<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FIPS Inside Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/tag/fips-inside/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/tag/fips-inside/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Wed, 15 Jul 2026 12:56:00 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>FIPS Inside Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/tag/fips-inside/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Deconstructing FIPS 140-3: 5 Myths &#038; Realities</title>
		<link>https://www.corsec.com/fips-myths/</link>
		
		<dc:creator><![CDATA[Mary Broerman]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 12:56:00 +0000</pubDate>
				<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[FIPS Inside]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Federal Compliance]]></category>
		<category><![CDATA[FIPS Myths]]></category>
		<category><![CDATA[FIPS Validation]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=22624</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-myths/">Deconstructing FIPS 140-3: 5 Myths &#038; Realities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p class="isSelectedEnd">For organizations developing products that rely on cryptography to protect sensitive information, <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/" target="_blank" rel="noopener">FIPS 140-3</a></span> validation has become the benchmark for security compliance. Whether serving federal agencies, government contractors, critical infrastructure providers, or highly regulated industries, organizations often encounter FIPS 140-3 requirements as part of procurement, compliance, and security assurance efforts.</p>
<p class="isSelectedEnd">Despite its widespread recognition, FIPS 140-3 is frequently misunderstood. Teams may assume that using a validated cryptographic component automatically makes their product compliant. Product managers may view validation as a documentation exercise. Engineering teams may underestimate the technical meticulousness involved, while executives may question why validation is necessary at all.</p>
<p class="isSelectedEnd">These misconceptions can lead to delayed projects, unexpected costs, architectural rework, and missed market opportunities. More importantly, they can create a false sense of readiness when customers or procurement requirements demand validation.</p>
<p class="isSelectedEnd">This blog series, <em>Deconstructing FIPS 140-3: 5 Myths and Realities</em>, examines five common misconceptions that continue to shape how organizations approach cryptographic validation. We will explore how these assumptions affect product planning, development, compliance strategies, and go-to-market decisions.</p>
<p class="isSelectedEnd">We begin with one of the most common misconceptions in the industry which is confusing the use of validated cryptography with validation of the product itself.</p>
<h2><span style="color: #000000;">Myth 1: “FIPS Inside” Is the Same as Being FIPS 140-3 Validated</span></h2>
<p class="isSelectedEnd"><strong>Reality:</strong> Incorporating a FIPS-validated cryptographic module into a product does not automatically make the product FIPS 140-3 validated.</p>
<p class="isSelectedEnd">Organizations frequently advertise that their solution contains or utilizes validated cryptography. While this may be technically accurate, FIPS validation applies to the specific cryptographic module that underwent testing and validation through the Cryptographic Module Validation Program (CMVP). Simply inserting that module does not transfer validation status to the broader product.</p>
<p class="isSelectedEnd">Depending on how the cryptographic module is integrated, configured, and exposed to users, additional evaluation activities may be required to demonstrate adherence with FIPS requirements. Organizations must carefully understand the validation boundary, operational environment, and implementation details to accurately represent their security posture.</p>
<p class="isSelectedEnd">Confusing &#8220;FIPS Inside&#8221; with FIPS validation can create challenges during procurement reviews, customer assessments, and certification planning efforts. Understanding this distinction early helps organizations avoid costly misunderstandings and better prepare for validation activities.</p>
<p><strong>For more information on FIPS Inside, <span style="color: #008000;"><a style="color: #008000;" href="https://ww3.corsec.com/FIPS-Validated-vs-Inside" target="_blank" rel="noopener">download an in depth overview on the topic</a></span>.</strong></p>
<hr />
<h2><span style="color: #000000;">Upcoming Myths in This Series</span></h2>
<p class="isSelectedEnd">In the remaining posts, we will examine four additional myths that continue to influence FIPS validation strategies:</p>
<p class="isSelectedEnd"><strong>Myth 2:</strong> FIPS Is Only Required for Federal Agencies</p>
<p class="isSelectedEnd"><strong>Myth 3:</strong> FIPS Validation Is Just a Documentation Exercise</p>
<p class="isSelectedEnd"><strong>Myth 4:</strong> Our Product Has a FIPS 140-2 Validation, We Don&#8217;t Need FIPS 140-3</p>
<p class="isSelectedEnd"><strong>Myth 5:</strong> The Cost and Timeline of FIPS Validation Aren&#8217;t Justified</p>
<p class="isSelectedEnd">Each of these assumptions fail to capture the full reality of today&#8217;s validation landscape. Left unchallenged, they can influence decisions that impact product architecture, project timelines, security adherence, product readiness, and market access. Throughout this series, we will break down each myth, explain the underlying realities, and highlight practical considerations organizations should evaluate when developing a FIPS 140-3 validation strategy.</p>
