<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/category/security/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Wed, 01 Jul 2026 19:39:54 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Security Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/category/security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Post Quantum Compliance: A New White House PQC Order Impacts Federal Product Vendors</title>
		<link>https://www.corsec.com/eo-pqc/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 02 Jul 2026 13:30:33 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[PQC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[STIG]]></category>
		<category><![CDATA[EO]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22662</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/eo-pqc/">Post Quantum Compliance: A New White House PQC Order Impacts Federal Product Vendors</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>On June 22, 2026, the White House issued Executive Order 14412, <strong>“Securing the Nation Against Advanced Cryptographic Attacks,”</strong> signaling a major acceleration in the federal government&#8217;s transition to post-quantum cryptography (PQC). The Executive Order recognizes a growing national security concern: adversaries can collect encrypted data today and potentially decrypt it in the future once large-scale quantum computers become operational, a threat commonly referred to as <em>“harvest now, decrypt later.”</em></p>
<p>While the Order is directed primarily at federal agencies, the implications extend far beyond government networks. For technology vendors that sell into the federal market, the message is clear: <strong>quantum readiness is becoming a compliance and procurement issue, not just a technical roadmap discussion.</strong></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>A Faster Federal Timeline for Post-Quantum Security</h3>
<div>
<p>The Executive Order directs federal agencies to accelerate their migration to NIST-approved post-quantum cryptographic standards and establish agency-wide PQC migration strategies. Agencies must inventory cryptographic assets, designate PQC migration leaders, prioritize high-value systems, and transition critical use cases to PQC by 2030 and 2031. The Order also calls for expanded guidance from NIST, NSA, and DHS, along with pilot implementations to demonstrate successful migrations.</p>
<p>Perhaps most significant for industry, the accompanying White House Fact Sheet states that the Federal Acquisition Regulatory Council will require covered contractors to meet certain federal cybersecurity standards and vulnerability disclosure requirements by the end of 2030.</p>
<div>For federal product companies, this represents another clear signal that cybersecurity certifications and validated security claims will increasingly influence procurement decisions and contract eligibility.</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="2608" data-end="2759"><span style="font-size: 16px;">Why FIPS 140-3 Matters More Than Ever</span></h3>
<div>
<p>One of the most important details in the Executive Order is its direct reference to the <strong>Cryptographic Module Validation Program (CMVP)</strong> and <span style="color: #339966;"><a style="color: #339966;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener"><strong>FIPS 140-3</strong></a></span>, the federal standard governing cryptographic modules. The Order explicitly defines the CMVP by referencing FIPS 140-3, underscoring the central role validated cryptography will play in the federal government&#8217;s PQC migration. For vendors, the challenge is not simply adopting new post-quantum algorithms.</p>
<p>The federal market will increasingly expect cryptographic implementations to be incorporated into validated cryptographic modules and supported by formal assurance programs. Organizations should begin assessing how their cryptographic architectures will evolve as post-quantum algorithms become integrated into future FIPS 140-3 validations.</p>
<p>Many vendors have historically viewed FIPS validation as a program needed only when a procurement requirement explicitly calls for it. The new Executive Order suggests a broader reality: <strong>validated cryptography is becoming foundational to federal quantum readiness.</strong></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>The Growing Connection to Common Criteria and NIAP</h3>
<div>
<p>The Executive Order does not directly mandate <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener">Common Criteria certification</a></span>. However, federal agencies face a practical challenge when adopting quantum-resistant technologies: they must be confident that security functions continue to operate as intended after significant architectural changes.</p>
<p>This is where the National Information Assurance Partnership (NIAP) and Common Criteria evaluations become increasingly relevant.</p>
<p>Historically, federal procurement policies have emphasized the use of NIAP-approved products for many cybersecurity categories. Internal federal guidance has long linked the use of Common Criteria-certified products and FIPS-validated cryptography as complementary assurance mechanisms for technology acquisitions.</p>
<p>As vendors redesign security products to incorporate:</p>
<ul>
<li>Quantum-resistant key exchange</li>
<li>New digital signature algorithms</li>
<li>Hybrid cryptographic implementations</li>
<li>Updated trust architectures</li>
</ul>
<p>those changes may impact both cryptographic validation boundaries and evaluated security functionality.</p>
<p>For organizations already maintaining NIAP certifications, quantum migration should be viewed through a compliance lens rather than solely a technical one. Engineering changes introduced to support PQC may have implications for future certification maintenance, evaluation activities, and product roadmaps.</p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3><span style="font-size: 16px;">What About DoD STIGs?</span></h3>
<div>
<p>The Department of Defense will face many of the same quantum migration challenges outlined in the Executive Order. Although <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">DoD Security Technical Implementation Guides (STIGs)</a></span> are not specifically addressed in the Order, they play an important role in how secure technologies are deployed within defense environments.</p>
<p>Historically, STIG requirements evolve to reflect emerging federal cybersecurity mandates and approved technologies. As NIST, NSA, and other agencies publish guidance for post-quantum implementation, vendors should expect quantum-resilient cryptography to gradually influence secure configuration baselines and deployment expectations across defense environments.</p>
<p>For products deployed within DoD environments, compliance teams should monitor future updates for:</p>
<ul>
<li>Cryptographic configuration requirements</li>
<li>Key management practices</li>
<li>Certificate and PKI guidance</li>
<li>Approved algorithm usage</li>
<li>Secure communications controls</li>
</ul>
<p>Vendors that proactively align product roadmaps with emerging federal quantum guidance will be better positioned when future requirements are incorporated into operational frameworks.</p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3><span style="font-size: 16px;">Compliance Is Becoming a Competitive Advantage</span></h3>
<div>
<p>The most important takeaway from the Executive Order is that quantum readiness is no longer a distant research topic. It is entering the realm of procurement policy, cybersecurity requirements, and compliance strategy.</p>
<p>Federal buyers are not simply looking for products that support post-quantum cryptography; they will increasingly need assurance that those capabilities are implemented securely, validated appropriately, and deployable in regulated environments.</p>
<p>Organizations that begin planning now by developing a post-quantum migration strategy will be better positioned to maintain eligibility for federal opportunities as the government&#8217;s quantum transition accelerates.</p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p data-start="1449" data-end="1741" data-is-last-node="" data-is-only-node=""><span style="color: #339966;"><strong>To help organizations navigate PQC requirements and FiPS 140-3, <a style="color: #339966;" href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener">Corsec is setting calls with product vendors</a> to outline security roadmaps.</strong></span></p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For 28+ years Corsec has guided companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and the <span style="color: #0000ff;"><strong>DoD (<a style="color: #0000ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">STIGs</a>, <a style="color: #0000ff;" href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener">DoDIN APL, UC APL</a>)</strong></span>. From mobile devices to satellites, Corsec helps companies reduce validation risk, shorten timelines, and expand into regulated markets.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><a href="https://ww3.corsec.com/linkedin"><img decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h5>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Head of Marketing &amp; BD<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/eo-pqc/">Post Quantum Compliance: A New White House PQC Order Impacts Federal Product Vendors</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Corsec to Attend the 7th International Conference on the EU Cybersecurity and Resilience Acts</title>
		<link>https://www.corsec.com/eu-cyber-acts-conference/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 10 Mar 2026 15:03:32 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[EUCC]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CRA]]></category>
		<category><![CDATA[Events]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22425</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/eu-cyber-acts-conference/">Corsec to Attend the 7th International Conference on the EU Cybersecurity and Resilience Acts</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>As the European Union continues to reshape its cybersecurity regulatory landscape, product vendors face a growing need for clarity, alignment, and practical guidance. Corsec is pleased to announce our attendance at the <a href="https://eucyberact.org/" target="_blank" rel="noopener"><strong>7th International Conference on the EU Cyber Security and Resilience Acts</strong></a>, taking place <strong>March 24–26 in Brussels</strong>.</p>
<div>
<p>This year’s conference comes at a critical moment, as implementation of the <strong>Cyber Resilience Act (CRA)</strong> accelerates and the <strong>EU Common Criteria Scheme (EUCC)</strong> continues to evolve. Corsec will be on site to engage with regulators, certification bodies, industry peers, and product manufacturers to deepen our understanding—and to help translate regulatory intent into actionable security and compliance strategies.</p>
<h3>Representing Corsec in Brussels</h3>
<p>Corsec will be represented by <strong>Dayanandini Pathmanathan</strong>, Corsec&#8217;s Senior Program Manager for <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener">Common Criteria</a></span>. With more than seven years of experience guiding Common Criteria certifications—and hands‑on involvement in FIPS 140 certification efforts—Dayanandini brings deep expertise at the intersection of product security engineering, certification schemes, and regulatory compliance. She holds a degree in Electrical Engineering and works closely with vendors navigating complex, multi‑jurisdictional requirements.</p>
<h3>Why This Conference Matters to Product Vendors</h3>
