FIPS 197
FIPS 197 is a U.S. federal standard, issued by NIST and approved by the Secretary of Commerce, that specifies the Advanced Encryption Standard (AES), an approved algorithm used to protect electronic data. It was originally approved in 2001 and is compulsory and binding on federal agencies for the purposes described in the standard. A later release updated the publication without making technical changes to the algorithm itself.
FIPS 197 (Advanced Encryption Standard) is a Federal Information Processing Standard maintained by NIST that specifies AES, a FIPS-approved symmetric block cipher algorithm used to protect electronic data. The Secretary of Commerce approved FIPS 197 in 2001, making it compulsory and binding on federal agencies for the purposes set out in the standard. According to the evidence, a subsequent release (dated May 9, 2023 in the cited source) updated the original 2001 publication but made no technical changes to the specified algorithm. FIPS 197 defines the AES algorithm specification itself; it is distinct from FIPS 140, which addresses cryptographic module security requirements and validation, and readers should not conflate algorithm conformance with cryptographic module validation. Practitioners should verify the current revision and any applicable approved modes against the authoritative NIST text, as details outside the algorithm specification (such as approved modes and module-level requirements) are governed by separate publications.
Why it matters
FIPS 197 defines the Advanced Encryption Standard (AES), the symmetric block cipher that has become the workhorse for protecting electronic data across federal systems and the broader private sector. Because the Secretary of Commerce approved FIPS 197 in 2001 and made it compulsory and binding on federal agencies for the purposes described in the standard, it establishes AES as an approved cryptographic algorithm that agencies can rely on when they need to protect the confidentiality of data. For compliance officers and system security managers, citing FIPS 197 is a way to point to an authoritative, government-approved algorithm specification rather than an ad hoc or proprietary encryption scheme.
A frequent and consequential mistake is to treat conformance to the FIPS 197 algorithm specification as equivalent to cryptographic module validation. FIPS 197 defines the AES algorithm itself; it does not, on its own, address the security requirements or validation of the cryptographic modules that implement AES, which are governed by the separate FIPS 140 line of publications. An organization can use AES and still fall short of module-level validation requirements that a given authorization or contract demands. Practitioners should confirm which requirement a control or clause actually imposes, because 'uses AES' and 'uses a validated cryptographic module' are not interchangeable claims.
AES has remained technically stable: the evidence indicates that a later release updated the original 2001 publication without making technical changes to the specified algorithm. That stability is useful for long-lived systems, but it should not lull practitioners into assuming the surrounding requirements are equally static. Approved modes of operation and module-level requirements are governed by separate publications and can be revised independently, so relying solely on FIPS 197 without checking the current authoritative text and any applicable modes can leave gaps.
Who it's relevant to
Inside FIPS 197
Common questions
Answers to the questions practitioners most commonly ask about FIPS 197.