LICENSEWARE

Entrust nShield HSM licensing

This article is about licensing Entrust nShield hardware security modules, their feature activations, client licences, support releases, nShield Monitor and the Container Option Pack. It is not about the Cryptographic Security Platform, PKI as a Service or Entrust Identity, which have their own articles, and it is not legal advice.

On This Page

Entrust nShield hardware security modules (HSMs) are licensed as hardware plus a set of perpetual activations. The Entrust documentation frames the purchase as a series of customer choices: hardware model, performance level or tier, certification, features, and add-ons and extras.[1] What a customer may do with the hardware is governed by a short permitted-use statement, by serial-bound client licences and feature certificates, and by separate software licences for tools such as KeySafe 5 monitoring, nShield Monitor and option packs. Software releases run on a published support policy. The sections below describe each element and what a licence manager can reconcile.

Permitted use

The licensing page defines the “Customer” as an Entrust customer that has purchased one or more HSMs, or an individual that the customer authorises to access components or features.[1] HSMs and HSM software “are sold or licensed for internal Customer use”, meaning use for the customer’s own business purposes. Employees of external contractors may be given access, but only to the extent that they use the HSMs on the customer’s behalf in operating or managing the customer’s business.[1]

The page also states that, except under an express licence agreement signed by Entrust, neither the customer nor any user may use HSMs or HSM software to set up or provide its own managed service for other companies, giving the examples of acting as a Managed Service Provider or Systems Integrator.[1] Service providers who host keys for several tenants on their own HSMs should therefore confirm that their agreement with Entrust expressly allows it. The nCOP licence contains the same restriction for the Container Option Pack.[10]

Hardware models and tiers

The licensing page groups the models into form factors:[1]

  • PCI Express: nShield Solo XC and nShield 5s, installed in a host server, shipped with a smart card reader, accessories and documentation.
  • Network-attached: nShield Connect XC, nShield 5c and nShield 5c 10G, stand-alone devices supporting one or more connected clients. The 10G variant offers copper or fibre. All network appliance HSMs include a card reader and three client licences by default, with no operator cards deployed by default; smart card packs are ordered separately.
  • USB: nShield Edge, a tamper-resistant device with an integrated smart card reader, attached to a host by USB and described for uses such as offline certificate authorities.

Performance is chosen as Base, Mid or High, and the page notes that datasheets give the baseline transaction speed for common algorithms. A customer may later upgrade the performance level (Base or Mid) as an additional licence, physical or electronic.[1] The user guide explains that the speed rating is set at manufacture to match the model number ordered, and that a lower-speed model can be upgraded by purchasing an upgrade licence that is applied like any other optional feature.[2]

Certification choices include Common Criteria eIDAS and FIPS 140. The page notes that Common Criteria orders ship from the United Kingdom with tamper-evident packaging, and lists serialised tamper-evident packaging as a feature required for Common Criteria eIDAS certification.[1]

Client licences

A client licence controls the number of application hosts that can consume a network appliance HSM (nShield 5c, 5c 10G or Connect XC). Each such HSM includes three client licences, permitting a maximum of three concurrent client connections, and more can be purchased.[1] The page makes four points a licence manager should record:[1]

  1. Client licences are perpetual HSM feature activations, applied to an individual HSM.
  2. The maximum that can be added to one HSM is capped by performance tier (Base, Mid or High), as set out in the product notes.
  3. Where the number of extra clients is considerable, typically over 30, an Enterprise Client licence is available at a higher price to allow the maximum number of clients.
  4. Licences are typically linked to the serial of an HSM and can be transferred to another unit subject to a licence transfer fee.

The user guide adds an operational detail with licensing consequences: on a network-attached HSM, client licences are dynamic and must be re-applied if the HSM is initialised.[2] Applying a dynamic feature certificate is done from the client with the nethsmadmin utility, after which the client-side hardserver is restarted and the “max exported modules” value in the enquiry output confirms the new client count.[3] Static features applied from the front panel clear the module without warning, which drops any running SEE machine and loses loaded application keys.[3] An audit that compares entitlements with the HSM’s actual state should therefore be run before any initialisation or factory reset, so that purchased licences can be re-applied.

