SEALSQ's FIPS 140-3 Headline Is for a Chip With No Post-Quantum Algorithms. The Same Release Moves Its Post-Quantum Chip's First Lab Report From March to October

SEALSQ Corp (Nasdaq: LAES) said on Sept. 24 that it is commercially expanding its VaultIC408 secure element following FIPS 140-3 Level 3 validation under the U.S. National Institute of Standards and Technology's Cryptographic Module Validation Program, published as NIST Certificate No. 5463. According to the release, datelined Geneva and furnished to the Securities and Exchange Commission on a Form 6-K the following day, NIST issued the validation on Aug. 5, 2026 and the certificate runs to Aug. 4, 2031. The release's title pairs that validation with 'Post-Quantum Hardware-Security Programs'. The certificate itself covers no post-quantum algorithm, and the release, further down, says as much.
NIST's certificate page lists the module as 'VaultIC408 1.2.4', a single-chip hardware module at overall Level 3, validated on Aug. 5, 2026 by the laboratory Penumbra Security, Inc. Its approved-algorithm list runs through the AES modes, Counter DRBG, ECDSA and RSA key generation and signing under FIPS 186-4, HMAC with SHA-1 and SHA-2, elliptic-curve key agreement, an SP 800-108 key-derivation function and the SHA-1 and SHA-2 hash family. Neither ML-KEM nor ML-DSA, the two NIST post-quantum standards SEALSQ's own March roadmap says its QS7001 chip supports, appears on the certificate.
The company does not hide this. Under a heading about the post-quantum transition, the release states: 'While the FIPS 140-3 validation announced today applies specifically to the conventional cryptographic functions and approved configuration of VaultIC408 version 1.2.4, the milestone also reinforces the engineering, certification and industrial capabilities supporting SEALSQ's expanding post-quantum semiconductor portfolio.' A later paragraph adds that the validation 'should not be interpreted as validation of other SEALSQ products or of post-quantum algorithms not identified in Certificate No. 5463.' Those two sentences are the most useful in the document. They sit well down a release whose headline says 'Post-Quantum'.
The certificate's own caveat is worth reading. NIST's listing says the validation applies 'When installed, initialized and configured as specified in Section 11 of the Security Policy. When operated in approved mode,' and adds: 'No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.' That is standard CMVP language, but the assurance attaches to the module in one configuration, not to any product built around it.
The second half of the release's headline promises an 'Updated Certification and Commercialization Timetable', and the update is a slip. SEALSQ's Sept. 24 list of 'completed and targeted milestones' for the QS7001 post-quantum secure element reads: March 2026, fault-injection and side-channel testing completed; May 2026, NIST SP 800-90B entropy source validation, certificate E333; 'October 2026 — Targeting the QS7001 V1 Hardware Evaluation Test Report from the Common Criteria lab'; 'January 2027 — Targeting the QS7001 V2 full Post-Quantum Hardware Evaluation Test Report from the Common Criteria lab'; and '2027 — Progression toward completion of the formal Common Criteria EAL5+ certification process, subject to certification-authority review and timelines.'
Set that against the timetable SEALSQ published on March 6, 2026, under the sub-headline 'All Four Post-Quantum Security Products on Track for Common Criteria, FIPS 140-3, and TCG Certifications Through Q4 2026'. That release's table gave the QS7001 V1 hardware evaluation test report a target date of March 2026, and its text said the report 'is expected by end of March 2026, initiating the formal CC certification process.' For V2, the March release targeted the hardware ETR for September 2026 and production samples for October 2026. On April 2, a follow-up release repeated the V2 September target and described the V1 'certification program on track', without restating a V1 report date.
On the September numbers, the V1 report has moved from March to October, seven months, and the V2 report from September to January, four months. Neither the Sept. 24 release nor the Sept. 11 half-year results release describes these dates as revisions, explains the change, or uses the word 'delay'. The only qualifying language is the new '2027' line for EAL5+ completion, 'subject to certification-authority review and timelines', which did not appear in either spring document. The company's chief executive, Carlos Moreira, said in March that 'having certified silicon available is not optional' ahead of 'the NSA CNSA 2.0 January 2027 compliance timeline'. On the updated schedule, the V2 lab report that covers the full post-quantum scope is now targeted for the same month as that deadline.