<p class="isSelectedEnd">Successfully navigating FIPS 140-3 requires more than simply understanding the standard. It often demands early coordination across engineering, product management, compliance, and certification stakeholders. Organizations that align validation requirements with product development activities from the start are typically better positioned to avoid rework, reduce risk, and achieve validation more efficiently.</p>
<p class="isSelectedEnd"><strong>Corsec supports organizations throughout the FIPS 140-3 lifecycle from architectural reviews and validation planning to documentation development, laboratory coordination, testing support, and CMVP submission activities. If FIPS 140-3 validation is part of your action plan or becoming a requirement for your customers and target markets—engaging early can help establish a clear path forward. <span style="color: #008000;"><a style="color: #008000;" href="https://ww3.corsec.com/get-in-touch" target="_blank" rel="noopener">Contact Corsec</a></span> to learn how your organization can approach FIPS 140-3 validation with confidence and ease.</strong></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-myths/">Deconstructing FIPS 140-3: 5 Myths &#038; Realities</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FIPS Inside: Is It Right For Me?</title>
		<link>https://www.corsec.com/fips-inside/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 12 Jul 2016 16:38:08 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS Inside]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6967</guid>

					<description><![CDATA[<p>Implementing a FIPS 140-2 validation into your product is a great way to strengthen your solution, enhance your brand, and secure your bottom line. When pursuing FIPS, you will be faced with difficult and often confusing ... </p>
<p class="read-more-container"><a title="FIPS Inside: Is It Right For Me?" class="read-more button" href="https://www.corsec.com/fips-inside/#more-6967" aria-label="More on FIPS Inside: Is It Right For Me?">Read more</a></p>
<p>The post <a href="https://www.corsec.com/fips-inside/">FIPS Inside: Is It Right For Me?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Implementing a <span style="color: #000080;"><a style="color: #000080;" href="https://www.corsec.com/certifications/fips-140-2/">FIPS 140-2</a></span> validation into your product is a great way to strengthen your solution, enhance your brand, and secure your bottom line. When pursuing FIPS, you will be faced with difficult and often confusing decisions; leaving you with many questions. One such question we are always asked is the difference between being FIPS Validated and FIPS Compliant (sometimes referred to as FIPS Inside). But first, lets take a step back and uncover how the difference arose.</p>
<p>Early on in the pursuit of validations for cryptography-enabled products, the roadmap was clear: a crypto device meant for federal networks processing SBU information needed to undergo a FIPS validation.  These products were hardware-based, and the standards written against which they’d be evaluated were written with hardware-based solutions in mind.</p>
<p>Fast-forward to today. Continuing improvements in cryptography has resulted in solutions that come in many forms, including software, hardware, firmware, and combinations thereof. To address the changing landscape of cryptographic enablement, the FIPS standard also had to change over time.  Vendors were no longer locked into FIPS validations that targeted appliances. FIPS validations could be performed on sub-components such as server blades, embedded cards, crypto chips, and even software libraries. With the proliferation of such solutions, the concept of FIPS Inside was born.</p>
<p><strong><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">What is FIPS Inside?</span></span></strong></p>
<p>FIPS Inside is a term used to reference a device or appliance that employs a FIPS-validated subcomponent to provide its cryptographic services. This became an attractive validation alternative, particularly for vendors that only developed software, or for those that wanted to insulate their validation status from non-security-related product changes.</p>
<p>The option of validating a software-based FIPS Inside solution opened the door for third-party vendors to develop, validate, and market their own cryptographic solutions. Open-source libraries like OpenSSL, Crypto++, and NSS, as well as licensed libraries like RSA’s BSAFE and Mocana’s Crypto Module, have been heavily leveraged over the past few years because they offer a “plug and play” validation solution. Vendors needing to make the claim of using FIPS-validated cryptography would simply integrate these third-party libraries into their proprietary code, and voila!  Mission accomplished!</p>
<p>Or was it?</p>
<h5><span style="text-decoration: underline;"><span style="color: #000000;"><strong>Is FIPS Inside Right For Me?</strong></span></span></h5>
<p>The FIPS Inside validation approach is very convenient, and can, in fact, be a viable option in certain situations. The optimal scenario is that the vendor of the device also controls the targeted subcomponent. However, when relying on a third-party’s software solution, this path also comes with its share of very real pitfalls.</p>
<p><u>It provides very limited assurance:</u></p>
