<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Tue, 11 Aug 2026 18:44:53 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Deconstructing FIPS 140-3: Myth #4 &#8211; Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</title>
		<link>https://www.corsec.com/fips-myth-4/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 18:43:08 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[FIPS Compliance]]></category>
		<category><![CDATA[FIPS Validation]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22764</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-myth-4/">Deconstructing FIPS 140-3: Myth #4 &#8211; Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="isSelectedEnd">Organizations that already have a FIPS 140-2 validation may assume that their work is finished. After all, the product already went through a formal validation process, so why would another validation be necessary?</p>
<p class="isSelectedEnd">The answer is that <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> and <span data-contrast="auto"><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></span> are different standards. FIPS 140-3 replaced FIPS 140-2 as the current standard for new validations and introduced updated requirements for evaluating cryptographic modules. With that and the looming FIPS 140-2 sunset date approaching, all vendors considering an approach for FIPS 140 will need to validate to the newest version of the publication.</p>
<p>This post is the fourth installment in our <a href="https://www.corsec.com/fips-myths/"><strong data-start="1459" data-end="1511">Deconstructing FIPS 140-3: 5 Myths and Realities</strong></a> series, where we examine common misconceptions surrounding FIPS validation and explain what organizations should understand before beginning the certification process.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Myth #4:</h3>
<h3>“Our product has a FIPS 140-2 validation, so we don’t need FIPS 140-3.”</h3>
<p>At first glance, this assumption seems reasonable. If a product has already completed FIPS validation, it can be easy to think that the existing validation automatically carries over to the newer standard.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Reality:</h3>
<h3>A FIPS 140-2 validation does not automatically make a product FIPS 140-3 validated.</h3>
<p class="isSelectedEnd">FIPS 140-2 was the standard used to validate cryptographic modules for many years. FIPS 140-3 is its successor and was developed to update the requirements and align the U.S. standard more closely with international standards.</p>
<p>While FIPS 140-3 builds on many of the concepts found in FIPS 140-2, it also includes updated requirements and changes to how cryptographic modules are evaluated. FIPS 140-2 and even FIPS 140-3 validations have a sunset date, traditionally 5 years. <strong>However, all remaining FIPS 140-2 validations will be automatically sunset on Sept. 21, 2026</strong>.</p>
<p>For vendors selling into the U.S. federal government, the CMVP states that all modules with a status designation of Historical &#8220;<span style="color: #ff0000;"><em>should not be included by Federal Agencies in new procurements</em></span>.&#8221;</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="isSelectedEnd">If an organization has already invested significant time and resources into obtaining a FIPS 140-2 validation, it is understandable to assume that the existing validation should be sufficient for the newer standard. However, a FIPS 140-2 certificate does not simply become a FIPS 140-3 certificate. The two standards have different requirements, and organizations need to understand what their existing validation means and what requirements apply to their specific product and use case.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Validation &amp; Boundaries</h3>
<p class="isSelectedEnd">If an organization has already invested significant time and resources into obtaining a FIPS 140-2 validation, it is understandable to assume that the existing validation should be sufficient for the newer standard. However, a FIPS 140-2 certificate does not simply become a FIPS 140-3 certificate. The two standards have different requirements, and organizations need to understand what their existing validation means and what requirements apply to their specific product and use case.</p>
<p class="isSelectedEnd">Another important consideration is that FIPS validation applies to a specific cryptographic module and its defined configuration. It is not a blanket certification that automatically covers every version or configuration of a product.</p>
<p>This means that when a product is updated or a new version is released, organizations need to understand whether those changes affect the scope of the existing validation. The fact that an earlier version was validated does not necessarily mean that a newer version has the same validation status.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Moving From One Standard to the Next</h3>
<p class="isSelectedEnd">For organizations with an existing FIPS 140-2 validation, the transition to FIPS 140-3 does not necessarily mean starting from scratch. The existing validation can provide a useful foundation for understanding what may need to change.</p>
<p>Planning early can help organizations identify differences between their current FIPS 140-2 validation and the requirements of FIPS 140-3. This can help teams anticipate potential design, documentation, and testing impacts before beginning a new validation effort.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>The Takeaway</h3>
<p class="isSelectedEnd">Having a FIPS 140-2 validation is valuable, but it should not be confused with having a FIPS 140-3 validation. As organizations plan new products, product updates, or future validation efforts, understanding the differences between the two standards is an important first step.</p>
<p class="isSelectedEnd">FIPS validation is not simply a label that applies to every version of a product. The applicable standard, validated module, configuration, and current requirements all matter.</p>
<p>Understanding where your product stands today can help ensure that your next step is the right one.</p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-myth-4/">Deconstructing FIPS 140-3: Myth #4 &#8211; Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fed Roundup: July 2026</title>
		<link>https://www.corsec.com/fed-july26/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 19:05:24 +0000</pubDate>
				<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[STIG]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22753</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fed-july26/">Fed Roundup: July 2026</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;">DISA News</strong></h5>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Announcements:</span></h5>
