FAQs: Deprecation of IBM Cloud Hyper Protect Crypto Services
IBM Cloud® Hyper Protect Crypto Services is deprecated. As of 28 March 2026, you can't create new instances, and access to free instances will be removed. Existing premium plan instances are supported until 28 March 2027. Any instances that still exist on that date will be deleted.
1. What is happening and why?
IBM Cloud is withdrawing (service deprecation) IBM Cloud Hyper Protect Crypto Services (HPCS) across selected regions. This aligns with IBM’s strategy to deliver a more consistent experience across key management services and to unify BYOK/KYOK capabilities via IBM Cloud Key Protect Dedicated. This withdrawal affects all HPCS capabilities, including CloudKMS (KMIP), CloudHSM/GREP11, and Unified Key Orchestrator.
- Impacted regions
-
- Dallas (us-south)
- Washington D.C. (us-east)
- Toronto (ca-tor)
- Frankfurt (eu-de)
- London (eu-gb)
- Madrid (eu-es)
- Tokyo (jp-tok)
- São Paulo (br-sao)
2. Which HPCS capabilities are affected?
- CloudKMS (including KMIP for VMware)
- CloudHSM / GREP11 (PKCS#11)
- Unified Key Orchestrator (UKO)
3. Key dates and milestones
| Milestone | Date |
|---|---|
| External announcement | March 20, 2026 |
| End of marketing | March 28, 2026 |
| End of support / service shutdown: | March 20, 2027 |
4. Supported migration paths (by use case)
-
CloudKMS (including KMIP for VMware):
- Migrate to IBM Cloud Key Protect Dedicated (where available).
- If Dedicated is not available in-region, migrate to IBM Cloud Key Protect (multi-tenant).
-
CloudHSM / GREP11 (PKCS#11)
- Migrate to on-premises deployment to continue on IBM LinuxONE technology.
- IBM Cloud Key Protect Dedicated PKCS#11 is planned for 2Q 2026 (where supported).
-
Unified Key Orchestrator (UKO)
- Migrate to on-premises: UKO for Containers or UKO for z/OS.
5. Migration tooling availability
IBM Cloud migration tooling for HPCS → Key Protect is planned to be available on March 20, 2026.
6. How to prepare (in a phased approach)?
- Understand changes and target options going forward
- Assess affected assets/services and cryptographic dependencies
- Select and prepare the target environment (Key Protect or on-premises)
- Align cryptographic configuration and policies
- Select a key-migration approach and test
- Migrate applications and assets; update runbooks and procedures
- Cut over and decommission legacy HPCS resources
7. Migration Checklist for Customers for IBM Cloud Key Protect
-
Choose Your Target Key Protect Tier
- Use Key Protect Dedicated (single‑tenant, KYOK‑enabled with KMIP for VMware) in regions where it is available.
- Use Key Protect Multi‑Tenant in regions where the Dedicated tier is not available.
-
Prepare Your Environment
- Review the HPCS to Key Protecet Migration guide
- Create a Key Protect instance in your development or test environment. For test purposes we recommend to set up a Cloud Object Storage instance encrypted with a key from Hyper Protect Crypto Services, to get familiar with the migration tool once it is available
-
Plan and Execute Migration
- Use the IBM Cloud migration tools to move keys from HPCS to Key Protect Dedicated or Multi‑Tenant tiers. You can test the tool with the COS instance setup in step 2.
Migration tools will be available on March 20, 2026.
Please refer to our detailed Migration Guide for further details (Migration Guide for IBM Cloud HPCS KMS and KMIP for vmware).
8. On‑premises migration (CloudHSM / UKO)
- Review the detailed migration guide for your use case (GREP11/PKCS#11 or UKO).
- Assess and validate datacenter requirements and capacity.
- Build a complete crypto asset/dependency inventory to manage interdependencies.
- Plan for operational model changes (people/process/monitoring).
- Provision target environment and conduct stability/performance testing.x
On‑prem migration may require purchase of hardware, software, and services.
9. Roles, responsibilities, and financial planning
Customers are responsible for planning and executing migration activities based on their current HPCS usage. Please work with your Customer Success Manager (CSM) on planning and risk identification.
Some migration options shift from managed cloud service to customer‑managed deployments; budget and financial planning may be required.
10. References
- HPCS → Key Protect Migration Guide (Refer to KP-Dedicated Migration Guide)
- GREP11/PKCS#11 On‑prem Migration Guide (Refer to GREP11/PKCS#11 Migration Guide)
- UKO Migration Guide (Refer to UKO Migration Guide)
- ServiceNow request templates (Refer to the FAQ no 16. Support during the transition in the same page)
11. What does this mean for customers?
Customers are responsible for planning and executing their migration based on how they currently use HPCS. Depending on the use case, this may include migrating to Key Protect Dedicated Migration tooling is planned to become available starting March 20, 2026 or moving to an onpremises deployment for CloudHSM or UKO scenarios.
