FIPS 140-3
FIPS 140-3 is a U.S. government computer security standard used to validate cryptographic modules, which are the hardware or software components that protect sensitive data through encryption. It is the current version of the standard and is used when federal departments and agencies design, implement, or operate cryptographic modules. Validation against the standard is carried out through a formal program rather than being self-declared.
FIPS 140-3, titled 'Security Requirements for Cryptographic Modules,' is a Federal Information Processing Standard that specifies security requirements to be satisfied by cryptographic modules operated by or on behalf of federal departments and agencies. The standard identifies the Cryptographic Module Validation Program (CMVP), a joint effort of the U.S. and Canadian governments, as the validation authority for modules claiming conformance. Practitioners should note that FIPS 140-3 governs the validation of cryptographic modules specifically and does not by itself constitute a broader system authorization; readers should verify current effective dates, applicable revisions, and CMVP transition timelines against the authoritative NIST/CSRC publications, as validation status and program requirements evolve over time.
Why it matters
FIPS 140-3 matters because it establishes a common, government-recognized baseline for the cryptographic modules that protect sensitive federal data. Rather than relying on a vendor's own assertion that its encryption is sound, the standard channels those claims through an independent validation process, giving agencies and their contractors a defensible basis for trusting that a module's cryptography has been tested against published security requirements. For compliance officers and system owners, this distinction between self-declared and formally validated cryptography is often the difference between meeting and failing a procurement or authorization requirement.
Because FIPS 140-3 is the current version of the standard for validating cryptographic modules operated by or on behalf of federal departments and agencies, it frequently appears as a prerequisite in acquisition language and system security requirements. A practical consequence is that organizations may need to confirm not only that a product uses strong algorithms, but that the specific module is validated under the applicable program and that its validation remains current. Practitioners should note that validation status and program requirements evolve over time, so a module considered acceptable at one point may require re-verification against current CMVP information.
A common expert correction is that FIPS 140-3 validation of a cryptographic module is not the same as a broader system authorization. Validation addresses the module specifically; it does not by itself establish that an information system is compliant, secure, or authorized to operate. Treating a validated module as if it satisfies wider compliance obligations conflates a narrow cryptographic assurance with an overall security posture, and readers should confirm how module validation fits within their applicable authorization framework.
Who it's relevant to
Inside FIPS 140-3
Common questions
Answers to the questions practitioners most commonly ask about FIPS 140-3.