<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cryptography Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/tag/cryptography/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/tag/cryptography/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Thu, 30 Jul 2026 19:09:26 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Cryptography Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/tag/cryptography/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Deconstructing FIPS 140-3: Myth #3 &#8211; FIPS Validation Is Just a Documentation Exercise</title>
		<link>https://www.corsec.com/myth-3/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 19:09:13 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[FIPS Validation]]></category>
		<category><![CDATA[Security Testing]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22745</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/myth-3/">Deconstructing FIPS 140-3: Myth #3 &#8211; FIPS Validation Is Just a Documentation Exercise</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="PDq2pG_selectionAnchorContainer" data-start="855" data-end="1116">By the time organizations begin planning for <span data-contrast="auto"><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></span> validation, they usually understand that documentation is required. Security policies, design documentation, finite state models, and other artifacts are all necessary components of the validation package.</p>
<p data-start="1118" data-end="1415">Because of the volume of required documentation, it&#8217;s easy to assume that FIPS validation is primarily an exercise in writing documents. In reality, documentation is only one part of a much broader process that evaluates how a cryptographic module is designed, implemented, tested, and maintained.</p>
<p data-start="1417" data-end="1679">This post is the third installment in our <a href="https://www.corsec.com/fips-myths/"><strong data-start="1459" data-end="1511">Deconstructing FIPS 140-3: 5 Myths and Realities</strong></a> series, where we examine common misconceptions surrounding FIPS validation and explain what organizations should understand before beginning the certification process.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1rcsd1j" data-start="1686" data-end="1697">Myth #3:</h3>
<h3 data-section-id="12e5cy0" data-start="1698" data-end="1753">&#8220;FIPS validation is just a documentation exercise.&#8221;</h3>
<p data-start="1755" data-end="1945">At first glance, this assumption seems reasonable. Organizations often see the extensive list of required documents and conclude that success depends primarily on producing enough paperwork.</p>
<p data-start="1947" data-end="2125">While documentation is essential, it exists to support something much larger such as demonstrating that a cryptographic module satisfies the security requirements defined by FIPS 140-3.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1gwrx5t" data-start="2132" data-end="2143">Reality:</h3>
<h3 data-section-id="20ycmf" data-start="2144" data-end="2237">Documentation supports validation but it doesn&#8217;t replace engineering, testing, or compliance.</h3>
<p data-start="2239" data-end="2470">A successful FIPS validation requires far more than completed documents. Every document must accurately reflect the implementation of the cryptographic module and align with the evidence generated throughout the validation process.</p>
<p data-start="2472" data-end="2538">Organizations should expect work across multiple areas, including:</p>
<ul data-start="2540" data-end="2883">
<li data-section-id="1aym2bo" data-start="2540" data-end="2599">Cryptographic module architecture and boundary definition</li>
<li data-section-id="13et2u6" data-start="2600" data-end="2635">Approved algorithm implementation</li>
<li data-section-id="vmj6su" data-start="2636" data-end="2662">Security function design</li>
<li data-section-id="1hxsla0" data-start="2663" data-end="2707">Role, service, and authentication analysis</li>
<li data-section-id="grt789" data-start="2708" data-end="2744">Self-tests and operational testing</li>
<li data-section-id="1uklys8" data-start="2745" data-end="2823">Documentation required by the Cryptographic Module Validation Program (CMVP)</li>
<li data-section-id="19op301" data-start="2824" data-end="2883">Independent testing performed by an accredited laboratory</li>
</ul>
<p data-start="2885" data-end="3395">Documentation ties these pieces together, but it cannot compensate for implementation gaps or design issues discovered during testing. If engineering decisions and documentation do not align, the validation process often slows as teams revisit product design, update documentation, or correct implementation issues. The overall process requires close collaboration between engineering, documentation, testing, and program management to keep the project moving swiftly.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1fy31xg" data-start="3402" data-end="3427">Why This Myth Persists</h3>
<p data-start="3429" data-end="3686">Documentation is often the most visible part of the validation process. Teams spend significant time preparing security policies, reviewing technical descriptions, and responding to documentation feedback, making it appear that paperwork drives the project.</p>