<ul>
<li>July 2026 Quarterly Release</li>
<li>Group Policy Objects (GPOs) &#8211; July 2026</li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://www.cyber.mil/stigs/downloads" target="_blank" rel="noopener">Security Technical Implementation Guide Updates:</a></span></h5>
<ul>
<li data-section-id="mimdvc" data-start="795" data-end="826">Omnissa Workspace ONE UEM STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Nokia Service Router (SR) OS 25.x STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Unified Endpoint Management SRG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">MongoDB Enterprise Advanced 7.x STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">VMware vSphere 8.0 STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Microsoft Intune (Desktop &amp; Mobile) STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Microsoft IIS 10.0 STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Juniper EX Series Switches STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">IBM z/OS STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Forescout STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">F5 BIG-IP TMOS STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Cisco NX OS Switch STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Cisco ISE STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Cisco IOS Switch STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Cisco IOS Router STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Cisco ASA STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Apache Server 2.4 Unix STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Ivanti Policy Secure STIG</li>
<li data-section-id="mimdvc" data-start="795" data-end="826">Google Android 17 STIG</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Updates &amp; Announcements:</span></h5>
<ul>
<li>None</li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Special Publications, Interagency Reports, &amp; Cybersecurity White Papers:</span></h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2026/nist-releases-sp-1326" target="_blank" rel="noopener">Cybersecurity Supply Chain Risk Management (C-SCRM) Due Diligence Assessment Quick-Start Guide</a></li>
<li><a href="https://csrc.nist.gov/News/2026/security-guidelines-storage-infrastructure-draft" target="_blank" rel="noopener">Draft SP 800-209r1, Security Guidelines for Storage Infrastructure</a></li>
<li><a href="https://csrc.nist.gov/News/2026/ai-data-center-security-analysis-draft-sp-800-239" target="_blank" rel="noopener">Draft SP 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/announcements">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;"><span style="color: #000000;">Updates &amp; Announcements:</span></h5>
<ul>
<li>None</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;"><span style="color: #000000;">Protection Profile Announcements:</span></h5>
<ul>
<li>None</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fed-july26/">Fed Roundup: July 2026</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deconstructing FIPS 140-3: Myth #3 &#8211; FIPS Validation Is Just a Documentation Exercise</title>
		<link>https://www.corsec.com/myth-3/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 19:09:13 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[FIPS Validation]]></category>
		<category><![CDATA[Security Testing]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22745</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/myth-3/">Deconstructing FIPS 140-3: Myth #3 &#8211; FIPS Validation Is Just a Documentation Exercise</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="PDq2pG_selectionAnchorContainer" data-start="855" data-end="1116">By the time organizations begin planning for <span data-contrast="auto"><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></span> validation, they usually understand that documentation is required. Security policies, design documentation, finite state models, and other artifacts are all necessary components of the validation package.</p>
<p data-start="1118" data-end="1415">Because of the volume of required documentation, it&#8217;s easy to assume that FIPS validation is primarily an exercise in writing documents. In reality, documentation is only one part of a much broader process that evaluates how a cryptographic module is designed, implemented, tested, and maintained.</p>
<p data-start="1417" data-end="1679">This post is the third installment in our <a href="https://www.corsec.com/fips-myths/"><strong data-start="1459" data-end="1511">Deconstructing FIPS 140-3: 5 Myths and Realities</strong></a> series, where we examine common misconceptions surrounding FIPS validation and explain what organizations should understand before beginning the certification process.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1rcsd1j" data-start="1686" data-end="1697">Myth #3:</h3>
<h3 data-section-id="12e5cy0" data-start="1698" data-end="1753">&#8220;FIPS validation is just a documentation exercise.&#8221;</h3>
<p data-start="1755" data-end="1945">At first glance, this assumption seems reasonable. Organizations often see the extensive list of required documents and conclude that success depends primarily on producing enough paperwork.</p>
<p data-start="1947" data-end="2125">While documentation is essential, it exists to support something much larger such as demonstrating that a cryptographic module satisfies the security requirements defined by FIPS 140-3.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1gwrx5t" data-start="2132" data-end="2143">Reality:</h3>
<h3 data-section-id="20ycmf" data-start="2144" data-end="2237">Documentation supports validation but it doesn&#8217;t replace engineering, testing, or compliance.</h3>
<p data-start="2239" data-end="2470">A successful FIPS validation requires far more than completed documents. Every document must accurately reflect the implementation of the cryptographic module and align with the evidence generated throughout the validation process.</p>
<p data-start="2472" data-end="2538">Organizations should expect work across multiple areas, including:</p>
<ul data-start="2540" data-end="2883">
<li data-section-id="1aym2bo" data-start="2540" data-end="2599">Cryptographic module architecture and boundary definition</li>
<li data-section-id="13et2u6" data-start="2600" data-end="2635">Approved algorithm implementation</li>
<li data-section-id="vmj6su" data-start="2636" data-end="2662">Security function design</li>