The QVault TPM line has moved too, though the Sept. 24 release gives no dates for it. In March the QVault TPM 183 was targeted for a FIPS 140-3 lab letter to NIST in May 2026 and TCG certification in August 2026; by April 2 the FIPS submission target had already moved to September 2026 and TCG to October. The Sept. 24 text says only that SEALSQ 'is advancing the certification roadmap for its QVault TPM family, including TCG and FIPS 140-3 milestones extending through 2027.'
Moreira's closing statement in the release is reproduced in full: 'The transition to post-quantum security will not happen through software alone. It requires a secure hardware root of trust, trusted provisioning and cryptographic agility across the entire lifecycle of each connected device. With VaultIC408 and our next generation of post-quantum secure semiconductors, SEALSQ is building the bridge between the cybersecurity requirements of today and the quantum-resistant infrastructure of tomorrow.'
The VaultIC line is the part of SEALSQ that makes money today. The company's Sept. 11 half-year release reported revenue of $11.2 million for the six months to June 30, 2026, up 131% from $4.8 million, and said growth 'was driven primarily by renewed demand for SEALSQ's Vault-IC secure-element product family', alongside PKI subscriptions, initial Quantix Edge Security revenue and six months of the acquired IC'Alps, which contributed approximately $2.5 million. Gross profit was $5.4 million, operating loss $32.2 million and net loss $27.8 million. Cash, cash equivalents and restricted cash were $486.1 million at June 30, with 'the broader liquidity measure including short-term investments' at approximately $495 million.
The same release put post-quantum revenue in the future tense: 'Initial commercial revenue from QS7001 and QVault TPM is expected toward the end of H2 2026, with a more significant contribution anticipated as customers complete technical integration and move into production in 2027 and beyond. Timing remains subject to laboratory review, certification, customer qualification and procurement.' It said 30 prospective customers and partners were evaluating the two product lines at June 30, and put the 'active business pipeline' at more than $225 million through 2029 as of Sept. 9, including more than $100 million associated with the post-quantum projects, figures it described as management estimates subject to conversion risk. Full-year 2026 revenue guidance of $27 million to $36 million was reaffirmed.
The Sept. 24 release attaches no revenue, customer name, order or contract to the VaultIC408 validation. It describes the commercial effect as expected: the validation 'is therefore expected to support SEALSQ's commercial expansion across the United States and international markets'. It does not say whether VaultIC408 was already shipping to government or defence customers before the certificate.
What comes next is measurable against the company's own calendar. If the QS7001 V1 hardware evaluation test report arrives in October, SEALSQ will have hit the first date on its revised list; the V2 report in January 2027 and initial QS7001 revenue 'toward the end of H2 2026' are the next two. What is not known is what caused the seven-month move on V1, or whether the October and January targets are laboratory commitments or company estimates; the Sept. 24 release does not name the Common Criteria laboratory for the QS7001 work in the way the March release named SERMA. The FIPS 140-3 certificate for the VaultIC408 is real, published and active. It is a certificate for the cryptography of the last thirty years.
Sources & further reading
- SEALSQ, "SEALSQ Leverages NIST FIPS 140-3 Level 3 Validation to Accelerate Government, Critical-Infrastructure and Post-Quantum Hardware-Security Programs; Provides Updated Certification and Commercialization Timetable", press release, Sept. 24, 2026
- U.S. Securities and Exchange Commission, SEALSQ Corp Form 6-K, Exhibit 99.1 (Sept. 24 release), furnished Sept. 25, 2026
- NIST Computer Security Resource Center, Cryptographic Module Validation Program, Certificate #5463, VaultIC408 1.2.4 (validation date Aug. 5, 2026; sunset Aug. 4, 2031)
- SEALSQ, "SEALSQ Announces Comprehensive 2026 Certification Roadmap for QS7001 Secure Element and QVault TPM Product Lines", press release, March 6, 2026
- SEALSQ, "SEALSQ and IC'Alps Achieve Key Common Criteria Certification Milestones, Publish Full Post-Quantum Certification Roadmap", press release, April 2, 2026
- SEALSQ, "SEALSQ Reports H1 2026 Financial and Operational Results; Revenue Increases 131% to $11.2 Million; FY2026 Guidance Reaffirmed", press release, Sept. 11, 2026