Important News:SafeLogic's CryptoComply Achieves FIPS 140-3 Validation for 28 OEs and Receives Certificate #4781! Read the blog post!
The SafeLogic Blog
NIST and the Federal Shutdown
October 10, 2013 •Walt Paley
If you’ve been to the NIST site lately, you saw this.
Two weeks into the federal government shutdown, the debt ceiling is looming and your guess is as good as mine what will happen next. It doesn’t matter which side of the aisle you’re on, because we are all annoyed, aggravated, and disappointed. What we do know is that the shutdown has already furloughed NIST employees and all of us are going to suffer the consequences.
Apparently national data security is non-essential. NIST employees were sent home and both the CAVP and CMVP have suspended validation activity. Employees are legally barred from using government-issued devices to check e-mail or do any work while on furlough, so if you need anything, your only option is to contact CSEC, NIST’s Canadian counterpart and cooperating partner in the CAVP and CMVP programs. The bad news? CSEC cannot complete any validations without a NIST representative present.
Others have illustrated this shutdown as a mild inconvenience, or a minor pain because you cannot access the In Process List on the website or download a form. I’m sorry to say that it is much, much more than that.
For those of you who are about to begin the process, you’ll quickly find out that without validation of your encryption algorithms, you won’t get very far. Good luck with that, since CAVP workers are furloughed. Once NIST re-opens, you can bet that the rush to submit to the CAVP queue will be significant. It’s going to be a total crapshoot where you land in the queue, and you’re as likely to have to wait a couple months as a few weeks.
Then, and only then, can you submit your complete documentation to the CMVP. You can forget about competing with the Black Friday-style rush of submissions on their first day open, because you’re still twiddling your thumbs and waiting for the CAVP. No, you can be sure that you’ll be buried at the bottom of the pile, behind the incredibly long queue that was already in process on September 30th. You can add all the folks who will complete their lab testing and submit on the first day open. It’s going to be ugly.
If you’ve already received your CAVP validations, then congrats! You only have to deal with one swarm of submissions, instead of two. Since we don’t know when NIST will re-open, the pressure is on. Every day that the CMVP is closed, the number of prepared submissions rises, and you better believe that you’ll want to be among those accepted by CMVP on their first day back. If you’re not, prepare for an extra long wait. The queue will be particularly impacted.
I hope you’re not completely discouraged, because we’ve got plenty of good news for you. For example, CryptoComply offers immediate drop-in compliance. For many enterprise buyers, a letter of confirmation that you are leveraging our validated module will satisfy their internal FIPS mandate.
Instant compliance – that’s tough to beat, especially when things at NIST are as far as possible from instant. Give us a call.
Walt Paley
Walter Paley is the VP of Communications for SafeLogic. He is responsible for strategy, content, marketing, and outreach. Walt has worked with a series of start-ups and companies in growth stages, including Nukona (acquired by Symantec), Qubole, Bitzer Mobile (acquired by Oracle), and TigerText, among others. An Alumnus of the psychology program at UC San Diego, Walt lives in Southern California with his wife, kids, and their black lab, Echo.
Popular Posts
Search for posts
Tags
- FIPS 140 (111)
- FIPS validation (85)
- Encryption (70)
- cryptography (68)
- NIST (62)
- CryptoComply (60)
- SafeLogic (58)
- Industry News (54)
- cryptographic module (51)
- Conversations (49)
- CMVP (48)
- RapidCert (46)
- compliance (41)
- Ray Potter (33)
- SafeLogic News (33)
- Event (27)
- federal (27)
- CAVP (23)
- Cybersecurity (23)
- FIPS 140-3 (18)
- OpenSSL (16)
- government (14)
- FedRAMP (13)
- CryptoCompact (12)
- Cryptology (12)
- DoD (12)
- RSA (12)
- healthcare (12)
- partners (12)
- NSA (11)
- post-quantum cryptography (11)
- Cloud (9)
- PQC (9)
- security (9)
- CMMC (8)
- Suite B (8)
- testing (8)
- whitepaper (8)
- Approved Products List (APL) (6)
- HITECH (6)
- ICMC (6)
- lab (6)
- CEO (5)
- NIST 800-171 (5)
- NIST 800-53 (5)
- OpenSSL 3.0 (5)
- iOS (5)
- procurement (5)
- C3PAO (4)
- Common Criteria (4)
- HITECH Act (4)
- deadline (4)
- encrypt (4)
- innovation (4)
- procure (4)
- public sector (4)
- Air Force (3)
- BSAFE (3)
- DFARS (3)
- HIPAA Safe Harbor (3)
- HITECH Safe Harbor (3)
- OpenSSL 1.1.1 (3)
- OpenSSL 3.x (3)
- POA&M (3)
- TLS 1.3 (3)
- magazine (3)
- queue (3)
- transition (3)
- 3PAO (2)
- ACVP (2)
- BAA (2)
- CIO (2)
- CSP (2)
- Cyber Defense Magazine (2)
- Defense Industrial Base (2)
- HIPAA security controls (2)
- Historical Status (2)
- MFA (2)
- OpenSSL 1.0.2 (2)
- SPRS (2)
- StateRAMP (2)
- entropy (2)
- excellence (2)
- finance (2)
- founder (2)
- gold (2)
- leader (2)
- maturity (2)
- overlap (2)
- pilot (2)
- rsa conference (2)
- solution (2)
- sponsors (2)
- sunset (2)
- vendor (2)
- year (2)
- Active Status (1)
- Alliance for Digital Innovation (1)
- Android (1)
- CIO Prime Views (1)
- DHS (1)
- DIU (1)
- DIUx (1)
- DOJ (1)
- DoDIN APL (1)
- Entropy Source Validation (1)
- FCA (1)
- FIPS Compliance (1)
- FISMA (1)
- GSA (1)
- HITRUST (1)
- Matt Cornelius (1)
- Matthew Cornelius (1)
- Maturity Model (1)
- NCCoE (1)
- OMB (1)
- SLED (1)
- SP800-131A (1)
- SP800-90A (1)
- TLS 1.1 (1)
- background (1)
- best (1)
- co-founder (1)
- codies (1)
- congress (1)
- cybertech (1)
- education (1)
- elliptic curve cryptography (1)
- extended (1)
- faq (1)
- fintech (1)
- fiscal (1)
- fiscal year (1)
- fraud (1)
- globee (1)
- hill (1)
- interview (1)
- kratos (1)
- libgcrypt (1)
- national cybersecurity strategy (1)
- opportunities (1)
- parallel (1)
- profile (1)
- public (1)
- representatives (1)
- reseller (1)
- senate (1)
- senators (1)
- simplify (1)
- state (1)
- stealth mode (1)
- story (1)
- terminology (1)
- trophy (1)
- whistleblower (1)
- whistleblowing (1)