Microsoft, Marvell Technology and Utimaco have introduced Azure Payment HSM v2, a new managed cloud-security platform aimed at moving highly sensitive payment cryptography onto infrastructure designed to operate at hyperscale. The companies announced the service on September 17, with public-preview availability beginning immediately in Western U.S. and Western Europe. The platform combines Microsoft Azure with Marvell LiquidSecurity hardware security modules and Utimaco’s Atalla Payments Module software.

The launch addresses a specialized part of the financial-technology stack that has historically been harder to migrate into cloud environments than ordinary banking applications. Payment hardware security modules, or HSMs, perform critical cryptographic operations involving payment credentials, personal identification numbers, card issuance and transaction authentication. These systems must protect highly sensitive keys while also meeting demanding requirements for latency, availability, auditability and compliance.

Azure Payment HSM v2 is designed to provide those functions through a fully managed Azure service rather than requiring a bank, processor or payment-service provider to purchase, provision and maintain its own dedicated payment HSM infrastructure. Marvell said the offering is intended to give customers a hardware-backed foundation for payment transactions while reducing the operational complexity associated with deploying and maintaining physical devices.

The architecture assigns a distinct role to each of the three technology providers. Marvell supplies its LiquidSecurity HSM technology, which is designed for high-density cloud deployments and hardware-based protection of cryptographic keys. Utimaco provides the Atalla Payments Module, the payment-specific cryptographic software layer. Microsoft integrates the components within Azure and provides the managed cloud-service environment through which financial institutions can consume the platform.

For payment companies, that combination matters because general-purpose cloud cryptography and payment cryptography have evolved differently. Key-management services used for activities such as certificate protection, data encryption and digital signing have become widely available as managed cloud products. Payment infrastructure has remained more dependent on specialized appliances because of industry-specific protocols, operational controls and compliance regimes surrounding payment credentials and PIN processing.

Marvell described the new platform as an attempt to close that gap. In a technical discussion accompanying the launch, the company said payment HSM deployments have traditionally forced customers to provision infrastructure for peak transaction requirements and operate specialized hardware themselves. Azure Payment HSM v2 instead brings the payment software onto Marvell’s cloud-oriented LiquidSecurity 2 hardware and places management of the underlying infrastructure within the Azure service model.

Utimaco’s Atalla technology is central to maintaining compatibility with established payment environments. According to the launch materials, the software supports card issuance, PIN translation, mobile-payment functions and cryptographic key management. Marvell said banks and processors already using the Atalla application programming interface can direct existing applications toward the Azure service without rewriting those applications for a new cryptographic interface.

That compatibility could be important for financial institutions with large portfolios of legacy payment applications. Core transaction-processing systems are often tightly integrated with established cryptographic interfaces, making wholesale application changes expensive and operationally sensitive. A service that preserves familiar interfaces while changing the infrastructure underneath them could offer institutions a more incremental path toward cloud-based payment processing.

The v2 architecture also reflects a change in how Azure can deliver payment-specific HSM capacity. Microsoft’s existing public documentation describes Azure Payment HSM as a bare-metal service using Thales payShield 10K devices. Under that documented model, customers receive single-tenant HSM appliances connected directly to their virtual networks and retain administrative control over the allocated devices. Microsoft describes those HSMs as suitable for payment processing, PIN and EMV cryptogram validation, credential issuance, remote key loading, tokenization and related functions.

Azure Payment HSM v2, by contrast, is being presented as a more cloud-native managed model built around Marvell and Utimaco technology. Marvell said Azure can manage scaling, high availability, backup and restore functions behind the service, reducing the need for customers to provision dedicated capacity around expected peak loads. That approach brings payment cryptography closer to the consumption model already common across other cloud infrastructure services.

Cloud payment-security infrastructure representing Microsoft Azure, Marvell LiquidSecurity and Utimaco Atalla technology supporting regulated financial transactions.

The companies are emphasizing compliance as much as scalability. Payment HSM infrastructure sits inside heavily controlled security environments, and moving those workloads into the cloud does not eliminate obligations covering cryptographic key protection, payment-card standards, auditing and data residency. The new service was designed around requirements including PCI PIN Security, PCI HSM controls and regional data-sovereignty considerations, according to Marvell.

Microsoft’s broader Azure Payment HSM documentation lists compliance frameworks associated with its payment-HSM offering, including PCI DSS, PCI PIN and PCI 3DS, alongside multiple ISO, SOC and cloud-security certifications. Because Azure Payment HSM v2 has just entered public preview, customers evaluating it will still need to review the specific certifications, service scope and shared-responsibility documentation applicable to the v2 configuration and to their individual regulatory environments.

Key sovereignty is another focus of the launch. Financial institutions increasingly operate across jurisdictions that impose requirements on where sensitive information is processed and how cryptographic material is controlled. Microsoft, Marvell and Utimaco said the v2 platform is intended to allow customers to protect sensitive payment assets and maintain cryptographic key sovereignty while benefiting from cloud infrastructure.

Initial deployment in Western U.S. and Western Europe gives the platform access to two major financial-services markets while providing separate geographic footprints for organizations considering regional data requirements. Broader geographic expansion was not detailed in the September 17 announcement, making regional availability one area likely to be watched as the service progresses beyond public preview.

