Hardware-encrypted portable storage has a persistent design bottleneck: fitting more capacity into a USB flash drive geometry while satisfying FIPS 140-3 Level 3 requirements, which impose physical and cryptographic constraints that grow harder to meet as storage density increases. San Diego-based Apricorn says its new 4TB Aegis Secure Key 3 meets and exceeds those Level 3 requirements. The company has formally submitted the device to the National Institute of Standards and Technology's Cryptographic Module Validation Program for certification.
What FIPS 140-3 Level 3 demands
FIPS 140-3 is the federal standard governing cryptographic modules used across government and regulated industries. Level 3 adds physical tamper-evidence and response controls on top of the cryptographic algorithm requirements at lower levels. For a flash drive, satisfying those physical requirements inside a compact enclosure while also delivering fast throughput at 4TB of capacity is the engineering trade-off Apricorn is claiming to have resolved. The Aegis Secure Key 3 is the product making that claim. The CMVP submission remains pending review, which means a formal validation certificate has not yet been issued and the device is not listed on NIST's active validated modules database.
Submission is not certification
Apricorn's announcement, dated July 15, 2026, names the formal CMVP submission. It does not cite a certificate number. The two are different: submission starts the NIST review process; the certificate ends it. Government procurement frameworks in many contexts require the completed validation, not an application in queue. Regulated buyers will need to check the CMVP active list before relying on the ASK3 for compliant deployments.
Quantum-resistant framing and the open algorithm question
Apricorn describes itself as a provider of quantum-resistant hardware-encrypted external storage solutions. The Aegis Secure Key 3 positions within that line as federal post-quantum cryptography standards mature. The announcement does not name which post-quantum algorithms the device implements.