808bits

fips 140-3 and 140-2 certificate tracker

Every NIST CMVP FIPS 140 certificate as a fast, linkable page. Status moves are derived by diffing snapshots of the NIST lists, which NIST itself does not date. Data as of 2026-09-15.

5515 certificates
1188 active (705 on 140-3, 483 on 140-2)
4302 historical
25 revoked
Of the 1188 active certificates, 483 still validate against FIPS 140-2. All 483 move to the historical list on 2026-09-21, 5 days from now; the rest are FIPS 140-3 and sunset five years after their own validation dates. See the full list.

recent changes rss

  1. 2026-09-15 DigiCert TrustCore NanoCrypto Module (DigiCert, Inc.) left the implementation-under-test list
  2. 2026-09-15 Apple corecrypto Module OS 26 [Apple Silicon, Secure Key... (Apple Inc.) left the implementation-under-test list
  3. 2026-09-15 Micron® MSA11-P5 Controller Sub Chip Security Subsystem (Micron Technology, Inc.) left the modules-in-process list
  4. 2026-09-15 SUSE Linux Enterprise Libica Cryptographic Module (SUSE, LLC) moved from Comment Resolution - Lab to Comment Resolution - CMVP
  5. 2026-09-15 NVIDIA Vera PSC Cryptographic Module (NVIDIA Corporation) moved from Pending Review to Review
  6. 2026-09-15 Google Kernel Cryptographic Module (Google, LLC) moved from Pending Review to Review
  7. 2026-09-15 DigiCert TrustCore NanoCrypto Module (DigiCert, Inc.) entered the modules-in-process list
  8. 2026-09-15 Apple corecrypto Module OS 26 [Apple Silicon, Secure Key... (Apple Inc.) entered the modules-in-process list
  9. 2026-09-15 Amazon Linux 2023 Kernel Cryptographic API (Amazon Web Services, Inc.) moved from Pending Review to Review
  10. 2026-09-14 Android Kernel Cryptographic Module (Google, LLC) moved from Cost Recovery to Pending Review

cve cross-reference

16 certificates have high-confidence CVE associations in their module family, matched heuristically against NVD. How matching works and what it does not claim.

  1. 4109 3 CVEs Purity Encryption Module Pure Storage, Inc.
  2. 4150 12 CVEs Intel® Converged Security and Manageability Engine (CSME)... Intel Corporation
  3. 4158 12 CVEs Cryptographic Module for Intel® Converged Security and... Intel Corporation
  4. 4273 1 CVE Microsoft Azure Networking Adapter Kernel Microsoft Corporation
  5. 4282 37 CVEs OpenSSL FIPS Provider The OpenSSL Project
  6. 4361 16 CVEs FortiAnalyzer 6.2 Fortinet, Inc.
  7. 4362 17 CVEs FortiManager 6.2 Fortinet, Inc.
  8. 4404 1 CVE IBM Cloud Object Storage System’s™ FIPS Cryptographic Module IBM Corporation
  9. 4493 1 CVE Oracle Cloud Infrastructure for BoringCrypto Oracle Corporation
  10. 4641 1 CVE SonicWall Network Security Manager Appliance SonicWall, Inc.
  11. 4669 1 CVE RapidIdentity FIPS Cryptographic Module Identity Automation
  12. 4811 37 CVEs OpenSSL FIPS Provider The OpenSSL Project
  13. 4867 1 CVE Forcepoint Next Generation Firewall Forcepoint
  14. 4937 3 CVEs Purity Encryption Module Pure Storage, Inc.
  15. 4968 4 CVEs SUSE Rancher Kubernetes Cryptographic Library SUSE LLC
  16. 5032 36 CVEs Intel® QuickAssist Technology (QAT) Provider Intel Corporation

reading

What each FIPS 140-3 level actually requires, with the certificate counts behind it, and why a validated module is not a safe one: ROCA, EUCLEAK, and a YubiKey flaw caused by the FIPS self-tests themselves.

browse

  1. f012026-09-21The FIPS 140-2 sunset483 active certificates and counting down
  2. f02Certificate status changesobserved moves to historical, revocations, new validations
  3. f03Modules in processthe validation queue, phase by phase
  4. f04Implementations under testmodules in lab testing, before submission
  5. f05Vendorsevery vendor and their certificates
  6. f06FIPS 140-3 modules787 certificates, and why level 4 is empty
  7. f07FIPS 140-2 modules483 still active, all sunsetting on 2026-09-21
  8. f08Hardware security moduleswhere level 3 and level 4 actually live
  9. f09Drives, SSDs and storageself-encrypting drives, and the level they really hold
  10. f10Software modulesthe largest category, and the one level 3 never reaches
  11. f11The tracker as an MCP serverquery all of this from Claude or any MCP client
  12. f12About this trackersources, cadence, methodology, what we leave out