FIPS 140-2
FIPS 140-2 is a U.S. government standard that defines the security requirements a cryptographic module must meet to be trusted for protecting sensitive information. A product that has been tested and validated against this standard has demonstrated that its encryption components work as intended. Note that validation applies to the specific cryptographic module tested, and readers should verify current status and applicability against official sources, as newer revisions of the FIPS 140 series exist.
FIPS 140-2 is a Federal Information Processing Standard, issued and maintained by NIST, that specifies the security requirements to be satisfied by a cryptographic module protecting sensitive information in information technology systems. Conformance is established through independent testing under the Cryptographic Module Validation Program (CMVP), which uses Derived Test Requirements and associated implementation guidance covering Approved and non-Approved security functions. Validation is scoped to a particular module configuration rather than to a general product line, and practitioners should distinguish validation of a cryptographic module from broader system authorization or security assurances. As of the applicable revision, requirements and program guidance may differ from successor standards in the FIPS 140 series, and the reader should confirm current authoritative text.
Why it matters
FIPS 140-2 matters because it provides a government-recognized basis for trusting that a cryptographic module actually performs as claimed. Rather than relying on a vendor's assertion that its encryption is sound, agencies and contractors can point to independent validation under the Cryptographic Module Validation Program (CMVP), maintained by NIST, as evidence that the module was tested against defined security requirements. In many federal contexts, the use of validated cryptographic modules is treated as a baseline expectation for protecting sensitive information, which is why the standard frequently appears in procurement language, control implementation statements, and assessment findings.
A critical point that experienced practitioners emphasize is that validation is scoped narrowly to a specific module configuration that was tested, not to a general product line or a vendor's broader portfolio. Purchasing a product from a vendor that holds some FIPS 140-2 validations does not automatically mean the particular version, build, or operating configuration you deploy is itself validated. Readers should confirm the exact module, version, and configuration status against the official CMVP listings rather than assuming coverage from marketing claims.
Equally important, validation of a cryptographic module should not be confused with authorization of a system or with broader security assurance. A validated module addresses whether the cryptography works as intended within its defined boundary; it does not by itself demonstrate that a system is securely configured, properly integrated, or authorized to operate. Because newer revisions of the FIPS 140 series exist and program guidance evolves, the applicable requirements and current validation status should always be verified against authoritative NIST sources.
Who it's relevant to
Inside FIPS 140-2
Common questions
Answers to the questions practitioners most commonly ask about FIPS 140-2.