Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

What Is FIPS and How Do You Become Compliant?

The Federal Information Processing Standards (FIPS) are publicly announced U.S. government standards, developed by NIST, that specify how cryptographic modules must be designed and tested; FIPS 140-3 is the current standard, replacing FIPS 140-2, which is set to sunset on September 21, 2026.

FIPS 140-3 is the current NIST standard governing cryptographic modules used to encrypt data at rest and in transit, superseding FIPS 140-2, whose validations sunset on September 21, 2026. It defines four security levels, from Level 1’s basic production-grade requirements to Level 4’s tamper-active protections, and is mandatory for federal agencies and their vendors.

Key Takeaways

  • FIPS 140-3 is the current cryptographic module standard; FIPS 140-2 validations sunset on September 21, 2026, so new deployments should target FIPS 140-3 validated modules.
  • FIPS 140-3 defines four security levels, with Level 1 requiring basic production-grade equipment and Level 4 requiring tamper-active, self-erasing protections.
  • Federal agencies, their contractors, and any vendor selling cryptographic modules for federal use must hold current FIPS validation.
  • Windows FIPS mode restricts an operating system to only use FIPS-validated cryptographic algorithms and key lengths.
  • A FIPS code is a separate, unrelated numbering system that identifies U.S. geographic areas, not a cryptographic standard.

What is the difference between FIPS 140-2 and FIPS 140-3?

FIPS 140-3 replaces FIPS 140-2 as NIST’s standard for cryptographic module validation. NIST has set September 21, 2026 as the date FIPS 140-2 validation certificates move to historical status, meaning organizations still relying on FIPS 140-2 validated modules should plan migration to FIPS 140-3 validated hardware and software before that date.

Customizable HSM Solutions

Get high-assurance HSM solutions and services to secure your cryptographic keys.

What are the four FIPS 140-3 security levels?

LevelCore requirement
Level 1Production-grade equipment and at least one validated encryption algorithm
Level 2Level 1 requirements plus role-based authentication and tamper-evident physical devices
Level 3Level 2 requirements plus tamper-resistant devices, identity-based authentication, and separation of interfaces carrying critical security parameters
Level 4Level 3 requirements plus tamper-active protection, including erasure of the device’s contents if an environmental attack is detected

Who needs to be FIPS compliant?

Federal agencies that collect, store, share, transfer, or disseminate sensitive data, along with their contractors and any cryptographic module vendor selling into the federal market, must hold current FIPS validation. Many organizations outside the federal space pursue FIPS validation voluntarily, since it is recognized internationally as a baseline for secure cryptographic modules, and some regulated industries such as healthcare and financial services require it from vendors.

What is Windows FIPS mode?

Windows FIPS mode is a configuration setting that restricts the operating system to FIPS-validated cryptographic algorithms and key lengths for its encryption and decryption operations. Enabling it does not, by itself, make an entire system FIPS compliant; the underlying cryptographic modules still need their own current FIPS validation.

How Encryption Consulting Helps

HSM-as-a-Service from Encryption Consulting runs on FIPS 140-3 validated hardware, and our Encryption Advisory Services help organizations plan the migration off FIPS 140-2 validated modules before the September 2026 sunset date. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

Is FIPS 140-2 still valid?

FIPS 140-2 validation certificates are set to move to historical status on September 21, 2026. Organizations still deploying FIPS 140-2 validated modules should plan a migration to FIPS 140-3 validated hardware and software ahead of that date.

What are the four FIPS 140-3 security levels?

The four levels are Level 1 (basic production-grade equipment and one validated algorithm), Level 2 (adds role-based authentication and tamper-evident devices), Level 3 (adds tamper-resistant devices and identity-based authentication), and Level 4 (adds tamper-active, self-erasing protection).

What is a FIPS code?

A FIPS code is a separate, unrelated numbering system that uniquely identifies U.S. geographic areas, such as states and counties. It has no connection to the cryptographic module standards defined under FIPS 140-3.

Do I need FIPS compliance if I do not work with the federal government?

It is not legally required outside the federal space, but many organizations pursue FIPS 140-3 validation voluntarily because it is internationally recognized as a baseline for secure cryptographic modules, and some regulated industries require it of their vendors regardless of federal contract status.

Migrate to FIPS 140-3 Validated Modules

Take the next step
Encryption Consulting helps you assess current FIPS 140-2 dependencies and migrate to FIPS 140-3 validated HSMs before the September 2026 sunset. Explore HSM-as-a-Service to see FIPS 140-3 validated hardware in action.