Performance is also a core design consideration because payment authorization systems must complete large numbers of cryptographic operations with consistently low latency. Marvell says its LiquidSecurity architecture was developed for dense, multi-tenant cloud environments and high transaction throughput. In its technical explanation of the service, the company said a LiquidSecurity 2 adapter can manage as many as 100,000 key pairs and perform more than one million cryptographic operations per second, although actual application performance will depend on service configuration and workload characteristics.

For fintech companies and payment processors, elastic infrastructure could be particularly relevant during periods when authorization traffic changes rapidly. Conventional payment-security deployments may require operators to purchase capacity for forecast peaks, leaving hardware underutilized during normal periods. A cloud-managed architecture potentially allows infrastructure resources to be aligned more closely with changing demand while shifting maintenance and availability tasks to the service provider.

Microsoft framed that operational shift as one of the core benefits of the collaboration. Soumya Subramanian, Microsoft’s vice president of Cloud Security Engineering, said the service is intended to remove the burden of managing payment-specific HSM infrastructure so customers can devote more resources to product development and other business priorities. Marvell similarly positioned the service as a way to expand payment-security capacity without the cost and operational work associated with traditional dedicated deployments.

The model may be relevant to several groups across the payments market. Large banks can use cloud-based HSM infrastructure as part of broader data-center modernization programs. Payment processors can potentially scale cryptographic capacity alongside transaction volumes. Digital banks and fintech companies that were built around public-cloud infrastructure can gain access to specialized payment cryptography without first establishing physical HSM estates in privately operated data centers.

The service could also reduce an architectural mismatch faced by financial firms whose applications have already moved into cloud environments while payment-security hardware remains in private facilities. Maintaining that split can require network connectivity between cloud applications and remote cryptographic appliances, adding infrastructure dependencies and potentially complicating resilience planning. Locating payment cryptography within the cloud environment can simplify some of those architectures, although institutions will still need to design connectivity, redundancy and disaster-recovery arrangements around their own risk requirements.

Cloud payment-security infrastructure representing Microsoft Azure, Marvell LiquidSecurity and Utimaco Atalla technology supporting regulated financial transactions.

Microsoft’s security guidance for the existing Azure Payment HSM service illustrates how specialized these environments remain. The company recommends isolated network configurations, tightly managed connectivity and careful planning for links between cloud and on-premises resources. Its documentation also notes that payment HSM deployments protect particularly sensitive cryptographic material and therefore require strong controls across networking, identity, monitoring, governance and recovery.

Azure Payment HSM v2 does not eliminate those security responsibilities. Instead, the commercial proposition is to move more of the hardware lifecycle and infrastructure operations behind a managed service boundary while preserving the cryptographic assurances demanded by payment workloads. For financial institutions, the practical value will depend on how responsibilities are divided between Azure and the customer, which controls remain customer-operated and how compliance assessors treat the architecture.

The involvement of Utimaco gives the platform a connection to one of the payment industry’s longest-running cryptographic technology lines. The Atalla name traces back to early commercial HSM development for banking and PIN protection. Utimaco now operates the Atalla payment-security technology, and Chief Executive Stefan Auerbach said the Azure project places the Atalla Payments Module on Marvell’s multi-vendor HSM infrastructure.

For Marvell, the agreement expands the scope of its LiquidSecurity technology beyond general-purpose cloud cryptography into dedicated payment workloads. The company said the same broader hardware family is already used for cloud HSM and key-management infrastructure, allowing the payment offering to build on hardware intended for hyperscale operation rather than creating a separate appliance architecture exclusively for payments.

Microsoft, meanwhile, strengthens Azure’s financial-services infrastructure portfolio at a time when banks and payment companies continue moving selected workloads toward public-cloud platforms while retaining strict controls around their most sensitive systems. Payment HSMs represent a relatively narrow infrastructure category, but they sit on a critical path for card transactions, authentication and credential management, making their cloud deployment strategically important to broader payment modernization efforts.

The public-preview designation means the service remains at an early stage of commercial deployment. Financial institutions considering Azure Payment HSM v2 will likely evaluate performance under real transaction patterns, regional availability, migration procedures, interface compatibility, resiliency behavior, audit evidence and the precise scope of applicable PCI certifications before adopting it for large-scale production workloads.

The launch nevertheless signals a broader direction for payment infrastructure. Rather than treating specialized cryptographic appliances as permanently separate from cloud architecture, Microsoft, Marvell and Utimaco are attempting to deliver payment-grade security through the same managed-infrastructure principles that have already reshaped computing, storage, databases and general-purpose key management. If that model proves suitable for regulated production environments, payment HSM capacity could increasingly become a cloud service consumed alongside the applications that depend on it.

For the fintech sector, that shift is significant because payment innovation increasingly depends on infrastructure that can expand across products and regions without requiring every provider to build its own underlying security hardware estate. Azure Payment HSM v2 brings one of the payments industry’s most specialized security functions closer to that model, combining established payment cryptography with cloud-oriented hardware and Azure operations. Its public preview will provide the first test of whether banks, processors and fintech platforms are ready to move more of their payment-security layer from dedicated appliances to managed cloud infrastructure.