Skip to main content
Category: NIST Standards & Publications

Federal Information Processing Standards

Also known as: FIPS, Federal Information Processing Standard, FIPS Publications, FIPS PUBs
Simply put

Federal Information Processing Standards (FIPS) are technology standards developed by the National Institute of Standards and Technology (NIST) and approved for use by U.S. federal departments and agencies. They set a common baseline of quality and security for federal computer systems, and many focus on information and computer security topics. Organizations that work with the federal government are often expected to meet applicable FIPS as well.

Formal definition

FIPS are standards issued under NIST authority and approved for adoption and use by federal departments and agencies, each addressing a specific topic in information technology to achieve a common level of quality or security. Individual FIPS publications address distinct scopes and should not be treated as interchangeable: for example, FIPS 200 establishes government-wide minimum security requirements for federal information and information systems, while the FIPS 140 series specifies security requirements for cryptographic modules only. Practitioners should note that FIPS 140-2 has been superseded by FIPS 140-3, and any reference to 'FIPS 140-2' should be verified against the currently applicable revision, since transition timelines and validation status affect which standard governs a given module. Because FIPS publications are periodically revised, superseded, or withdrawn, readers should confirm the current applicable version and its effective status against the authoritative NIST publications rather than relying on a fixed edition.

Why it matters

Federal Information Processing Standards define the common baseline of quality and security that federal departments and agencies are expected to meet, and that expectation frequently extends to contractors and other organizations that work with the government. Because FIPS carry the weight of NIST authority and federal adoption, misidentifying which standard applies to a given problem can lead to real compliance gaps. A frequent expert-level error is conflating distinct publications: FIPS 200 establishes government-wide minimum security requirements for federal information and information systems, whereas the FIPS 140 series specifies security requirements for cryptographic modules only. Treating the FIPS 140 series as if it set broad, system-wide minimum requirements, or treating FIPS 200 as if it governed cryptographic validation, produces both under- and over-scoped controls.

Who it's relevant to

Compliance officers and ISSMs
Those responsible for building and maintaining system security documentation need to cite the correct FIPS for the correct purpose, for example, distinguishing government-wide minimum security requirements under FIPS 200 from cryptographic module requirements under the FIPS 140 series, and confirm that referenced editions are current rather than superseded.
Government contractors and vendors
Organizations engaging with the U.S. government are often expected to meet applicable FIPS. Contractors should verify which specific standards and revisions apply to their offerings, particularly for cryptographic modules where 'FIPS 140-2' references may need to be reconciled with FIPS 140-3 and current validation status.
Authorizing officials and assessors
Personnel who evaluate systems and make authorization decisions should confirm that the FIPS cited in assessment artifacts reflect the currently applicable versions, since a superseded or withdrawn standard can misrepresent whether a system meets applicable federal requirements.
Auditors and third-party reviewers
Reviewers verifying compliance evidence should treat authoritative NIST publications as the controlling source, watch for the common error of conflating distinct FIPS publications, and check the effective status of any standard referenced in the artifacts under review.

Inside FIPS

FIPS as a category of standards
Federal Information Processing Standards are publicly announced standards developed by NIST and approved by the Secretary of Commerce for use in federal information systems. They are generally mandatory for federal agencies where an applicable FIPS exists and no waiver applies, and are distinct from NIST Special Publications (such as SP 800-53 or SP 800-171), which are guidelines rather than approved standards.
FIPS 199 (Security Categorization)
Establishes standards for categorizing information and information systems by potential impact (low, moderate, high) against the confidentiality, integrity, and availability objectives. This categorization generally drives baseline selection in the Risk Management Framework. Readers should confirm impact determinations against current agency guidance.
FIPS 200 (Minimum Security Requirements)
Specifies the government-wide minimum security requirements for federal information and information systems across defined security-related areas. FIPS 200 is the standard that establishes minimum security requirements at the system level; it is distinct from FIPS 140-2/140-3, which address cryptographic modules only. Implementation detail is typically drawn from NIST SP 800-53 as tailored by the agency.
FIPS 140 series (Cryptographic Module Security Requirements)
Specifies security requirements for cryptographic modules only, not for information systems generally. FIPS 140-2 was the long-standing version; FIPS 140-3 was approved March 22, 2019 and became effective September 22, 2019, and it is the current standard for validating cryptographic modules. Readers should verify the applicable version, transition timelines, and the status of any validated module against the current NIST validation program listings.
Applicability and scope boundaries
FIPS generally apply to federal civilian agency systems under FISMA. National security systems and certain defense systems may follow separate authorities and tailoring, and DoD systems under the RMF apply FIPS within DoD-specific processes. State, local, tribal, and territorial obligations may differ. Confirm applicability against the governing authority for the specific system.

