encounter far less controlled conditions than conventional servers, particularly when used in field, industrial, defence, or investigative applications.
The software-free approach also allows the drive to be used on different host systems supporting USB mass storage without requiring the organisation to install a proprietary client application. That can simplify deployment on locked-down or heterogeneous equipment, although host-system security still determines what happens to data after it has been legitimately unlocked and copied.
Apricorn previously achieved AS9100 aerospace quality certification, another independent credential but one covering manufacturing and quality-management processes rather than cryptography. The FIPS validation is therefore complementary rather than equivalent: one addresses the organisation’s quality framework, while the other validates a specific cryptographic module.
For ASK3, the significant change on 9 September was not another increase in capacity or transfer speed. Certificate 5517 changed the product’s procurement status by completing a validation process that some federal and regulated customers require before deployment. Apricorn now intends to extend that transition across more of its portfolio as older FIPS 140-2-era products approach replacement.