<p>The EU Cybersecurity Act Conference is not just about policy—it is about <strong>operational reality</strong>. For manufacturers selling into the European market, the CRA introduces new expectations around secure‑by‑design development, vulnerability handling, post‑market responsibilities, and supply‑chain accountability. At the same time, EUCC is redefining how <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener">Common Criteria</a></span> evaluations are performed and recognized across Europe.</p>
<p>Corsec’s focus at the conference is to:</p>
<ul>
<li>Gain deeper insight into <strong>how CRA requirements are being interpreted and operationalized</strong></li>
<li>Understand how <strong>EUCC and CRA conformity assessments intersect</strong></li>
<li>Collaborate with stakeholders to identify <strong>practical, scalable approaches</strong> for vendors of complex products</li>
<li>Bring clarity back to customers navigating overlapping standards, schemes, and enforcement timelines</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Key Tracks &amp; Sessions Corsec Will Be Following</h3>
<p>Throughout the conference, Corsec will be actively engaging across several tracks that are particularly relevant to manufacturers:</p>
<ul>
<li><strong>The EU Cybersecurity Agenda 2025–2029: What It Means for Industry<br />
</strong>This track provides a strategic view of the Commission’s priorities for the next legislative cycle, including CRA implementation, NIS 2 enforcement, and the future direction of certification schemes. For vendors, these discussions shape long‑term product and compliance planning.</li>
<li><strong>From Regulation to Reality: How the EC Is Supporting CRA Implementation Across Europe<br />
</strong>Sessions focused on how the European Commission is supporting harmonized CRA adoption offer insight into what “compliance” will look like in practice—and where flexibility or risk remains for manufacturers preparing today.</li>
<li><strong>Certification in Practice: From EUCC to CRA Conformity<br />
</strong>These discussions explore how EUCC, EUCS, and other schemes relate to CRA obligations. Understanding this mapping is essential for vendors deciding where certification adds value versus where it introduces unnecessary cost or duplication.</li>
<li><strong>Designing for Lifecycle Security and Post‑Market Responsibility<br />
</strong>CRA Articles addressing vulnerability reporting, patch delivery, and supply‑chain assurance are a major shift for many organizations. This track highlights what continuous compliance means beyond initial market entry.</li>
<li><strong>Panel Discussion: AI Act Cybersecurity—Real-World Risks, Requirements, and What Comes Next<br />
</strong>“The EU’s AI Act introduces sweeping new cybersecurity expectations—along with plenty of uncertainty. In this panel discussion, experts will break down how the rules reshape AI deployment, what “compliance” actually requires in practice, and where the biggest technical and organizational challenges lie. Panelists will provide a clear view of the security measures regulators expect, how to implement them without blowing up existing workflows, and what these obligations mean for your company’s risk landscape.”</li>
<li><strong>The Cost of Compliance: New Realities for Testing, Assessment, and Post-Market Obligations<br />
</strong>As assessment, testing, and post‑market obligations expand, vendors must budget realistically for long‑term compliance. This track addresses the emerging cost structures and tradeoffs organizations will face.</li>
<li><strong>What Market Surveillance Authorities Expect from Manufacturers under the CRA<br />
</strong>“What manufacturers need to provide under the CRA, information and supporting evidence to enable verification of compliance and assurance of requirements.”</li>
<li><strong>Too Much Already, Supply Chain Security? A Sensible Approach to Rating True Potential Vulnerabilities Is Needed<br />
</strong>“Threat modeling and product-context analysis to cut through the ~140 daily EUVD CVE filings and distinguish real, exploitable vulnerabilities from inflated worst-case assessments.”</li>
<li><strong>Vulnerability Management in Consumer IoT: Why No IoT Manufacturer Is Ready for CRA Vulnerability Management (And How to Fix It)<br />
</strong>With increasing scrutiny from Market Surveillance Authorities, manufacturers must be prepared to demonstrate not only secure design, but effective vulnerability monitoring, reporting, and remediation over time.</li>
<li><strong>Panel Discussion: Navigating Fragmented Global Cyber Regulations<br />
</strong>With overlapping global frameworks—from CRA and EUCC to international standards—this panel addresses whether meaningful harmonization is achievable and what manufacturers can do in the meantime.</li>
</ul>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div>
<h3>Corsec’s Approach: Learn, Collaborate, Guide</h3>
<p>Corsec’s participation reflects our commitment to <strong>learning directly from regulators and peers</strong>, collaborating across the ecosystem, and using those insights to guide product vendors with clear, experience‑based recommendations. Our goal is not just compliance—but helping vendors build security programs that are defensible, sustainable, and aligned with real regulatory expectations.</p>
<h3>Looking Ahead</h3>
<p>This conference is an important step in an ongoing conversation. Following the event, Corsec will share insights and observations on what manufacturers should be paying attention to as CRA enforcement approaches and EUCC continues to mature.</p>
<p>If you are preparing for CRA, evaluating EUCC certification paths, or reassessing your vulnerability management and post‑market strategies, we encourage you to <a href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener"><strong>connect with Corsec</strong></a> to discuss how these developments may impact your products and roadmap.</p>
<p><em>Stay tuned for post‑conference insights from Brussels.</em></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/eu-cyber-acts-conference/">Corsec to Attend the 7th International Conference on the EU Cybersecurity and Resilience Acts</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Designing for FIPS 140-3: A Practical Guide for Engineering</title>
		<link>https://www.corsec.com/fips-engineering/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Wed, 28 Jan 2026 20:34:57 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Engineering]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22241</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-engineering/">Designing for FIPS 140-3: A Practical Guide for Engineering</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="284" data-end="351">Security &amp; Design Engineering</h3>
<p data-start="353" data-end="1043">The Federal Information Processing Standard 140‑3 (<span style="color: #339966;"><a style="color: #339966;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span>) is a government-mandated framework for products sold into U.S. federal agencies. FIPS 140-3 defines how cryptographic modules must be designed, engineered, tested, and validated for use across U.S. federal agencies and regulated industries. Whether you’re an engineer new to FIPS, a seasoned security architect, or a product manager navigating compliance constraints, understanding the engineering implications is essential.</p>
<div>Beyond security, adherence to FIPS 140-3 can support interoperability, repeatable deployments, and predictable audit outcomes across complex systems.</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="284" data-end="351">Why FIPS 140‑3 Matters for Engineers and Product Teams</h3>
<p data-start="353" data-end="1043">Engineering teams are responsible for translating FIPS 140-3 requirements into practical design, implementation, and configuration decisions that support federal contracts, regulated industries such as critical infrastructure, finance, healthcare, IoT, and any environment handling highly sensitive data.</p>
<div>
<p>FIPS 140‑3 defines standardized security requirements for cryptographic modules across:</p>
<ul>
<li>Algorithm selection and cryptographic primitives</li>
<li>Key generation, handling, and destruction</li>
<li>Entropy sources and DRBG validation</li>
<li>Physical security protections (for hardware)</li>
<li>Secure boot, self‑tests, integrity checks, and error handling</li>
<li>Boundary definitions and operational environments</li>
</ul>
<p>Getting these engineering decisions right at design time minimizes the risk of costly rework, failed validations, and security gaps. Treating FIPS 140‑3 as a design discipline — not a post‑development audit, is critical.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="284" data-end="351">Security &amp; Design Engineering</h3>
<div>
<p>FIPS 140‑3 requirements shape both architecture and implementation. Engineers must consider how security functions behave from the moment the system boots through runtime operations and updates.</p>
<p>Examples of core engineering decisions influenced by FIPS requirements include:</p>
<ul>
<li><span style="color: #339966;"><strong>Choosing cryptographic libraries</strong></span>: Whether to use an open‑source module (e.g., OpenSSL FIPS provider), create a proprietary one, or privately label a validated module.</li>
<li><span style="color: #339966;"><strong>Boundary scoping</strong></span>: Deciding whether the &#8220;cryptographic boundary&#8221; is your entire product, a subcomponent, or a standalone module.</li>
<li><span style="color: #339966;"><strong>Entropy design</strong></span>: Ensuring your RNG/DRBG meets SP 800‑90 requirements and that entropy collection is testable and well‑documented.</li>
<li><span style="color: #339966;"><strong>Integrity monitoring</strong></span>: Implementing pre‑operational self‑tests and approved integrity checks that must pass before the module enters a FIPS‑approved mode.</li>
</ul>
<p>Evaluating these design decisions early helps prevent failures during testing.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="3865" data-end="3917">Engineering Mitigation Strategies</h3>
<div>
<p>Bridging security design with practical engineering execution is where many FIPS efforts succeed — or fail. This is the point in the development lifecycle where theoretical security requirements become engineering realities. Attempting to “retrofit” FIPS into an existing product is a common engineering failure. Corsec recommends integrating FIPS security requirements from the initial architectural design to reduce rework, cost, and validation delays. As an example, a team that chooses a non‑approved AES mode of operation (such as AES‑XTS for certain contexts) will later be forced to redesign its crypto pipeline once CMVP testing begins.</p>
<p><span style="color: #339966;">Plan for Compliance from Day One</span><br data-start="5328" data-end="5331" />Designing with FIPS 140-3 requirements in mind from the start—rather than attempting to retrofit compliance late in development—reduces engineering rework, lowers costs, and shortens validation timelines.</p>
<p><span style="color: #339966;">Document Gaps Using a POA&amp;M<br />
</span>The most essential mitigation strategy is documenting certification gaps. For engineers, this means clearly identifying and outlining validation boundary options and the technical areas that need to be addressed in order to achieve validation.</p>
<p><span style="color: #339966;">Enforce FIPS-Approved Mode Configuration<br />
</span>Validated modules must operate strictly in their FIPS-approved mode. Misconfiguration is a common engineering pitfall and one of the most frequent causes of non-compliance during reviews.</p>
<p><span style="color: #339966;">Use Approved Security Update Paths<br />
