Drei Jahrzehnte lang spielte die Kryptografie in der IT nur eine untergeordnete Rolle. Sie war ein technisches Detail, über das außerhalb des Sicherheitsteams kaum jemand sprach. Diese Ära ist vorbei.
Cryptographic module validation now sits in the middle of enterprise procurement worldwide. On September 21, 2026, every remaining FIPS 140-2 certificate moved to the Cryptographic Module Validation Program (CMVP) Historical List. An active FIPS 140-3 certificate is the entry condition for U.S. and Canadian government sales, and it is increasingly what financial, healthcare, and cloud buyers ask for in other markets, because their own frameworks point back to the same validated module list.
For IT and software vendors, this is not just a technical milestone. It is the gate that decides who remains eligible to bid.
What FIPS 140-3 is and its worldwide reach
FIPS 140-3, Security Requirements for Cryptographic Modules, is the U.S. federal standard for cryptographic modules that protect sensitive but unclassified information. The Secretary of Commerce approved it on March 22, 2019. It took effect on September 22, 2019, superseding FIPS 140-2.
Validation runs through the Cryptographic Module Validation Program (CMVP), operated jointly by NIST and Canada’s Cyber Centre. Accredited third-party labs test each module against eleven security requirement areas. Every validated module receives a certificate number on the CMVP Validated Modules List. That certificate is what tells a federal buyer that a specific version of your module has been independently tested.
Although the mandate is centered around North America, its reach is global because it follows the buyer rather than the vendor. Any of these buyers brings the requirement with it:
- A U.S. federal agency. Validation is mandatory wherever an agency uses cryptography to protect sensitive information, and agencies cannot waive it. That includes modules operated for an agency under contract.
- A Canadian federal department. The Cyber Centre recommends using only CMVP-validated products wherever a system relies on cryptography.
- A cloud provider serving U.S. agencies. Under FedRAMP’s 2026 rules, providers must document every cryptographic module that protects federal data and whether it is CMVP validated. Validated modules are mandatory at the highest certification class and recommended at the one below.
- A defense contractor. DFARS and CMMC require FIPS-validated cryptography wherever it protects controlled unclassified information. The obligation flows down to every subcontractor that handles that information, with no exemption for foreign firms.
- A regulated business. Payment processors and publicly trusted certificate authorities work to rules that name FIPS 140 Level 3 as a way to qualify their HSMs, and U.S. healthcare breach guidance points to FIPS-validated encryption.
A vendor in Berlin or Bangalore never has to sell to Washington to be affected. The requirement arrives when one of these buyers becomes a customer, or a customer’s customer. A German HSM inside a U.S. cloud service and an Indian encryption product on a defense supplier’s network both end up protecting U.S. government data. Both have to be accounted for.
What the buyer then asks for is a CMVP certificate number. It can be the vendor’s own, or that of a validated module embedded in the product. Either way, the version and operating environment have to match what the certificate lists. For a new federal system the certificate must be Active, which since September 21, 2026 means FIPS 140-3.
Was hat sich gegenüber FIPS 140-2 geändert?
The new standard keeps the familiar structure but tightens two requirements, one that FIPS 140-2 never demanded, and one where multiple exceptions were previously tolerated.
- Non-invasive attack mitigation: at higher security levels, modules must be tested against non-invasive attacks such as side-channel analysis.
- Entropy source documentation: vendors must formally document the entropy sources that feed key generation. Under FIPS 140-3, non-conformance can no longer be waived by certificate caveat.
Both additions raise the bar on how a module is built and evidenced, not just how it performs.
FIPS 140-3, ISO/IEC 19790, and Common Criteria
Unlike the 140-2 version, FIPS 140-3 does not carry its own requirement text. It references ISO/IEC 19790:2012 for requirements and ISO/IEC 24759:2017 for testing. NIST’s SP 800-140 series records where the CMVP departs from those standards, such as maintaining its own list of approved security functions. In effect, vendors build to an international standard with a defined set of U.S./Canadian deltas.
Common Criteria (ISO/IEC 15408) answers a different question. It evaluates the security functions of a whole IT product, while FIPS 140-3 validates the cryptographic module inside it.
