For more than a decade, the cloud has been rewriting the rules of cryptographic security. Signing, certificate management, tokenization and encryption key management have all found their way from on-premises hardware security modules (HSMs) into fully managed cloud services. But one corner of the HSM world has stubbornly resisted that shift: payments.
Until now, there has been no true cloud HSM for payments. That is changing with Azure Cloud HSM v2, a new offering built jointly by Marvell, Microsoft and Utimaco, entering public preview as of September 17, 2026.
To understand why this matters, it helps to look back at where payment security came from, and why it took a different path than the rest of the cryptography world.
Where It All Started: The Atalla Box
This is the payments chapter of a much broader evolution in Azure key management. Azure began by making HSM backed key protection available as a shared cloud service, expanded to dedicated HSM appliances for customers requiring exclusive hardware control, and then evolved toward cloud-native, single-tenant HSM services that deliver tenant isolation, customer control, and cloud-scale operations without requiring customers to manage the underlying hardware. Azure Payment HSM v2 extends that evolution to the highly specialized world of payment cryptography.
The hardware security module, as a category, traces back to the banking industry. In 1973, Dr. Mohamed Atalla, an inventor already known for his earlier work on semiconductor technology, founded the Atalla Corporation to solve a very specific problem: how to protect a personal identification number (PIN) as it travelled between an automated teller machine (ATM) and a bank's back-end systems. His answer, the Atalla Box, became the first commercial HSM and secured the majority of the world's ATM transactions for decades. Atalla's contributions to PIN security were significant enough that he became known in the industry as the father of the PIN.1
That heritage runs deeper than the hardware itself. The way payment HSMs exchange keys and metadata between systems today, still commonly called the Atalla Key Block after its origins, became the basis for banking standards used industry wide. It is one of the reasons payment HSMs speak a different language than general-purpose HSMs. While general-purpose cryptography settled around common APIs such as PKCS#11, JCE and Microsoft CAPI, payment HSMs have continued to rely on proprietary, vendor-specific interfaces built around this decades-old foundation, mainly from Atalla and Thales. That difference in how applications talk to hardware, not just the hardware itself, is a big part of why payment workloads have lagged in the move to the cloud.
The Atalla product line changed hands several times over the following decades, moving through Tandem Computers, Compaq and HP before eventually landing at Utimaco in 2018. What stayed constant through all of that change was the software itself. The same Atalla payment logic that banks and payment processors had already built their infrastructure around carried forward largely untouched, along with the standards it had helped create. That continuity, more than any particular owner, is why it remains foundational in payments today.
The Cloud HSM Era Arrives, But Payments Get Left Behind
As public key cryptography moved to the cloud, hyperscalers built out Cloud HSM services based on Marvell® LiquidSecurity® HSMs, opening the door for banks and financial institutions to move a wide range of cryptographic workloads off-premises, including signing, certificate management and tokenization-based payment services. But the traditional core of payment processing, operations like PIN translation that depend on a payment HSM, could not make the same move. The HSM handling those functions needed to remain on premises, tied to proprietary payment software that had no cloud equivalent.
The industry's workaround was to colocate traditional payment HSM appliances inside hyperscaler data centers as bare-metal or colocation services. It solved the immediate access problem, but it is fundamentally an anti-cloud pattern. Scaling means racking up another box. Peak capacity means customers buying and paying for headroom they may rarely use. And for the hyperscaler, every customer effectively needs a dedicated, hands-on deployment, which is difficult to sustain cost-effectively at scale. The result is a gap that has persisted for years: general-purpose cryptography went cloud-native, while payment cryptography stayed anchored to physical hardware.
Closing the Gap
Marvell closes that gap by taking the original Atalla payment software, now packaged as the Atalla Payment Module, and porting it onto Marvell LiquidSecurity 2 HSM hardware, the same hardware already deployed inside hyperscaler infrastructure and powering existing general-purpose Azure Cloud HSM, KeyVault and Trust services. A single LiquidSecurity 2 adapter can manage up to 100,000 key pairs2 and perform over one million cryptographic operations per second, giving the payments workload the same high-throughput, hardware-based foundation that already underpins signing, certificate management and key management at hyperscale. Rather than requiring a new integration or a rewrite of application code, banks and payment processors that already call the familiar Atalla application programming interface (API) can point that same application to the new Azure service and let Azure handle the scaling, high availability, backup and restore behind it.
That is the shift this offering represents: not a new payments platform to learn, and not new hardware to prove out, but the same trusted payment software finally running on cloud-proven Marvell hardware, the way general-purpose cryptography has run in the cloud for years.
New Payments Security Joint Offering
Marvell, Microsoft and Utimaco are bringing this together as a new payments security offering that combines three layers:
The offering is expected to enter public preview on September 17, 2026, with initial availability in North America and European Union markets.
Why It Matters
For banks, payment processors and financial technology companies, this closes a gap that has existed since the earliest days of cloud computing. Regulatory and compliance requirements, including PCI PIN Security, along with regional data sovereignty rules, do not go away in the cloud, and this offering is designed to meet them with hardware-based assurance while removing the operational burden of managing dedicated payment infrastructure. Existing applications do not need to change. Customers gain the ability to scale up or down with demand instead of provisioning for peak.
For Marvell, this marks an extension rather than a new bet. The same LiquidSecurity hardware already carrying general-purpose cryptographic workloads across hyperscaler Cloud HSM services now takes on the payments workload that had been stuck on-premises for decades. The hardware-based security model that has protected payment transactions since Dr. Atalla's original invention now runs on that hardware in the cloud rather than stopping at the data center door.
Cryptography at Hyperscaler Pace
Payments has simply been on a different timeline than the rest of the cryptography world, held back not by hardware but by decades of infrastructure built around a proprietary way of talking to it. Solving that took more than a new feature. It took the same hardware already carrying general-purpose cryptographic workloads across hyperscaler infrastructure, extended to carry a workload nobody had managed to move off-premises before.
This is the pattern behind LiquidSecurity: hardware built once, then extended across signing, certificate management, key management and now payments, rather than reinvented for each new workload. As transaction volumes climb and fraud grows more sophisticated, that pace matters, and it is only accelerating as AI demands reshape what encryption at scale needs to look like. The infrastructure banks and payment processors rely on needs to scale as fast as the threats against it, and it needs to do so without asking every customer to rack up another box. Marvell Security Products are built to move at that pace, with payments as the newest proof of it and more chapters still ahead.
# # #
This blog contains forward-looking statements within the meaning of the federal securities laws that involve risks and uncertainties. Forward-looking statements include, without limitation, any statement that may predict, forecast, indicate or imply future events or achievements. Actual events or results may differ materially from those contemplated in this blog. Forward-looking statements are only predictions and are subject to risks, uncertainties and assumptions that are difficult to predict, including those described in the “Risk Factors” section of our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q and other documents filed by us from time to time with the SEC. Forward-looking statements speak only as of the date they are made. Readers are cautioned not to put undue reliance on forward-looking statements, and no person assumes any obligation to update or revise any such forward-looking statements, whether as a result of new information, future events or otherwise.
Tags: Cloud, Security, HSMs, HSM services, cloud-optimized HSMs, HSM Applications, Data Center, Marvell