808bits

Secure Kernel Code Integrity (skci.dll) in Microsoft Windows 10 Enterprise, Windows 10 Enterprise LTSB

FIPS 140-2 certificate #2607 · Microsoft Corporation · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #2604. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with the module Code Integrity (ci.dll) in Microsoft Windows 10, Windows 10 Pro, Windows 10 Enterprise, Windows 10 Enterprise LTSB, Windows 10 Mobile, Windows 10 for Surface Hub under Cert. #2604 operating in FIPS mode or Code Integrity (ci.dll) in Microsoft Windows Enterprise LTSB under Cert. #3437 operating in FIPS mode

Certificate

Certificate number2607
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorMicrosoft Corporation · website
Software versions10.0.10240 [1], 10.0.10240.17643 [2], 10.0.10586 [3]

Module description

Secure Kernel Code Integrity (SKCI) running in the Virtual Secure Mode (VSM) of the Hyper-V hypervisor will only grant execute access to physical pages in the kernel that have been successfully verified. Executable pages will not have write permission outside of Hyper-V. Therefore, only verified code can be executed.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
RSA1784, 1871, 2829
SHS2871, 3048, 4249

Tested configurations

  • Windows 10 Enterprise (x64) running on a HP Compaq Pro 6305 with PAA [1][3]
  • Windows 10 Enterprise (x64) running on a Microsoft Surface 3 with PAA [1][3]
  • Windows 10 Enterprise (x64) running on a Microsoft Surface Book with PAA [3]
  • Windows 10 Enterprise (x64) running on a Microsoft Surface Pro 2 with PAA [1][3]
  • Windows 10 Enterprise (x64) running on a Microsoft Surface Pro 3 with PAA [1][3]
  • Windows 10 Enterprise (x64) running on a Microsoft Surface Pro 4 with PAA [3]
  • Windows 10 Enterprise (x64) running on a Microsoft Surface Pro with PAA [1][3]
  • Windows 10 Enterprise (x86) running on a Dell Inspiron 660s without PAA [1][3]
  • Windows 10 Enterprise LTSB (x64) running on a Dell XPS 8700 with PAA [1][2]
  • Windows 10 Enterprise LTSB (x64) running on a HP Compaq Pro 6305 with PAA [1][2]
  • Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface 3 with PAA [2]
  • Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface Pro 2 with PAA [2]
  • Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface Pro 3 with PAA [2]
  • Windows 10 Enterprise LTSB (x64) running on a Microsoft Surface Pro with PAA [2] (single-user mode)
  • Windows 10 Enterprise LTSB (x86) running on a Dell Inspiron 660s without PAA [1][2]

Validation history

DateTypeLab
2016-06-02InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-08-26UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2019-04-30UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-06-02, 2016-08-26, 2019-04-30

Source documents