The two connect through the fifth letter of the NIAP Policy. In the U.S. scheme, cryptography that NIST can test must be validated through CAVP and/or CMVP, and at minimum an appropriate CAVP certificate is required before NIAP awards a CC certificate. There are to important caveats:
- The floor is a CAVP algorithm certificate, not full CMVP module validation.
- This is NIAP policy, not a Common Criteria requirement worldwide.
The payoff is being able to reuse: NIAP accepts CAVP and CMVP test results for some Protection Profile assurance activities, so work done once can count twice. The trap is the operating environment. A CAVP certificate applies only if the processor and OS match those on the certificate and the algorithm code is unmodified. A single certificate inventory should serve both programs.
Die vier Sicherheitsstufen
The standard defines four security levels, numbered 1 to 4. Each step adds stronger physical and logical protection. Vendors should match the level to the sensitivity of the data a module protects. The overall level reflects the lowest level achieved across the individual security requirement areas, and certificates may list per-area exceptions, so read the certificate, not just the headline number.
- Level 1: basic requirements with approved algorithms and no specific physical protection.
- Level 2: adds tamper-evidence and role-based authentication.
- Level 3: adds tamper detection and response, plus identity-based authentication.
- Level 4: adds robust physical protection designed to resist advanced attack attempts.
For example, an organization protecting high-value keys will typically store them in an HSM validated to the appropriate level.
Why the September 21, 2026 sunset matters
The deadline has a clear endpoint. CMVP stopped accepting new FIPS 140-2 submissions in 2022. On September 21, 2026, every remaining active FIPS 140-2 certificate moves to the CMVP Historical List.
Bundesbehörden „sollten“ Module, die auf der historischen Liste stehen, nicht in neue Beschaffungsvorgänge aufnehmen. Genau diese eine Statusänderung macht aus einem rein technischen Datum eine Frage der Einnahmen.
FIPS 140-2 validation remains active through September 21, 2026. After that, modules in the Historical List can stay in use for existing systems, but new federal business depends on an active 140-3 certificate.
Wer wird ausgesperrt?
Die Änderung erstreckt sich über gängige Produktkategorien hinweg. Sie betrifft IT-Systeme des Bundes, VPN-Geräte, HSMs, sichere Kommunikationsplattformen und Betriebssysteme.
Vendors without an active certificate are effectively locked out of new federal acquisitions. With 18-30 month validation timelines, the window for starting from scratch has already closed. Vendors not currently in the CMVP queue should plan around the sunset rather than through it. .
Das Problem mit dem Zeitplan für die Validierung
Traditional FIPS 140-3 validation runs roughly 18 to 30 months from initiation to certificate issuance. That is why the deadline is closer than it appears on the calendar.
Wenn Ihr Zeitplan von einer schnellen Abwicklung ausgeht, wird die Warteschlange diese Annahme korrigieren. Ein später Start ist der häufigste Grund dafür, dass man das Zeitfenster verpasst.
Die Post-Quanten-Warteschlangenkollision
There is a compounding squeeze. The same CMVP queue needed for a standard validation certificate is now also validating post-quantum algorithms.
Standards such as CNSA 2.0 and NIST IR 8547 call for algorithms like ML-KEM and ML-DSA. As a result, a single submission increasingly has to clear both bars at once, which adds pressure to an already crowded pipeline.
Wie sich FIPS 140-3 auf Ihre Kryptografie auswirkt
Readiness comes down to a set of interlocking workstreams. Each one describes something you need to prove in practice.
- Validation status tracking: confirm every module in a product boundary carries an active CMVP certificate matched to the exact deployed version, not just the product family.
- PKI on validated modules: issue certificates and manage keys through certificate authorities and HSMs backed by validated modules.
- Module migration planning: track which deployed modules sit on FIPS 140-2 versus 140-3.
- Evidence for assessors: map every certificate and key to its validated module and certificate number (NIST SP 800-53 SC-13, SC-28, IA-7).
- Entropy and operating environment: confirm your deployment runs on an operating environment listed on the certificate, since entropy validation is tied to the tested environment.