</span>When addressing CVEs or updating to a newer version of your product, engineers should select and follow the appropriate and approved security update process. There are many different update scenarios available for modules, some paths are faster and more cost-effective than triggering a full revalidation. Keeping your module inline with the regulations to qualify for an update is key.</p>
<p><span style="color: #339966;">Select an Appropriate FIPS Partner<br />
</span>Involving a FIPS partner early in the development lifecycle allows engineers to receive feedback before designs are finalized. Early engagement helps ensure documentation accuracy and reduces the likelihood of delays during formal testing.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="2345" data-end="2397">Addressing FIPS 140-3 &amp; Key Considerations</h3>
<div>
<p>Reviewing FIPS requirements at every engineering milestone is highly recommended, from architecture to final testing.</p>
</div>
<p data-start="2399" data-end="2723"><span style="color: #339966;">Contracts and Revenue</span><br data-start="2436" data-end="2439" />Products sold to or deployed within federal environments require FIPS 140-3 validation. For engineering teams, failure to validate often means finished products sit idle while deals stall, procurements are canceled, or existing contracts are put at risk.</p>
<p data-start="2725" data-end="2976"><span style="color: #339966;">Operational Disruptions</span><br data-start="2752" data-end="2755" />Lack of validation can translate to engineering teams being blocked from deploying new systems, features, or updates. Any modification to a validated cryptographic module—or the introduction of a non-validated component—can render the system non-compliant.</p>
<p data-start="2978" data-end="3240"><span style="color: #339966;">Security Exposure</span><br data-start="3009" data-end="3012" />To preserve an existing certificate, engineers may delay applying critical operating system or dependency patches. While this maintains validation status, it can leave systems exposed to known vulnerabilities and active threats.</p>
<p data-start="3242" data-end="3564"><span style="color: #339966;">Legal, Financial, and Reputational Risk</span><br data-start="3285" data-end="3288" />Failure to meet FIPS 140-3 requirements can result in regulatory violations, financial penalties, and legal exposure, including potential False Claims Act implications. These outcomes can significantly impact both the organization and the engineering teams responsible for delivery.</p>
<p data-start="3566" data-end="3858"><span style="color: #339966;">Certificates Becoming “Historical”</span><br data-start="3604" data-end="3607" />When teams fail to plan for standard transitions—such as moving from FIPS 140-2 to FIPS 140-3—certificates may become historical. Once this happens, they can no longer be used for new federal acquisitions, forcing revalidation under tighter timelines.</p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="5588" data-end="6057">
<style>
a {<br />    text-decoration: none;<br />    color: #464feb;<br />}<br />tr th, tr td {<br />    border: 1px solid #e6e6e6;<br />}<br />tr th {<br />    background-color: #f5f5f5;<br />}<br /></style>
</h3>
<div>
<h3><strong>Ready to Engineer Your Product for FIPS 140‑3?</strong></h3>
<p>If you’re building cryptographic products for federal or regulated markets, Corsec recommends engaging early to avoid costly engineering rework.</p>
<p><strong>To accelerate your path to validation and ensure your engineering team is building FIPS‑ready designs from day one, <a href="https://www.corsec.com/contact-us/" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</strong></p>
</div>
</div>

		</div>
	</div>
<div class="vc_empty_space"   style="height: 12px"><span class="vc_empty_space_inner"></span></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-4"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 style="text-align: center;"><a href="https://www.corsec.com/fips-assessment/" target="_blank" rel="noopener"><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-22144" src="https://www.corsec.com/wp-content/uploads/Assessment-Complete-Icon-Green-266x300.png" alt="FIPS 140-3 Assessment Complete Icon" width="93" height="105" srcset="https://www.corsec.com/wp-content/uploads/Assessment-Complete-Icon-Green-266x300.png 266w, https://www.corsec.com/wp-content/uploads/Assessment-Complete-Icon-Green.png 662w" sizes="auto, (max-width: 93px) 100vw, 93px" /></strong></a></h5>
<h5 style="text-align: center;"><strong>FIPS Assessment</strong></h5>
</div>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-4"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><a href="https://www.corsec.com/enhance/" target="_blank" rel="noopener"><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-22143" src="https://www.corsec.com/wp-content/uploads/Design-Testing-Complete-Icon-Green-268x300.png" alt="FIPS 140-3 Design &amp; Testing Complete Icon" width="94" height="105" srcset="https://www.corsec.com/wp-content/uploads/Design-Testing-Complete-Icon-Green-268x300.png 268w, https://www.corsec.com/wp-content/uploads/Design-Testing-Complete-Icon-Green.png 662w" sizes="auto, (max-width: 94px) 100vw, 94px" /></strong></a></h5>
<h5 style="text-align: center;"><strong>FIPS Design &amp; Testing</strong></h5>
</div>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-4"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><a href="https://www.corsec.com/validate/" target="_blank" rel="noopener"><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-22145" src="https://www.corsec.com/wp-content/uploads/Validation-Complete-Icon-Green-266x300.png" alt="FIPS 140-3 Validation Complete Icon" width="93" height="105" srcset="https://www.corsec.com/wp-content/uploads/Validation-Complete-Icon-Green-266x300.png 266w, https://www.corsec.com/wp-content/uploads/Validation-Complete-Icon-Green.png 662w" sizes="auto, (max-width: 93px) 100vw, 93px" /></strong></a></h5>
<h5 style="text-align: center;"><strong>FIPS Validation</strong></h5>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For 27+ years Corsec<strong> </strong>has guided companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and the <span style="color: #0000ff;"><strong>DoD (<a style="color: #0000ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">STIGs</a>, <a style="color: #0000ff;" href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener">DoDIN APL, UC APL</a>)</strong></span>. From mobile devices to satellites, Corsec helps companies reduce validation risk, shorten timelines, and expand into regulated markets.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-engineering/">Designing for FIPS 140-3: A Practical Guide for Engineering</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Enabling Federal Sales: Winning Security Strategies</title>
		<link>https://www.corsec.com/fips-fed-sales/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 13 Jan 2026 20:16:32 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Federal Sales]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=20173</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-fed-sales/">Enabling Federal Sales: Winning Security Strategies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<p data-start="623" data-end="951">In today’s federal procurement environment, cybersecurity requirements are no longer aspirational—they are mandatory gatekeepers. As federal agencies modernize their infrastructure, adopt zero-trust architectures, and migrate mission systems to the cloud, the security expectations placed on technology vendors continue to rise.</p>
<p data-start="953" data-end="1259">While individual departments and agencies retain authority to define procurement-specific security requirements, several standards have become federally mandated. Among them, <a href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener"><span style="color: #339966;"><strong data-start="1146" data-end="1160">FIPS 140-3</strong></span> </a>stands out as one of the most critical—and misunderstood—requirements in federal technology sales.</p>
</div>
<p data-start="1261" data-end="1709">For federal sales teams, FIPS 140-3 is not simply a technical checkbox. It is often the difference between being eligible to compete and being disqualified before discussions even begin. Products that lack a credible FIPS validation path routinely stall in procurement, trigger ATO delays, or are excluded entirely from RFPs. In contrast, vendors that proactively align with FIPS 140-3 position themselves as lower-risk, procurement-ready partners.</p>
<p data-start="1711" data-end="1927">Understanding how FIPS 140-3 works, why agencies mandate it, and what it takes to achieve validation is now a core competency for both federal sales professionals and the engineering leaders who support them.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h3><strong>Understanding FIPS 140-3</strong></h3>
<p>The <a href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener"><strong><span style="color: #339966;">Federal Information Processing Standard (FIPS) 140-3</span></strong></a> defines the security requirements for cryptographic modules used to protect sensitive but unclassified information within federal systems. Issued by the National Institute of Standards and Technology (NIST), FIPS 140-3 replaces the long-standing FIPS 140-2 standard and aligns U.S. government cryptographic requirements with modern international standards. At a practical level, FIPS 140-3 governs how encryption, key management, authentication, and cryptographic functions are designed, implemented, tested, and operated.</p>
<p data-start="2708" data-end="2746">It is critical to distinguish between:</p>
<ul data-start="2747" data-end="2883">
<li data-start="2747" data-end="2817">
<p data-start="2749" data-end="2817"><a href="https://ww3.corsec.com/FIPS-Validated-vs-Inside" target="_blank" rel="noopener"><strong data-start="2749" data-end="2768">FIPS compliance</strong> (a vendor assertion or configuration claim), and</a></p>
</li>
<li data-start="2818" data-end="2883">
<p data-start="2820" data-end="2883"><a href="https://ww3.corsec.com/FIPS-Validated-vs-Inside" target="_blank" rel="noopener"><strong data-start="2820" data-end="2839">FIPS validation</strong> (formal certification issued through CMVP).</a></p>
</li>
</ul>
<p data-start="2885" data-end="3032">Federal agencies—and their Authorizing Officials—almost always require <strong data-start="2956" data-end="2991">validated cryptographic modules</strong>, not aspirational compliance statements.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h3><strong>The Significance for Federal Agencies:</strong></h3>
<p data-start="3072" data-end="3274">FIPS 140-3 has become more than a legacy federal requirement carried forward—it is now a defining control point in modern federal procurement. Several converging forces have elevated its importance:</p>
<p data-start="3276" data-end="3325"><strong>1. The Sunsetting of FIPS 140-2 Is Forcing Action<br />
</strong>FIPS 140-2 is officially sunsetting, with CMVP transitioning fully to FIPS 140-3 validations. Agencies are increasingly unwilling to approve new systems that rely on FIPS 140-2-only modules, especially for long-lived deployments. For sales teams, this means:</p>
<ul>
<li data-start="3578" data-end="3627">
<p data-start="3580" data-end="3627">Legacy validations are losing procurement value</p>
</li>
<li data-start="3628" data-end="3688">
<p data-start="3630" data-end="3688">“We’ll address it later” is no longer acceptable to buyers</p>
</li>
<li data-start="3689" data-end="3776">
<p data-start="3691" data-end="3776">Products without a FIPS 140-3 roadmap are seen as short-term or high-risk investments</p>
</li>
</ul>
<p data-start="3778" data-end="3915"><span style="color: #339966;">Vendors that delay transition often find themselves locked out of future RFPs or facing costly re-engineering under procurement pressure.</span></p>