<li data-section-id="1hxsla0" data-start="2663" data-end="2707">Role, service, and authentication analysis</li>
<li data-section-id="grt789" data-start="2708" data-end="2744">Self-tests and operational testing</li>
<li data-section-id="1uklys8" data-start="2745" data-end="2823">Documentation required by the Cryptographic Module Validation Program (CMVP)</li>
<li data-section-id="19op301" data-start="2824" data-end="2883">Independent testing performed by an accredited laboratory</li>
</ul>
<p data-start="2885" data-end="3395">Documentation ties these pieces together, but it cannot compensate for implementation gaps or design issues discovered during testing. If engineering decisions and documentation do not align, the validation process often slows as teams revisit product design, update documentation, or correct implementation issues. The overall process requires close collaboration between engineering, documentation, testing, and program management to keep the project moving swiftly.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1fy31xg" data-start="3402" data-end="3427">Why This Myth Persists</h3>
<p data-start="3429" data-end="3686">Documentation is often the most visible part of the validation process. Teams spend significant time preparing security policies, reviewing technical descriptions, and responding to documentation feedback, making it appear that paperwork drives the project.</p>
<p data-start="3688" data-end="3911">In reality, documentation reflects decisions that have already been made throughout product development. Every requirement documented must be supported by the module&#8217;s actual behavior and verified during laboratory testing.</p>
<p data-start="3913" data-end="4104">Organizations that wait until the documentation phase to identify design issues, frequently discover that changes are more expensive and time-consuming than if they had been addressed earlier.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1tfkyyq" data-start="4111" data-end="4131">A Better Approach</h3>
<p class="" data-start="4133" data-end="4278">The most successful FIPS projects treat documentation as one component of an integrated validation strategy—not the final task before submission.</p>
<p data-start="4280" data-end="4319">Planning early allows organizations to:</p>
<ul data-start="4321" data-end="4602">
<li data-section-id="lmsvt8" data-start="4321" data-end="4367">Define the cryptographic boundary correctly.</li>
<li data-section-id="138ey62" data-start="4368" data-end="4422">Identify design issues before formal testing begins.</li>
<li data-section-id="y39jib" data-start="4423" data-end="4481">Ensure documentation accurately reflects implementation.</li>
<li data-section-id="1hwqbmy" data-start="4482" data-end="4523">Reduce rework during laboratory review.</li>
<li data-section-id="1tdezcu" data-start="4524" data-end="4602">Keep engineering, testing, and documentation aligned throughout the project.</li>
</ul>
<p data-start="4604" data-end="4739">Approaching validation this way helps minimize delays while improving confidence that the module will successfully complete evaluation.</p>
<p data-start="4604" data-end="4739">Organizations that are unsure where to begin don&#8217;t have to navigate the process alone. Corsec&#8217;s <a href="https://www.corsec.com/fips-assessment/"><strong data-start="462" data-end="488">FIPS 140-3 Assessments</strong></a> help teams evaluate their current readiness, identify potential gaps early, and develop a practical path toward validation before formal testing begins.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="13dcvnv" data-start="4746" data-end="4762">Looking Ahead</h3>
<p data-start="4764" data-end="5113">Documentation is an essential part of every FIPS 140-3 validation, but it is only valuable when supported by sound engineering, accurate implementation, and successful testing. Viewing validation as a documentation-only effort can lead organizations to underestimate the technical work required and introduce unnecessary delays later in the project.</p>
<p data-start="5115" data-end="5198">In the next installment of this series, we&#8217;ll examine another common misconception:</p>
<p data-start="5200" data-end="5290"><strong data-start="5200" data-end="5290">Myth #4: Once a product is FIPS validated, it never needs to be updated or maintained.</strong></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/myth-3/">Deconstructing FIPS 140-3: Myth #3 &#8211; FIPS Validation Is Just a Documentation Exercise</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NVIDIA FIPS Validates H100 Tensor Core GPU</title>
		<link>https://www.corsec.com/nvidia-fips/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 19:26:59 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Secure Products]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22754</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/nvidia-fips/">NVIDIA FIPS Validates H100 Tensor Core GPU</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, NVIDIA Corporation, on completing the Federal Information Processing Standard Publication 140-3 (<span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span>) validation process on their H100 Tensor Core GPU. Completion of the FIPS 140-3 validation process provides reassurance and third-party confirmation that the product meets rigorous government security requirements for protecting sensitive data.</p>
<p>To achieve this benchmark, NVIDIA partnered with Corsec, completing the validation at a Level 2 as seen in certificate #<a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5446" target="_blank" rel="noopener">5446</a>. For more information on the validation and to find additional details on the module’s security policy, visit <a href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search" target="_blank" rel="noopener">NIST’s validated modules site</a>.</p>
<p>To learn how to engineer your product to meet federal and regulated industry requirements—and avoid common certification delays, <a href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About FIPS 140</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> are a joint effort by the National Institute of Standards and Technology (NIST) in the United States and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</p>
