A vendor returns a security questionnaire with "FIPS compliant" in one box and a certificate number in another, and the two do not always mean the same thing. FIPS 140 is the standard that decides whether the cryptography inside a product has been tested by an independent lab. This guide explains FIPS 140 for IT buyers: what validation covers, what changed in version 3, and what to check before you sign.
TL;DR
- FIPS 140 validates a cryptographic module, a defined boundary of hardware, software or firmware, and not the whole product around it.
- FIPS 140-3 replaced FIPS 140-2. The validation program began accepting 140-3 submissions on 22 September 2020, and active 140-2 certificates were scheduled to move to the Historical list after 21 September 2026.
- Three checks settle a vendor claim: the certificate number resolves, the version matches what you run, and the status is Active.
- Federal agencies and contractors handling controlled unclassified information need validated cryptography. Everyone else can treat it as a procurement filter, not a security guarantee.
What FIPS 140 Validates
FIPS stands for Federal Information Processing Standards, the series NIST publishes for US federal systems. Publication 140 covers one narrow thing: the security requirements for a cryptographic module. A module is the part of a product that performs encryption, hashing, signing and key handling, drawn as a boundary. Everything inside the boundary is tested. Everything outside it is not.
The Cryptographic Module Validation Program, or CMVP, runs the process. It is a joint effort of NIST and the Canadian Centre for Cyber Security, and each test lab is an independent laboratory accredited through NVLAP. The lab tests the module, CMVP reviews the report, and a certificate is issued. The CMVP program page holds the rules and the search.
Two terms sound alike and are not the same. Algorithm validation, run by the Cryptographic Algorithm Validation Program, confirms that an implementation of AES or SHA produces correct output. Module validation covers the whole boundary: how keys are generated and stored, how operators authenticate, and what the module does when a self-test fails. NIST states that a product does not meet FIPS 140 just by using an approved algorithm and earning algorithm validation. If you want the background on what those algorithms are, our explainer on what a cipher is covers it.
Marketing language blurs this quickly. "FIPS validated" should point to a certificate. "FIPS compliant" and "FIPS ready" usually describe the weaker claim, that the product uses approved algorithms, and need a follow-up question. "FIPS mode" is a configuration setting that changes how a validated module runs. The sections below turn those into questions you can put to a vendor.
FIPS 140-2 vs FIPS 140-3
NIST published FIPS 140-3 on 22 March 2019, and it supersedes FIPS 140-2, which dates from December 2002. The structural change is that 140-3 no longer holds the requirements itself. It points to two ISO standards, ISO/IEC 19790:2012 for the module requirements and ISO/IEC 24759:2017 for the test methods, and NIST layers its own changes on top through the SP 800-140 series. A vendor has to buy the ISO documents to work with them, which is one reason the queue moved slowly.
The shape of the requirements carries over. The ISO text defines four security levels across 11 requirement areas, with each level adding to the one below it. For a buyer reading certificates, the difference between the two standards is smaller than the difference between an Active certificate and a Historical one. The dates below, from the CMVP program page last updated on 21 August 2026, show how the handover ran.
| Date | What happened |
|---|---|
| 22 March 2019 | NIST publishes FIPS 140-3 |
| 22 September 2020 | CMVP begins accepting FIPS 140-3 submissions |
| 22 September 2021 | CMVP stops accepting FIPS 140-2 submissions for new certificates |
| 1 April 2022 | CMVP accepts only FIPS 140-2 reports that do not change the validation sunset date |
| 6 June 2024 | Two-year interim validations begin for modules submitted before 1 January 2024 |
| 21 September 2026 | Active FIPS 140-2 certificates move to the Historical list |
A FIPS 140-3 certificate stays on the Active list for five years, or two years for an interim validation. A FIPS 140-2 certificate carries a sunset date that no longer moves. That difference is why the same product can have a certificate that looks current and still fail a procurement check.
The September 2026 Date
The CMVP page set 21 September 2026 as the date FIPS 140-2 certificates move to the Historical list. That date has now passed. Modules on the Historical list can stay in existing systems, but agencies should not put them in new ones. Historical is not Revoked: NIST says a Historical certificate does not mean the validation was withdrawn, while a Revoked module may no longer be used to show compliance.