<p data-start="3922" data-end="3988"><strong>2. Zero Trust and Cloud Mandates Depend on Strong Cryptography<br />
</strong>Federal zero-trust initiatives, cloud-first policies, and identity-centric architectures all rely on provable cryptographic trust. Without validated cryptographic modules, these architectures fail to meet baseline federal security expectations. As a result, FIPS 140-3 validation is increasingly treated as foundational infrastructure, not an optional enhancement.</p>
<p data-start="4542" data-end="4719"><span style="color: #339966;">Sales teams that can articulate how their product’s cryptography aligns with FIPS 140-3—and how it supports zero-trust objectives—gain immediate credibility with federal buyers.</span></p>
<p data-start="4726" data-end="4776"><strong>3. FIPS 140-3 Is Directly Tied to ATO Outcomes<br />
</strong>One of the most common—and costly—procurement blockers in federal sales is Authority to Operate (ATO) friction. Systems that lack validated cryptography frequently encounter:</p>
<ul data-start="4961" data-end="5058">
<li data-start="4961" data-end="4978">
<p data-start="4963" data-end="4978">Extended POA&amp;Ms</p>
</li>
<li data-start="4979" data-end="5007">
<p data-start="4981" data-end="5007">Conditional authorizations</p>
</li>
<li data-start="5008" data-end="5029">
<p data-start="5010" data-end="5029">Delayed deployments</p>
</li>
<li data-start="5030" data-end="5058">
<p data-start="5032" data-end="5058">Additional agency scrutiny</p>
</li>
</ul>
<p data-start="5060" data-end="5264">From an Authorizing Official’s perspective, unvalidated cryptography introduces unnecessary risk. FIPS 140-3 validation simplifies security assessments, reduces ambiguity, and shortens approval timelines.</p>
<p data-start="5266" data-end="5304"><span style="color: #339966;">For sales teams, this translates into: 1.) Faster time-to-value for customers, 2.) Fewer late-stage deal delays, and 3.) Reduced risk of post-award surprises</span></p>
<p data-start="5418" data-end="5466"><strong>4. Procurement Language Is Becoming Explicit<br />
</strong>Federal acquisition language increasingly mandates FIPS 140-3 explicitly, referencing: NIST standards, OMB directives, Agency-specific cybersecurity policies, and FAR and DFARS clauses.</p>
<p data-start="5659" data-end="5719"><span style="color: #339966;">Vendors that cannot clearly demonstrate FIPS alignment risk:</span></p>
<ul data-start="5720" data-end="5884">
<li data-start="5720" data-end="5774">
<p data-start="5722" data-end="5774"><span style="color: #339966;">Failing compliance checks during proposal evaluation</span></p>
</li>
<li data-start="5775" data-end="5816">
<p data-start="5777" data-end="5816"><span style="color: #339966;">Being deemed “technically unacceptable”</span></p>
</li>
<li data-start="5817" data-end="5884">
<p data-start="5819" data-end="5884"><span style="color: #339966;">Losing deals before pricing or differentiation is even considered</span></p>
</li>
</ul>
<p data-start="5886" data-end="6014"><span style="color: #339966;">In competitive procurements, FIPS 140-3 readiness is often assumed—not rewarded. Its absence, however, is penalized immediately.</span></p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h3><strong>The Impact on Federal Sales Teams:</strong></h3>
<p data-start="7131" data-end="7260">For federal sales professionals and their engineering counterparts, FIPS 140-3 has direct, measurable impact on revenue outcomes, specifically when looking at competitive eligibility.</p>
<p data-start="7131" data-end="7260">Without a FIPS 140-3 validation, many opportunities are simply un-winnable. With it, teams gain access to a broader set of procurements and avoid early disqualification.</p>
<ul>
<li data-start="7453" data-end="7478">Trust and Credibility: Validated cryptography signals maturity, seriousness, and commitment to federal security standards. It reassures buyers that the vendor understands federal risk tolerance and compliance expectations.</li>
<li data-start="7681" data-end="7709">Sales-Cycle Acceleration: Products aligned with FIPS 140-3 encounter fewer objections during security reviews, enabling smoother evaluations and faster procurement decisions.</li>
<li data-start="7861" data-end="7879">Risk Reduction: Understanding validation scope, timelines, and dependencies helps sales teams avoid overpromising and protects engineering teams from last-minute compliance fire drills.</li>
</ul>
<p>Achieving FIPS 140-3 is not a single engineering task—it is a <strong data-start="8175" data-end="8206">cross-functional initiative</strong> that touches product architecture, release planning, sales strategy, and customer engagement.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="2583" data-end="2885"><strong>How Corsec Supports Federal Sales Success</strong></h3>
<p data-start="8752" data-end="8920">Corsec specializes in guiding technology companies through the complexity of FIPS 140-3 validation with a focus on business outcomes, not just technical compliance.</p>
<p data-start="8922" data-end="8988">We work with product, engineering, and federal sales teams to:</p>
<ul data-start="8989" data-end="9314">
<li data-start="8989" data-end="9052">
<p data-start="8991" data-end="9052">Map cryptographic components to real procurement requirements</p>
</li>
<li data-start="9053" data-end="9119">
<p data-start="9055" data-end="9119">Define validation scope aligned to target agencies and use cases</p>
</li>
<li data-start="9120" data-end="9178">
<p data-start="9122" data-end="9178">Forecast realistic timelines that support sales planning</p>
</li>
<li data-start="9179" data-end="9232">
<p data-start="9181" data-end="9232">Reduce risk through proven certification strategies</p>
</li>
<li data-start="9233" data-end="9314">
<p data-start="9235" data-end="9314">Strengthen competitive positioning with clear, defensible compliance narratives</p>
</li>
</ul>
<p data-start="9316" data-end="9442">By engaging early, teams avoid stalled deals, missed RFPs, and reactive compliance efforts that erode margins and credibility.</p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3><strong>Conclusion: FIPS 140-3 Is a Sales Enabler, Not a Checkbox</strong></h3>
<p data-start="9511" data-end="9768">In the modern federal market, FIPS 140-3 compliance is no longer optional—and it is no longer just a security concern. It is a <strong data-start="9638" data-end="9670">sales-enablement requirement</strong>, a <strong data-start="9674" data-end="9701">procurement accelerator</strong>, and a <strong data-start="9709" data-end="9725">trust signal</strong> that directly influences buying decisions.</p>
<p data-start="9770" data-end="10002">Federal sales teams that understand FIPS 140-3—and partner with experts to execute it effectively—position themselves for smoother procurement cycles, stronger customer relationships, and sustained growth in the federal marketplace.</p>
<p data-start="10053" data-end="10204">Whether you’re early in product development or facing active federal procurements, Corsec can help you align certification strategy with sales success.</p>
<p data-start="10206" data-end="10302"><strong data-start="10206" data-end="10302">Talk to Corsec today to start your FIPS 140-3 roadmap and unlock more federal opportunities.</strong></p>
</div>

		</div>
	</div>
<div class="vc_empty_space"   style="height: 12px"><span class="vc_empty_space_inner"></span></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-4"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 style="text-align: center;"><a href="https://www.corsec.com/fips-assessment/" target="_blank" rel="noopener"><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-22144" src="https://www.corsec.com/wp-content/uploads/Assessment-Complete-Icon-Green-266x300.png" alt="FIPS 140-3 Assessment Complete Icon" width="93" height="105" srcset="https://www.corsec.com/wp-content/uploads/Assessment-Complete-Icon-Green-266x300.png 266w, https://www.corsec.com/wp-content/uploads/Assessment-Complete-Icon-Green.png 662w" sizes="auto, (max-width: 93px) 100vw, 93px" /></strong></a></h5>
<h5 style="text-align: center;"><strong>FIPS Assessment</strong></h5>
</div>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-4"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><a href="https://www.corsec.com/enhance/" target="_blank" rel="noopener"><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-22143" src="https://www.corsec.com/wp-content/uploads/Design-Testing-Complete-Icon-Green-268x300.png" alt="FIPS 140-3 Design &amp; Testing Complete Icon" width="94" height="105" srcset="https://www.corsec.com/wp-content/uploads/Design-Testing-Complete-Icon-Green-268x300.png 268w, https://www.corsec.com/wp-content/uploads/Design-Testing-Complete-Icon-Green.png 662w" sizes="auto, (max-width: 94px) 100vw, 94px" /></strong></a></h5>
<h5 style="text-align: center;"><strong>FIPS Design &amp; Testing</strong></h5>
</div>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-4"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><a href="https://www.corsec.com/validate/" target="_blank" rel="noopener"><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-22145" src="https://www.corsec.com/wp-content/uploads/Validation-Complete-Icon-Green-266x300.png" alt="FIPS 140-3 Validation Complete Icon" width="93" height="105" srcset="https://www.corsec.com/wp-content/uploads/Validation-Complete-Icon-Green-266x300.png 266w, https://www.corsec.com/wp-content/uploads/Validation-Complete-Icon-Green.png 662w" sizes="auto, (max-width: 93px) 100vw, 93px" /></strong></a></h5>
<h5 style="text-align: center;"><strong>FIPS Validation</strong></h5>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For 27+ years Corsec<strong> </strong>has guided companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and the <span style="color: #0000ff;"><strong>DoD (<a style="color: #0000ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">STIGs</a>, <a style="color: #0000ff;" href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener">DoDIN APL, UC APL</a>)</strong></span>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <a href="https://www.corsec.com/contact-us/" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-fed-sales/">Enabling Federal Sales: Winning Security Strategies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Securing Cyber-Physical Systems in Smart Manufacturing</title>
		<link>https://www.corsec.com/certs-cps/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Thu, 04 Dec 2025 20:53:38 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[certifications]]></category>
		<category><![CDATA[Smart Manufacturing]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=21890</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/certs-cps/">Securing Cyber-Physical Systems in Smart Manufacturing</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="465" data-end="509">The Rise of CPS in Modern Manufacturing</h3>
<p data-start="510" data-end="1197">Smart factories are increasingly powered by <strong data-start="554" data-end="586">cyber-physical systems (CPS)</strong>—connected robots, industrial sensors, autonomous vehicles, and AI-enabled control software. These technologies combine computing, analytics, and real-world physical actions to create fast, efficient, and adaptable production environments. As this connectivity expands, so does the potential impact of a cybersecurity event. A compromised device is no longer just an IT issue; it can stop production, alter physical processes, or create safety concerns. This escalating risk is driving manufacturers to adopt formal security certifications as a way to guarantee resilience and trust in their CPS ecosystems.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="1204" data-end="1240">What Makes CPS Harder to Secure</h3>