Feature activations

An nShield feature activation “activates a specific function that is disabled on the HSM by default”.[1] The licensing page lists, among others, ISO smart card support, Remote Operator (per unattended HSM), Korean certificate-based digital signature algorithm support, elliptic curve cryptography, a faster random number generator for ECDSA, post-quantum activation, and CodeSafe activations.[1]

The user guide states that all features can be enabled after purchase by a feature certificate supplied by Entrust, as a downloadable file or as an Activator smart card delivered by post, and that some features such as speed ratings can be ordered at purchase and enabled in the factory.[2] To order a feature the customer must provide the HSM’s Electronic Serial Number, and Entrust returns a Feature Enabling Certificate.[2] The same guide records several version-dependent rules that change whether a licence is needed:

  • Elliptic curve support required specific activation before firmware v13.5 and is always enabled from v13.5; elliptic curve MQV support required activation before v13.7 and is always enabled from v13.7.[2]
  • Post-quantum algorithms are always enabled on nShield 5 HSMs; the feature licence is only required for nShield XC.[2]
  • The faster random number generator for ECDSA applies only to Solo XC and Connect XC, because nShield 5 HSMs already use a FIPS-approved algorithm without extra features.[2]
  • On nShield 5s, features set in the factory persist if the module is returned to factory state, while features set by certificate are lost and must be re-applied.[2]
  • The Remote Operator feature must be enabled on the HSM that is to be used as the unattended HSM, and for version 12 and later Entrust recommends Remote Administration instead.[2]

For records, the Feature Enable Tool on PCIe and USB HSMs and the front panel on network HSMs show which features are active, and the HSM can write its feature state to a file.[3]

CodeSafe

The CodeSafe runtime is included in all HSMs, but the CodeSafe SDK (the toolkit to create and sign an application) is separate, and for an application to be installed on an HSM that HSM must have a perpetual activation licence installed at additional cost, linked to the unit serial.[1] Unrestricted Activation allows an HSM to load and run a self-signed CodeSafe machine; Restricted Activation allows one signed by an Entrust-trusted developer.[1] The user guide distinguishes SEE Activation (CodeSafe 5) on nShield 5 HSMs from SEE Activation (EU+10) and (Restricted) on Connect and Solo HSMs, the latter being tied to specific products that include an SEE application and usable worldwide.[2]

Edge Developer Edition

The nShield Edge Developer Edition is a lower-cost unit “for development purposes only”; it is to be used only for non-production use in support of development or engineering of applications or systems that interact with the HSMs, and the standard terms continue to apply.[1] Any Developer Edition found in a production data path is outside its licence.

Software and add-ons

Beyond hardware the licensing page lists items that are additional charges unless included in a package: additional client licences and activations, the Remote Administration kit (cards, Trusted Verification Devices and Remote Administration Client software), optional software licences and option packs, professional services, support, accessories and rack-mounting rails (included with the nShield 5c 10G).[1] Firmware and the Connect image are preloaded and delivered as an ISO to update the HSM.[1]

KeySafe 5 provides central management and monitoring of a distributed HSM estate. The monitoring capability “is provided under an annual subscription license” at additional cost and requires a separate activation licence.[1] The Cryptographic Security Platform documentation names four KeySafe 5 Monitoring tiers (Base, Standard, Mid and Enterprise), determined by the number of HSMs monitored and subject to an annual twelve-month subscription.[11]

Option packs named on the page include the Cloud Integration Option Pack (CIOP), the Container Option Pack (nCOP), the Database Security Option Pack (nDSOP), the Web Services Option Pack, the Web Services SQLEKM provider and the post-quantum cryptography option pack. Option packs may be transferred from one HSM to another subject to a transfer fee.[1] The Key Attestation Verifier is obtained through an account representative because of a non-standard process.[1]

nShield Container Option Pack

The nCOP is “licensed on a per HSM basis”, so one licence covers use on a single network HSM, including nShield as a Service deployments, and it is supported on Linux only.[10] The number of container pods and application containers depends on the HSM client licences: each client licence entitles the customer to connect the HSM to one container pod, and each pod may run up to 10 application containers, a ratio of 1:1:10.[10] The page gives examples: 5 client licences allow 5 pods and 50 containers, 10 allow 10 and 100, and 25 or more allow 25 pods and more than 250 containers. A weighting factor is used to convert pods and containers into client licences, and an enterprise client licence removes the limits for that HSM.[10] Customers are expected to keep reasonable records of pods and containers and track increases so that enough client licences are in place.[10] This makes nCOP a case where container orchestration changes (more pods) create HSM licence demand without any change to the HSM inventory.