<p>FIPS 140 is mandated by law in the U.S. and very strictly enforced in Canada. FIPS 140 has gained worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140 validation of a product provides end users with a high degree of product security, assurance, and dependability.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5><strong>About the NVIDIA H100 Tensor Core GPU</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>H100 is part of the complete NVIDIA data center solution that incorporates building blocks across hardware, networking, software, libraries, and optimized AI models and applications from the NVIDIA NGC™ catalog. The second-generation Multi-Instance GPU (MIG), built-in NVIDIA confidential computing, and NVIDIA NVLink Switch System allows the H100 to securely accelerate workloads.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For over 28 years, Corsec has guided companies through complex security certifications, like <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and <strong><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">DoD STIG</a> / </span><a href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener"><span style="color: #3366ff;">DoDIN APL</span></a></strong>.</p>
<p>Corsec’s end-to-end approach helps organizations reduce risk, avoid certification delays, and accelerate time to market. From mobile devices to satellites, our expertise ensures a more predictable and efficient path to validation.</p>
</div>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/nvidia-fips/">NVIDIA FIPS Validates H100 Tensor Core GPU</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deconstructing FIPS 140-3: Myth #2 &#8211; FIPS Is Only Required for Federal Agencies</title>
		<link>https://www.corsec.com/fips-myth-2/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 13:52:34 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Government Compliance]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22712</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-myth-2/">Deconstructing FIPS 140-3: Myth #2 &#8211; FIPS Is Only Required for Federal Agencies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><span data-contrast="auto">In the <a href="https://www.corsec.com/fips-myths/" target="_blank" rel="noopener">first installment</a> of this series, we explored why incorporating a FIPS-validated cryptographic module into a product does not automatically make the product <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> validated. While understanding validation boundaries is critical, another common misconception often shapes organizations&#8217; decisions much earlier in the product lifecycle.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Many development teams assume FIPS 140-3 only matters if they plan to sell directly to the U.S. federal government. If federal contracts are not part of the business strategy, validation is often viewed as unnecessary.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">At first glance, this assumption seems reasonable. After all, FIPS standards are developed by the National Institute of Standards and Technology (NIST) for use by federal agencies. However, today&#8217;s cybersecurity landscape has significantly expanded the role of FIPS validation well beyond traditional government procurement.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Myth 2: &#8220;FIPS Is Only Required for Federal Agencies&#8221;</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p aria-level="3"><b><span data-contrast="none">Reality</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">While FIPS 140-3 originated as a federal security standard, its influence now extends across numerous commercial industries, regulated sectors, and global technology markets. Organizations pursuing FIPS validation are often motivated by customer requirements, contractual obligations, regulatory expectations, and competitive positioning and not by direct federal sales. Many organizations discover that FIPS validation becomes important because their customers expect it, their partners require it, or their industry recognizes it as an established benchmark for cryptographic assurance.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Why This Myth Exists</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">FIPS publications are issued by NIST, and federal agencies are required to use validated cryptography for protecting sensitive government information. Because of this, many organizations assume the standard applies exclusively to government systems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">However, cybersecurity expectations have evolved considerably. As cyber threats have become more sophisticated, many organizations have adopted established security frameworks originally developed for government use. FIPS validation has become one of the most widely recognized methods for demonstrating that cryptographic functionality has undergone independent testing and evaluation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Today, many procurement teams consider FIPS validation an indicator of security maturity rather than simply a government requirement.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Where FIPS Validation Is Commonly Requested</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">Organizations are often surprised by where FIPS validation appears during the sales process. Some examples include:</span></p>
<ul>
<li><span data-contrast="auto">Government contractors supporting federal programs,</span></li>
<li><span data-contrast="auto">State and local government projects,</span></li>
<li><span data-contrast="auto">Critical infrastructure providers,</span></li>
<li><span data-contrast="auto">Defense and aerospace organizations,</span></li>
<li><span data-contrast="auto">Healthcare technology vendors,</span></li>
<li><span data-contrast="auto">Financial services institutions,</span></li>
<li><span data-contrast="auto">Cloud service providers, and</span></li>
<li><span data-contrast="auto">Enterprise software vendors serving highly regulated industries.</span></li>
</ul>
<p><span data-contrast="auto">In many cases, customers include FIPS requirements in procurement documentation even when they are not federal agencies themselves. As a result, organizations that previously believed FIPS was irrelevant may suddenly discover validation has become a prerequisite for pursuing new business opportunities.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Beyond Compliance: Building Customer Confidence</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">Validation requires independent testing through the Cryptographic Module Validation Program (CMVP) and the result is it provides customers with greater confidence that the cryptographic implementation performs as intended and meets established security requirements.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">For many organizations, validation serves as an objective way to demonstrate their commitment to protecting sensitive information. This can help strengthen customer trust, reduce lengthy security questionnaire discussions, and support purchasing decisions where cryptographic assurance is an important evaluation criterion.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Planning Early Matters</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">One challenge organizations frequently encounter is waiting until late in product development before considering FIPS validation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">If validation requirements are introduced after product architecture has already been finalized, engineering teams may need to revisit cryptographic implementations, operational environments, documentation, or module boundaries.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Addressing these considerations early allows organizations to make informed architectural decisions, better estimate project timelines, and reduce the likelihood of costly rework later in the validation process.</span></p>
