808bits

IBM® z/OS® Version 2 Release 1 ICSF PKCS #11 Cryptographic Module

FIPS 140-2 certificate #2763 · IBM® Corporation · data as of 2026-09-15

IBM® z/OS® Version 2 Release 1 ICSF PKCS #11 Cryptographic Module, from IBM® Corporation, holds FIPS 140-2 certificate #2763 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. 186-2 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module IBM(R) z/OS(R) Version 2 Release 1 Security Server RACF(R) Signature Verification Module version 1.0 validated to FIPS 140-2 under Cert. #2691 operating in FIPS mode

Certificate

Certificate number2763
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM® Corporation · website
Software versionsOA50113
Hardware versionsCOP chips integrated within processor unit [1] and P/N 00LV487 [2]
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 22H [1] and CCA 5.2.27z RC30 [2]

Module description

Quoted from the NIST CMVP entry for this certificate.

ICSF is a software element of z/OS that works with hardware cryptographic features and the Security Server (RACF) to provide secure, high-speed cryptographic services in the z/OS environment. ICSF, which runs as a started task, provides the application programming interfaces by which applications request the cryptographic services.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AES3958, 4036
CVL882, 883
DRBG1206, 1212
DSA1092, 1097
ECDSA901
HMAC2633
KTS
RSA2070, 2088
SHS3196, 3327
Triple-DES2214

Other algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • IBM z/OS Version 2 Release 1 running on an IBM z13 (single-user mode)

Validation history

DateTypeLab
2016-10-06Initialatsec information security corporation
2018-02-20Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-10-06, 2018-02-20

Source documents