Cryptographic Module Validation Program
The Cryptographic Module Validation Program (CMVP) is a government program that tests and validates cryptographic modules, the hardware and software components that perform encryption, to confirm they meet established security standards. Its purpose is to promote the use of validated cryptographic modules and to give Federal agencies a security metric they can rely on when procuring equipment. A module that has been validated receives a certificate indicating that it conforms to the applicable security requirements.
The CMVP is a validation program, described in the evidence as a joint effort involving the National Institute of Standards and Technology (NIST), under which cryptographic modules are validated against the FIPS 140 standard. The program was established to ensure that hardware and software cryptographic implementations meet specified security requirements, and it issues certificates indicating a module's conformance to those requirements. The validation process is a joint effort among the CMVP, an accredited testing laboratory, and the vendor of the module. The goal is to promote the use of validated cryptographic modules and to provide Federal agencies with a security metric for use in procuring equipment. Note: the evidence provided does not fully specify the CMVP's partner organization(s) or the current FIPS 140 revision; practitioners should verify the governing standard revision and program partners against the current authoritative NIST/CSRC text, and should not treat a listing on the Modules in Process List as equivalent to a completed validation.
Why it matters
For Federal agencies and their contractors, the CMVP provides an independent, standards-based way to confirm that the encryption protecting sensitive data actually meets defined security requirements rather than relying on a vendor's unverified claims. Because the program validates cryptographic modules against the FIPS 140 standard and issues certificates of conformance, it gives procurement officials and system owners a concrete security metric to use when selecting equipment. This matters in compliance contexts where the use of validated cryptography is expected for protecting government information, including Controlled Unclassified Information, though practitioners should confirm the specific cryptographic requirements that apply to their system category and impact level against current authoritative guidance, since those obligations are set by the applicable framework rather than by CMVP itself.
Who it's relevant to
Inside CMVP
Common questions
Answers to the questions practitioners most commonly ask about CMVP.