What changes for you depends on the paperwork you hold. If a contract, an RFP or a customer questionnaire asks for FIPS 140 validated cryptography in a new system, a 140-2 certificate now needs a second look. Open the validated modules search, find the certificate number and read its status. If it says Historical, ask the vendor for a 140-3 certificate or for a dated plan to get one.
Vendors will sometimes point to a module that is "in process". CMVP publishes a Modules In Process list for products that have entered testing, and being on it is not the same as being validated. Treat it as a promise with a date to confirm, not a certificate. NIST's own page tells agencies to keep using 140-2 modules until 140-3 replacements are available, so expect Historical certificates to keep turning up in procurement for a while.
A short video from the FixMyCert channel walks through the same deadline.
Security Levels 1 to 4
The standard defines four security levels so that one framework can cover everything from low-value administrative data to sensitive government information. The same approved algorithms apply at every level. What climbs is the protection around the module: physical security, operator authentication and resistance to tampering. In broad terms, the levels look like this.
| Level | What it adds | Where you meet it |
|---|---|---|
| 1 | The baseline: approved algorithms in a tested module, with no physical security beyond production-grade components | Software libraries and operating system cryptographic modules |
| 2 | Tamper evidence, such as seals or coatings, and role-based authentication | Network appliances and some key storage devices |
| 3 | Tamper resistance, where the module erases keys when it detects an attack, and identity-based authentication | Hardware security modules and key management hardware |
| 4 | Protection against environmental attacks such as voltage and temperature extremes | Specialist hardware, rarely seen in office IT |
Level 1 is the normal answer for software. A validated operating system library at Level 1 is not a weaker product than a Level 3 appliance; it solves a different problem. A higher level makes the module harder to attack physically, so it matters most when someone can get hands on the device. Match the level to your threat, then read the rest of the certificate.
How to Read a Validation Certificate
Every validated module has a certificate in the CMVP database and a Security Policy document that describes how to run it. Six fields do most of the work.
| Field | What to check |
|---|---|
| Certificate number | Search the CMVP validated modules list and confirm it exists |
| Module name and version | It matches the product version you are buying or running, not an earlier release |
| Standard and level | FIPS 140-2 or 140-3, and the overall level |
| Status and dates | Active, Historical or Revoked, and the sunset date |
| Operating mode note | If it says "when operated in FIPS mode", the Security Policy lists the configuration steps you must follow |
| Algorithms and scope | The module covers specific algorithms and a specific boundary |
Microsoft's Windows FIPS 140 validation page, last updated on 2 September 2026, shows how this works for one vendor. Validation attaches to specific releases, and the page lists Windows 11 versions 22H2 and 21H2 under validated modules. A fleet on a newer build should check the certificate for its own release before it quotes the number to a customer.
Windows also has a legacy switch. In Group Policy it is "System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing", and in MDM it is the AllowFipsAlgorithmPolicy setting set to 1. Turning it on has side effects. Microsoft's policy page, last updated in 2018, notes that BitLocker recovery passwords are not available on such systems, so recovery keys must be used instead, and that RDP connections fail if both ends are not set to the same algorithms. Our guide to BitLocker for IT teams covers key escrow.
Across a fleet, the useful question is which machines have the policy switched on. OpenFrame can run a script across a client's devices that reads the FIPS policy value and collects the output, so the exceptions show up in one list.
powershellGet-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy' -Name Enabled
Questions to Ask a Vendor
Put these to the vendor in writing and keep the answers with the contract. The right column shows what a clean answer looks like and what should prompt a follow-up.
| Question | Good answer | Warning sign |
|---|---|---|
| Which certificate number covers the cryptography? | A number you can find in the CMVP search | "We use FIPS-approved algorithms" with no number |
| Is the module yours, or embedded from a third party? | Names the module and its vendor, and the certificate lists it | Vague about whose cryptography it is |
| Does the certificate cover the version I will run? | The version on the certificate matches the release | The certificate is for a release two versions back |
| Is it 140-2 or 140-3, and what is its status? | Active 140-3, or Active 140-2 with a dated replacement plan | Historical 140-2 offered for a new system |
| What must be set to run in FIPS mode? | A documented setting from the Security Policy | "It is on by default" with no document |
| Is the module validated or in process? | Validated, with a certificate | "Submitted" or "in test" presented as done |
The first three questions settle the argument quickly: either the number resolves in the CMVP search or it does not. If your questionnaires keep asking for this evidence, our guide to what IT compliance covers shows where to keep it.