<p data-start="1241" data-end="1868">Cyber-physical systems (CPS) operate very differently from traditional IT environments, which makes securing them a unique and challenging task. Unlike standard IT systems that primarily process data, CPS directly control and interact with physical machinery and industrial processes. This introduces several security complexities:</p>
<ol data-start="493" data-end="3096">
<li data-start="493" data-end="1030">
<p data-start="496" data-end="1030"><strong data-start="496" data-end="542">Direct Interaction with Physical Equipment</strong><br data-start="542" data-end="545" />CPS, such as robotic assembly lines or industrial control systems (ICS), directly manipulate machinery. A cyberattack or system misconfiguration can cause physical damage or safety hazards. For example, in 2010, the Stuxnet worm targeted Iranian centrifuges, causing them to spin out of control and physically destroy equipment—all while appearing normal to operators. This illustrates how tightly integrated cyber and physical components increase the stakes of security breaches.</p>
</li>
<li data-start="1032" data-end="1450">
<p data-start="1035" data-end="1450"><strong data-start="1035" data-end="1073">Real-Time Operational Requirements</strong><br data-start="1073" data-end="1076" />CPS often require precise, real-time responses. Even a fraction-of-a-second delay can disrupt operations or reduce product quality. In automotive manufacturing, for instance, robotic arms on an assembly line must synchronize perfectly. If a security patch or intrusion detection system introduces latency, production may stall or components may be improperly assembled.</p>
</li>
<li data-start="1452" data-end="1954">
<p data-start="1455" data-end="1954"><strong data-start="1455" data-end="1501">Downtime Risks and Continuous Availability</strong><br data-start="1501" data-end="1504" />Many CPS environments cannot tolerate interruptions. In power plants, oil refineries, or water treatment facilities, shutting down systems for maintenance or security updates can be costly or dangerous. The 2021 Colonial Pipeline ransomware attack in the U.S. forced a shutdown of critical fuel pipelines, causing widespread fuel shortages. This highlights how CPS downtime is not just inconvenient—it has real-world economic and safety impacts.</p>
</li>
<li data-start="1956" data-end="2584">
<p data-start="1959" data-end="2584"><strong data-start="1959" data-end="2003">Legacy and Modern Technology Integration</strong><br data-start="2003" data-end="2006" />CPS environments often combine decades-old industrial controllers with modern, cloud-connected software, IoT sensors, and AI tools. This mix of legacy and cutting-edge systems creates a complex network with inconsistent security standards. For example, a manufacturing facility may have older programmable logic controllers (PLCs) that lack encryption or modern authentication, yet these devices are now networked with cloud-based analytics platforms. Protecting such hybrid systems requires solutions that can bridge old and new technologies without disrupting operations.</p>
</li>
<li data-start="2586" data-end="3096">
<p data-start="2589" data-end="3096"><strong data-start="2589" data-end="2639">Operational Complexity and Multi-Layered Risks</strong><br data-start="2639" data-end="2642" />CPS security spans digital, physical, and operational dimensions simultaneously. A breach could not only compromise data but also cause safety incidents, environmental hazards, or regulatory non-compliance. For instance, in a chemical plant, a malicious actor could manipulate temperature or pressure controls, causing explosions or toxic leaks. This multi-dimensional risk profile makes a structured, comprehensive certification approach essential.</p>
</li>
</ol>
<p data-start="3098" data-end="3500">Because CPS integrate physical machinery, require uninterrupted real-time performance, and often involve hybrid legacy-modern networks, securing them goes far beyond standard IT cybersecurity. Manufacturers need structured frameworks and certifications that account for digital safeguards, operational continuity, and physical safety to ensure resilient and secure CPS deployment.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="1875" data-end="1915">Key Certifications for CPS Security</h3>
<p data-start="1916" data-end="3002">Several certification frameworks play a critical role in helping manufacturers build secure and reliable CPS. <strong data-start="2026" data-end="2040">FIPS 140-3</strong> establishes that cryptographic functions—including encryption, key management, and tamper protection—operate correctly and securely across devices. <strong data-start="2189" data-end="2208">Common Criteria</strong> provides assurance that essential security functions such as system integrity, secure boot, and access control are properly implemented and resistant to attack. As manufacturers increasingly adopt AI-driven tools for inspection, optimization, and predictive maintenance, emerging standards for AI assurance are also becoming important—they help ensure that machine-learning models remain reliable, tamper-resistant, and securely updated over time.</p>
<p data-start="1916" data-end="3002">The growing reliance on CPS has significantly expanded the manufacturing attack surface. If an attacker manipulates operational data, disrupts a digital twin, or interferes with autonomous equipment, the resulting impact can spread quickly across an entire production line. Certification helps reduce these risks by requiring thorough, independent evaluations of security controls. Certified systems must meet strict industry standards, demonstrate consistent behavior under stress, and provide evidence that both digital integrity and physical safety have been considered. This creates a higher level of trust for customers, suppliers, and internal stakeholders.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="3724" data-end="3762">How a Certification Partner Helps</h3>
<p data-start="3763" data-end="4416">Achieving certification for CPS can be challenging because of the number of interconnected components involved. A specialized certification partner helps manufacturers navigate this complexity by identifying which certifications apply to specific systems, uncovering architectural gaps early in the process, and guiding teams through secure development and documentation requirements. Partners also assist with preparing evidence packages, coordinating with testing labs, and managing the full certification lifecycle. This support reduces delays, improves compliance readiness, and helps ensure that CPS deployments meet rigorous security expectations.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="3968" data-end="3995"><strong data-start="3971" data-end="3995">The Corsec Advantage</strong></h3>
</div>
<div class="wpb_text_column wpb_content_element ">
<p data-start="138" data-end="416">Cyber-physical systems are transforming smart manufacturing, but their growing complexity demands stronger, verifiable security. Certification provides the independent assurance needed to protect operations, meet regulatory expectations, and build trust across the supply chain.</p>
<p data-start="3411" data-end="3774">For nearly 30 years, <strong data-start="4147" data-end="4157">Corsec</strong> has supported technology providers in achieving and maintaining security certifications essential for critical infrastructure, including <strong><a href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a> / <a href="https://www.corsec.com/fips-140-3/">FIPS 140-3</a></strong>, <a href="https://www.corsec.com/common-criteria/"><strong>Common Criteria</strong></a> (CC), <strong><a href="https://www.corsec.com/csfc/">CSfC</a></strong>, and <a href="https://www.corsec.com/dodin-apl/"><strong>DoD requirements (STIGs, UCR, APL)</strong></a>.</p>
<p data-start="3411" data-end="3774">Corsec’s certification methodology and broad industry knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element vc_custom_1763739924849" >
		<div class="wpb_wrapper">
			<h3 data-start="4769" data-end="4797"><strong data-start="4772" data-end="4797">Ready to Get Started?</strong></h3>
<p data-start="4799" data-end="5111">As manufacturers accelerate adoption of cyber-physical systems, the need for validated cryptography, hardened device security, and standards-based protection becomes essential for safeguarding production environments. Connect with Corsec to strengthen your product’s security posture, navigate complex certification requirements, and support the future of trusted, resilient smart-manufacturing infrastructure.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/">Jake Nelson</a></span> Corsec Director of Marketing jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			
		</div>
	</div>
</div></div></div></div><!-- /wp:post-content --></div><p>The post <a href="https://www.corsec.com/certs-cps/">Securing Cyber-Physical Systems in Smart Manufacturing</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Critical Role of Certs in Smart Cities</title>
		<link>https://www.corsec.com/certs-smart-cities/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Tue, 18 Nov 2025 15:30:23 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[Public Safety Tech]]></category>
		<category><![CDATA[Smart Cities]]></category>
		<category><![CDATA[Threat Mitigation]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=21776</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/certs-smart-cities/">The Critical Role of Certs in Smart Cities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="243" data-end="328"><strong data-start="245" data-end="328">Securing Tomorrow’s Cities: Why Smart Infrastructure Needs Certified Protection</strong></h3>
<p data-start="330" data-end="1029">As cities evolve into highly connected smart ecosystems, they increasingly depend on digital infrastructure to manage transportation, energy distribution, utilities, emergency response, and environmental monitoring. These interconnected systems generate and exchange massive volumes of data and keep daily life running smoothly, making them indispensable.</p>
<p data-start="330" data-end="1029">But as digital infrastructure advances and becomes more complex, it inherently becomes more vulnerable. A single compromised device or unsecured communication channel can disrupt essential services and compromise public safety. In modern urban environments, cybersecurity is no longer a supporting function; it is the backbone of reliable and safe city operations.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="1036" data-end="1081"><strong data-start="1039" data-end="1081">The New Digital Backbone of Urban Life</strong></h3>
<p data-start="1083" data-end="1482">Smart cities rely heavily on distributed technologies that gather, transmit, and act on huge amounts of data. Streetlights adjust based on activity, traffic systems reroute drivers with real-time updates, and public utilities monitor system health minute by minute. While these advancements make cities cleaner, safer, and more efficient, they also introduce countless entry points for cyberattacks.</p>
<p data-start="1484" data-end="1940">A vulnerability in a traffic signal controller can cause gridlock across an entire district. A compromised environmental sensor can feed false data to emergency responders. Even a small breach in a power system could flood into outages that affect businesses, hospitals, and residents. As urban infrastructure becomes more automated, the security stakes rise dramatically — and so does the need for strong, irrefutable assurance.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="1947" data-end="2003"><strong data-start="1950" data-end="2003">Where Certification Meets Critical Infrastructure</strong></h3>
