What solutions does Vault provide for transit engine with FIPS-140-2 compliance

I am currently looking for a solution wherein I want to encrypt the data in transit. The Vault transit engine perfectly suites my requirements but I wanted to know what solutions does Vault provide to store the transit engine keys which is FIPS-140-2 compliant.
I know that Vault Enterprise integrates with HSM platforms to opt-in automatic unsealing.
But, is there any other solutions available?
Can I use KMS such as Azure Key Vault as backend storage to store the keys?