When You Need FIPS and When You Do Not
US federal agencies must use validated cryptography when cryptography is required. The CMVP page puts it bluntly: non-validated cryptography is treated as providing no protection, in effect leaving the data as plaintext. The page cites 15 U.S.C. 278g-3 for the obligation.
Contractors reach the same requirement through their contracts. NIST SP 800-171 requirement 3.13.11 asks for FIPS-validated cryptography when it protects the confidentiality of controlled unclassified information, which is how it appears in assessments for the Cybersecurity Maturity Model Certification. Our guide to CMMC compliance covers the program.
Outside those cases, FIPS 140 is a procurement filter. A commercial buyer with no federal contract does not need a certificate to be safe. The value is that the testing is independent, and some customers and insurers ask for the evidence, so a validated module saves you a debate later. For a wider view of the frameworks that ask for it, our cybersecurity frameworks list is the place to start.
A certificate also has limits. A March 2025 post on r/cybersecurity pointed to research on enterprise network switches that held FIPS and Common Criteria certifications and still carried serious vulnerabilities for years. The poster disputes the vendor's advisories, so treat the claim as theirs, but the lesson matches the boundary point at the start of this guide: testing a module is not the same as testing the product around it.
The cost of meeting the requirement shows up in operations. An October 2025 thread on the same subreddit asks how other teams handle FIPS across container fleets, where validated modules, limited base image options and slower deployments all collide.
The Short Version
FIPS 140 tests a cryptographic module, not a product, and FIPS 140-3 is the version that is now being issued. Active 140-2 certificates were scheduled to move to the Historical list on 21 September 2026, so check the status of any 140-2 certificate you are handed. Ask for the certificate number, confirm the version, read the status, and follow the Security Policy to run the module in FIPS mode. You need it for federal work and for controlled unclassified information, and it is a useful filter everywhere else.
Start with the vendor questions table and send it with your next renewal. The rest of the process follows from the answers.
FAQ
What does FIPS stand for?
FIPS stands for Federal Information Processing Standards. NIST publishes them for US federal systems. FIPS 140 is the one that sets security requirements for cryptographic modules, and FIPS 140-3 is its current version.
What is the difference between FIPS 140-2 and FIPS 140-3?
FIPS 140-3 supersedes FIPS 140-2. It points to the ISO/IEC 19790 module requirements and the ISO/IEC 24759 test methods instead of holding the requirements itself. The structure of four levels and 11 requirement areas carries over. CMVP began accepting 140-3 submissions on 22 September 2020.
Is a FIPS 140-2 certificate still valid after September 2026?
CMVP set 21 September 2026 as the date active FIPS 140-2 certificates move to the Historical list. A Historical certificate stays on record and the module can stay in existing systems, but agencies should not put it in new ones. Check the status in the CMVP validated modules search.
Is "FIPS compliant" the same as "FIPS validated"?
No. "FIPS validated" should point to a CMVP certificate for a specific module and version. "FIPS compliant" usually means the product uses approved algorithms, which is a weaker claim, so ask for the certificate number.
Do I need FIPS validated encryption for CMMC or controlled unclassified information?
If cryptography protects the confidentiality of controlled unclassified information, NIST SP 800-171 requirement 3.13.11 asks for FIPS-validated cryptography. Confirm the exact wording in your contract and with your assessor.
Conrad Lunderstedt
Solution Architect
I'm Conrad, Solution Architect at Flamingo. I've spent about 26 years in IT, roughly half of it inside MSPs and the rest in enterprise environments, so I've watched vendor decisions get made on both sides of that line. Now I spend my days talking with MSPs about the stack they already run, and helping them work through the requests and issues that come with it.