<p data-start="3688" data-end="3911">In reality, documentation reflects decisions that have already been made throughout product development. Every requirement documented must be supported by the module&#8217;s actual behavior and verified during laboratory testing.</p>
<p data-start="3913" data-end="4104">Organizations that wait until the documentation phase to identify design issues, frequently discover that changes are more expensive and time-consuming than if they had been addressed earlier.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="1tfkyyq" data-start="4111" data-end="4131">A Better Approach</h3>
<p class="" data-start="4133" data-end="4278">The most successful FIPS projects treat documentation as one component of an integrated validation strategy—not the final task before submission.</p>
<p data-start="4280" data-end="4319">Planning early allows organizations to:</p>
<ul data-start="4321" data-end="4602">
<li data-section-id="lmsvt8" data-start="4321" data-end="4367">Define the cryptographic boundary correctly.</li>
<li data-section-id="138ey62" data-start="4368" data-end="4422">Identify design issues before formal testing begins.</li>
<li data-section-id="y39jib" data-start="4423" data-end="4481">Ensure documentation accurately reflects implementation.</li>
<li data-section-id="1hwqbmy" data-start="4482" data-end="4523">Reduce rework during laboratory review.</li>
<li data-section-id="1tdezcu" data-start="4524" data-end="4602">Keep engineering, testing, and documentation aligned throughout the project.</li>
</ul>
<p data-start="4604" data-end="4739">Approaching validation this way helps minimize delays while improving confidence that the module will successfully complete evaluation.</p>
<p data-start="4604" data-end="4739">Organizations that are unsure where to begin don&#8217;t have to navigate the process alone. Corsec&#8217;s <a href="https://www.corsec.com/fips-assessment/"><strong data-start="462" data-end="488">FIPS 140-3 Assessments</strong></a> help teams evaluate their current readiness, identify potential gaps early, and develop a practical path toward validation before formal testing begins.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3 class="PDq2pG_selectionAnchorContainer" data-section-id="13dcvnv" data-start="4746" data-end="4762">Looking Ahead</h3>
<p data-start="4764" data-end="5113">Documentation is an essential part of every FIPS 140-3 validation, but it is only valuable when supported by sound engineering, accurate implementation, and successful testing. Viewing validation as a documentation-only effort can lead organizations to underestimate the technical work required and introduce unnecessary delays later in the project.</p>
<p data-start="5115" data-end="5198">In the next installment of this series, we&#8217;ll examine another common misconception:</p>
<p data-start="5200" data-end="5290"><strong data-start="5200" data-end="5290">Myth #4: Once a product is FIPS validated, it never needs to be updated or maintained.</strong></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/myth-3/">Deconstructing FIPS 140-3: Myth #3 &#8211; FIPS Validation Is Just a Documentation Exercise</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deconstructing FIPS 140-3: Myth #2 &#8211; FIPS Is Only Required for Federal Agencies</title>
		<link>https://www.corsec.com/fips-myth-2/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 13:52:34 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Government Compliance]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22712</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-myth-2/">Deconstructing FIPS 140-3: Myth #2 &#8211; FIPS Is Only Required for Federal Agencies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><span data-contrast="auto">In the <a href="https://www.corsec.com/fips-myths/" target="_blank" rel="noopener">first installment</a> of this series, we explored why incorporating a FIPS-validated cryptographic module into a product does not automatically make the product <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> validated. While understanding validation boundaries is critical, another common misconception often shapes organizations&#8217; decisions much earlier in the product lifecycle.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Many development teams assume FIPS 140-3 only matters if they plan to sell directly to the U.S. federal government. If federal contracts are not part of the business strategy, validation is often viewed as unnecessary.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">At first glance, this assumption seems reasonable. After all, FIPS standards are developed by the National Institute of Standards and Technology (NIST) for use by federal agencies. However, today&#8217;s cybersecurity landscape has significantly expanded the role of FIPS validation well beyond traditional government procurement.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Myth 2: &#8220;FIPS Is Only Required for Federal Agencies&#8221;</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p aria-level="3"><b><span data-contrast="none">Reality</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:281,&quot;335559739&quot;:281}"> </span></p>
