top of page


FIPS 140-3 Gap Analysis: fix the module before the lab, not after
For many years we have run cryptographic module readiness reviews inside larger governance and assurance engagements. It was never a named line item. It was the work done before a vendor spent money at a testing laboratory, so the money was not wasted. We have now formalised it as a defined service: the SITG FIPS 140-3 Gap Analysis. The context is a hard deadline. FIPS 140-2 certificates sunset on 21 September 2026 and move to the Historical List. From that date, a module wit
Brian Couzens
1 day ago2 min read
Â
Â
Â
FIPs140-3 A Thematic Review
A half-year read on where FIPS 140-3 validation actually stands. Between January and mid-July 2026, 30 new FIPS 140-3 certificates were issued or announced across non-hyperscaler, non-tier-1 vendors, spanning HSMs, authentication, cryptographic libraries, edge/IoT and embedded modules. With FIPS 140-2 fully retiring on 21 September 2026, this is no longer a future consideration. It's active, measurable, and already reshaping vendor selection. This SITG-Consulting Thematic Rev
Brian Couzens
6 days ago1 min read
Â
Â
Â
bottom of page