nShield Monitor

nShield Monitor is a virtual appliance with software licences (single, dual and Enterprise) and endpoint licences for the nShield devices monitored. Order codes include NT-SW-V2S, NT-SW-V2D and NT-SW-V2E for the software and NT-LIC-ADD5, ADD10, ADD20 and ADD50 or NT-LIC-ENTERPRISE for endpoints, with upgrades NT-LICU-S2D, S2E and D2E. A maximum of 500 endpoints per monitoring software licence is available, and the Enterprise endpoint licence is 500 endpoints for versions 2.5 and later and 300 for 2.4.1 and earlier.[8] Monitor ships with an evaluation licence that enrols and monitors up to eight devices for up to 30 days; afterwards it stops monitoring and restricts access to the administrator role. Licences are generated against the serial number of the deployed appliance.[9]

Software releases and support

Security World software releases (client software, HSM firmware, Connect image, CodeSafe Developer and Remote Admin Client) follow a release policy first published on 2024-10-21 and revised on 2025-07-02.[4] Other option packs and standalone software are outside the policy.[4]

Release type Support Notes 
LTS Regular updates about every three months for up to three years from the start of the LTS support phase, then extended support for a maximum of one year New LTS roughly every 18 months with a one-year overlap; usually at most two active LTS releases[5] 
STS Support and patches for approximately nine months after STS support begins No regular update schedule; features roll into a later LTS[6] 
LTS-C For the length of the certification or the period stated at release Certified firmware from an STS release; Connect and client-side support from all active LTS releases[7] 

The LTS page recommends LTS releases by default, notes that firmware and Connect updates are released at least once per year and that updates are cumulative.[5] The licensing page lists support services at Standard, Premium and Premium Plus levels, with additional on-site replacement options for UK customers only.[1]

Transfers and end of life

Transfers of licences between HSMs are normally subject to a fee. The page says free transfer is provided only from end-of-support HSMs to new HSMs, as long as the customer has an active support contract for the new HSMs.[1] A refresh programme should therefore be planned so that support on the new units is in place before licences are moved.

Trade compliance

The page notes that HSMs and HSM software contain cryptographic components subject to United States and United Kingdom export restrictions, and that import and export rules in the customer’s jurisdiction may also apply.[1]

Out of scope

This article does not give nShield prices, which are quoted by Entrust sales and are not published in the documents cited. It does not cover the General Terms, the Hardware and Supplies Schedule, the Support Schedule, the End User License or the nShield as a Service Direct Schedule, which Entrust lists on its Terms and Conditions page as separate documents, and does not describe nShield as a Service subscription metrics beyond the nCOP compatibility statement.

References

  1. nShield HSM licensing (nShield Docs)Permitted use, hardware models, performance tiers, features, add-ons, software and support. Undated.Retrieved 2026-10-08.
  2. Optional features (nShield HSM User Guide)Optional features, persistence, client licences, speed ratings and ordering. Undated.Retrieved 2026-10-08.
  3. Enable features on a network-attached HSM (nShield HSM User Guide)Applying static and dynamic feature certificates. Undated.Retrieved 2026-10-08.
  4. nShield Security World Software Release PolicyRevision 1.1 dated 2025-07-02; revision 1.0 published 2024-10-21.Effective 2025-07-02. Retrieved 2026-10-08.
  5. Long Term Support (LTS) Releases (nShield Security World Software Release Policy)LTS phases, cadence and extended support. Undated page.Retrieved 2026-10-08.
  6. Standard Term Support (STS) Releases (nShield Security World Software Release Policy)STS support period. Undated page.Retrieved 2026-10-08.
  7. Long Term Support Certified Firmware (LTS-C) Releases (nShield Security World Software Release Policy)Certified firmware released inside STS releases. Undated page.Retrieved 2026-10-08.
  8. Licensing (nShield Monitor)Order codes for software and endpoint licences. Undated.Retrieved 2026-10-08.
  9. License Installation (nShield Monitor)Evaluation licence and installation. Undated.Retrieved 2026-10-08.
  10. nCOP Licensing (nShield Container Option Pack)Per-HSM licence and the pod and container ratio. Undated.Retrieved 2026-10-08.
  11. Cryptographic Security Platform customer licenseKeySafe 5 Monitoring tiers named in the Cryptographic Security Platform add-on list. Undated.Retrieved 2026-10-08.

See also

Catalog Rows Cited

7Metrics5Programs

Esc