NIST publicly announced this week a brand-new interim validation option whereby cryptographic modules that have been submitted to NIST’s cryptographic module validation program (CMVP) will be able to secure fast-tracked interim FIPS 140-3 validation. With a large backlog of FIPS 140-3 validations in the NIST CMVP queue, NIST is making some important structural changes to the validation process, such as rolling out automation that will make it far more efficient to identify non-conformances and thus move the review process along more quickly. Interim validation is introduced as a way to reduce the size of the current queue and to ensure that a sufficient number of modules can achieve FIPS 140-3 validation status before modules validated under FIPS 140-2 sunset and go historical.
To qualify for this interim validation, cryptographic modules submitted to NIST CMVP will need to meet very specific requirements. The following bulleted lists come verbatim from NIST’s CMVP website (https://csrc.nist.gov/projects/cryptographic-module-validation-program):
NIST CMVP will review modules for completeness and there will be a short period of coordination between NIST CMVP and the CST Lab to resolve any questions. Once the interim validation is completed:
The pursuit of the interim validation option is voluntary, and cryptographic module vendors can choose to wait for full validation without taking any action.
NIST is taking this important action after consultation with its Cryptographic and Security Testing (CST) laboratories and the cryptographic module vendor community. It was necessary to make some changes in the FIPS 140-3 validation process to meet the demand that the world has for FIPS 140-3 validated cryptographic modules, and so NIST is doing just that.
Given these new developments, it is natural that many organizations will have questions. If you find yourself having questions, please do not hesitate to reach out to us. SafeLogic is well prepared and positioned to help its customers with an orderly transition from FIPS 140-2 to FIPS 140-3 modules in a white-glove fashion. We can help your organization obtain your very own FIPS 140 certification in approximately eight weeks, then keep that certification active through all the transitions, including the FIPS 140-2 to FIPS 140-3 transition. This way, your organization can rest assured that the SafeLogic cryptography you use in your own products will meet the requirements of government agencies for both continued operation and for new procurements, giving your company a distinct competitive advantage.