NIST SP 800-140 series
The NIST SP 800-140 series is a set of Special Publications issued by the National Institute of Standards and Technology (NIST) that supports FIPS 140-3, the federal standard for security requirements of cryptographic modules. These documents spell out the detailed testing requirements and supplemental information used to check whether a cryptographic module meets the standard. They are the reference material that testing laboratories and validators rely on when evaluating cryptographic products.
The NIST SP 800-140 series is a family of NIST Special Publications that supports Federal Information Processing Standard (FIPS) Publication 140-3, Security Requirements for Cryptographic Modules. The base document, SP 800-140, specifies modifications to the Derived Test Requirements (DTR) for FIPS 140-3, while the lettered members of the series (for example, SP 800-140Br1 and SP 800-140D Rev. 2) provide supplemental and periodically updated requirements within the Cryptographic Module Validation Program (CMVP), such as CMVP-approved sensitive security parameter generation and establishment methods and guidance on transitioning cryptographic algorithms and key lengths. Practitioners should note that specific documents in the series are revised over time and are administered in connection with the CMVP; the current authoritative text and applicable revision for any given member of the series should be verified against official NIST/CSRC sources.
Why it matters
Federal agencies and many defense contractors are generally required to use cryptographic modules that have been validated under FIPS 140-3, and the SP 800-140 series is the practical mechanism that makes that validation possible. Without documented, consistent testing requirements, laboratories evaluating cryptographic products would have no common baseline, and agencies would have limited assurance that a module labeled as compliant actually meets the federal standard. The series translates the high-level security requirements of FIPS 140-3 into the detailed criteria that the Cryptographic Module Validation Program (CMVP) uses in practice.
Because the members of the series are revised on their own schedules, they also serve as the vehicle for keeping validation aligned with evolving cryptographic guidance. For example, certain documents in the series address transitioning the use of cryptographic algorithms and key lengths, and others define CMVP-approved sensitive security parameter generation and establishment methods. This matters to practitioners because a module validated against one revision may need to be reassessed as the underlying supplemental requirements change; validation is tied to the applicable revision at the time of testing rather than being a permanent status.
Who it's relevant to
Inside NIST SP 800-140 series
Common questions
Answers to the questions practitioners most commonly ask about NIST SP 800-140 series.