top of page

FIPS 140-3 Gap Analysis: fix the module before the lab, not after

  • Writer: Brian Couzens
    Brian Couzens
  • 11 minutes ago
  • 2 min read

For many years we have run cryptographic module readiness reviews inside larger governance and assurance engagements. It was never a named line item. It was the work done before a vendor spent money at a testing laboratory, so the money was not wasted. We have now formalised it as a defined service: the SITG FIPS 140-3 Gap Analysis.

The context is a hard deadline. FIPS 140-2 certificates sunset on 21 September 2026 and move to the Historical List. From that date, a module without an active FIPS 140-3 certificate is legacy for new public sector procurement. A self-attested "FIPS compliant" claim carries no standing. Vendors selling into US or Canadian federal and regulated markets need an independent validation certificate, and the route to one is constrained: NVLAP paused new testing-laboratory accreditations while demand rises into the deadline.

That constraint is the reason to review a module before it reaches a lab, not during. Each non-conformance found early is one fewer round trip through a queue that is already full, and one fewer unbudgeted cost.

The service is independent and pre-lab. We assess the module against ISO/IEC 19790:2012, ISO/IEC 24759:2017 and the SP 800-140 series across three areas: documentation and cryptographic boundary review; cryptographic inventory and entropy source readiness, including SP 800-90B; and a final gap report with a submission strategy. The output is a written readiness verdict, a documentation deficiency audit, boundary verification, and a non-compliance matrix prioritised by what blocks submission, what to fix first, and what can run in parallel with the lab.

Formalising it changes three things for a client. Scope is fixed, not absorbed into a broader engagement. The deliverable is a single readiness report a board or a laboratory intake team can read directly. And the verdict is explicit: Ready, Conditional, or Not Ready, with named fixes against each finding. It applies to hardware, firmware, software and hybrid modules, from silicon and HSMs to VPN and platform crypto.

One point of governance, stated plainly. SITG is not an NVLAP-accredited testing laboratory and does not issue certificates. That separation is deliberate. It removes the conflict of a firm marking its own remediation, and it keeps our verdict an independent second opinion that lowers risk before the formal clock starts. It is not a substitute for the lab that grants the certificate.

If you hold FIPS 140-2 modules, or you are preparing a first 140-3 submission, the window to act without a queue penalty is closing. An independent readiness review now is the difference between a clean submission and costly re-work later.

Details and intake: FIPS 140-3 Gap Analysis | Sitg-Consulting



 
 
 

Comments


bottom of page