Path to PCI HSM: IBM (I13b)
IBM first achieved PCI HSM for the Crypto Express 6S (CEX6S) with Common Cryptographic Architecture (CCA) firmware for IBM Z in 2018. IBM achieved an update certification in 2019 and the 2021 certification of the new Crypto Express 7S (CEX7S). Guiding principles for the original design were flexibility, low disruption and *usability* for our customers while adhering to the PCI requirements. This talk highlights the changes made for PCI HSM certification of the CEX6S and how the design principles were carried through.