This is a potential security issue, you are being redirected to https://csrc.nist.gov
Special Publications (SPs)
Security & Privacy
Laws & Regulations
Activities & Products
Computer Security Division
Applied Cybersecurity Division
Date Published: March 22, 2019
Planning Note (5/1/2019):
See the FIPS 140-3 Development project for information on the Implementation Schedule and development of supporting SP 800-140x documents.
Supersedes: FIPS 140-2 (May 25, 2001 (Change Notice 2, 12/3/2002))
National Institute of Standards and Technology
The selective application of technological and related procedural safeguards is an important responsibility of every federal organization in providing adequate security in its computer and telecommunication systems. This standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106 and the Federal Information Security Management Act of 2002, Public Law 107-347.
This standard shall be used in designing and implementing cryptographic modules that federal departments and agencies operate or are operated for them under contract. The standard provides four increasing, qualitative levels of security intended to cover a wide range of potential applications and environments. The security requirements cover areas related to the secure design, implementation and operation of a cryptographic module. These areas include cryptographic module specification; cryptographic module interfaces; roles, services, and authentication; software/firmware security; operating environment; physical security; non-invasive security; sensitive security parameter management; self-tests; life-cycle assurance; and mitigation of other attacks.
FIPS 140-3 (DOI)
Cryptographic Module Validation Program (CMVP) (other)
NIST News Article (other)
Related NIST Publications:
Draft FIPS 140-3 (7/13/07)Draft FIPS 140-3 (12/11/09)FIPS 140-3 (3/22/19)
Security and Privacycryptography; testing & validation
Laws and RegulationsE-Government Act; Federal Information Security Modernization Act