Cryptographic Testing

FIPS 140-3 Testing

Consult our experts. We are happy to support you.

FIPS 140-3 – short for the U.S. Federal Information Processing Standard 140-3 – are security requirements for cryptographic modules related to the secure design and implementation of cryptographic modules that provide protection for sensitive or valuable data.

We also offer legacy updates for cryptographic modules previously certified under FIPS 140-2 until September 2026.

What atsec offers:

atsec US provides the following cryptographic module testing services:

  • Training for FIPS 140-3 and validation process
  • Assessment of your cryptographic module test readiness
  • Support for the production of the security policy, finite state mode, and user documentation
  • Conformance testing of cryptographic modules, resulting in a certificate issued by the National Institute of Standards and Technology (NIST) and the Canadian Center of Cyber Security (CCCS) Cryptographic Module Validation Program (CMVP)

Why our services are important to you:

If you plan to sell a product that includes a cryptographic module to a U.S. Federal Government agency that uses cryptographic-based security systems to protect sensitive data in computer or telecommunication systems, FIPS 140-3 certification of that product is mandatory. In addition, FIPS 140-3 certification of cryptographic modules is increasingly valued in other industry sectors (for example, banking) in which the protection of sensitive data by cryptographic-based solutions is critical. atsec is ready to partner with you to help you understand the requirements of the standard, assess your product’s readiness for FIPS 140-3 validation, and perform the conformance testing that will earn certification of your cryptographic product.

FIPS 140-2 and FIPS 140-3 certificates earned through atsec testing:

Vendor / Product Sec. level / Type Number / Date
Red Hat®, Inc.
Red Hat Enterprise Linux 9 Kernel Cryptographic API
1
Software
4796
2024-09-11
Canonical Ltd.
Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module
1
Software
4794
2024-09-11
Canonical Ltd.
Canonical Ltd. Ubuntu 22.04 Libgcrypt Cryptographic Module
1
Software
4793
2024-09-10
IBM
IBM DataPower FIPS Provider
1
Software
4789
2024-09-06
Juniper Networks, Inc.
Junos® OS Evolved Kernel Cryptographic Module
1
Software
4776
2024-09-03
Juniper Networks, Inc.
Junos® OS Evolved OpenSSL Cryptographic Module
1
Software
4775
2024-09-03
Oracle Corporation
Oracle Linux 9 OpenSSL FIPS Provider
1
Software
4779
2024-08-25
Qualcomm Technologies, Inc.
Qualcomm® Pseudo Random Number Generator
1
Firmware-Hybrid
4778
2024-08-25
Red Hat®, Inc.
Red Hat Enterprise Linux 9 NSS Cryptographic Module
1
Software
4774
2024-08-21
Rambus Inc.
CryptoManager Root of Trust RT-660
2
Hardware
4758
2024-08-12
Apple Inc.
Apple corecrypto Module v11.1
[Apple silicon, Secure Key Store, Hardware, SL2/PHY3]
2
Hardware
4757
2024-08-09
Apple Inc.
Apple corecrypto Module v11.1
[Apple silicon, Secure Key Store, Hardware] (SL2)
2
Hardware
4756
2024-08-09

Introduction to the
CMVP and CAVP

Watch our Introduction to the Cryptographic Module Validation Program and the Cryptographic Algorithm Validation Program video, which will provide you with a head start on understanding the certification process.

Still have questions?

Can’t find what you’re looking for? Let’s talk!

Cryptographic Algorithm Testing

Testing that cryptographic algorithms are implemented correctly is a prerequisite for FIPS 140-3 cryptographic module testing and NIAP Common Criteria evaluations.

Entropy Source Assessment

Documented conformance, where applicable, to the SP 800-90B is required by the CMVP for all FIPS 140-3 module validation submissions.

Common Criteria Evaluation

The Common Criteria (CC), also known as ISO 15408, is an internationally recognized standard used to specify and assess the security of IT products.

The Information Security Provider

Read Our Latest Blog Articles

Learn the latest and greatest about information security. You’ll find insights and analyses of recent developments in technology and policy on our blog.