What is FIPS 140-3
FIPS 140-3 is the current joint U.S. and Canadian standard for the validation of cryptographic modules. Administered by the National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security (CCCS) through the Cryptographic Module Validation Program (CMVP), it defines the rigour required for modules protecting sensitive data. Vendors targeting federal or regulated sectors require an independent validation certificate; a self-attested claim of being 'FIPS compliant' is insufficient and constitutes a commercial risk for government suppliers.
Compliance is a hard requirement for the sale of hardware and software security products into the public sector. It is critical to note that existing FIPS 140-2 certificates will sunset on 21 September 2026. From this date, modules without a valid FIPS 140-3 certificate will be considered legacy and non-compliant for new procurement. Engineering leads must transition module boundaries and architecture to meet the enhanced security requirements of the -3 standard immediately to avoid market exclusion.
01
Documentation and Cryptographic Boundary Review
A structured audit of your Security Policy, Finite State Model, and architectural specifications against ISO/IEC 19790:2012 and ISO/IEC 24759:2017.
03
Final Gap Report and Lab Strategy
A written deficiency report and a prioritised roadmap for submission to an accredited testing laboratory.
02
Cryptographic Inventory and Entropy Readiness.
Mapping declared algorithms against the NIST approved and allowed lists, and reviewing SP 800-90B entropy source documentation, to surface gaps before lab ingestion rather than during it.
What You Get
CMVP Submission Readiness Report
Documentation Deficiency Audit
Cryptographic Boundary Verification
Non-Compliance Matrix, prioritised by whether it blocks submission, should be fixed before submission, or can be resolved in parallel with lab engagement
Why Independent Review First
Attempting formal validation without a preliminary gap analysis frequently results in extended laboratory delays, non-conformance reports, and significant unbudgeted costs. An independent review ensures that boundary definitions, physical security requirements, and operational documentation are verified against ISO/IEC 19790 and NIST SP 800-140x requirements before the formal clock begins. This service is a readiness assessment and does not constitute a formal FIPS 140-3 validation certificate.
What occurs if our module fails the readiness review?
The readiness review identifies non-conformities before they enter the formal lab queue. We provide specific technical remediation paths for boundary definitions and documentation gaps to ensure the module meets NIST requirements.
How does the FIPS 140-2 sunset impact our current inventory?
Modules validated under FIPS 140-2 will move to the Historical List on 21 September 2026. Agencies may continue using them for existing deployments, but new procurements typically mandate active FIPS 140-3 validation.
Can SITG act as our accredited testing laboratory?
No. SITG is an independent consultancy. We provide a gap analysis to ensure your module is ready for submission to a NVLAP-accredited lab. This separation prevents conflicts of interest and reduces total validation time.