← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

FIPS 140-3 validation does not guarantee overall product security, auditors confirm

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Over 90% of FIPS-enabled HSMs are run with FIPS mode disabled by customers.
  • FIPS 140-2 certificates will be moved to a historical list by September 21, 2026.
  • FIPS validation covers only the cryptographic module, not the full product or its operation.
  • The program eliminated poor cryptographic practices, but its scope is often misunderstood.

Misconceptions about FIPS Validation

A significant number of customers who purchase FIPS-enabled Hardware Security Modules (HSMs) disable FIPS mode, despite paying a premium for the certification. This practice highlights a common misunderstanding regarding the scope of FIPS validation. The certification attests to a narrow set of criteria, not the overall security of a product or its deployment.

Upcoming Changes to FIPS Certificates

By September 21, 2026, all remaining FIPS 140-2 certificates will be moved to NIST's historical list, meaning modules on this list should not be used in new federal procurements. This change is driving procurement teams to seek FIPS 140-3 certifications from vendors, leading to increased activity and investment in the validation process.

Scope of FIPS 140-3 Certification

FIPS 140-3 validation specifically applies to the cryptographic module boundary. It confirms that approved algorithms are correctly implemented, keys can be zeroized, the module performs power-up self-tests, and, at higher levels, the hardware resists physical tampering. The certification does not cover the security of the surrounding application, access controls, key management policies, or human operational procedures. Misinterpreting the certificate as a guarantee for these broader security aspects can lead to vulnerabilities.

Importance of FIPS Program

Despite its limitations, the FIPS program has been instrumental in eliminating substandard cryptographic practices. The requirement for FIPS validation remains a sensible baseline for procurement. The issue lies in the consistent gap between what the certificate actually covers and what users and organizations believe it covers, which has been documented in various incidents, including certified products being weaker than consumer models or operational failures in specific configurations.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

FIPS 140-3 validation certifies only a cryptographic module's correct implementation of approved algorithms and design requirements, not the security of the entire product or its operational configuration. Many customers disable FIPS mode in certified hardware, indicating a gap between perceived and actual security assurances. This distinction is critical as FIPS 140-2 certificates are being phased out, pushing vendors and procurement teams towards FIPS 140-3.