FIPS-Validated Cryptographic Module
A FIPS-validated cryptographic module is a piece of hardware, software, or firmware that performs encryption or other cryptographic functions and has been formally tested and confirmed to meet U.S. government security requirements. The validation is performed under the Cryptographic Module Validation Program (CMVP), and a module that passes receives a certificate showing it conforms to the FIPS 140 standard. It is important to note that being 'FIPS-validated' is not the same as merely being 'FIPS-compliant' or claiming to use approved algorithms; validation refers to formal testing and a certificate, not a self-assertion.
A cryptographic module that has been validated by the Cryptographic Module Validation Program (CMVP) against the applicable revision of the FIPS 140 standard, with a certificate indicating conformance to the security requirements of that standard. Per the evidence, the CMVP is currently accepting FIPS 140-3 validations, and validated modules are placed on the CMVP Active list for a defined period (described in the evidence as five years, or two years in certain cases); practitioners should verify current CMVP list status, applicable revision, and validity dates against official CMVP records rather than relying on a vendor's compliance claim. Validation is distinct from operational use: a system running in 'FIPS mode' is configured at runtime to restrict cryptographic operations to FIPS-approved algorithms, but this runtime configuration does not by itself establish that the underlying module holds a valid CMVP certificate. The evidence does not fully specify security levels, embodiment types, or agency- and program-specific requirements (for example, particular FedRAMP or DoD obligations), which readers must confirm against current authoritative sources.
Why it matters
For systems that protect Controlled Unclassified Information (CUI) and other sensitive federal data, the distinction between a FIPS-validated cryptographic module and one that merely claims to use approved algorithms is often decisive. Many federal and defense requirements call specifically for validated cryptography, meaning cryptography that carries a certificate from the Cryptographic Module Validation Program (CMVP), not a vendor's self-assertion of compliance. A compliance officer or assessor who accepts a marketing claim of 'FIPS-compliant' without confirming an active CMVP certificate risks a finding, because validation refers to formal testing and a certificate rather than a claim about algorithm selection.
Who it's relevant to
Inside FIPS-Validated Cryptographic Module
Common questions
Answers to the questions practitioners most commonly ask about FIPS-Validated Cryptographic Module.