Skip to main content
Category: Cryptography & Encryption

Cryptographic Module Validation Program

Also known as:
Simply put

The Cryptographic Module Validation Program (CMVP) is a government program that tests and validates cryptographic modules, the hardware and software components that perform encryption, to confirm they meet established security standards. Its purpose is to promote the use of validated cryptographic modules and to give Federal agencies a security metric they can rely on when procuring equipment. A module that has been validated receives a certificate indicating that it conforms to the applicable security requirements.

Formal definition

The CMVP is a validation program, described in the evidence as a joint effort involving the National Institute of Standards and Technology (NIST), under which cryptographic modules are validated against the FIPS 140 standard. The program was established to ensure that hardware and software cryptographic implementations meet specified security requirements, and it issues certificates indicating a module's conformance to those requirements. The validation process is a joint effort among the CMVP, an accredited testing laboratory, and the vendor of the module. The goal is to promote the use of validated cryptographic modules and to provide Federal agencies with a security metric for use in procuring equipment. Note: the evidence provided does not fully specify the CMVP's partner organization(s) or the current FIPS 140 revision; practitioners should verify the governing standard revision and program partners against the current authoritative NIST/CSRC text, and should not treat a listing on the Modules in Process List as equivalent to a completed validation.

Why it matters

For Federal agencies and their contractors, the CMVP provides an independent, standards-based way to confirm that the encryption protecting sensitive data actually meets defined security requirements rather than relying on a vendor's unverified claims. Because the program validates cryptographic modules against the FIPS 140 standard and issues certificates of conformance, it gives procurement officials and system owners a concrete security metric to use when selecting equipment. This matters in compliance contexts where the use of validated cryptography is expected for protecting government information, including Controlled Unclassified Information, though practitioners should confirm the specific cryptographic requirements that apply to their system category and impact level against current authoritative guidance, since those obligations are set by the applicable framework rather than by CMVP itself.

Who it's relevant to

Government contractors and product vendors
Vendors seeking to sell cryptographic products to Federal agencies work with an accredited testing laboratory and the CMVP to have their modules validated against the FIPS 140 standard. Vendors should track where their module sits in the process and recognize that appearing on the Modules in Process List does not constitute a completed validation or a certificate of conformance.
Procurement and acquisition officials
Because the goal of the CMVP is to promote the use of validated cryptographic modules and provide Federal agencies with a security metric for procuring equipment, acquisition personnel can use validation status as an objective reference point when evaluating products. Officials should verify a module's current validation status against the authoritative validated modules listing rather than relying on vendor assertions.
Information system security managers and authorizing officials
System owners responsible for protecting government information can use CMVP validation as evidence that a module's cryptography conforms to established requirements. They should confirm which cryptographic requirements apply to their specific system and information category against current authoritative guidance, and should not treat module validation alone as satisfying broader security or authorization obligations.
Auditors and assessors
Assessors reviewing whether a system uses validated cryptography can consult the CMVP's certificates and validated modules listing to confirm conformance. When verifying claims, they should check the specific module and its tested configuration, and confirm the applicable FIPS 140 revision against the current authoritative NIST/CSRC text.

Inside CMVP

Joint NIST and CCCS Administration
The CMVP is a joint program administered by the U.S. National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security (CCCS), which is part of Canada's Communications Security Establishment (CSE). The program validates cryptographic modules against applicable federal standards.
FIPS 140 Standard Basis
Validation is performed against the Federal Information Processing Standard (FIPS) 140 series, which specifies security requirements for cryptographic modules. Practitioners should verify which revision of the standard applies, as the requirements evolve across versions.
Accredited Testing Laboratories
Independent, accredited laboratories conduct the conformance testing of cryptographic modules submitted by vendors. The laboratory performs the assessment; NIST and CCCS issue the validation, reflecting the distinction between assessment and authorization/validation.
Validated Modules List
The program maintains a public listing of cryptographic modules that have completed validation, along with associated details such as the validation status. Readers should consult the current official list rather than relying on cached or secondary sources.
Security Levels
The underlying standard generally defines multiple security levels reflecting increasing rigor of physical and logical protections. The specific level required depends on the applicable system requirements and agency tailoring.

Common questions

Answers to the questions practitioners most commonly ask about CMVP.

