Organizations that already have a FIPS 140-2 validation may assume that their work is finished. After all, the product already went through a formal validation process, so why would another validation be necessary?
The answer is that FIPS 140-2 and FIPS 140-3 are different standards. FIPS 140-3 replaced FIPS 140-2 as the current standard for new validations and introduced updated requirements for evaluating cryptographic modules. With that and the looming FIPS 140-2 sunset date approaching, all vendors considering an approach for FIPS 140 will need to validate to the newest version of the publication.
This post is the fourth installment in our Deconstructing FIPS 140-3: 5 Myths and Realities series, where we examine common misconceptions surrounding FIPS validation and explain what organizations should understand before beginning the certification process.
Myth #4:
“Our product has a FIPS 140-2 validation, so we don’t need FIPS 140-3.”
At first glance, this assumption seems reasonable. If a product has already completed FIPS validation, it can be easy to think that the existing validation automatically carries over to the newer standard.
Reality:
A FIPS 140-2 validation does not automatically make a product FIPS 140-3 validated.
FIPS 140-2 was the standard used to validate cryptographic modules for many years. FIPS 140-3 is its successor and was developed to update the requirements and align the U.S. standard more closely with international standards.
While FIPS 140-3 builds on many of the concepts found in FIPS 140-2, it also includes updated requirements and changes to how cryptographic modules are evaluated. FIPS 140-2 and even FIPS 140-3 validations have a sunset date, traditionally 5 years. However, all remaining FIPS 140-2 validations will be automatically sunset on Sept. 21, 2026.
For vendors selling into the U.S. federal government, the CMVP states that all modules with a status designation of Historical “should not be included by Federal Agencies in new procurements.”
If an organization has already invested significant time and resources into obtaining a FIPS 140-2 validation, it is understandable to assume that the existing validation should be sufficient for the newer standard. However, a FIPS 140-2 certificate does not simply become a FIPS 140-3 certificate. The two standards have different requirements, and organizations need to understand what their existing validation means and what requirements apply to their specific product and use case.
Validation & Boundaries
If an organization has already invested significant time and resources into obtaining a FIPS 140-2 validation, it is understandable to assume that the existing validation should be sufficient for the newer standard. However, a FIPS 140-2 certificate does not simply become a FIPS 140-3 certificate. The two standards have different requirements, and organizations need to understand what their existing validation means and what requirements apply to their specific product and use case.
Another important consideration is that FIPS validation applies to a specific cryptographic module and its defined configuration. It is not a blanket certification that automatically covers every version or configuration of a product.
This means that when a product is updated or a new version is released, organizations need to understand whether those changes affect the scope of the existing validation. The fact that an earlier version was validated does not necessarily mean that a newer version has the same validation status.
Moving From One Standard to the Next
For organizations with an existing FIPS 140-2 validation, the transition to FIPS 140-3 does not necessarily mean starting from scratch. The existing validation can provide a useful foundation for understanding what may need to change.
Planning early can help organizations identify differences between their current FIPS 140-2 validation and the requirements of FIPS 140-3. This can help teams anticipate potential design, documentation, and testing impacts before beginning a new validation effort.
The Takeaway
Having a FIPS 140-2 validation is valuable, but it should not be confused with having a FIPS 140-3 validation. As organizations plan new products, product updates, or future validation efforts, understanding the differences between the two standards is an important first step.
FIPS validation is not simply a label that applies to every version of a product. The applicable standard, validated module, configuration, and current requirements all matter.
Understanding where your product stands today can help ensure that your next step is the right one.