<p>Recall that the primary goal of a FIPS validation effort is to provide assurance that a cryptographic module is in conformance with the standard. This assurance comes from the knowledge that the module was independently tested by an accredited testing lab whose work was reviewed and approved by an oversight body made up of representatives for both the U.S. and Canada. That’s very powerful, and when a vendor undergoes a FIPS validation process, the resulting certificate is very marketable.  However, when a vendor relies on another vendor’s certificate, the story of assurance grows considerably weaker.  As a potential product consumer, which statement would you find more assuring:</p>
<p>“<em>You can trust our product, because we’re trusting someone else who went through the FIPS validation process and received a certificate! Further, although we provide no proof, you can trust that we’re using that FIPS-validated product exactly as specified in other vendor’s security policy!</em>”</p>
<p>or</p>
<p>“<em>You can trust our product, because we went through the FIPS validation process and received a certificate! Our algorithms and module functionality were tested and found conformant … and as proof, here’s a link to <u>our</u> module’s entry on NIST’s Validated Modules List!</em>”</p>
<p><u>Your product becomes dependent on a third-party’s issues and schedule:</u></p>
<p>If your third-party crypto library is discovered to have a conformance issues, then you’ve just inherited their conformance issues. Their validation may have just been revoked, so your claims of using FIPS-validated crypto functionality are no longer true. What do you do?</p>
<p>You do have options. If it’s a licensed library, you can buy the update. If it’s an open-source library, you can download the new release and integrate it. But in both options, you have to hope that the conformance issue is important enough to the third-party developers to (a) make the fix at all and (b) complete the fix AND re-validate in a timeframe that fits your own business pursuits. And in both options, you’re forced to wait.</p>
<p>When competing for time-sensitive business opportunities, waiting is not always an option. A loss of your positioning due to a third-party’s change in validation status could cost you millions of dollars in unrealized revenues and lost opportunities.</p>
<p><u>It limits your ability to compete:</u></p>
<p>Using a third-party crypto solution is a clear indication that you are not fully responsible for your product’s security functionality. In today’s security-aware industry, purchasers are looking to vendors that are performing their due diligence and taking ownership of security. In the absence of an independent FIPS validation (which provides assurance that’s accepted industry-wide), many questions will be raised about a product’s security capabilities and viability for processing SBU information.</p>
<p>There was a time not long ago that the U.S. Army had its own Approved Product’s List, and product vendors needed to have their own validation certificates in order to be added to this list. Today, many purchasers in the U.S. federal space still feel strongly that a vendor should obtain all of the necessary validations in order to be considered for purchase … reliance on third-parties is just not as acceptable as it once was.</p>
<p><u>It brings your company’s commitment to security into question:</u></p>
<p>Again, there are scenarios where incorporating a FIPS-validated third-party cryptographic library (FIPS Inside) into a bigger solution makes sense. But how much do you really know about that library? Consider these questions:</p>
<ul>
<li>Which algorithms are implemented in the library?</li>
<li>Which algorithms does your solution use from the library?</li>
<li>Does the library have any built-in backdoors?</li>
<li>Is this the most recent version of the library?</li>
<li>Does the library meet all <u>current</u> FIPS requirements?</li>
<li>Does the library generate keys in a FIPS-Approved manner?</li>
<li>Was the library built as specified in its published Security Policy?</li>
</ul>
<p>These are very fair questions, and they are questions that any vendor should be able to answer about their own product. However, many vendors today will integrate a crypto library with a full understanding of what just got added to their solutions’ codebase … they simply trust it to work.</p>
<h5><span style="text-decoration: underline;"><span style="color: #000000;"><strong>Conclusion:</strong></span></span></h5>
<p>There’s nothing wrong with trusting an embedded FIPS-validated solution. But if these questions can’t be answered, it makes it very difficult to vouch for your own product’s security, and if you can’t truly vouch for your own product’s security, that becomes a reflection of your true commitment to providing a secured solution.</p>
<p>When choosing a strategy to meet strict security conformance requirements, as in any business decision, one must gather as much information as possible in order to make an educated decision. Factors such as convenience, resource availability, time-to-market, sustainability, long- and short-terms costs, benefits, and risks must all be weighed to determine the most viable course of action. While integrating a third-party crypto service solution in order to meet FIPS requirements seems like the best choice (and sometimes, it actually is), there are a growing number of business-related drawbacks to this path that must be identified and weighed. Choosing a path with taking these drawbacks under careful consideration could impact your validation status and ability to compete for years to come</p>
<p>The post <a href="https://www.corsec.com/fips-inside/">FIPS Inside: Is It Right For Me?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
