Buy the HYP2003 — a FIPS 140-3 DSC token
A Digital Signature Certificate cannot be held as a file on a computer — it lives on a secure USB crypto token. The HyperPKI HYP2003 is validated to FIPS 140-3 Level 3 and lists CCA India among its certifications, so a certificate issued onto it today will still be issuable after the change. Order from our Salem, Tamil Nadu office — shipped anywhere in India.

Notice: FIPS 140-3 — FIPS 140-3 becomes mandatory for new DSC issuance from 21 September 2026. Certificates can no longer be downloaded onto FIPS 140-2 tokens after that date. Existing certificates on 140-2 tokens keep working until they expire.
Tell us where to send it
The token is the same for everyone. Your details and the quantity are all we need to quote and dispatch.
- A new Class 3 or DGFT certificate being issued
- A renewal, where your current token is worn, damaged or you would rather start fresh
- Replacing a token that is lost, damaged or locked
- Stocking up as a professional or channel partner issuing to your own clients
- Total
- On request
We confirm the full amount, including GST and delivery, before anything is paid.
This opens WhatsApp with your order written out — nothing is sent or stored until you press send there, and nothing is paid until you have the quote.
What the specification actually buys you
Token choice looks like a commodity decision until something goes wrong. Three specifications on this datasheet are the ones that matter in practice.
01
Onboard key generation
The private key is generated and used inside the token and never leaves it. This is not a convenience feature — it is what makes the signature trustworthy, and why a certificate cannot be held as a file on a computer.
02
FIPS 140-3 Level 3
Level 3 adds physical tamper resistance and identity-based authentication over Level 2. Most tokens in this market are validated to the older FIPS 140-2 standard; this one is validated to 140-3.
03
Middleware that installs itself
An onboard auto-run partition installs the driver automatically. Driver installation is where most support calls in this business originate, so this removes the commonest failure point — particularly for clients you never meet in person.
HYP2003 full specification
As published by the manufacturer in the HyperPKI HYP2003 datasheet.
Hardware
- Dimensions
- 53 × 16.5 × 8.5 mm
- Weight
- 6 g
- Storage
- 64 KB for signing and encryption
- Connectivity
- USB 2.0 compliant
- Data retention
- At least 10 years
- Rewrite cycles
- At least 500,000
- Storage temperature
- −20°C to 70°C
- Humidity
- 0–100% RH
Security and compatibility
- FIPS 140-3
- Security Level 3
- Certifications
- FIPS 140-3 Level 3 · CCA India · FCC/CE/ICES · RoHS/REACH
- Algorithms
- RSA 2048–4096, AES, SHA, ECDSA
- Hash
- SHA-256, SHA-384, SHA-512
- Operating systems
- Windows, Linux, macOS
- Standards
- Microsoft CAPI/CNG · PKCS#11 v2.20 · Smart Card Minidriver · PC/SC, CCID · SSL v3 · IPSec/IKE
- Middleware
- Onboard auto-run partition, automatic install
Operating temperature range is stated in the manufacturer's datasheet. Confirm the current figure with us before specifying the token for an unusual environment.
The token rule is changing. Here is what it means for you.
01
If you are buying a certificate now
Ask which token it will be issued onto. A certificate issued onto a FIPS 140-2 token before the change stays valid for its full term — but when it comes up for renewal, you will need new hardware.
02
If you already hold a certificate
Nothing stops working. Your existing certificate on a 140-2 token runs to expiry as normal. Plan for a new token at renewal rather than replacing anything today.
03
If you issue for clients
Check your stock. Any 140-2 tokens still on the shelf after the change cannot take a new certificate. Partners ordering through us are supplied on FIPS 140-3 hardware.
A 140-3 token costs no more than a 140-2 token and saves replacing it at your next renewal. That is the entire practical difference — there is no reason to buy the older hardware at this point.
