Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google Cloud HSM is not a physical encryption module that Google ships to you. It is a managed hardware-security-module option within Cloud Key Management Service (Cloud KMS). You create and control keys through Cloud KMS APIs and integrations, while Google operates the HSM infrastructure, including its clustering, scaling and patching.

What Google Cloud HSM is

Cloud HSM hosts cryptographic keys and performs cryptographic operations in certified HSMs managed by Google. Cloud KMS is the customer-facing control plane: it provides the APIs and tools for creating, importing, managing and using keys, including keys protected by HSMs.

For ordinary Cloud KMS integrations, applications generally use the same KMS interfaces whether a key is software-backed or HSM-backed. The protection level changes behind that interface, so workloads do not normally need HSM-specific application code.

How the service works

  1. Create or import a key in Cloud KMS. Select the appropriate protection level and key purpose for the workload.
  2. Use Cloud KMS APIs or a compatible Google Cloud service. Applications request encryption, decryption, signing or related operations through the supported integration.
  3. Cloud HSM performs the operation in hardware. For an HSM-protected key, the key material and operation are handled by the managed HSM service rather than ordinary software storage.
  4. Google runs the underlying service. Google manages HSM clusters and their operational tasks; your team remains responsible for IAM, key policies, rotation decisions, application configuration and verifying service suitability.

Cloud KMS protection choices

Cloud HSM is one option in a broader key-management design. The right choice depends on whether hardware validation, dedicated isolation, external custody or simply centralized key management is the primary requirement.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Option Where protection or custody sits When it is a fit Key trade-offs to check
Software-backed Cloud KMS key Software-based protection in Google Cloud Workloads that need managed keys but do not have a hardware-protection requirement Usually the lower-cost choice; confirm that the target service and policy do not require HSM protection
Multi-tenant Cloud HSM HSM clusters serving multiple customers Workloads that require HSM-backed protection without a dedicated partition Shared cluster model; verify supported services, locations, algorithms and current pricing
Single-tenant Cloud HSM Dedicated HSM partitions for one customer Cases where dedicated partitioning and additional administrative control are material Higher isolation and operational considerations; confirm current availability, terms, regions and cost
Cloud EKM Keys remain with an external key-management provider outside Google infrastructure Organizations that must retain key custody in an external system External-provider availability, connectivity, supported Google Cloud services, location and operational responsibility

These are different custody and isolation models, not interchangeable names for the same product. Before choosing, check the exact Google Cloud service that will consume the key, its supported regions and protection levels, and the current documentation for quotas and pricing.

When an HSM-backed key is justified

  • A policy or contract requires hardware-protected keys. Cloud HSM can provide that protection through Cloud KMS rather than requiring your team to run an HSM cluster.
  • You need managed cryptographic operations in certified hardware. This can reduce the infrastructure work associated with deploying, patching and scaling HSMs yourself.
  • A workload has sensitive signing or encryption keys. Confirm that the specific algorithm, key purpose and consuming service are supported before migration.

Choose a software-backed key when your requirement is centralized, managed key control and no hardware-validation requirement applies. HSM protection adds a control layer, but it does not by itself solve identity, authorization, rotation, logging, data-residency or application-security problems.

Multi-tenant versus single-tenant Cloud HSM

Multi-tenant HSM

Google describes multi-tenant keys as residing in HSM clusters that serve multiple customers. This model provides HSM-backed operations while Google operates the shared infrastructure.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Single-tenant HSM

Google’s single-tenant option uses dedicated HSM partitions for one customer. Consider it when customer isolation or partition-level administrative control is a material requirement rather than an assumption that every HSM deployment is dedicated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The choice should be based on documented isolation, service compatibility, regional availability, administrative duties and cost—not simply on the word “HSM.”

When Cloud EKM is the better model

Cloud External Key Manager (Cloud EKM) is separate from Cloud HSM. With EKM, key material is held by an external key-management provider outside Google infrastructure. That model is appropriate when organizational policy, contractual terms or a control framework requires external custody.

