FIPS 140-3 Gap Analysis: What the September Deadline Exposed

On 21 September 2026, NIST's Cryptographic Module Validation Programme moved all remaining FIPS 140-2 certificates to historical status. The date had been signposted for years. The preparation, across a significant number of regulated organisations, had not kept pace.
Historical status does not mean the modules stop functioning. It means they no longer satisfy federal procurement requirements and, by extension, the compliance expectations of any regulated sector that references FIPS validation as a baseline. For organisations still running FIPS 140-2 validated modules in production, the question is no longer whether to migrate. The question is whether anyone has conducted a structured FIPS 140-3 gap analysis of what is actually deployed, what has lapsed, and what the remediation pathway looks like.
The uncomfortable answer, in a significant number of cases, is that no one has.
A FIPS 140-3 Gap Analysis Starts with the Module Register
The first obstacle is visibility. Cryptographic modules are embedded across operating systems, middleware, hardware security modules, TLS stacks, VPN concentrators, database encryption engines, and identity infrastructure. No single team owns the complete inventory. Procurement tracks vendor contracts. Security tracks perimeter tools. Engineering tracks what it built. The cryptographic module layer sits underneath all of these and, in practice, it is frequently undocumented.
A credible gap analysis starts by constructing a module register: an auditable record of every cryptographic module in the environment, mapped to its CMVP certificate number, validation status, security level, and firmware version. Without this register, any migration plan is speculative.
SITG-Consulting's FIPS 140-3 Thematic Review, published in July 2026 and revised in September 2026, tracked the active FIPS 140-3 certificate landscape across HSMs, software libraries, authentication devices, and embedded modules. That review identified 16 PQC-in-boundary certificates, five Level 3 HSMs, and four software lineages with post-quantum algorithm support already validated. The gap between what is available in the market and what is deployed in a given organisation is precisely what a FIPS 140-3 gap analysis quantifies.
The Structural Difference Between a Checklist and a Gap Analysis
Procurement teams and auditors frequently treat FIPS validation as a binary state: the module is validated, or it is not. This framing obscures the structural risks that a proper gap analysis is designed to surface.
A FIPS 140-3 certificate is bound to a specific firmware version, a defined module boundary, and a set of approved algorithms. Change the firmware, extend the boundary, or introduce a new algorithm, and the certificate no longer covers what is deployed. The version rigidity problem is well documented: vendors release security patches that technically invalidate the certified configuration, leaving operators to choose between a validated but unpatched module and a patched but uncertified one.
A genuine FIPS 140-3 gap analysis examines several structural dimensions: certificate-to-deployment mapping (does the deployed firmware match the validated version, and if not, does the vendor have a re-validation in the CMVP queue?); algorithm inventory (which approved algorithms will require replacement under CNSA 2.0 timelines, given that a module validated with RSA-2048 and ECDSA P-256 will need a PQC migration pathway regardless of FIPS status?); boundary definition (does the module boundary in the security policy match the operational deployment?); entropy source verification (FIPS 140-3 requires SP 800-90B compliance, and the gap analysis must confirm the entropy source has been assessed independently); and lifecycle evidence, since FIPS 140-3 aligns with ISO/IEC 19790:2012 and demands auditable documentation of key management, module installation, and operational guidance.
What a FIPS 140-3 Gap Analysis Is Not
It is not a penetration test. It is not a compliance checkbox. It is not a vendor assessment of their own product. A gap analysis conducted by the party that built the module, or by the reseller that sold it, carries an inherent conflict of interest. Independent assessment, conducted by a party with no commercial relationship to the module under review, is the only configuration that produces findings the board can rely on.
From Gap Analysis to Governance
The output of a FIPS 140-3 gap analysis is not a pass/fail report. It is a structured remediation roadmap that connects cryptographic module status to procurement decisions, vendor management, and migration timelines.
For organisations subject to DORA, NIS2, or sector-specific regulation referencing NIST standards, the gap analysis provides the evidence base for regulatory correspondence. For those pursuing or maintaining FedRAMP authorisation, it identifies which modules require urgent re-validation and which vendors have submissions already in the CMVP queue.
Where modules hold historical FIPS 140-2 certificates with no 140-3 submission in progress, the gap analysis should trigger a vendor engagement protocol: contractual commitments for re-validation, defined timelines, and fallback procurement options where the vendor cannot deliver.
For organisations that have not yet begun post-quantum migration planning, the gap analysis serves a dual purpose. It establishes the cryptographic module baseline that any PQC readiness assessment requires. SITG-Consulting's PQC Readiness Assessment builds on exactly this foundation, extending the module register into algorithm-level exposure mapping and CNSA 2.0 alignment.
The Window Is Open, but Narrowing
The September 2026 deadline has passed. Modules that held FIPS 140-2 certificates are now historical. The regulatory and procurement consequences will unfold over the coming months as audit cycles catch up with the new reality.
Organisations that will navigate this transition with the least disruption are those that have already conducted a structured gap analysis: they know what is deployed, they know what has lapsed, and they hold a remediation plan tied to vendor commitments and regulatory timelines.
SITG-Consulting provides independent FIPS 140-3 gap analysis as a standalone engagement and as a component of broader cryptographic governance programmes. The thematic reviews published by SITG-Consulting track the FIPS 140-3 validation landscape in near real-time, providing the market intelligence that grounds every gap analysis in current data.
For organisations that need to understand their exposure, the first step is straightforward: build the register. Everything else follows from there.
Author: Brian Couzens




Comments