<p><strong>For help with planning and guidance, Corsec offers <span style="color: #339966;"><a style="color: #339966;" href="https://www.corsec.com/fips-assessment/" target="_blank" rel="noopener">FIPS 140-3 Assessments</a></span>. These engagements help clarify requirements, outline paths to validation, and give business leaders the information they need to make decisions on validation.</strong></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Looking Ahead</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">The next installment in this series examines another common misconception:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Myth #3: FIPS Validation Is Just a Documentation Exercise</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">While documentation is certainly an important part of the process, successful validation depends on much more than producing the required paperwork. We&#8217;ll explore why engineering decisions, implementation details, testing, and documentation all play equally important roles in achieving FIPS 140-3 validation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-myth-2/">Deconstructing FIPS 140-3: Myth #2 &#8211; FIPS Is Only Required for Federal Agencies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deconstructing FIPS 140-3: 5 Myths &#038; Realities</title>
		<link>https://www.corsec.com/fips-myths/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 12:56:00 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[FIPS Inside]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Federal Compliance]]></category>
		<category><![CDATA[FIPS Myths]]></category>
		<category><![CDATA[FIPS Validation]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22624</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-myths/">Deconstructing FIPS 140-3: 5 Myths &#038; Realities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="isSelectedEnd">For organizations developing products that rely on cryptography to protect sensitive information, <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> validation has become the benchmark for security compliance. Whether serving federal agencies, government contractors, critical infrastructure providers, or highly regulated industries, organizations often encounter FIPS 140-3 requirements as part of procurement, compliance, and security assurance efforts.</p>
<p class="isSelectedEnd">Despite its widespread recognition, FIPS 140-3 is frequently misunderstood. Teams may assume that using a validated cryptographic component automatically makes their product compliant. Product managers may view validation as a documentation exercise. Engineering teams may underestimate the technical meticulousness involved, while executives may question why validation is necessary at all.</p>
<p class="isSelectedEnd">These misconceptions can lead to delayed projects, unexpected costs, architectural rework, and missed market opportunities. More importantly, they can create a false sense of readiness when customers or procurement requirements demand validation.</p>
<p class="isSelectedEnd">This blog series, <em>Deconstructing FIPS 140-3: 5 Myths and Realities</em>, examines five common misconceptions that continue to shape how organizations approach cryptographic validation. We will explore how these assumptions affect product planning, development, compliance strategies, and go-to-market decisions.</p>
<p class="isSelectedEnd">We begin with one of the most common misconceptions in the industry which is confusing the use of validated cryptography with validation of the product itself.</p>
<h2><span style="color: #000000;">Myth 1: “FIPS Inside” Is the Same as Being FIPS 140-3 Validated</span></h2>
<p class="isSelectedEnd"><strong>Reality:</strong> Incorporating a FIPS-validated cryptographic module into a product does not automatically make the product FIPS 140-3 validated.</p>
<p class="isSelectedEnd">Organizations frequently advertise that their solution contains or utilizes validated cryptography. While this may be technically accurate, FIPS validation applies to the specific cryptographic module that underwent testing and validation through the Cryptographic Module Validation Program (CMVP). Simply inserting that module does not transfer validation status to the broader product.</p>
<p class="isSelectedEnd">Depending on how the cryptographic module is integrated, configured, and exposed to users, additional evaluation activities may be required to demonstrate adherence with FIPS requirements. Organizations must carefully understand the validation boundary, operational environment, and implementation details to accurately represent their security posture.</p>
<p class="isSelectedEnd">Confusing &#8220;FIPS Inside&#8221; with FIPS validation can create challenges during procurement reviews, customer assessments, and certification planning efforts. Understanding this distinction early helps organizations avoid costly misunderstandings and better prepare for validation activities.</p>
<p><strong>For more information on FIPS Inside, <span style="color: #008000;"><a style="color: #008000;" href="https://ww3.corsec.com/FIPS-Validated-vs-Inside" target="_blank" rel="noopener">download an in depth overview on the topic</a></span>.</strong></p>
<hr />
<h2><span style="color: #000000;">Upcoming Myths in This Series</span></h2>
<p class="isSelectedEnd">In the remaining posts, we will examine four additional myths that continue to influence FIPS validation strategies:</p>
<p class="isSelectedEnd"><strong>Myth 2:</strong> FIPS Is Only Required for Federal Agencies</p>
<p class="isSelectedEnd"><strong>Myth 3:</strong> FIPS Validation Is Just a Documentation Exercise</p>
<p class="isSelectedEnd"><strong>Myth 4:</strong> Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</p>
