fips 140-3 and 140-2 certificate tracker
Every NIST CMVP FIPS 140 certificate as a fast, linkable page. Status moves are derived by diffing snapshots of the NIST lists, which NIST itself does not date. Data as of 2026-09-15.
5515 certificates
1188 active (705 on 140-3, 483 on 140-2)
4302 historical
25 revoked
recent changes rss
- 2026-09-15 DigiCert TrustCore NanoCrypto Module (DigiCert, Inc.) left the implementation-under-test list
- 2026-09-15 Apple corecrypto Module OS 26 [Apple Silicon, Secure Key... (Apple Inc.) left the implementation-under-test list
- 2026-09-15 Micron® MSA11-P5 Controller Sub Chip Security Subsystem (Micron Technology, Inc.) left the modules-in-process list
- 2026-09-15 SUSE Linux Enterprise Libica Cryptographic Module (SUSE, LLC) moved from Comment Resolution - Lab to Comment Resolution - CMVP
- 2026-09-15 NVIDIA Vera PSC Cryptographic Module (NVIDIA Corporation) moved from Pending Review to Review
- 2026-09-15 Google Kernel Cryptographic Module (Google, LLC) moved from Pending Review to Review
- 2026-09-15 DigiCert TrustCore NanoCrypto Module (DigiCert, Inc.) entered the modules-in-process list
- 2026-09-15 Apple corecrypto Module OS 26 [Apple Silicon, Secure Key... (Apple Inc.) entered the modules-in-process list
- 2026-09-15 Amazon Linux 2023 Kernel Cryptographic API (Amazon Web Services, Inc.) moved from Pending Review to Review
- 2026-09-14 Android Kernel Cryptographic Module (Google, LLC) moved from Cost Recovery to Pending Review
cve cross-reference
16 certificates have high-confidence CVE associations in their module family, matched heuristically against NVD. How matching works and what it does not claim.
- 4109 3 CVEs Purity Encryption Module Pure Storage, Inc.
- 4150 12 CVEs Intel® Converged Security and Manageability Engine (CSME)... Intel Corporation
- 4158 12 CVEs Cryptographic Module for Intel® Converged Security and... Intel Corporation
- 4273 1 CVE Microsoft Azure Networking Adapter Kernel Microsoft Corporation
- 4282 37 CVEs OpenSSL FIPS Provider The OpenSSL Project
- 4361 16 CVEs FortiAnalyzer 6.2 Fortinet, Inc.
- 4362 17 CVEs FortiManager 6.2 Fortinet, Inc.
- 4404 1 CVE IBM Cloud Object Storage System’s™ FIPS Cryptographic Module IBM Corporation
- 4493 1 CVE Oracle Cloud Infrastructure for BoringCrypto Oracle Corporation
- 4641 1 CVE SonicWall Network Security Manager Appliance SonicWall, Inc.
- 4669 1 CVE RapidIdentity FIPS Cryptographic Module Identity Automation
- 4811 37 CVEs OpenSSL FIPS Provider The OpenSSL Project
- 4867 1 CVE Forcepoint Next Generation Firewall Forcepoint
- 4937 3 CVEs Purity Encryption Module Pure Storage, Inc.
- 4968 4 CVEs SUSE Rancher Kubernetes Cryptographic Library SUSE LLC
- 5032 36 CVEs Intel® QuickAssist Technology (QAT) Provider Intel Corporation
reading
What each FIPS 140-3 level actually requires, with the certificate counts behind it, and why a validated module is not a safe one: ROCA, EUCLEAK, and a YubiKey flaw caused by the FIPS self-tests themselves.
browse
- f012026-09-21The FIPS 140-2 sunset483 active certificates and counting down
- f02Certificate status changesobserved moves to historical, revocations, new validations
- f03Modules in processthe validation queue, phase by phase
- f04Implementations under testmodules in lab testing, before submission
- f05Vendorsevery vendor and their certificates
- f06FIPS 140-3 modules787 certificates, and why level 4 is empty
- f07FIPS 140-2 modules483 still active, all sunsetting on 2026-09-21
- f08Hardware security moduleswhere level 3 and level 4 actually live
- f09Drives, SSDs and storageself-encrypting drives, and the level they really hold
- f10Software modulesthe largest category, and the one level 3 never reaches
- f11The tracker as an MCP serverquery all of this from Claude or any MCP client
- f12About this trackersources, cadence, methodology, what we leave out