Quantum eMotion's SecureKey Module Secures NIST IUT Status, Advancing Toward FIPS 140-3 Certification

7 min read | July 16, 2026 08:00 AM EDT | By Manish Choudhary

Quantum eMotion Corp. (NYSE American: QNC; TSXV: QNC; FSE: 34Q0) has announced that its SecureKey Cryptographic Module has been officially recognized as an "Implementation Under Test" (IUT) by the National Institute of Standards and Technology (NIST), marking a pivotal step in the company’s commercialization efforts. The module is now listed on the NIST Cryptographic Module Validation Program (CMVP) registry, formally entering the regulatory validation process for cryptographic security products. In collaboration with Intertek Laboratories, Quantum eMotion anticipates the module will advance to the "Modules In Process" list within three to four months as it moves closer to full FIPS 140-3 certification.

Key Highlights

  • Quantum eMotion Corp. (QNC) attains NIST IUT status for its SecureKey Cryptographic Module.
  • The module is now publicly recorded in the NIST CMVP registry, officially entering the regulatory validation pipeline.
  • Projected progression to the "Modules In Process" phase within approximately three to four months, supported by Intertek Laboratories.
  • IUT designation is a critical milestone toward achieving full FIPS 140-3 certification, enabling deployment in regulated industries requiring validated cryptographic security.

NIST IUT Status Enables Access to Regulated Markets for SecureKey Module

The NIST IUT listing signifies SecureKey’s formal entry into the stringent regulatory validation framework governing cryptographic modules used in government and regulated commercial sectors. This designation qualifies Quantum eMotion’s SecureKey Cryptographic Module for independent evaluation against the Federal Information Processing Standards (FIPS) 140-3 requirements. The module’s inclusion in the public NIST CMVP registry provides an authoritative record of cryptographic modules undergoing validation or already certified.

This milestone holds strategic importance beyond its administrative nature. Industries such as financial services, healthcare, and government systems mandate that cryptographic solutions comply with FIPS 140-3 certification standards. By entering NIST’s validation pipeline, Quantum eMotion positions SecureKey to meet the compliance demands of these regulated markets, where independent validation and cryptographic provenance are essential. The public listing also enhances transparency for enterprise procurement and compliance teams assessing cryptographic solutions.

Technical Foundation and Enterprise Security Role

The SecureKey Cryptographic Module acts as a foundational trust root within enterprise data protection architectures. It provides an independently validated cryptographic root of trust essential for secure key generation, storage, protection, and cryptographic operations across both enterprise and embedded systems. This positions SecureKey at the critical layer where cryptographic trust originates in an organization’s security infrastructure.

Designed to meet modern cybersecurity demands, the module ensures cryptographic operations are performed using independently validated, standards-compliant implementations rather than proprietary or unverified methods. For enterprises managing sensitive data across diverse applications and infrastructure layers, possessing a certified cryptographic root of trust lowers risks associated with key management and cryptographic processes. SecureKey’s entry into the NIST validation process confirms Quantum eMotion’s compliance with FIPS 140-3’s rigorous technical and operational requirements.

FIPS 140-3 Certification Progress and Intertek Collaboration

Quantum eMotion is advancing through the CMVP validation process in partnership with Intertek Laboratories, an accredited independent testing organization for FIPS 140-3 assessments. The company expects the SecureKey module to transition from IUT status to the "Modules In Process" list within three to four months, reflecting ongoing preparation of vendor evidence documentation and technical submissions for NIST’s review.

This transition marks the next formal phase in the validation process, indicating NIST’s acceptance of the module’s technical documentation for adjudication. Although no specific timeline for full FIPS 140-3 certification has been provided, moving to "Modules In Process" typically precedes final certification. Jason Thomas, Director of Product Development at Quantum eMotion, noted the team is "moving rapidly alongside Intertek to finalize the Vendor Evidence documentation," highlighting active progress in the certification effort.

Strategic Integration Within Quantum eMotion’s Cryptographic Solutions

The SecureKey module complements Quantum eMotion’s broader cryptographic and cybersecurity technology portfolio, which includes quantum random number generation (QRNG) and post-quantum cryptography solutions. CEO Francis Bellido stated that the SecureKey IUT designation "marks an important advancement in QeM's mission to deliver trusted cryptographic foundations for the next generation of digital infrastructure" and that it "further strengthens our position as a provider of advanced cybersecurity solutions for regulated and mission-critical environments."

This integrated portfolio approach addresses multiple layers of cryptographic security: QRNG delivers high-quality entropy for key generation, post-quantum cryptography counters emerging quantum computing threats, and SecureKey’s validated module provides a regulatory-compliant foundation for deploying these technologies in enterprise settings. Together, these solutions position Quantum eMotion to serve organizations requiring advanced cryptographic capabilities with proven regulatory compliance.