<p data-start="2005" data-end="2280">Securing smart-city technologies requires more than basic cybersecurity hygiene. It demands tested and evaluated system architectures that can withstand real-world adversarial conditions. This is where internationally recognized standards provide essential security assurance.</p>
<ul>
<li data-start="2115" data-end="2492">
<p data-start="2117" data-end="2492"><strong data-start="2117" data-end="2131">FIPS 140-3</strong>, mandated by U.S. federal agencies and widely adopted across critical infrastructure sectors, validates cryptographic modules used for securing communications, authentication, and key management. In a smart-city environment, FIPS-validated cryptography ensures that distributed IoT devices, gateways, and control systems can protect sensitive operational data.</p>
</li>
<li data-start="2494" data-end="2805">
<p data-start="2496" data-end="2805"><strong data-start="2496" data-end="2520">Common Criteria (CC)</strong> evaluates the broader security properties of devices and platforms, confirming that their design, implementation, and threat mitigations hold up under rigorous testing. CC is especially relevant for complex IoT systems, control platforms, and multi-component infrastructure solutions.</p>
</li>
</ul>
<p data-start="2672" data-end="3023">For developers and product managers, certification provides a measurable, globally recognized standard of security assurance. For system integrators and municipalities, it ensures that the technologies underpinning critical infrastructure can be trusted against tampering, manipulation, and cyber intrusion.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="3030" data-end="3063">The Expanding Attack Surface of Smart Cities</h3>
<p data-start="3065" data-end="3409">Smart-city deployments introduce broad and often decentralized attack surfaces. Public Wi-Fi access points, EV charging stations, distributed IoT devices, surveillance systems, and next-generation utilities all connect to municipal networks—frequently operating in environments where physical access is difficult to control.</p>
<p data-start="3411" data-end="3774">A single unvalidated or insecure device can provide attackers with a foothold into operational systems. Threat actors can intercept data, alter sensor readings, or disrupt essential services remotely. Without strong assurance mechanisms, these vulnerabilities can escalate into citywide outages or public safety risks.</p>
<p data-start="3776" data-end="3961">Certification frameworks mitigate these challenges by enforcing proven security controls, reducing the likelihood of configuration errors, and ensuring that every component in the system—from edge devices to cloud orchestration—has been tested for resilience. In a world where cities depend on continuous connectivity, certified technologies are essential to building resilience, maintaining public trust, and preventing large-scale disruptions.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h3 data-start="3968" data-end="3995"><strong data-start="3971" data-end="3995">The Corsec Advantage</strong></h3>
</div>
<div class="wpb_text_column wpb_content_element ">
<p data-start="3411" data-end="3774">For nearly 30 years, <strong data-start="4147" data-end="4157">Corsec</strong> has supported technology providers in achieving and maintaining security certifications essential for critical infrastructure, including <strong><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a> / </span><a href="https://www.corsec.com/fips-140-3/"><span style="color: #008000;">FIPS 140-3</span></a></strong>, <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC), <span style="color: #993300;"><strong><a style="color: #993300;" href="https://www.corsec.com/csfc/">CSfC</a></strong>,</span> and <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://www.corsec.com/dodin-apl/"><strong>DoD requirements (STIGs, UCR, APL)</strong></a></span>.</p>
<p data-start="3411" data-end="3774">Corsec&#8217;s certification methodology and broad industry knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element vc_custom_1763479741815" >
		<div class="wpb_wrapper">
			<h3 data-start="4769" data-end="4797"><strong data-start="4772" data-end="4797">Ready to Get Started?</strong></h3>
<p data-start="4799" data-end="5111">As cities expand their connected ecosystems, the need for <strong data-start="4870" data-end="4907">FIPS 140-3–validated cryptography</strong>, <strong data-start="4909" data-end="4935">certified IoT security</strong>, and <strong data-start="4941" data-end="4971">standards-based protection</strong> becomes central to operational resilience. Connect with Corsec to strengthen your product’s security, navigate complex certification requirements, and support the future of trusted smart-city infrastructure.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/">Jake Nelson</a></span> Corsec Director of Marketing jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/certs-smart-cities/">The Critical Role of Certs in Smart Cities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Architecting a Smarter Path to FIPS 140-3 Validation</title>
		<link>https://www.corsec.com/architecting-to-fips/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 18 Sep 2025 14:25:24 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[10Pearls]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[Secure Products]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=21456</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/architecting-to-fips/">Architecting a Smarter Path to FIPS 140-3 Validation</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>For companies entering regulated markets—defense, federal, finance, healthcare, critical infrastructure—<span style="color: #339966;"><a style="color: #339966;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> validation is non-negotiable. But for many product teams, the process feels overwhelming and disruptive to development timelines.</p>
<p>Corsec specializes in guiding clients through FIPS 140 validation, from assessment to certification. In a <a href="https://www.youtube.com/watch?v=vngKzljB9JY" target="_blank" rel="noopener">recent webinar</a>, Corsec CEO Matthew Appler joined Peter Hesse, EVP at <a href="https://10pearls.com">10Pearls</a> – a global product engineering partner that helps enterprises design, build, and modernize secure, scalable software solutions.</p>

		</div>
	</div>

	<div class="wpb_video_widget wpb_content_element vc_clearfix   vc_video-aspect-ratio-169 vc_video-el-width-70 vc_video-align-left" >
		<div class="wpb_wrapper">
			
			<div class="wpb_video_wrapper"><iframe loading="lazy" title="Architecting for FIPS Building Solutions From the Ground Up" width="500" height="281" src="https://www.youtube.com/embed/vngKzljB9JY?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>Together, we explore what it takes to architect validation-ready systems from the outset and how combining expert certification strategy with agile development support helps teams avoid costly rework and accelerate time-to-validation.</p>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b>Why the Right Architecture Matters</b></p>
<p>FIPS 140 validation applies to the cryptographic sources within a product—not always the entire system. But many teams fail to isolate the cryptographic boundary in a way that is testable, flexible, and maintainable. This results in inefficient code rewrites or re-architecting late in the process.</p>
<p><strong>Key architectural considerations include:</strong></p>
<ul>
<li>Centralizing cryptographic functions</li>
<li>Ensuring testability of algorithms and key modules</li>
<li>Avoiding hardcoded or outdated algorithm implementations</li>
<li>Planning for algorithm evolution, such as post-quantum cryptography</li>
</ul>
<p>This is where Corsec’s early-stage <a href="https://www.corsec.com/fips-assessment/" target="_blank" rel="noopener">FIPS Assessments</a> help identify gaps—and where partners like <a href="https://10pearls.com">10Pearls</a> provide the development expertise to implement recommended changes quickly and effectively.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b>Embedding Validations into the Roadmap</b></p>
<p>Too often, teams treat validation as a final hurdle rather than an integral part of product strategy. But building with validation in mind reduces delays and creates long-term value.</p>
<p>Corsec provides clear guidance on requirements strategy, cryptographic boundary definition, and documentation, while <a href="https://10pearls.com">10Pearls</a> implements system-level changes to align architecture with validation goals. Together, we enable clients to move forward confidently without derailing innovation.</p>
<p style="padding-left: 40px;">“You don’t have to stop building features—you just need a smarter, more modular strategy that supports both compliance and agility.” &#8211; Peter Hesse</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><strong>Managing Performance Without Compromising Security</strong></p>
<p>Performance concerns are one of the top reasons companies hesitate to pursue FIPS 140 validation. Startup tests, memory constraints, and algorithm overhead can introduce friction—especially in lightweight or resource-constrained environments.</p>
<p><strong>Effective strategies include:</strong></p>
<ul>
<li>Using FIPS mode toggles to balance runtime needs</li>
<li>Validating subcomponents, not entire systems</li>
<li>Benchmarking early and often across FIPS-compatible environments</li>
<li>Leveraging validated cryptographic libraries</li>
</ul>
<p>Corsec helps clients identify the best technical pathways to validation, while <a href="https://10pearls.com">10Pearls</a> ensures those pathways are built with efficiency and performance in mind.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><strong>CI/CD Pipelines Built for Validation</strong></p>
<p>FIPS 140 doesn’t have to slow down your release cycles—if your CI/CD workflows are structured to support it. Separating feature delivery from validation-focused release tracks helps prevent unnecessary rework and keeps product updates moving.</p>
<p>Locking validated modules to specific versions and automating dependency checks ensures changes to the cryptographic boundary are identified early. With the right structure, teams can maintain validation while continuing to deliver at speed.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><strong>Validation vs. Compliance—and Why the Distinction Matters</strong></p>
<p>As Matthew Appler explained, the term “FIPS compliant” is often misunderstood. True FIPS 140 validation involves strict documentation, third-party lab testing, and a formal government review process. Corsec guides clients through that process and help to decode vague customer requirements and select the most efficient and effective path to validation.</p>
<p><a href="https://10pearls.com">10Pearls</a> complements this by supporting the necessary engineering adjustments—so compliance aspirations turn into validation outcomes.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><strong>Why Corsec and 10Pearls Work Together</strong></p>
<p>Navigating FIPS 140 validation is complex. It requires more than technical documentation—it demands architectural foresight, performance planning, and disciplined execution. That’s why Corsec partners with <a href="https://10pearls.com">10Pearls</a>: to ensure that every gap identified in a <a href="https://www.corsec.com/fips-assessment/" target="_blank" rel="noopener">FIPS Assessment</a> can be resolved by a trusted and capable development team.</p>
<p><strong>Corsec brings:</strong></p>
<ul>
<li>Over 500 certifications completed</li>
<li>Proven validation strategies for FIPS 140-2/FIPS 140-3, Common Criteria, CSfC, STIGs, DoDIN APL, and more</li>
<li>Deep relationships with accredited labs and federal authorities</li>
<li>End-to-end program oversight, from gap analysis to final validation</li>
