FIPS 140-3, Security Requirements for Cryptographic Modules, becomes effective today, replacing FIPS 140-2 as the US federal standard for validating cryptographic modules.
Key points
- Aligns US requirements with the international standards ISO/IEC 19790 and ISO/IEC 24759.
- Validation continues under the Cryptographic Module Validation Program (CMVP).
- The CMVP will begin accepting FIPS 140-3 submissions in September 2020.
- Existing FIPS 140-2 validations remain valid for a transition period.
- Federal systems, FedRAMP services and CMMC requirements rely on validated modules.
UK suppliers selling technology to US government or regulated US clients are often asked for FIPS validated encryption. Check your product roadmaps and supplier validations for the transition to FIPS 140-3.
Source: FIPS 140-3 (NIST CSRC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.