<p><span data-contrast="auto">While FIPS 140-3 originated as a federal security standard, its influence now extends across numerous commercial industries, regulated sectors, and global technology markets. Organizations pursuing FIPS validation are often motivated by customer requirements, contractual obligations, regulatory expectations, and competitive positioning and not by direct federal sales. Many organizations discover that FIPS validation becomes important because their customers expect it, their partners require it, or their industry recognizes it as an established benchmark for cryptographic assurance.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Why This Myth Exists</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">FIPS publications are issued by NIST, and federal agencies are required to use validated cryptography for protecting sensitive government information. Because of this, many organizations assume the standard applies exclusively to government systems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">However, cybersecurity expectations have evolved considerably. As cyber threats have become more sophisticated, many organizations have adopted established security frameworks originally developed for government use. FIPS validation has become one of the most widely recognized methods for demonstrating that cryptographic functionality has undergone independent testing and evaluation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Today, many procurement teams consider FIPS validation an indicator of security maturity rather than simply a government requirement.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Where FIPS Validation Is Commonly Requested</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">Organizations are often surprised by where FIPS validation appears during the sales process. Some examples include:</span></p>
<ul>
<li><span data-contrast="auto">Government contractors supporting federal programs,</span></li>
<li><span data-contrast="auto">State and local government projects,</span></li>
<li><span data-contrast="auto">Critical infrastructure providers,</span></li>
<li><span data-contrast="auto">Defense and aerospace organizations,</span></li>
<li><span data-contrast="auto">Healthcare technology vendors,</span></li>
<li><span data-contrast="auto">Financial services institutions,</span></li>
<li><span data-contrast="auto">Cloud service providers, and</span></li>
<li><span data-contrast="auto">Enterprise software vendors serving highly regulated industries.</span></li>
</ul>
<p><span data-contrast="auto">In many cases, customers include FIPS requirements in procurement documentation even when they are not federal agencies themselves. As a result, organizations that previously believed FIPS was irrelevant may suddenly discover validation has become a prerequisite for pursuing new business opportunities.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Beyond Compliance: Building Customer Confidence</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">Validation requires independent testing through the Cryptographic Module Validation Program (CMVP) and the result is it provides customers with greater confidence that the cryptographic implementation performs as intended and meets established security requirements.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">For many organizations, validation serves as an objective way to demonstrate their commitment to protecting sensitive information. This can help strengthen customer trust, reduce lengthy security questionnaire discussions, and support purchasing decisions where cryptographic assurance is an important evaluation criterion.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Planning Early Matters</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">One challenge organizations frequently encounter is waiting until late in product development before considering FIPS validation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">If validation requirements are introduced after product architecture has already been finalized, engineering teams may need to revisit cryptographic implementations, operational environments, documentation, or module boundaries.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Addressing these considerations early allows organizations to make informed architectural decisions, better estimate project timelines, and reduce the likelihood of costly rework later in the validation process.</span></p>
<p><strong>For help with planning and guidance, Corsec offers <span style="color: #339966;"><a style="color: #339966;" href="https://www.corsec.com/fips-assessment/" target="_blank" rel="noopener">FIPS 140-3 Assessments</a></span>. These engagements help clarify requirements, outline paths to validation, and give business leaders the information they need to make decisions on validation.</strong></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p aria-level="2"><b><span data-contrast="none">Looking Ahead</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></p>
<p><span data-contrast="auto">The next installment in this series examines another common misconception:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Myth #3: FIPS Validation Is Just a Documentation Exercise</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">While documentation is certainly an important part of the process, successful validation depends on much more than producing the required paperwork. We&#8217;ll explore why engineering decisions, implementation details, testing, and documentation all play equally important roles in achieving FIPS 140-3 validation.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-myth-2/">Deconstructing FIPS 140-3: Myth #2 &#8211; FIPS Is Only Required for Federal Agencies</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deconstructing FIPS 140-3: 5 Myths &#038; Realities</title>