</ul>
<p><strong>10Pearls brings:</strong></p>
<ul>
<li>Engineering expertise to redesign and refactor systems for validation-readiness</li>
<li>DevSecOps best practices for building, testing, and maintaining validated software</li>
<li>Agile, scalable teams to support FIPS-driven development without sacrificing speed</li>
</ul>
<p>Together, we simplify the path to certification—so your product is ready for high-assurance markets.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b><span data-contrast="none">Ready to Get Started?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">Connect with us to streamline your validation journey. → <a href="https://www.corsec.com/contact-us/" target="_blank" rel="noopener">Contact Us</a></span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/">CSfC</a></span></strong>, and the <a href="https://www.corsec.com/dodin-apl/"><strong>DoD’s requirements</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>

		</div>
	</div>
<div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/architecting-to-fips/">Architecting a Smarter Path to FIPS 140-3 Validation</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Securing the Internet of Things: Why Certification is the Key to Market Success</title>
		<link>https://www.corsec.com/certs-iot/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Fri, 29 Aug 2025 18:23:18 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[STIG]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=21413</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/certs-iot/">Securing the Internet of Things: Why Certification is the Key to Market Success</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b><span data-contrast="none">A Connected World, A Growing Risk</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">From smart thermostats and wearable fitness trackers to industrial control systems and autonomous vehicles, the Internet of Things (IoT) has become an essential part of modern life. These connected devices provide convenience, efficiency, and new capabilities across nearly every industry. But with innovation comes risk. Each new device that connects to a network expands the potential attack surface for cybercriminals. Weak encryption, outdated firmware, or poor authentication can expose sensitive data, disrupt critical operations, or even threaten national security.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The expansion of IoT has outpaced the security measures needed to protect it. For manufacturers, securing devices is no longer optional—it is a requirement for market entry.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b><span data-contrast="none">The Challenge of IoT Security</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">IoT products are often developed with speed-to-market in mind, and security features can be left behind in the rush to innovate. The consequences of these oversights are significant. Vulnerabilities in consumer devices can lead to privacy violations, while flaws in industrial or medical IoT systems can cause operational failures or put lives at risk.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Manufacturers face an increasingly complex regulatory landscape as well. Governments, enterprises, and consumers alike now expect clear proof that IoT devices are secure. Meeting these expectations requires not only strong engineering practices but also formal certification to demonstrate compliance with established security standards.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b><span data-contrast="none">Certification as a Path to Trust</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">Certifications have become the cornerstone of IoT trust. Security frameworks such as </span><b><span data-contrast="auto">Common Criteria, FIPS 140-3, CSfC, STIGs, and the UCR</span></b><span data-contrast="auto"> provide assurance that devices meet rigorous industry requirements. For manufacturers, achieving certifications unlock access to critical markets, including federal, defense, and enterprise sectors where uncertified devices cannot compete.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Certifications also offer long-term advantages. By validating a device against internationally recognized standards, companies demonstrate their commitment to security, differentiate themselves from competitors, and reduce barriers to adoption. In an environment where buyers are increasingly security-conscious, certifications are not just about compliance— they are about gaining a competitive edge.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b><span data-contrast="none">Building Security from the Start</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">The most successful IoT companies integrate security into their products from the very beginning. Certifications should not be treated as a checkbox at the end of development, but as a guiding framework for product design. By aligning early with certification requirements, manufacturers can avoid costly redesigns, accelerate approval timelines, and ensure that security is woven into the DNA of their devices.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="3"><b><span data-contrast="none">Ready to Get Started?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">The IoT revolution is here—but only secure and certified devices will earn lasting trust. Don’t let certification challenges slow you down.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Let Corsec help you navigate the complexities of IoT certification and bring secure products to market faster. Learn more about our certification services → </span><a href="https://www.corsec.com/services"><span data-contrast="none">https://www.corsec.com/services</span></a><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/">CSfC</a></span></strong>, and the <a href="https://www.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>

		</div>
	</div>
<div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/certs-iot/">Securing the Internet of Things: Why Certification is the Key to Market Success</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How Security Is Changing the Game for Medical Device Companies</title>
		<link>https://www.corsec.com/fips-medical/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Tue, 19 Aug 2025 17:43:18 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[Medical]]></category>
		<category><![CDATA[Patient Health]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=21376</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-medical/">How Security Is Changing the Game for Medical Device Companies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-weight: 400;"><span class="TextRun SCXW152687295 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW152687295 BCX0">As the healthcare industry becomes more connected, securing medical devices is no longer optional—</span><span class="NormalTextRun SCXW152687295 BCX0">it’s</span><span class="NormalTextRun SCXW152687295 BCX0"> essential. Systems and devices that handle sensitive patient data are now being required to meet strict security </span><span class="NormalTextRun SCXW152687295 BCX0">standards. Evaluating protection of sensitive data within products will no longer be a differentiator, it will be a barrier to entry</span></span><span class="TextRun SCXW152687295 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW152687295 BCX0">.</span></span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><strong><span class="TextRun Underlined MacChromeBold SCXW134641004 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW134641004 BCX0">A New Way of Supporting Patient Health</span></span></strong></p>
<p>Innovation in connectivity has not stopped at consumer technology; it has become deeply embedded in the medical field through advanced equipment and devices. Modern hospitals and clinics now rely on interconnected medical technologies such as infusion pumps, ventilators, imaging systems, and wearable monitors, all designed to share data seamlessly across networks. These devices enable healthcare providers to track patient conditions in real time, improve diagnostic accuracy, and deliver faster, more personalized treatment. The benefits are undeniable: increased efficiency, improved outcomes, and more accessible care. Yet, this growing reliance on networked medical devices also introduces significant risks. A single vulnerability in a connected device can open the door to cyberattacks, leading to data breaches, exposure of patient records, or even the manipulation of life-sustaining equipment. Protecting these devices is therefore not only a matter of securing information but of safeguarding patient safety and trust. As medical technology continues to advance, the demand for robust cybersecurity measures tailored specifically to medical equipment has never been more urgent.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><strong><span class="TextRun Underlined MacChromeBold SCXW134641004 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW134641004 BCX0"><span class="TextRun Underlined MacChromeBold SCXW242018182 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW242018182 BCX0">The Challenge Ahead</span></span></span></span></strong></p>
<p><span data-contrast="auto">Medical device companies operate in one of the most tightly regulated industries in the world—and the path becomes even more difficult when targeting the U.S. federal government as a customer. While the opportunity can be lucrative, gaining access to this market comes with a unique set of challenges that can quickly become overwhelming without a clear strategy. To succeed, companies must prove not only that their products are safe and effective, but also that they meet stringent regulatory and cybersecurity requirements. They must navigate a landscape shaped by evolving federal mandates, rigorous compliance expectations, and complex procurement processes that can extend sales cycles for months or even years. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">For medical device manufacturers looking to expand into the U.S. federal market, these are just a few of the major hurdles:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="Aptos" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:&#091;65533,0&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="none">Constantly Changing Global and Federal Regulations</span></b><br />
<span data-contrast="none">The regulatory environment is in constant flux. Agencies such as the FDA, Department of Defense, and Department of Veterans Affairs regularly update their standards to reflect new technologies, threats, and political priorities. Staying compliant means staying informed—and often requires reworking product features, documentation, or security architectures just to remain eligible for federal contracts.</span></li>
<li data-leveltext="%1." data-font="Aptos" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:&#091;65533,0&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="none">Extensive Documentation and Testing Requirements<br />
</span></b>Entering the federal market isn&#8217;t just about having a functional product. Companies must invest in rigorous testing protocols and produce detailed documentation that proves product safety, performance, and interoperability. This includes everything from clinical validation studies to cybersecurity posture assessments. One overlooked requirement can delay approvals by months or disqualify a bid entirely.<span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"><br />
</span></li>
<li data-leveltext="%1." data-font="Aptos" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:&#091;65533,0&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="none">Long Sales Cycles and Strict Contracting Rules</span></b><br />
