Secure Kernel Code Integrity (skci.dll) in Microsoft Windows 10 Enterprise, Windows 10 Enterprise LTSB
Caveat: When operated in FIPS mode with the module Code Integrity (ci.dll) in Microsoft Windows 10, Windows 10 Pro, Windows 10 Enterprise, Windows 10 Enterprise LTSB, Windows 10 Mobile, Windows 10 for Surface Hub under Cert. #2604 operating in FIPS mode or Code Integrity (ci.dll) in Microsoft Windows Enterprise LTSB under Cert. #3437 operating in FIPS mode
Certificate
| Certificate number | 2607 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Microsoft Corporation · website |
| Software versions | 10.0.10240 [1], 10.0.10240.17643 [2], 10.0.10586 [3] |
Module description
Secure Kernel Code Integrity (SKCI) running in the Virtual Secure Mode (VSM) of the Hyper-V hypervisor will only grant execute access to physical pages in the kernel that have been successfully verified. Executable pages will not have write permission outside of Hyper-V. Therefore, only verified code can be executed.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 2
Approved algorithms
Tested configurations
- Windows 10 Enterprise (x64) running on a HP Compaq Pro 6305 with PAA [1][3]
- Windows 10 Enterprise (x64) running on a Microsoft Surface 3 with PAA [1][3]
- Windows 10 Enterprise (x64) running on a Microsoft Surface Book with PAA [3]
- Windows 10 Enterprise (x64) running on a Microsoft Surface Pro 2 with PAA [1][3]
- Windows 10 Enterprise (x64) running on a Microsoft Surface Pro 3 with PAA [1][3]
- Windows 10 Enterprise (x64) running on a Microsoft Surface Pro 4 with PAA [3]
- Windows 10 Enterprise (x64) running on a Microsoft Surface Pro with PAA [1][3]
- Windows 10 Enterprise (x86) running on a Dell Inspiron 660s without PAA [1][3]
- Windows 10 Enterprise LTSB (x64) running on a Dell XPS 8700 with PAA [1][2]
- Windows 10 Enterprise LTSB (x64) running on a HP Compaq Pro 6305 with PAA [1][2]
- Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface 3 with PAA [2]
- Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface Pro 2 with PAA [2]
- Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface Pro 3 with PAA [2]
- Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface Pro with PAA [2] (single-user mode)
- Windows 10 Enterprise LTSB (x86) running on a Dell Inspiron 660s without PAA [1][2]
Validation history
| Date | Type | Lab |
|---|---|---|
| 2016-06-02 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
| 2016-08-26 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
| 2019-04-30 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2016-06-02, 2016-08-26, 2019-04-30