<p class="isSelectedEnd"><strong>Myth 5:</strong> The Cost and Timeline of FIPS Validation Aren&#8217;t Justified</p>
<p class="isSelectedEnd">Each of these assumptions fail to capture the full reality of today&#8217;s validation landscape. Left unchallenged, they can influence decisions that impact product architecture, project timelines, security adherence, product readiness, and market access. Throughout this series, we will break down each myth, explain the underlying realities, and highlight practical considerations organizations should evaluate when developing a FIPS 140-3 validation strategy.</p>
<p class="isSelectedEnd">Successfully navigating FIPS 140-3 requires more than simply understanding the standard. It often demands early coordination across engineering, product management, compliance, and certification stakeholders. Organizations that align validation requirements with product development activities from the start are typically better positioned to avoid rework, reduce risk, and achieve validation more efficiently.</p>
<p class="isSelectedEnd"><strong>Corsec supports organizations throughout the FIPS 140-3 lifecycle from architectural reviews and validation planning to documentation development, laboratory coordination, testing support, and CMVP submission activities. If FIPS 140-3 validation is part of your action plan or becoming a requirement for your customers and target markets—engaging early can help establish a clear path forward. <span style="color: #008000;"><a style="color: #008000;" href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener">Contact Corsec</a></span> to learn how your organization can approach FIPS 140-3 validation with confidence and ease.</strong></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-myths/">Deconstructing FIPS 140-3: 5 Myths &#038; Realities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wind River Completes FIPS 140-3 Validation with Corsec</title>
		<link>https://www.corsec.com/wind-river-fips-object-module/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Sun, 12 Jul 2026 19:57:49 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[Secure Products]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22726</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/wind-river-fips-object-module/">Wind River Completes FIPS 140-3 Validation with Corsec</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, Wind River Systems, Inc., on completing the Federal Information Processing Standard Publication 140-3 (<span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span>) validation process on their Wind River FIPS Object Module. Completion of the FIPS 140-3 validation process provides reassurance and third-party confirmation that the product meets rigorous government security requirements for protecting sensitive data.</p>
<p>To achieve this benchmark, Wind River partnered with Corsec, completing the validation at a Level 1 as seen in certificate <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5396" target="_blank" rel="noopener">#5396</a>. For more information on the validation and to find additional details on the module’s security policy, visit <a href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search" target="_blank" rel="noopener">NIST’s validated modules site</a>.</p>
<p>To learn how to engineer your product to meet federal and regulated industry requirements—and avoid common certification delays, <a href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About FIPS 140</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> are a joint effort by the National Institute of Standards and Technology (NIST) in the United States and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</p>
<p>FIPS 140 is mandated by law in the U.S. and very strictly enforced in Canada. FIPS 140 has gained worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140 validation of a product provides end users with a high degree of product security, assurance, and dependability.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5><strong>About the Wind River FIPS Object Module</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>The Wind River FIPS Object Module is a general-purpose software cryptographic library offering symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions.</p>
<p>It is designed for ease of use with the popular OpenSSL cryptographic library and toolkit and is available for use as part of Wind River’s platforms.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For over 28 years, Corsec has guided companies through complex security certifications, like <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and <strong><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">DoD STIG</a> / </span><a href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener"><span style="color: #3366ff;">DoDIN APL</span></a></strong>.</p>
<p>Corsec’s end-to-end approach helps organizations reduce risk, avoid certification delays, and accelerate time to market. From mobile devices to satellites, our expertise ensures a more predictable and efficient path to validation.</p>
</div>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/wind-river-fips-object-module/">Wind River Completes FIPS 140-3 Validation with Corsec</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Sunhillo Completes FIPS 140-3 Validation</title>
		<link>https://www.corsec.com/sunhillo-fips-2/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Sun, 12 Jul 2026 19:46:47 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Secure Products]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22720</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/sunhillo-fips-2/">Sunhillo Completes FIPS 140-3 Validation</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, Sunhillo Corporation, on completing the Federal Information Processing Standard Publication 140-3 (<span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span>) validation process on their Sunhillo Cryptographic Module. Completion of the FIPS 140-3 validation process provides reassurance and third-party confirmation that the product meets rigorous government security requirements for protecting sensitive data.</p>
<p>To achieve this benchmark, Sunhillo partnered with Corsec, completing the validation at a Level 1 as seen in certificate <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5394" target="_blank" rel="noopener">#5394</a>. For more information on the validation and to find additional details on the module’s security policy, visit <a href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search" target="_blank" rel="noopener">NIST’s validated modules site</a>.</p>
