<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FIPS Compliance Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/tag/fips-compliance/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/tag/fips-compliance/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Tue, 11 Aug 2026 18:44:53 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>FIPS Compliance Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/tag/fips-compliance/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Deconstructing FIPS 140-3: Myth #4 &#8211; Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</title>
		<link>https://www.corsec.com/fips-myth-4/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 18:43:08 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[FIPS Compliance]]></category>
		<category><![CDATA[FIPS Validation]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22764</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-myth-4/">Deconstructing FIPS 140-3: Myth #4 &#8211; Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="isSelectedEnd">Organizations that already have a FIPS 140-2 validation may assume that their work is finished. After all, the product already went through a formal validation process, so why would another validation be necessary?</p>
<p class="isSelectedEnd">The answer is that <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/" target="_blank" rel="noopener">FIPS 140-2</a></span> and <span data-contrast="auto"><span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span></span> are different standards. FIPS 140-3 replaced FIPS 140-2 as the current standard for new validations and introduced updated requirements for evaluating cryptographic modules. With that and the looming FIPS 140-2 sunset date approaching, all vendors considering an approach for FIPS 140 will need to validate to the newest version of the publication.</p>
<p>This post is the fourth installment in our <a href="https://www.corsec.com/fips-myths/"><strong data-start="1459" data-end="1511">Deconstructing FIPS 140-3: 5 Myths and Realities</strong></a> series, where we examine common misconceptions surrounding FIPS validation and explain what organizations should understand before beginning the certification process.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Myth #4:</h3>
<h3>“Our product has a FIPS 140-2 validation, so we don’t need FIPS 140-3.”</h3>
<p>At first glance, this assumption seems reasonable. If a product has already completed FIPS validation, it can be easy to think that the existing validation automatically carries over to the newer standard.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Reality:</h3>
<h3>A FIPS 140-2 validation does not automatically make a product FIPS 140-3 validated.</h3>
<p class="isSelectedEnd">FIPS 140-2 was the standard used to validate cryptographic modules for many years. FIPS 140-3 is its successor and was developed to update the requirements and align the U.S. standard more closely with international standards.</p>
<p>While FIPS 140-3 builds on many of the concepts found in FIPS 140-2, it also includes updated requirements and changes to how cryptographic modules are evaluated. FIPS 140-2 and even FIPS 140-3 validations have a sunset date, traditionally 5 years. <strong>However, all remaining FIPS 140-2 validations will be automatically sunset on Sept. 21, 2026</strong>.</p>
<p>For vendors selling into the U.S. federal government, the CMVP states that all modules with a status designation of Historical &#8220;<span style="color: #ff0000;"><em>should not be included by Federal Agencies in new procurements</em></span>.&#8221;</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="isSelectedEnd">If an organization has already invested significant time and resources into obtaining a FIPS 140-2 validation, it is understandable to assume that the existing validation should be sufficient for the newer standard. However, a FIPS 140-2 certificate does not simply become a FIPS 140-3 certificate. The two standards have different requirements, and organizations need to understand what their existing validation means and what requirements apply to their specific product and use case.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Validation &amp; Boundaries</h3>
<p class="isSelectedEnd">If an organization has already invested significant time and resources into obtaining a FIPS 140-2 validation, it is understandable to assume that the existing validation should be sufficient for the newer standard. However, a FIPS 140-2 certificate does not simply become a FIPS 140-3 certificate. The two standards have different requirements, and organizations need to understand what their existing validation means and what requirements apply to their specific product and use case.</p>
<p class="isSelectedEnd">Another important consideration is that FIPS validation applies to a specific cryptographic module and its defined configuration. It is not a blanket certification that automatically covers every version or configuration of a product.</p>
<p>This means that when a product is updated or a new version is released, organizations need to understand whether those changes affect the scope of the existing validation. The fact that an earlier version was validated does not necessarily mean that a newer version has the same validation status.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>Moving From One Standard to the Next</h3>
<p class="isSelectedEnd">For organizations with an existing FIPS 140-2 validation, the transition to FIPS 140-3 does not necessarily mean starting from scratch. The existing validation can provide a useful foundation for understanding what may need to change.</p>
<p>Planning early can help organizations identify differences between their current FIPS 140-2 validation and the requirements of FIPS 140-3. This can help teams anticipate potential design, documentation, and testing impacts before beginning a new validation effort.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h3>The Takeaway</h3>