External custody also makes availability and operations more dependent on the provider and the connection between Google Cloud and that system. Verify the supported Google Cloud services, locations, failure behavior and provider responsibilities before selecting it.

What the 2018 announcement actually introduced

On August 22, 2018, Data Center Knowledge reported Google’s announcement of Cloud HSM, asymmetric keys in Cloud KMS and a Vault token helper. The report described Cloud HSM and asymmetric-key support as beta at launch; that status is historical and should not be used to describe the current service.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The announcement said the Vault helper encrypted tokens with Cloud KMS or Cloud HSM keys before storing them. It also reported RSA 2048, 3072 and 4096 and elliptic-curve P-256 and P-384 for signing, with RSA 2048, 3072 and 4096 available for decryption at that time. Those were launch-era details, not a complete current algorithm list. Check Google’s current Cloud KMS documentation for today’s algorithms and restrictions.

Best Value
Yale Wi-Fi Smart Module for Yale Assure Digital Electronic Locks or Levers
  • ADD WI-FI TO YOUR YALE ASSURE LOCK OR LEVER: No hub or Connect needed. Note: This product only works on 2.4 GHz Wi-Fi in the U.S. and Canada.
  • SIMPLE TO ADD: Simply insert the Yale Wi-Fi Smart Module in the slot above the batteries. Add the module as an accessory in the Yale Access app.
  • UPGRADE YALE ASSURE LOCKS: Add Wi-Fi to your Yale Assure Lock or Lever with no hub or Connect needed.
  • ACCESS FROM ANYWHERE: Lock, unlock, share access and see who comes and goes from anywhere using the Yale Access app.
  • AUTO-UNLOCK: Your Assure Lock/Lever will automatically unlock as you get home and relock for you.

The report attributed this launch-era description to Google Cloud product manager Il-Sung Lee: “Cloud HSM allows you to host encryption keys and perform cryptographic operations in FIPS 140-2 Level 3 certified HSMs.” It also quoted him describing the service as fully managed so customers would not have to operate an HSM cluster. These quotations describe the 2018 announcement and should not be treated as current product wording without checking Google’s latest documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does Cloud HSM satisfy a compliance requirement?

Not automatically. Google documents FIPS validation information and key-attestation capabilities for its services, but a compliance conclusion depends on your regulation, jurisdiction, data location, edition, key configuration and the exact control being assessed.

  • Identify the required validation level or control language in your policy.
  • Confirm the relevant Google Cloud region and service configuration.
  • Check whether the consuming service supports the required HSM key type.
  • Review current Google documentation and your assessor’s interpretation.
  • Keep evidence for IAM, key lifecycle, rotation, logging and incident procedures; HSM hardware alone does not establish those controls.

Pricing and operational responsibility

Cloud HSM uses usage-based pricing. Google’s pricing information lists separate charges for Cloud KMS, Cloud HSM and Cloud EKM. The amount depends on the current region, currency, key type and operation volume, so obtain a live quote from the official pricing page before budgeting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google operates the HSM cluster, but customers still administer the service through Cloud KMS. Plan ownership for permissions, key rings and versions, import or creation procedures, rotation, destruction safeguards, audit logs, service quotas and recovery. A managed HSM removes appliance operations; it does not remove key-governance work.

A practical selection checklist

  1. List the workloads, Google Cloud services and regions that must use the key.
  2. Decide whether software protection meets the requirement.
  3. If hardware is required, determine whether a shared cluster is acceptable or a dedicated partition is necessary.
  4. If Google must not hold the key material, evaluate Cloud EKM and its external-provider dependencies.
  5. Verify algorithms, key purposes, CMEK compatibility, quotas and current availability in the official documentation.
  6. Estimate KMS, HSM or EKM charges using current operation volume and regional pricing.
  7. Map IAM, rotation, attestation, logging and destruction controls to the applicable compliance obligation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.