12. What happens if no action is taken?
After March 20, 2027, any remaining HPCS instances will be terminated and cryptographic material will be deleted. Applications depending on HPCS will stop functioning. Customers will receive advance notifications.
13. Which migration options are available by Use Case?
- CloudKMS and KMIP for VMware
-
- IBM Cloud Key Protect Dedicated (single‑tenant, supports Keep Your Own Key; available in selected regions)
- IBM Cloud Key Protect Multi‑Tenant (all regions)
Migration tooling will support key migration from HPCS to Key Protect. For more details, refer to HPCS‑to‑KP-Dedicated Migration Guide.
- CloudHSM (GREP11 and PKCS#11)
-
- On‑premises deployment on IBM LinuxONE technology
- IBM Cloud Key Protect Dedicated PKCS#11 (planned availability: Q2 2026)
For HPCS to Confidential Computing Container Runtime (on-prem)(PID (5737-I09)) migration guide, follow HPCS to CCRT migration guide.
- Unified Key Orchestrator
-
- Unified Key Orchestrator for Containers (on‑premises)
- Unified Key Orchestrator for z/OS (on‑premises)
Follow UKO to UKO on-prem migration guide.
If the customer is using ISV applications that are affected by the migration, the migration needs to be planned and performed in shared responsibility / in coordination between the customer and the ISV.
| Product / Capability | Alternative / Recommendation |
|---|---|
| IBM Cloud Hyper Protect Crypto Services IBM CloudKMS including KMIP for vmware |
Migrate to
|
| IBM Cloud Hyper Protect Crypto Services CloudHSM / GREP11 |
Migrate to
|
| IBM Cloud Hyper Protect Crypto Services CloudHSM PKCS#11 |
Migrate to
|
| IBM Cloud Hyper Protect Crypto Services Unified Key Orchestrator |
Migrate to
|
14. How can I migrate my CloudKMS and KMIP for vmware keys to IBM Cloud Key Protect (Dedicated) – High level?
Migration Checklist for Customers for IBM Cloud Key Protect
- Choose Your Target Key Protect Tier
- Use Key Protect Dedicated (single‑tenant, KYOK‑enabled with KMIP for VMware) in regions where it is available.
- Use Key Protect Multi‑Tenant in regions where the Dedicated tier is not available.
- Prepare Your Environment
- Review the HPCS to Key Protect Migration guide.
- Create a Key Protect instance in your development or test environment.
- For test purposes we recommend setting up a Cloud Object Storage instance encrypted with a key from Hyper Protect Crypto Services, to get familiar with the migration tool once it is available.
- Plan and Execute Migration
- Use the IBM Cloud migration tools to move keys from HPCS to Key Protect Dedicated or Multi‑Tenant tiers. You can test the tool with the COS instance setup in step.
Migration tools will be available on March 20, 2026.
For further details, please refer to KP-Dedicated Migration Guide.
15. How can I migrate to on‑premises environments?
On‑premises migrations represent a significant transformation, including new operational responsibilities, hardware/software procurement, and updated security/compliance processes. Perform a full cryptographic asset inventory, review applicable migration guides, and plan a phased migration with testing and validation.
Important documents
- Unified Key Orchestrator to UKO on-prem migration guide. Refer UKO on-prem migration guide
- IBM Cloud Hyper Protect Crypto Services CloudHSM to on-prem migration guide. Refer IBM Cloud Hyper Protect Crypto Services CloudHSM to on-prem migration guide
16. Support during the transition
For assistance, please reach out via your defined support channels.
Consider Expert-Labs-Services to help, guide, and support this migration.
If the appropriate point of contact is unknown, please send an email to ZaaS.Client.Acceleration@ibm.com
- Work with your Customer Success Manager (CSM)
If applicable, please open an IBM Cloud Support ticket.
To do this,
- Go to https://cloud.ibm.com/unifiedsupport/supportcenter.
- Create a case and provide title:
Help with IBM Cloud Hyper Protect Crypto Services migration
- Provide description and your instance id, if available.
For any additional matters
- IBM Cloud Hyper Protect Crypto Services: Christopher Smith – chsmith@de.ibm.com
- KeyProtect: Damneet Basak - damneet@us.ibm.com
17. Recommended next steps for customers
- Perform inventory of all applications and services using HPCS. If ISV applications are affected, coordinate migration (planning and implementation) with the ISV.
- Select target platform per use case.
- Review the relevant migration guides and identify dependencies.
- Build a migration plan aligned with the migration window and test thoroughly.
- Engage IBM for planning and technical assistance; schedule regular checkpoints.