<p class="isSelectedEnd">Having a FIPS 140-2 validation is valuable, but it should not be confused with having a FIPS 140-3 validation. As organizations plan new products, product updates, or future validation efforts, understanding the differences between the two standards is an important first step.</p>
<p class="isSelectedEnd">FIPS validation is not simply a label that applies to every version of a product. The applicable standard, validated module, configuration, and current requirements all matter.</p>
<p>Understanding where your product stands today can help ensure that your next step is the right one.</p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-myth-4/">Deconstructing FIPS 140-3: Myth #4 &#8211; Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FIPS Compliance and OpenSSL</title>
		<link>https://www.corsec.com/fips-compliance/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 20 Jan 2016 16:08:55 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS Compliance]]></category>
		<category><![CDATA[OpenSSL]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6881</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-compliance/">FIPS Compliance and OpenSSL</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>Product vendors often rely on <strong>OpenSSL</strong> to meet <strong>FIPS 140 requirements</strong>.</p>
<p>However, with the new CMVP<a href="http://csrc.nist.gov/groups/STM/cmvp/notices.html"> requirements and regulations</a>, vendors using certain versions of the OpenSSL cryptographic library to meet FIPS 140-2/FIPS 140-3 requirements are in jeopardy of being out of FIPS compliance.</p>
<p>This update makes it crucial for vendors to understand the implications of FIPS 140-2/FIPS 140-3 certification and how to navigate the FIPS validation process.</p>
<h2 id="fips-140-3-compliance-vs-fips-140-2-validation-key-differences">FIPS 140-3 Compliance vs. FIPS 140-3 Validation: Key Differences</h2>
<p>There is a substantial difference between stating your product meets FIPS compliance and being &#8216;FIPS 140-2 validated.&#8217;</p>
<h3 id="fips-compliance">FIPS Compliance</h3>
<p>FIPS compliance refers to a product that has incorporated within its design another company&#8217;s cryptographic module that went through the complete FIPS validation process. While this may seem sufficient, it does not hold as much weight as achieving full FIPS 140-2/FIPS 140-3 validation.</p>
<h3 id="fips-140-3-validation">FIPS 140-3 Validation</h3>
<p>FIPS 140-2/FIPS 140-3 validation means a vendor has gone through the entire FIPS 140-2/FIPS 140-3 process and has received a certificate issued by the government for their specific product. This certificate signifies that the product meets legal requirements passed by Congress, as well as procurement requirements for the U.S. government and various industries, including healthcare, financial services, and critical infrastructure.</p>
<p>When considering the security of a product, every measure must be taken to ensure all entry and access points are secure and meet full government requirements. Choosing the FIPS compliance route covers only a portion of what truly needs to be protected. Achieving FIPS 140-3 validation means both you and the government are attesting to the security of the entire cryptographic module.</p>
<h2 id="why-fips-140-3-certification-matters">Why FIPS 140-3 Certification Matters</h2>
<p>With the introduction of FIPS 140-2/FIPS 140-3, product vendors who previously relied on FIPS 140-2/FIPS 140-3 or FIPS compliance may find themselves out of step with the latest standards. The new set of requirements impacts not only those who have relied on a FIPS inside strategy but also affects other certifications such as Common Criteria and listing on the DoDIN APL.</p>
<h3 id="the-risks-of-non-compliance">The Risks of Non-Compliance</h3>
<p>Modules that were once thought to have met FIPS compliance will soon be unprocurable and removed from the FIPS 140-2/FIPS 140-3 validated list. This will significantly impact product vendors who are unaware of these changes.</p>
<h2 id="the-fips-140-3-process-steps-to-achieve-certification">The FIPS 140-3 Process: Steps to Achieve Certification</h2>
<p>Achieving FIPS 140-3 certification involves a comprehensive process, including:</p>
<ol>
<li><strong>Initial Assessment:</strong> Understanding the specific requirements for FIPS 140-3 and how they apply to your product.</li>
<li><strong>Cryptographic Module Validation:</strong> Ensuring that your cryptographic module meets all FIPS 140-3 standards.</li>
<li><strong>Documentation and Submission:</strong> Preparing and submitting the required documentation to the CMVP.</li>
<li><strong>Government Evaluation:</strong> Your product undergoes a thorough evaluation by government bodies to ensure compliance.</li>
<li><strong>Certification Issuance:</strong> Once your product passes all evaluations, a FIPS 140-3 certificate is issued, confirming its compliance.</li>
</ol>
<h2 id="the-role-of-fips-140-3-validation-experts">The Role of FIPS 140-3 Validation Experts</h2>
<p>Given the complexity of the FIPS 140-2/FIPS 140-3 process, working with FIPS validation experts is crucial. These experts can guide you through each step of the process, helping you avoid costly mistakes and ensuring your product meets all necessary standards.</p>
<h2 id="take-action-now">Take Action Now</h2>
<p>For help determining if and how your product will be affected by this change, <a href="https://corsec.com/company/contact-us/">contact us</a> to ensure you avoid timely and costly delays, or worse, de-listing from the CMVP website. Our team of FIPS 140-2/FIPS 140-3 validation experts is ready to assist you.</p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-compliance/">FIPS Compliance and OpenSSL</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