		<link>https://www.corsec.com/fips-myths/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 12:56:00 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[FIPS Inside]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Federal Compliance]]></category>
		<category><![CDATA[FIPS Myths]]></category>
		<category><![CDATA[FIPS Validation]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22624</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-myths/">Deconstructing FIPS 140-3: 5 Myths &#038; Realities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="isSelectedEnd">For organizations developing products that rely on cryptography to protect sensitive information, <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> validation has become the benchmark for security compliance. Whether serving federal agencies, government contractors, critical infrastructure providers, or highly regulated industries, organizations often encounter FIPS 140-3 requirements as part of procurement, compliance, and security assurance efforts.</p>
<p class="isSelectedEnd">Despite its widespread recognition, FIPS 140-3 is frequently misunderstood. Teams may assume that using a validated cryptographic component automatically makes their product compliant. Product managers may view validation as a documentation exercise. Engineering teams may underestimate the technical meticulousness involved, while executives may question why validation is necessary at all.</p>
<p class="isSelectedEnd">These misconceptions can lead to delayed projects, unexpected costs, architectural rework, and missed market opportunities. More importantly, they can create a false sense of readiness when customers or procurement requirements demand validation.</p>
<p class="isSelectedEnd">This blog series, <em>Deconstructing FIPS 140-3: 5 Myths and Realities</em>, examines five common misconceptions that continue to shape how organizations approach cryptographic validation. We will explore how these assumptions affect product planning, development, compliance strategies, and go-to-market decisions.</p>
<p class="isSelectedEnd">We begin with one of the most common misconceptions in the industry which is confusing the use of validated cryptography with validation of the product itself.</p>
<h2><span style="color: #000000;">Myth 1: “FIPS Inside” Is the Same as Being FIPS 140-3 Validated</span></h2>
<p class="isSelectedEnd"><strong>Reality:</strong> Incorporating a FIPS-validated cryptographic module into a product does not automatically make the product FIPS 140-3 validated.</p>
<p class="isSelectedEnd">Organizations frequently advertise that their solution contains or utilizes validated cryptography. While this may be technically accurate, FIPS validation applies to the specific cryptographic module that underwent testing and validation through the Cryptographic Module Validation Program (CMVP). Simply inserting that module does not transfer validation status to the broader product.</p>
<p class="isSelectedEnd">Depending on how the cryptographic module is integrated, configured, and exposed to users, additional evaluation activities may be required to demonstrate adherence with FIPS requirements. Organizations must carefully understand the validation boundary, operational environment, and implementation details to accurately represent their security posture.</p>
<p class="isSelectedEnd">Confusing &#8220;FIPS Inside&#8221; with FIPS validation can create challenges during procurement reviews, customer assessments, and certification planning efforts. Understanding this distinction early helps organizations avoid costly misunderstandings and better prepare for validation activities.</p>
<p><strong>For more information on FIPS Inside, <span style="color: #008000;"><a style="color: #008000;" href="https://ww3.corsec.com/FIPS-Validated-vs-Inside" target="_blank" rel="noopener">download an in depth overview on the topic</a></span>.</strong></p>
<hr />
<h2><span style="color: #000000;">Upcoming Myths in This Series</span></h2>
<p class="isSelectedEnd">In the remaining posts, we will examine four additional myths that continue to influence FIPS validation strategies:</p>
<p class="isSelectedEnd"><strong>Myth 2:</strong> FIPS Is Only Required for Federal Agencies</p>
<p class="isSelectedEnd"><strong>Myth 3:</strong> FIPS Validation Is Just a Documentation Exercise</p>
<p class="isSelectedEnd"><strong>Myth 4:</strong> Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</p>
<p class="isSelectedEnd"><strong>Myth 5:</strong> The Cost and Timeline of FIPS Validation Aren&#8217;t Justified</p>
<p class="isSelectedEnd">Each of these assumptions fail to capture the full reality of today&#8217;s validation landscape. Left unchallenged, they can influence decisions that impact product architecture, project timelines, security adherence, product readiness, and market access. Throughout this series, we will break down each myth, explain the underlying realities, and highlight practical considerations organizations should evaluate when developing a FIPS 140-3 validation strategy.</p>
