A significant number of customers who purchase FIPS-enabled Hardware Security Modules (HSMs) disable FIPS mode, despite paying a premium for the certification. This practice highlights a common misunderstanding regarding the scope of FIPS validation. The certification attests to a narrow set of criteria, not the overall security of a product or its deployment.
By September 21, 2026, all remaining FIPS 140-2 certificates will be moved to NIST's historical list, meaning modules on this list should not be used in new federal procurements. This change is driving procurement teams to seek FIPS 140-3 certifications from vendors, leading to increased activity and investment in the validation process.
FIPS 140-3 validation specifically applies to the cryptographic module boundary. It confirms that approved algorithms are correctly implemented, keys can be zeroized, the module performs power-up self-tests, and, at higher levels, the hardware resists physical tampering. The certification does not cover the security of the surrounding application, access controls, key management policies, or human operational procedures. Misinterpreting the certificate as a guarantee for these broader security aspects can lead to vulnerabilities.
Despite its limitations, the FIPS program has been instrumental in eliminating substandard cryptographic practices. The requirement for FIPS validation remains a sensible baseline for procurement. The issue lies in the consistent gap between what the certificate actually covers and what users and organizations believe it covers, which has been documented in various incidents, including certified products being weaker than consumer models or operational failures in specific configurations.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
FIPS 140-3 validation certifies only a cryptographic module's correct implementation of approved algorithms and design requirements, not the security of the entire product or its operational configuration. Many customers disable FIPS mode in certified hardware, indicating a gap between perceived and actual security assurances. This distinction is critical as FIPS 140-2 certificates are being phased out, pushing vendors and procurement teams towards FIPS 140-3.