Target Markets and Compliance-Driven Deployment

Quantum eMotion targets several high-value sectors with its cryptographic solutions, including financial services, healthcare, blockchain, cloud IT security, classified government networks, IoT device keying, automotive, consumer electronics, and quantum cryptography applications. Many of these industries operate under regulatory frameworks that mandate or strongly prefer cryptographic solutions validated by independent third parties.

The SecureKey module’s NIST IUT designation enables compliance with procurement requirements in these regulated markets. Financial institutions adhering to the Gramm-Leach-Bliley Act, healthcare providers under HIPAA, and government agencies managing classified data require FIPS-validated cryptographic modules. Advancing SecureKey through the NIST validation pipeline removes critical barriers to entry in these compliance-sensitive sectors.

Executive Insights on Commercialization Milestone

Leadership highlighted the commercial impact of achieving NIST IUT status. Jason Thomas described the IUT listing as "a definitive breakthrough in our commercialization roadmap," underscoring its importance in facilitating SecureKey’s market entry. He added that the IUT status "validates the architecture of the SecureKey module and moves us closer to achieving full FIPS compliance," emphasizing the role of NIST’s evaluation in mitigating technology risk for enterprise clients.

CEO Francis Bellido emphasized SecureKey’s role within the company’s cybersecurity strategy, stating it "strengthens our position as a provider of advanced cybersecurity solutions for regulated and mission-critical environments." The focus on "independently validated, standards-based cryptographic security solutions" aligns with procurement priorities in regulated industries.

Regulatory Compliance and Validation Standards

The NIST CMVP framework provides independent assurance that cryptographic modules comply with defined security and operational standards. FIPS 140-3, the federal standard for cryptographic module validation, assesses modules across multiple security levels and criteria covering design, implementation, testing, and operations. Progression from IUT designation to "Modules In Process" and ultimately full certification represents sequential validation stages within this regulatory structure.

For enterprises and government bodies, FIPS 140-3 certification serves as an objective, independently verified benchmark of cryptographic module security. This standardized validation reduces procurement risk by establishing a consistent security baseline across vendors. Quantum eMotion’s advancement through the NIST pipeline enhances customer confidence in SecureKey’s compliance as it approaches full certification.

Market Differentiation and Competitive Advantage

Possessing independently validated cryptographic modules is a competitive necessity in regulated markets. Organizations deploying cryptographic solutions in compliance-sensitive environments typically prioritize vendors with FIPS certification. By progressing SecureKey through NIST’s validation process, Quantum eMotion gains a significant advantage over non-validated or proprietary cryptographic offerings.

The company’s multi-technology strategy—integrating QRNG, post-quantum cryptography, and FIPS-validated modules—enables it to meet comprehensive cryptographic needs for enterprise and government clients. This holistic approach appeals to customers seeking validated cryptographic foundations alongside emerging technologies that address future quantum threats.

Upcoming Milestones in Validation Process

The near-term goal is to advance SecureKey from IUT status to the "Modules In Process" list within three to four months, as NIST completes its review of vendor evidence documentation currently being finalized by Quantum eMotion and Intertek. This phase represents active progress toward the next formal validation stage.

The ultimate objective remains full FIPS 140-3 certification, after which SecureKey will be officially recognized on NIST’s list of validated modules approved for deployment in regulated environments. While no exact timeline for final certification was provided, the company’s steady progress indicates that each stage brings SecureKey closer to availability in compliance-driven markets requiring certified cryptographic solutions.


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations and video (Content) is a service of Kalkine Media Incorporated (Kalkine Media), Business Number: 720744275BC0001 and is available for personal and non-commercial use only. The advice given by Kalkine Media through its Content is general information only and it does not take into account the user’s personal investment objectives, financial situation and specific needs. Users should make their own enquiries about any investment and Kalkine Media strongly suggests the users to seek advice from a financial adviser, stockbroker or other professional (including taxation and legal advice), as necessary. Kalkine Media is not registered as an investment adviser in Canada under either the provincial or territorial Securities Acts. Some of the Content on this website may be sponsored/non-sponsored, as applicable, however, on the date of publication of any such Content, none of the employees and/or associates of Kalkine Media hold positions in any of the stocks covered by Kalkine Media through its Content. Kalkine Media hereby disclaims any and all the liabilities to any user for any direct, indirect, implied, punitive, special, incidental or other consequential damages arising from any use of the Content on this website, which is provided without warranties. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media. Some of the images/music that may be used in the Content are copyright to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music used in the Content unless stated otherwise. The images/music that may be used in the Content are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have used reasonable efforts to accredit the source wherever it was indicated or was found to be necessary.


We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.