<p class="isSelectedEnd">Successfully navigating FIPS 140-3 requires more than simply understanding the standard. It often demands early coordination across engineering, product management, compliance, and certification stakeholders. Organizations that align validation requirements with product development activities from the start are typically better positioned to avoid rework, reduce risk, and achieve validation more efficiently.</p>
<p class="isSelectedEnd"><strong>Corsec supports organizations throughout the FIPS 140-3 lifecycle from architectural reviews and validation planning to documentation development, laboratory coordination, testing support, and CMVP submission activities. If FIPS 140-3 validation is part of your action plan or becoming a requirement for your customers and target markets—engaging early can help establish a clear path forward. <span style="color: #008000;"><a style="color: #008000;" href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener">Contact Corsec</a></span> to learn how your organization can approach FIPS 140-3 validation with confidence and ease.</strong></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-myths/">Deconstructing FIPS 140-3: 5 Myths &#038; Realities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cradlepoint Kernel FIPS 140-3 Validated</title>
		<link>https://www.corsec.com/cradlepoint-fips/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 05 Nov 2024 16:32:41 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[CSEC]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Secure Products]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=21009</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/cradlepoint-fips/">Cradlepoint Kernel FIPS 140-3 Validated</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, Cradlepoint, Inc., on completing the Federal Information Processing Standard Publication 140-3 (<span style="color: #339966;"><a style="color: #339966;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span>) validation process on their Kernel Cryptographic Module.</p>
<p>To achieve this milestone, Cradlepoint partnered with Corsec, completing the validation at a Level 1 as seen in certificate <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4863" target="_blank" rel="noopener">#4863</a>. For more information on the validation and to find additional details on the module’s security policy, visit <a href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search" target="_blank" rel="noopener">NIST’s validated modules site</a>.</p>
<p>To learn more about engineering your product to meet Federal and regulated industry security requirements, <a href="https://www.corsec.com/contact-us/" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About FIPS 140</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><span class="s1"><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> are a joint effort by the National Institute of Standards and Technology (NIST) in the United States and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</span></p>
<p><span class="s1">FIPS 140 is mandated by law in the U.S. and very strictly enforced in Canada. FIPS 140 has gained worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Cradlepoint&#8217;s Kernel Cryptographic Module</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>The Cradlepoint Kernel Cryptographic Module (versions 1.0 and 2.0) is a software module with a multi-chip standalone embodiment. The module is designed to operate within a modifiable operational environment. The module comprises kernel loadable components, a static kernel binary, an integrity test utility, and digest files for testing integrity.</p>
<p>The cryptographic module maintains validation compliance when operating on any general-purpose computer (GPC) provided that the GPC uses any single-user operating system/mode specified on the validation certificate, or another compatible single-user operating system.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and the <a href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/cradlepoint-fips/">Cradlepoint Kernel FIPS 140-3 Validated</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Masimo Completes New FIPS 140-3 Validation</title>
		<link>https://www.corsec.com/masimo-fips/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 10 Sep 2024 19:59:51 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=20800</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/masimo-fips/">Masimo Completes New FIPS 140-3 Validation</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, Masimo Corporation, on completing the Federal Information Processing Standard Publication 140-3 (<span style="color: #339966;"><a style="color: #339966;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span>) validation process on their Masimo Cryptographic Module.</p>
<p>To achieve this milestone, Masimo partnered with Corsec, completing the validation at a Level 1 as seen in certificate <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4788">#4788</a>. For more information on the validation and to find additional details on the module’s security policy, visit <a href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search" target="_blank" rel="noopener">NIST’s validated modules site</a>.</p>