Does a FIPS 140 validation from the CMVP mean my system is compliant or secure?
No. A CMVP validation certifies that a specific cryptographic module met the requirements of the applicable FIPS 140 standard under the tested configuration; it is not a statement that a system built with that module is secure or compliant overall. Validation applies to the module as defined by its security policy and tested boundary, and correct deployment, operating the module in its validated (often called 'FIPS mode') configuration, proper key management, and integration into a broader control environment, remains the operator's responsibility. Validation of a component should not be equated with authorization or with the security of the complete information system, which are assessed separately.
If a product appears on a vendor's site as 'FIPS compliant,' is that the same as being CMVP validated?
Not necessarily. Vendor marketing terms such as 'FIPS compliant,' 'FIPS inside,' or 'FIPS ready' do not by themselves establish that a module completed CMVP validation. Only modules that have received a validation certificate and appear on the CMVP validated modules list should be treated as validated, and even then the validation is tied to the specific module version, configuration, and operational conditions stated in the module's security policy. Readers should confirm the exact module name, version, and certificate against the official CMVP listing rather than relying on general product-level claims.
How do I confirm that a specific product uses a CMVP-validated module?
Identify the exact cryptographic module name and version the product incorporates, then match it against the corresponding CMVP validation certificate and the module's published security policy. Products often bundle or embed a validated module, so the certificate applies to that underlying module rather than to the entire product. Verify the certificate is active and note any conditions in the security policy, such as required configuration settings, that define the validated boundary. Consult the current official CMVP resources to confirm the listing.
What does it mean to operate a module in its validated configuration?
Each validated module has a security policy that describes the approved mode of operation, including which algorithms, settings, and procedures must be in effect for the module to be running as validated. Operating outside that configuration, for example enabling non-approved algorithms, can place the module outside the scope of its validation. Compliance generally requires enabling and maintaining the module's approved mode as specified in its security policy, and operators should review that policy for the specific initialization and operational steps applicable to their version.
How should I handle a module whose CMVP status has moved to a historical or superseded state?
CMVP validation status can change over time as standards revise and as modules move through the program's lifecycle, and a certificate may transition to a status that limits its acceptability for new procurements. Because acquiring agencies and contractual requirements may treat such statuses differently, organizations should check the current status of any module they rely on, understand any transition timelines the program has published, and plan for remediation or replacement where a module is no longer acceptable for the intended use. Verify current status and any applicable dates against official CMVP sources rather than assuming a past validation remains sufficient.
Where does CMVP validation fit relative to broader authorization requirements such as FedRAMP or the DoD RMF?
CMVP validation addresses cryptographic modules and is typically one input among many when a system pursues authorization. Frameworks such as FISMA-based agency authorizations, FedRAMP, and the DoD RMF generally reference the use of validated cryptography for protecting relevant information, but satisfying that cryptographic requirement does not by itself confer an Authority to Operate or satisfy the full set of controls those frameworks impose. Assessment and authorization are distinct from component validation, and requirements can vary by agency tailoring, impact level, and data type. Confirm the specific cryptographic and authorization requirements applicable to your system against the current governing guidance.

Common misconceptions

The CCCS is a former name of the Communications Security Establishment.
The Canadian Centre for Cyber Security (CCCS) is a part of the Communications Security Establishment (CSE), which continues to exist as Canada's national cryptologic agency. The CCCS is a branch within CSE, not a predecessor or renaming of it.
Using a cryptographic algorithm that appears in FIPS is the same as using a validated module.
Validation under the CMVP applies to a specific cryptographic module as tested and listed, not merely to the algorithm. A product must reference an actual validated module entry; algorithm compliance alone does not equate to module validation.
A CMVP validation is permanent and never needs revisiting.
Validation status is tied to a specific module configuration and the applicable standard revision, and status can change over time. Practitioners should confirm that a module remains in an active, applicable validation status rather than assuming a prior validation is indefinitely current.

Best practices

Confirm that a cryptographic module is listed on the current official CMVP validated modules list rather than relying on vendor marketing claims or secondary sources.
Verify the specific validated module entry, including its tested configuration, rather than assuming algorithm-level compliance satisfies validation requirements.
Check which revision of the applicable FIPS 140 standard the module was validated against and whether that revision meets your system's requirements.
Confirm the required security level for your use case based on your system requirements and agency tailoring, rather than assuming any validated module suffices.
Periodically re-verify a module's validation status, since status is tied to configuration and standard revisions and can change over time.
Distinguish laboratory testing from the validation issued by NIST and CCCS, and confirm final validation status through the official program rather than the testing laboratory alone.