<span data-contrast="none"><span data-contrast="none">Selling to the government is nothing like selling to the private sector. The process is often protracted and layered with approvals, vendor registrations, procurement vehicles, and compliance checks. Understanding how to navigate FAR (Federal Acquisition Regulations), secure a place on approved contract vehicles like GSA Schedules, or build relationships with system integrators is essential—but time-consuming.</span></span></li>
<li data-leveltext="%1." data-font="Aptos" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:&#091;65533,0&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="none">Security and Compliance Demands</span></b><br />
Beyond FDA approval, federal buyers demand proof that devices meet the highest security standards. Frameworks like <b><span data-contrast="none">FIPS 140-3</span></b><span data-contrast="none"> for cryptographic modules, </span><b><span data-contrast="none">HIPAA</span></b><span data-contrast="none"> for patient data privacy, and other </span><b><span data-contrast="none">NIST-based requirements</span></b><span data-contrast="none"><span data-contrast="none"> are table stakes for participation. Meeting these standards often requires significant re-architecture of systems and undergoing third-party validations—especially for products that store, transmit, or process sensitive information.</span></span></li>
<li data-leveltext="%1." data-font="Aptos" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:&#091;65533,0&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="none">High Costs Tied to Engineering, Marketing, and Monitoring</span></b><br />
All of these challenges translate into substantial upfront and ongoing investment. Whether it&#8217;s hiring compliance consultants, modifying product designs, or building custom sales materials for federal buyers, the costs can mount quickly. And even post-sale, companies are expected to monitor system performance, report vulnerabilities, and ensure continued compliance—driving long-term resource commitments.<span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ol>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><strong><span class="TextRun Underlined MacChromeBold SCXW134641004 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW134641004 BCX0">Supporting Industry Requirements Through Validation</span></span></strong></p>
<p>The good news is that proven steps and processes exist to strengthen this protection. One of the most effective is the use of FIPS 140-3 validated products, which provide a recognized standard for cryptographic security. For medical device manufacturers, implementing FIPS 140-3 validation offers a strategic advantage: it ensures the data collected and transmitted by devices is safeguarded against compromise, while also reducing concerns about device integrity. Certification builds trust not only with patients, but also with healthcare providers, regulators such as the FDA, and organizations that deploy these solutions—including federal agencies like the Department of Veterans Affairs and large hospital systems. In a competitive market, achieving FIPS 140-3 validation helps products stand out, especially for critical devices such as heart monitors, pacemakers, and infusion pumps where patient safety and data security are paramount. By aligning innovation with certified security, medical device manufacturers can both differentiate their products and reassure stakeholders that safety has been built into the core of their technology.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><strong><span class="TextRun Underlined MacChromeBold SCXW134641004 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW134641004 BCX0"><span class="TextRun Underlined MacChromeBold SCXW242018182 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW242018182 BCX0"><span class="TextRun Underlined MacChromeBold SCXW22717634 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW22717634 BCX0">What is FIPS 140-3?</span></span></span></span></span></span></strong></p>
<p>FIPS 140-3 validation ensures that cryptographic modules meet rigorous standards for encryption, key management, authentication, and tamper resistance. This includes protections against common attack vectors such as side-channel attacks, brute-force decryption, and unauthorized firmware updates. Devices validated under this standard demonstrate strong resistance to both software-based and physical attacks, making them resilient in the face of evolving cyber threats. For manufacturers, adopting FIPS 140-3 validated cryptographic modules not only streamlines compliance with federal and healthcare regulations, but also provides a scalable foundation for securing future device generations.</p>
<p>In short, this certification is more than a regulatory checkbox—it is a technical safeguard that strengthens the integrity, reliability, and trustworthiness of modern medical devices.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><strong><span class="TextRun Underlined MacChromeBold SCXW134641004 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW134641004 BCX0"><span class="TextRun Underlined MacChromeBold SCXW242018182 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW242018182 BCX0"><span class="TextRun Underlined MacChromeBold SCXW22717634 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW22717634 BCX0"><span class="NormalTextRun SCXW36772685 BCX0">The </span><span class="NormalTextRun SpellingErrorV2Themed SCXW36772685 BCX0">Co</span><span class="NormalTextRun SpellingErrorV2Themed SCXW36772685 BCX0">rsec</span><span class="NormalTextRun SCXW36772685 BCX0"> Advantage</span></span></span></span></span></span></span></strong></p>
<p>As a privately owned company with over 27 years of experience, Corsec has partnered with organizations worldwide to deliver comprehensive security certification solutions. Having guided medical device companies and technology vendors through more than 500 successful certifications—including FIPS 140, Common Criteria, CSfC, and DoD STIGs —Corsec offers unmatched expertise in navigating complex certification landscapes. From early design reviews to lab coordination and final approval, our proven process streamlines every step, mitigating delays and avoiding costly pitfalls. With experience securing products across diverse industries, from storage devices to satellites, Corsec provides the knowledge and hands-on support manufacturers need to bring FIPS 140-3 validated medical devices to market quickly and confidently.</p>
<p>By partnering with Corsec, medical device companies gain not just a guide through certification, but a trusted ally in building secure, compliant, and market-ready solutions.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><strong><span class="TextRun Underlined MacChromeBold SCXW134641004 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW134641004 BCX0"><span class="TextRun Underlined MacChromeBold SCXW242018182 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW242018182 BCX0"><span class="TextRun Underlined MacChromeBold SCXW22717634 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW22717634 BCX0"><span class="NormalTextRun SCXW36772685 BCX0">Ready to Get Started?</span></span></span></span></span></span></span></strong></p>
<p><span class="TextRun SCXW174548497 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW174548497 BCX0">Let </span><span class="NormalTextRun SpellingErrorV2Themed SCXW174548497 BCX0">Corsec</span><span class="NormalTextRun SCXW174548497 BCX0"> help you bring secure, certified products to the market faster. Learn more about our FIPS services → </span></span><a class="Hyperlink SCXW174548497 BCX0" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noreferrer noopener"><span class="TextRun Underlined SCXW174548497 BCX0" lang="EN-US" xml:lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW174548497 BCX0" data-ccp-charstyle="Hyperlink">https://www.corsec.com/fips-140-3/</span></span></a><span class="EOP SCXW174548497 BCX0" data-ccp-props="{&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559739&quot;:240,&quot;335559740&quot;:276}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/">CSfC</a></span></strong>, and the <a href="https://www.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>

		</div>
	</div>
<div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-medical/">How Security Is Changing the Game for Medical Device Companies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fed Roundup: July 2025</title>
		<link>https://www.corsec.com/fed-july25/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 06 Aug 2025 15:30:12 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[STIG]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=21387</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fed-july25/">Fed Roundup: July 2025</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Announcements:</span></h5>
<ul>
<li><a href="https://www.corsec.com/dodinapl-end/" target="_blank" rel="noopener">DISA ends DoDIN APL Program</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">Security Technical Implementation Guide Updates:</a></span></h5>
<ul>
<li>None</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Updates &amp; Announcements:</span></h5>
<ul>
<li>None</li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Special Publications, Interagency Reports, &amp; Cybersecurity White Papers:</span></h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2025/comment-on-sp-800-57-parts-2-and-3" target="_blank" rel="noopener">Comments for SP 800-57 Parts 2 and 3 &#8211; Recommendation for Key Management</a></li>
<li><a href="https://csrc.nist.gov/News/2025/nist-withdraws-sp-800-102" target="_blank" rel="noopener">Withdrawal of SP 800-102, Recommendation for Digital Signature Timeliness</a></li>
<li><a href="https://csrc.nist.gov/News/2025/cyber-risks-of-portable-storage-media-in-ot-enviro">Draft SP 1334, Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments</a></li>
<li><a href="https://csrc.nist.gov/News/2025/considerations-for-achieving-crypto-agility-2nd-dr">2nd Draft NIST Cybersecurity White Paper (CSWP) 39, Considerations for Achieving Crypto Agility: Strategies and Practices</a></li>
<li><a href="https://csrc.nist.gov/News/2025/guidelines-for-media-sanitization-draft-sp-800-88r">Draft SP 800-88r2 (Revision 2), Guidelines for Media Sanitization</a></li>
<li><a href="https://csrc.nist.gov/News/2025/sp-800-53-draft-controls-available-for-comment">Updates to Draft SP 800-53 Controls on Secure and Reliable Patches</a></li>
<li><a href="https://csrc.nist.gov/News/2025/proposal-for-sp-800-56-reports">Proposed Updates to SP 800-56A and Revise SP 800-56C</a></li>
<li><a href="https://csrc.nist.gov/News/2025/draft-sp-1800-44a-available-for-comment">Preliminary draft Volume A of NIST SP 1800-44, Secure Software Development, Security, and Operations (DevSecOps) Practices</a></li>
<li><a href="https://csrc.nist.gov/News/2025/nist-ir-8536-second-public-draft">Second public draft of NIST Internal Report 8536, Supply Chain Traceability: Manufacturing Meta-Framework</a></li>
<li><a href="https://csrc.nist.gov/News/2025/draft-nist-ir-8579-nccoe-chatbot">IR 8579, Developing the NCCoE Chatbot: Technical and Security Learnings from the Initial Implementation</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/announcements">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;"><span style="color: #000000;">Updates &amp; Announcements:</span></h5>
<ul>
<li>NIAP held the first &#8220;NIAP Industry Community Event&#8221; (NICE) on July 31st, 2025</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;"><span style="color: #000000;">Protection Profile Announcements:</span></h5>
<ul>
<li>None</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fed-july25/">Fed Roundup: July 2025</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