Common questions

Answers to the questions practitioners most commonly ask about FIPS.

Does FIPS 140-2 establish the minimum security requirements for federal information systems?
No. This is a common point of confusion. FIPS 140-2 specifies security requirements for cryptographic modules only, the components that perform encryption and related functions. The government-wide minimum security requirements for federal information systems are established in FIPS 200, which references the control catalog in NIST SP 800-53. Do not treat a cryptographic module standard as the source of an information system's overall security baseline; these are distinct publications with distinct scopes.
Is FIPS 140-2 still the current standard for validating cryptographic modules?
Not as the standard going forward. FIPS 140-3 was approved March 22, 2019 and became effective September 22, 2019, superseding FIPS 140-2. Depending on the applicable revision and transition timelines managed through the validation program, previously issued FIPS 140-2 validations may remain listed for a period while new validations proceed under FIPS 140-3. Readers should verify the current status of any specific module and the applicable standard against the authoritative program listings rather than assuming FIPS 140-2 remains the operative standard.
How do I determine which FIPS publications apply to my system?
Applicability generally depends on the type of system and the governing authority. FIPS publications issued by NIST are generally mandatory for federal civilian agency information systems under FISMA, subject to any waivers or exceptions in effect. Applicability to DoD systems, national security systems, and non-federal systems handling CUI may differ and can be shaped by agency tailoring, DoD policy, or contractual requirements. Confirm which specific FIPS publications your program is obligated to follow against current official sources and your authorizing official's guidance, as this entry does not address contractual or agency-specific specifics.
How does FIPS 199 relate to selecting security controls?
FIPS 199 provides the standards for categorizing information and information systems according to potential impact, generally expressed as low, moderate, or high across the confidentiality, integrity, and availability objectives. That categorization in turn informs the minimum security requirements in FIPS 200 and the baseline control selection drawn from NIST SP 800-53. FIPS 199 categorization is a foundational input to the Risk Management Framework, but categorization itself is distinct from control selection, assessment, and authorization, which are separate steps.
If a product uses a FIPS-validated cryptographic module, does that make my system compliant?
No. Using a validated cryptographic module addresses only the cryptographic requirements covered by the applicable FIPS cryptographic module standard. It does not by itself satisfy a system's broader minimum security requirements, control implementation, assessment, or authorization obligations. Compliance is not the same as security, and module validation is only one element of a compliant and secure system. Verify how module validation maps to your specific requirements against current authoritative guidance.
Are FIPS requirements subject to change across revisions?
Yes. FIPS publications are revised over time, and requirements, categorization guidance, and cryptographic module standards can change across revisions and through transition periods. Because of this, requirements should be evaluated against the applicable revision in effect for your system. As of the applicable revision, verify the current text and status of any FIPS publication through official NIST sources rather than relying on a prior version.

Common misconceptions

FIPS 140-2 (or 140-3) defines the minimum security requirements for federal information systems.
The FIPS 140 series specifies security requirements for cryptographic modules only. The government-wide minimum security requirements for federal information systems are established in FIPS 200, with implementation detail generally drawn from NIST SP 800-53.
FIPS 140-2 is still the standard to design and validate against.
FIPS 140-2 was superseded by FIPS 140-3, which was approved March 22, 2019 and became effective September 22, 2019. Readers should treat FIPS 140-3 as the current standard and verify applicable transition timelines and the validation status of specific modules against current NIST program listings.
FIPS and NIST Special Publications are interchangeable authorities.
FIPS are approved standards issued by NIST and approved by the Secretary of Commerce and are generally mandatory for federal agencies where applicable, whereas NIST Special Publications (such as SP 800-53 and SP 800-171) are guidelines. Confirm the binding status of any document against its stated authority.

Best practices

Match each FIPS to its actual scope: use FIPS 199 for categorization, FIPS 200 for system-level minimum security requirements, and the FIPS 140 series strictly for cryptographic module requirements.
Design and procure to FIPS 140-3 as the current standard rather than FIPS 140-2, and verify a module's validation status and any applicable transition timelines against current NIST validation program listings before relying on it.
Do not treat FIPS 140 validation as evidence that a system meets minimum security requirements; confirm system-level compliance through FIPS 200 and the tailored NIST SP 800-53 baseline.
Distinguish FIPS (approved, generally mandatory for applicable federal systems) from NIST Special Publications (guidelines) when citing requirements, and record the governing authority for each obligation.
Confirm applicability for the specific system type, federal civilian under FISMA, DoD under the RMF, or national security systems, since separate authorities and agency tailoring may change which FIPS apply and how.
Verify version numbers, effective dates, and validation statuses against current official NIST sources before use, since FIPS and their implementing guidance change across revisions.