Cryptographic Module Validation (FIPS 140-3)
FIPS 140-3 is a U.S. government computer security standard that sets requirements for cryptographic modules—the hardware, software, or firmware components that perform encryption and related security functions. Rather than being validated automatically, a module must be tested and confirmed against the standard through the Cryptographic Module Validation Program (CMVP), a joint effort of the U.S. and Canadian governments. Validation under this program is how a module is recognized as meeting the standard's requirements. Readers should verify the current standard text and validation details against the official NIST source, as standards and program lists change over time.
FIPS 140-3 ('Security Requirements for Cryptographic Modules') is a U.S. government standard used to design, implement, and validate cryptographic modules that federal departments and agencies operate or that are operated on their behalf. The standard designates the Cryptographic Module Validation Program (CMVP), operated jointly by the U.S. and Canadian governments, as the validation authority; CMVP is the mechanism through which conformance is assessed and validated modules are listed. It is important to distinguish the standard (FIPS 140-3, which specifies the security requirements) from the validation program (CMVP, which determines and records whether a specific module conforms) and from a validated module itself (an individual product entry on CMVP's list). The evidence provided does not specify security levels, testing methodologies, effective or transition dates, or applicability outside the U.S. federal context; practitioners should consult the current FIPS 140-3 text and the CMVP validated-module search for authoritative, up-to-date details. This entry is informational and does not constitute compliance or legal advice; applicability to a particular module or procurement requires professional judgment.
Why it matters
For U.S. federal departments and agencies—and the vendors that supply them—the distinction between a cryptographic module that has been validated and one that merely claims to implement encryption is significant. FIPS 140-3 sets the security requirements for cryptographic modules, and the Cryptographic Module Validation Program (CMVP) is the mechanism through which a specific module is tested and confirmed against those requirements. A product's own assertion that it uses strong encryption is not the same as a CMVP-validated module: validation is recorded through the program, and a module either appears on the CMVP validated-module list or it does not. This matters because procurement, contractual, and internal security decisions in the federal context frequently turn on whether a module has actually been validated rather than on marketing claims.
Who it's relevant to
Inside CMVP
Common questions
Answers to the questions practitioners most commonly ask about CMVP.