- Hardware-backed key protection: store keys in HSMs at the appropriate security level.
Are you audit ready? Questions assessors will ask
Bundesprüfer und -gutachter neigen dazu, immer wieder dieselben Punkte zu hinterfragen. Betrachten Sie diese als eine Art Selbstkontrolle, bevor daraus Beanstandungen werden.
- Active certificate verification: does every module carry an active CMVP certificate, confirmed through the CMVP validated modules search rather than vendor marketing?
- Version-to-certificate matching: does the deployed version match the version the certificate actually covers?
- Historical List exposure: have you identified every module still validated only under FIPS 140-2, with a documented transition plan?
- FIPS mode enforcement: can you show FIPS mode is enabled at runtime, not just present in the image?
- Entropy documentation: is the entropy source feeding key generation documented to the required standard?
- Migration roadmap: is there a plan of action and milestones for any module approaching Historical status, with named ownership and a realistic timeline?
Wie Keyfactor helfen Keyfactor
The challenges above map cleanly to a small set of capabilities. Keyfactor covers each one so readiness becomes an operational program rather than a scramble.
- Keyfactor AgileSec discovers cryptographic assets across your landscape and tracks validation status, matching certificates to the exact deployed versions.
- EJBCA builds PKI on validated modules and generates keys from documented entropy sources. It also gives you access to Bouncy Castle’s FIPS 140-3 validated module for versatile, secure cryptographic primitives.
- Keyfactor SignServer signs build and release artifacts so deployments into the authorization boundary are verifiable.
- Keyfactor Command orchestrates module migration, re-keying, and centralized evidence reporting.
Fazit und nächste Schritte
Die Richtung ist klar. Die Anforderungen werden immer konkreter, und der Spielraum für ältere Module wird immer kleiner.
Die Anbieter, die weiterhin in Frage kommen, sind diejenigen, die handeln, bevor die Warteliste voll ist. Drei praktische Schritte machen den Unterschied:
- Verschaffen Sie sich einen Überblick über Ihre kryptografischen Vermögenswerte.
- Prüfen Sie diese anhand der aktuellen FIPS 140-3-Anforderungen.
- Get into the validation queue now rather than later
Ready to see how Keyfactor supports FIPS 140-3 readiness? Request a Demo.
Got FIPS 140-3 questions? We’ve got answers.
What is FIPS 140-3?
FIPS 140-3 is the standard for validating cryptographic modules followed by the U.S. and Canadian governments. Approved in March 2019, it superseded its previous version FIPS 140-2. It aligns U.S. validation with the international standards ISO/IEC 19790 and ISO/IEC 24759.
When does FIPS 140-2 expire?
FIPS 140-2 validation remains active through September 21, 2026. On that date, remaining active FIPS 140-2 certificates move to the CMVP Historical List. Federal agencies should not include Historical List modules in new procurements.
What happens on the September 21, 2026 sunset?
Modules validated under FIPS 140-2 within the last five years can stay in use for existing systems. However, new federal business depends on an active 140-3 certificate. Without one, a vendor is effectively locked out of new federal acquisitions.
How long does FIPS 140-3 validation take?
Traditional validation runs roughly 18 to 30 months from initiation to certificate issuance. The CMVP queue can extend timelines further. That is why starting early is the safest way to stay eligible.
What changed between FIPS 140-2 and FIPS 140-3?
The newer standard adds two requirements that were either relaxed in FIPS 140-2, or were not included at all. Higher security levels now require non-invasive attack mitigation testing, such as protection against side-channel analysis. Vendors must also formally document the entropy sources that feed key generation.
How does FIPS 140-3 relate to post-quantum cryptography?
The same CMVP queue that validates 140-3 modules is also validating post-quantum algorithms like ML-KEM and ML-DSA. Standards such as CNSA 2.0 and NIST IR 8547 drive that demand. A single submission increasingly has to satisfy both requirements at once.
Who needs FIPS 140-3 validation?
Any vendor selling cryptographic technology into new federal acquisitions needs an active certificate. This includes federal IT systems, VPN appliances, HSMs, secure communication platforms, and operating systems. Vendors that delay risk missing the validation window entirely.