FIPS-Validated Cryptography
FIPS-validated cryptography refers to encryption tools that have been formally tested and confirmed to meet U.S. government security standards for protecting sensitive information. The testing is carried out through an official program run by NIST, and a module that passes is added to a public list of validated products. This is stronger than merely claiming to follow the standard, because an independent, government-approved laboratory has actually verified the module.
FIPS-validated cryptography denotes a cryptographic module that has been validated by the Cryptographic Module Validation Program (CMVP) to meet the requirements specified in the applicable Federal Information Processing Standard (FIPS 140-3, with FIPS 140-3 validations currently being accepted). Validation is performed through testing by a NIST-accredited laboratory, after which the module receives a certificate indicating conformance to the standard's security requirements and is placed on the CMVP Active list. Per CMVP practice, validated modules remain on the Active list for a defined period (typically 5 years, or 2 years in certain cases) before transitioning off. This concept should be distinguished from mere FIPS 'compliance': validation reflects an actual tested and certified module rather than a self-asserted claim of meeting the requirements. FIPS validation is a U.S. federal cryptographic standard and is separate from the SOC 2 Trust Services Criteria and ISO/IEC 27001 requirements; where a scope invokes cryptographic controls, use of a FIPS-validated module may support but does not by itself satisfy those frameworks.
Why it matters
For organizations handling sensitive data, the distinction between cryptography that claims to follow a standard and cryptography that has been independently validated is significant. A vendor may assert that its encryption 'uses FIPS-approved algorithms' or is 'FIPS compliant,' but only a module validated through the Cryptographic Module Validation Program (CMVP) has actually been tested by a NIST-accredited laboratory and issued a certificate confirming conformance to the security requirements of the applicable standard. This independent verification matters because implementation errors in cryptography are common and difficult to detect through self-assessment alone; validation provides assurance that a specific module, as tested, meets defined requirements rather than relying on an unverified claim.
FIPS validation is a U.S. federal cryptographic standard and is distinct from both the SOC 2 Trust Services Criteria and ISO/IEC 27001 requirements. Where an audit or certification scope invokes cryptographic controls, use of a FIPS-validated module may help support those controls, but it does not by itself satisfy either framework. Compliance teams should treat FIPS validation as evidence that can strengthen a control narrative rather than as a substitute for demonstrating that cryptography is appropriately selected, deployed, and managed within the environment.
Validation status is also time-bound. Under CMVP practice, validated modules remain on the Active list for a defined period, typically five years, or two years in certain cases, before transitioning off. A module that was validated in the past may no longer be on the Active list, so relying on a module's historical validation without confirming its current status can create a gap between what an organization believes it has in place and what remains actively validated.
Who it's relevant to
Inside FIPS-Validated Cryptography
Common questions
Answers to the questions practitioners most commonly ask about FIPS-Validated Cryptography.