U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

White Paper (Draft)

[Project Description] Automation of the Cryptographic Module Validation Program (CMVP)

Date Published: April 12, 2021
Comments Due: May 12, 2021 (public comment period is CLOSED)
Email Questions to: applied-crypto-testing@nist.gov


Apostol Vassilev (NIST), Chris Celi (NIST), Gavin O'Brien (NIST), Murugiah Souppaya (NIST), William Barker (Dakota Consulting)


The National Cybersecurity Center of Excellence (NCCoE) has released a new draft project description, Automation of the Cryptographic Module Validation Program (CMVP). Publication of this project description begins a process to further identify project requirements, scope, and hardware and software components for use in a laboratory environment.

The NCCoE will solicit participation from industry to demonstrate first-party and third-party tests and test tools for automation of the CMVP, as well as first-party processes and means for communicating the results to NIST. Increased automation is necessary because a number of elements of the current validation processes are manual in nature, making third-party testing and government validation of cryptographic modules often incompatible with industry requirements. In addition to demonstrating tests, tools, and processes, this project will also result in practice descriptions in the form of white papers, playbook generation, and implementation demonstrations, which aim to improve the ability and efficiency of organizations.

The public comment period for this draft is open through May 12, 2021. You can also help shape and contribute to this project. Join the Community of Interest by sending an email to applied-crypto-visibility@nist.gov.



automated cryptographic validation (ACV); Automated Cryptographic Validation Protocol (ACVP); Cryptographic Algorithm Validation Program (CAVP); Cryptographic Module Validation Program (CMVP); cryptography; first-party testing; Implementation Under Test (IUT); National Voluntary Laboratory Accreditation Program (NVLAP); third-party testing
Control Families

None selected


Draft Project Description

Supplemental Material:
Submit comments (web)
Project homepage (web)

Document History:
04/12/21: White Paper (Draft)
07/01/21: White Paper (Final)


Security and Privacy
cryptography; testing & validation