HYP2003 against a typical FIPS 140-2 token
A handful of tokens cover most Class 3 certificates issued in India, and on most specifications they are close. One row on this table is about to matter far more than the rest.
| Specification | HYP2003 | Typical FIPS 140-2 token |
|---|---|---|
| FIPS validation | HYP2003140-3, Level 3 | Typical FIPS 140-2140-2, Level 3 |
| Issuable after the change | HYP2003Yes | Typical FIPS 140-2No — new certificates require a 140-3 token |
| Key sizes | HYP2003RSA 2048–4096, ECDSA | Typical FIPS 140-2Commonly RSA up to 2048 |
| PKCS#11 support | HYP2003v2.20 | Typical FIPS 140-2Commonly v2.10 |
| Rewrite cycles | HYP2003500,000+ | Typical FIPS 140-2Varies — 100,000 upward |
| Storage capacity | HYP200364 KB | Typical FIPS 140-2Varies — some offer more |
| Operating systems | HYP2003Windows, macOS, Linux | Typical FIPS 140-2Usually all three |
| Onboard key generation | HYP2003Yes | Typical FIPS 140-2Yes — required for a Class 3 certificate |
| Auto-install middleware | HYP2003Yes, onboard partition | Typical FIPS 140-2Usually yes |
| Data retention | HYP200310+ years | Typical FIPS 140-2Usually 10 years |
Being straight about this: most crypto tokens sold for Indian DSCs are broadly similar. They all keep the private key non-exportable, they all install without much fuss, and they all outlast the certificates you will put on them. On storage capacity the HYP2003 is not the largest available, and capacity is rarely the constraint anyway.
Where it genuinely leads is validation standard, supported key sizes and PKCS#11 version. Once the change takes effect, the validation row stops being a specification comparison and becomes the difference between a token that can take a new certificate and one that cannot.
The right-hand column describes FIPS 140-2 tokens generally, not any particular product. Using a specific token and want to know where it stands? Send us the model and we will tell you plainly, including when the answer is that it is fine as it is.
Single tokens and bulk supply
With a new certificate
Ordering a Class 3, Combo or DGFT certificate through us? The token comes with it, pre-checked, and we install the driver with you. Nothing to source separately.
Replacing a token
Lost, damaged or locked? A new token is needed, and the certificate has to be re-issued onto it — a certificate cannot be copied across. Tell us what happened and we will handle both.
Bulk and partner supply
Consultants and DSC partners ordering in volume are supplied at partner rates, quoted on application.
See the partner programmeQuestions about tokens
What a token is for, what happens when one locks, and what the FIPS 140-3 change actually asks of you.
Because the private key has to be non-exportable. A key held as a file on a computer could be copied without your knowledge, which would make the signature meaningless. The HYP2003 generates and uses the key onboard, so it never leaves the device — that is the whole basis on which a digital signature is trusted.
The manufacturer's datasheet lists CCA India among its certifications, alongside FIPS 140-3 Level 3, FCC, CE, ICES and RoHS/REACH.
Yes — Windows, Linux and macOS are all supported, and the token carries an onboard partition that installs the middleware automatically. Worth flagging, because macOS support is where token choice most often catches people out.
The HYP2003 has 64 KB for signing and encryption, which holds multiple certificates. Useful where one person signs in more than one capacity — an individual certificate for their own filings and an organisation certificate for the company.
No. The certificate expires; the token does not. With at least ten years of data retention and 500,000 rewrite cycles, the same token carries you through several renewal cycles.
No. Cryptographic tokens lock permanently after a set number of incorrect password attempts — that is a security feature, not a fault. The certificate cannot be recovered and must be re-issued onto a new token. If you are close to the attempt limit, stop guessing and call us.
From 21 September 2026, Certifying Authorities stop issuing new Digital Signature Certificates onto FIPS 140-2 tokens, so fresh issuance and renewals will need a FIPS 140-3 token. Certificates already sitting on a 140-2 token continue to work normally until they expire — nothing is switched off. What changes is that at your next renewal you will need 140-3 hardware.
No. If you hold a working certificate on a FIPS 140-2 token, use it until it expires. The time to move is at renewal. If you are buying a new certificate today, though, ask for a 140-3 token — it costs no more and saves you buying hardware twice.
Yes. The manufacturer's datasheet states FIPS 140-3 Security Level 3, validated by NIST, and lists CCA India among its certifications. That is why we stock it — a certificate issued onto it today will still be issuable after the change.
Usually, if it is a compliant crypto token in working order and not locked. Send us the model and we will confirm before you order anything.
Specifications sourced from the HyperPKI HYP2003 datasheet, HSTE-NB0026 RV 3.1-IND. Last reviewed: 05-09-2026.
Ordering more than a handful?
Tell us how many and who they are for. Bulk orders are quoted together and dispatched together, rather than one at a time.
