Federal Information Processing Standards
Federal Information Processing Standards (FIPS) are technology standards developed by the National Institute of Standards and Technology (NIST) and approved for use by U.S. federal departments and agencies. They set a common baseline of quality and security for federal computer systems, and many focus on information and computer security topics. Organizations that work with the federal government are often expected to meet applicable FIPS as well.
FIPS are standards issued under NIST authority and approved for adoption and use by federal departments and agencies, each addressing a specific topic in information technology to achieve a common level of quality or security. Individual FIPS publications address distinct scopes and should not be treated as interchangeable: for example, FIPS 200 establishes government-wide minimum security requirements for federal information and information systems, while the FIPS 140 series specifies security requirements for cryptographic modules only. Practitioners should note that FIPS 140-2 has been superseded by FIPS 140-3, and any reference to 'FIPS 140-2' should be verified against the currently applicable revision, since transition timelines and validation status affect which standard governs a given module. Because FIPS publications are periodically revised, superseded, or withdrawn, readers should confirm the current applicable version and its effective status against the authoritative NIST publications rather than relying on a fixed edition.
Why it matters
Federal Information Processing Standards define the common baseline of quality and security that federal departments and agencies are expected to meet, and that expectation frequently extends to contractors and other organizations that work with the government. Because FIPS carry the weight of NIST authority and federal adoption, misidentifying which standard applies to a given problem can lead to real compliance gaps. A frequent expert-level error is conflating distinct publications: FIPS 200 establishes government-wide minimum security requirements for federal information and information systems, whereas the FIPS 140 series specifies security requirements for cryptographic modules only. Treating the FIPS 140 series as if it set broad, system-wide minimum requirements, or treating FIPS 200 as if it governed cryptographic validation, produces both under- and over-scoped controls.
Who it's relevant to
Inside FIPS
Common questions
Answers to the questions practitioners most commonly ask about FIPS.