808bits

CoSign

FIPS 140-2 certificate #1422 · ARX (Algorithmic Research) · data as of 2026-09-03

CoSign, from ARX (Algorithmic Research), holds FIPS 140-2 certificate #1422 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1422
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-chip standalone
VendorARX (Algorithmic Research) · website
Hardware versions7.0
Firmware versions5.2 and 6.0

Module description

Quoted from the NIST CMVP entry for this certificate.

CoSign is a digital signature appliance that is connected to the organizational network and manages all signature keys and certificates of organization's end-users. End-users will connect securely to CoSign from their PC for the purpose of signing documents and data.

Approved algorithms (6)

AlgorithmCAVP certificates
HMAC799, 1405
RNG750, 1139
RSA665, 1177
SHS1244, 1245, 1970, 1971
Triple-DES939, 940, 1437, 1438
Triple-DES MACvendor affirmed

Other algorithms

MD5; RSA (key wrapping; key establishment methodology provides 80 bits of encryption strength; non-compliant)

Validation history

DateTypeLab
2010-10-25InitialCYGNACOM SOLUTIONS INC
2013-01-22UpdateCYGNACOM SOLUTIONS INC

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2010-10-25, 2013-01-22

Source documents