<p>To learn how to engineer your product to meet federal and regulated industry requirements—and avoid common certification delays, <a href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About FIPS 140</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> are a joint effort by the National Institute of Standards and Technology (NIST) in the United States and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</p>
<p>FIPS 140 is mandated by law in the U.S. and very strictly enforced in Canada. FIPS 140 has gained worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140 validation of a product provides end users with a high degree of product security, assurance, and dependability.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5><strong>About the Sunhillo Cryptographic Module</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>The Sunhillo Cryptographic Module 1.1.1zd.001 is a cryptographic library embedded in the Sunhillo SureLine OS and SureSentry application software. The Sunhillo Cryptographic Module 1.1.1zd.001 offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, and message authentication; support for key establishment functions to secure data-at-rest and data-in-flight; and support for secure communications protocols (including TLS 1.2 and 1.3).</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For over 28 years, Corsec has guided companies through complex security certifications, like <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and <strong><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">DoD STIG</a> / </span><a href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener"><span style="color: #3366ff;">DoDIN APL</span></a></strong>.</p>
<p>Corsec’s end-to-end approach helps organizations reduce risk, avoid certification delays, and accelerate time to market. From mobile devices to satellites, our expertise ensures a more predictable and efficient path to validation.</p>
</div>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/sunhillo-fips-2/">Sunhillo Completes FIPS 140-3 Validation</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FIPS 140-3 Validated: Citrix (CSG) NetScaler VPX Product</title>
		<link>https://www.corsec.com/fips-csg-vpx/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 19:45:31 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Secure Products]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22717</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-csg-vpx/">FIPS 140-3 Validated: Citrix (CSG) NetScaler VPX Product</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, Citrix (Cloud Software Group), on completing the Federal Information Processing Standard Publication 140-3 (<span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span>) validation process on their NetScaler VPX product. Completion of the FIPS 140-3 validation process provides reassurance and third-party confirmation that the product meets rigorous government security requirements for protecting sensitive data.</p>
<p>To achieve this benchmark, Citrix partnered with Corsec, completing the validation at a Level 1 as seen in certificate #<a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5391" target="_blank" rel="noopener">5391</a>. For more information on the validation and to find additional details on the module’s security policy, visit <a href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search" target="_blank" rel="noopener">NIST’s validated modules site</a>.</p>
<p>To learn how to engineer your product to meet federal and regulated industry requirements—and avoid common certification delays, <a href="https://www.corsec.com/contact-us/" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About FIPS 140</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> are a joint effort by the National Institute of Standards and Technology (NIST) in the United States and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</p>
<p>FIPS 140 is mandated by law in the U.S. and very strictly enforced in Canada. FIPS 140 has gained worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140 validation of a product provides end users with a high degree of product security, assurance, and dependability.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5><strong>About the Citrix NetScaler VPX Product</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>The NetScaler product line optimizes delivery of applications over the Internet and private networks. It is an Application Delivery Controller (ADC) that performs application-specific traffic analysis to intelligently distribute, optimize, and secure L4-L7 network traffic for web-applications. All these capabilities are combined into a single, integrated appliance for increased productivity, with lower overall total cost of ownership.</p>
<p>The NetScaler VPX is a virtual appliance consisting of a control plane processing function (providing all configuration and management processing functions) and multiple data planes which provide data packet processing functions. All configuration and management activities are performed via the web-based GUI, RESTful Nitro API, and CLI interfaces. The GUI includes a configuration utility for configuring the appliance as well as a statistical utility called Dashboard.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For over 28 years, Corsec has guided companies through complex security certifications, like <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and <strong><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">DoD STIG</a> / </span><a href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener"><span style="color: #3366ff;">DoDIN APL</span></a></strong>.</p>
<p>Corsec’s end-to-end approach helps organizations reduce risk, avoid certification delays, and accelerate time to market. From mobile devices to satellites, our expertise ensures a more predictable and efficient path to validation.</p>
</div>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-csg-vpx/">FIPS 140-3 Validated: Citrix (CSG) NetScaler VPX Product</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deconstructing Common Criteria: Lessons Learned</title>
		<link>https://www.corsec.com/cc-myths-lessons-learned/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:16:03 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[EUCC]]></category>
		<category><![CDATA[IT compliance]]></category>
		<category><![CDATA[product certification]]></category>
