For Azure architects, security teams and payments engineers, the interesting part is the operating model. The announcement's claims about scale, compliance and availability are the partners' own. The documentation sets out what customers still have to do themselves.
What the three partners each bring
The service has three layers:
- Utimaco supplies the Atalla Payment Module (APM). This is cryptographic software for card issuance, PIN translation, mobile payments and key management, deployed across global payment networks.
- Marvell supplies LiquidSecurity HSM hardware. It is built for high transaction throughput in dense, multi-tenant cloud environments.
- Microsoft delivers the combination as a managed Azure service. That lets customers scale capacity to demand.
Marvell's own blog says a single LiquidSecurity 2 adapter can manage up to 100,000 key pairs and perform over one million cryptographic operations per second. Treat those as Marvell's adapter-level figures. They are not a Microsoft service-level capacity or a per-customer guarantee.
Marvell's blog also argues the payments side lagged because payment HSMs rely on proprietary, vendor-specific interfaces rather than general-purpose APIs such as PKCS#11. The company says applications that already call the Atalla API can be pointed at the Azure service without a rewrite. That is a vendor claim, so test it before relying on it.
"Managed" does not mean "hands-off"
Microsoft describes the service as a highly available, single-tenant payment HSM service. Customers keep exclusive administrative control of an isolated cluster, while Microsoft manages the underlying infrastructure, availability and lifecycle operations.
That sits next to the hardware's "multi-tenant" billing in the launch materials. The multi-tenant label describes how the LiquidSecurity hardware is designed. Microsoft's service documentation says each subscription gets its own isolated cluster.
Microsoft's security guidance also leaves responsibilities with the customer:
- Capacity and resilience. Customers must keep enough active HSM capacity for their own backup, disaster recovery and resilience targets. Microsoft does not manage this on their behalf.
- Key backups. Customers back up their Master File Key and payment keys through the Secure Configuration Assistant (SCA) and backup smart cards.
- Credentials. The administrator and backup smart cards and the C3 Key Loading Device are treated as administrative credentials.
- Data erasure. Microsoft says it has no access to customer data. When a cluster is released, customer data is zeroized and erased.
Preview limits and onboarding
The service is in preview and delivered through gated onboarding, in the West US and West Europe regions. Customers must engage their Microsoft account manager or Customer Support to have their subscription registered and enabled. The preview is available at no charge.
Microsoft's quickstart adds more detail. After Microsoft approves an onboarding request, it connects the customer with the Utimaco Azure team. New Utimaco account requests can take up to 48 hours to process and activate. Plan for that lead time.
Pricing is the open question. Coverage of the launch notes that Microsoft did not disclose pricing, customer contracts or expected revenue. A WindowsForum analysis of the launch also describes the preview as entering without an SLA or pricing.
Network design: private by default
Microsoft's network guidance is specific. The service requires a private endpoint. Deploy the cluster with public network access disabled. Two private endpoints are needed:
| Interface | Port | Used by |
|---|---|---|
| Management | TCP 7005 | Utimaco SCA and the C3 Key Loading Device |
| Application | TCP 2200 | Payment application (Atalla commands and cryptographic operations) |
Several steps follow from that guidance:
- Register the AllowPrivateEndpoints feature for the Microsoft.Network resource provider on each subscription. Otherwise the networking steps fail.
- Create a separate private endpoint for the management interface and one for the application interface.
- Configure a private DNS zone for privatelink.phsm.azure.net. Link it to the virtual networks that hold your admin and application VMs.
- Add outbound NSG rules that allow TCP traffic only to the private endpoint IP addresses on those two ports.
- Run an admin VM in a network that can reach the management endpoint. Use it for the SCA, setup, user management, key management and backup.
- For on-premises access, use a site-to-site or point-to-site VPN. Configure DNS forwarding or Azure DNS Private Resolver so HSM hostnames resolve to private IPs.
Microsoft also suggests keeping the HSM resources in their own resource group, apart from the client VMs and virtual network.
Certificates and trust
Clients authenticate to both interfaces over mutual TLS. Microsoft's guidance sets tight limits:
- Use a self-signed root CA with an elliptic-curve public key on NIST P-256 (prime256v1).
- Intermediate CA certificates and other key types are not supported.
- Use separate trusted issuers for the management and application interfaces.
- Confirm mutual TLS is active in the SCA before administering the cluster.
If your PKI team assumes an enterprise intermediate chain will work, this is the first thing to correct.
Compliance claims and audit logging
Microsoft says the service runs in PCI DSS and PCI 3DS compliant Azure data centers. It says the security infrastructure is certified to FIPS 140-3 Level 3, PCI DSS, PCI 3DS and PCI PIN. It also says the isolated cluster can be deployed as a component within a customer's own PCI solution.
That is not the same as the customer's environment being compliant. The WindowsForum analysis notes that PCI requirements cover the whole payment environment, including key ceremonies, administration, segmentation and monitoring. It also says the public materials do not identify a v2-specific PCI assessment or shared-responsibility matrix. Confirm those documents with Microsoft for your audit scope.
For audit trails, Microsoft says to enable Azure Monitor diagnostic settings. They send the HsmOperations log category to a Log Analytics workspace and a storage account. You can query the CloudHsmHardwareOperationAuditLogs table. Microsoft also suggests reviewing the "Daily self-tests passed" entries that the APM generates.
Not a drop-in upgrade for existing Azure Payment HSM users
This is a separate service from the existing Azure Payment HSM, which uses Thales payShield 10K hardware. Microsoft says the two coexist. For general-purpose key storage, Microsoft points customers to Azure Cloud HSM.
The WindowsForum analysis puts it bluntly: the hardware, control plane and service model differ, so existing customers should treat v2 as a new platform qualification rather than an ordinary upgrade. That seems right. A shared application API may make porting easier, but HSM migrations also involve key ceremonies, tooling and audit evidence.
One discrepancy in the source material: Marvell's blog calls the offering "Azure Cloud HSM v2" in one passage and later says it is expected to start with North America and European Union markets. Microsoft's documentation and the joint press release use the name Azure Payment HSM v2 and name the West US and West Europe regions. Use the Microsoft naming and region details.
What to do now
- Evaluate only if you're a payments shop. This is for banks, processors and payment service providers. It is not a general key vault.
- Request onboarding early. Gated access and Utimaco account setup add lead time.
- Prototype the network and PKI. Private Link, DNS, NSG rules and the P-256 root CA requirement are where early friction is most likely.
- Don't plan production on it yet. It's a preview with no published pricing, and capacity and resilience planning remain yours.
- Ask for compliance evidence. Get service-specific PCI documentation and a shared-responsibility breakdown before any audit commitment.
The bigger picture is that payment HSMs were one of the last cryptography workloads tied to racks and appliances. If the preview holds up in practice, that changes the operating model. Whether it clears the bar for regulated production is a separate question that Microsoft and its partners haven't yet answered.
References
- Microsoft, Marvell and Utimaco Launch Cloud-Scale Payment Security Platform - The Fast Mode The Fast Mode · Fri, 09 Oct 2026 00:40:57 GMT
- Network security for Azure Payment HSM v2 | Microsoft Learn learn.microsoft.com
- Microsoft, Marvell and Utimaco to Deliver Industry-first Secure, Cloud-scale Payments Solution markets.financialcontent.com