<p>To learn more about engineering your product to meet Federal and regulated industry security requirements, <a href="https://www.corsec.com/contact-us/" target="_blank" rel="noopener">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About FIPS 140</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><span class="s1"><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> are a joint effort by the National Institute of Standards and Technology (NIST) in the United States and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</span></p>
<p><span class="s1">FIPS 140 is mandated by law in the U.S. and very strictly enforced in Canada. FIPS 140 has gained worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Masimo</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Masimo Corporation is a global medical technology company that develops and produces a wide array of industry leading monitoring technologies, including innovative measurements, sensors, patient monitors, and automation and connectivity solutions.</p>
<p>The Masimo Cryptographic Module v1.0 is a software library providing a C language API1 for use by Masimo products requiring cryptographic functionality. The Masimo Cryptographic Module v1.0 includes symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and SSP establishment functions to secure data-at-rest/data-inflight and offers cryptographic support for secure communications protocols (including TLS2 1.2/1.3).</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/" target="_blank" rel="noopener"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/" target="_blank" rel="noopener">CSfC</a></span></strong>, and the <a href="https://www.corsec.com/dodin-apl/" target="_blank" rel="noopener"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe" target="_blank" rel="noopener"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img loading="lazy" decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img loading="lazy" decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/" target="_blank" rel="noopener">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/masimo-fips/">Masimo Completes New FIPS 140-3 Validation</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fed Roundup: December 2022</title>
		<link>https://www.corsec.com/fed-dec22/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 03 Jan 2023 21:55:28 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[CCRA]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[CSfC]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[STIG]]></category>
		<category><![CDATA[TCOE]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=19693</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fed-dec22/">Fed Roundup: December 2022</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><a href="https://www.disa.mil/en/NewsandEvents/2022/Provisional-authorization-for-Google">DISA issued a provisional authorization for cloud services by Google Services</a></li>
<li style="text-align: left;"><a href="https://www.disa.mil/en/NewsandEvents/2022/DISA-eye-a-cloud-focused-future">DISA decommissioned the DoD Enterprise Email (DEE) system on Nov 30, 2022</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">STIG Updates:</a></span></h5>
<ul>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-toss-4-security-technical-implementation-guide/">TOSS 4 Security Technical Implementation Guide</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-microsoft-windows-server-2022-security-technical-implementation-guide-benchmark/">Microsoft Windows Server 2022 Security Technical Implementation Guide</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2022/aes-draft-fips-197-update-available-for-comment">Proposed update to FIPS 197, The Advanced Encryption Standard (AES)</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-transitioning-away-from-sha-1-for-all-apps">Transition date for SHA-1</a></li>
<li><a href="https://csrc.nist.gov/News/2022/proposal-to-revise-fips-180-4-secure-hash-standard">Proposed revision to FIPS 140-4, Secure Hash Standard (SHS)</a></li>
</ul>
<h5 style="padding-left: 30px;">Special Publications &amp; Interagency Reports:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2022/withdrawal-of-nist-sp-800-107-revision-1">Withdrawal of SP 800-107 Revision 1</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-draft-revision-4-of-sp-800-63">Revision of Draft SP 800-63, Digital Identity Guidelines</a></li>
<li><a href="https://csrc.nist.gov/News/2022/withdrawal-of-nist-sp-800-106">Withdrawal of NIST SP 800-106, Randomized Hashing for Digital Signatures (2009)</a></li>
<li><a href="https://csrc.nist.gov/publications/detail/nistir/8278a/rev-1/draft">Draft NIST IR 8278Ar1, National Online Informative References (OLIR) Program: Submission Guidance for OLIR Developers</a></li>
<li><a href="https://csrc.nist.gov/publications/detail/nistir/8278/rev-1/draft">Draft NIST IR 8278r1, National Online Informative References (OLIR) Program: Overview, Benefits, and Use</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li><a href="https://www.niap-ccevs.org/Ref/Tracked/OT_ProgressRpt2022.Q3.php">3rd Quarter Progress Report</a></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li><a href="https://www.niap-ccevs.org/Announcements/Announcements.cfm#ann1283">Functional Package for Transport Layer Security (TLS) Version 2.0</a></li>
<li><a href="https://www.niap-ccevs.org/Announcements/Announcements.cfm#ann1281">Session Border Controller (SBC) PP-Module V1.0</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fed-dec22/">Fed Roundup: December 2022</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