		<category><![CDATA[security assurance]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22592</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/cc-myths-lessons-learned/">Deconstructing Common Criteria: Lessons Learned</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>Throughout this series, we explored some of the most common misconceptions surrounding <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener">Common Criteria</a></span> certification which included assumptions about cost, timelines, to misunderstandings about maintenance and global recognition. While each myth addressed a different aspect of the process, together they reveal a larger truth: organizations that approach certification strategically are often far more successful than those reacting to misconceptions or incomplete information.</p>
<p data-start="525" data-end="1064">For many organizations, Common Criteria can initially appear overwhelming. The certification process is often associated with long timelines, extensive documentation requirements, and complex technical expectations. In many cases, these perceptions are shaped by secondhand experiences, outdated assumptions, or a lack of visibility into how evaluations actually work. As a result, organizations may delay pursuing certification, underestimate the preparation involved, or assume the process only applies to a narrow segment of the market.</p>
<p data-start="525" data-end="1064">However, Common Criteria certification is not designed to be an obstacle. At its core, it is a structured framework for validating security functionality and assurance activities in a consistent, internationally recognized way. Organizations that take the time to understand the process, define realistic goals, and plan strategically are often able to navigate evaluations more efficiently than expected.</p>
<p>While each myth focused on a specific concern, the broader takeaway remained consistent: successful certification efforts are often shaped by preparation, collaboration, and long-term planning. As we conclude the series, it is worth revisiting the key lessons organizations should understand when approaching Common Criteria evaluations.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p data-start="1449" data-end="1741" data-is-last-node="" data-is-only-node=""><span style="color: #ff6600;"><strong>To help organizations navigate Common Criteria Myths, Corsec has developed a document which outlines these 5 myths and an addition 5 that Corsec has identified over the years. </strong></span><em><strong><a href="https://ww3.corsec.com/myths-common-criteria" target="_blank" rel="noopener">Learn More</a></strong></em></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 data-start="2608" data-end="2759">Lessons from Myths 1 &#8211; 5</h3>
<p data-start="27" data-end="374">Across the series, we examined several common misconceptions., we examined several common misconceptions surrounding Common Criteria certification. From assumptions about who certification applies to, to misunderstandings about cost, maintenance, and global recognition, each myth highlighted an important reality that organizations should understand before beginning the evaluation process.</p>
<ul data-start="376" data-end="1447">
<li data-section-id="kr7d9" data-start="376" data-end="574"><strong data-start="378" data-end="389"><a href="https://www.corsec.com/cc-myths/" target="_blank" rel="noopener">Myth 1</a>:</strong> Common Criteria is not limited to government vendors. Certification can also support commercial market differentiation, customer trust, and procurement opportunities across industries.</li>
<li data-section-id="7yripg" data-start="576" data-end="814"><strong data-start="578" data-end="589"><a href="https://www.corsec.com/myths2/" target="_blank" rel="noopener">Myth 2</a>:</strong> While evaluations require time and resources, successful certification can present immediate ROI.</li>
<li data-section-id="1vbjdma" data-start="816" data-end="1022"><strong data-start="818" data-end="829"><a href="https://www.corsec.com/deconstructing-common-criteria-myth-3/" target="_blank" rel="noopener">Myth 3</a>:</strong> There is more than one way to navigate Common Criteria.</li>
<li data-section-id="1jbly7v" data-start="1024" data-end="1218"><strong data-start="1026" data-end="1037"><a href="https://www.corsec.com/common-criteria-myth-4/" target="_blank" rel="noopener">Myth 4</a>:</strong> An active Common Criteria Certification is a requirement in government and highly regulated industries.</li>
<li data-section-id="11rl8b7" data-start="1220" data-end="1447"><strong data-start="1222" data-end="1233"><a href="https://www.corsec.com/common-criteria-myth-5/" target="_blank" rel="noopener">Myth 5</a>:</strong> Common Criteria and the EUCC are tied to one another, not independent certifications.</li>
</ul>
<p data-start="10578" data-end="10907">Common Criteria certification is frequently misunderstood because organizations often encounter it only when a procurement requirement, customer request, or market opportunity suddenly makes certification necessary. Without context or prior experience, the process can appear more intimidating or restrictive than it actually is.</p>
<p>Many of the perceived barriers surrounding Common Criteria are rooted more in misconceptions than reality. Certification is not limited to government vendors, it is not exclusively relevant to Europe, and it is not simply a one-time technical checkbox. Instead, Common Criteria provides a consistent and globally recognized approach for demonstrating security assurance.</p>
<p>Organizations that approach evaluations strategically — with realistic expectations, strong internal collaboration, and long-term planning — are often far better positioned for successful outcomes. Many organizations also benefit from working with experienced evaluation partners who understand the complexities of the Common Criteria process. Structured guidance and evaluation support can help teams streamline preparation efforts, improve readiness, and avoid common pitfalls throughout the certification journey.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For 28+ years Corsec<strong> </strong>has guided companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and the <span style="color: #0000ff;"><strong>DoD (<a style="color: #0000ff;" href="https://www.corsec.com/stig/" target="_blank" rel="noopener">STIGs</a>, <a style="color: #0000ff;" href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener">DoDIN APL, UC APL</a>)</strong></span>. From mobile devices to satellites, Corsec helps companies reduce validation risk, shorten timelines, and expand into regulated markets.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h5>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Head of Marketing &amp; BD<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/cc-myths-lessons-learned/">Deconstructing Common Criteria: Lessons Learned</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
