808bits

Apple macOS CoreCrypto Module, v7.0

FIPS 140-2 certificate #2832 · Apple Inc. · data as of 2026-09-15

Apple macOS CoreCrypto Module, v7.0, from Apple Inc., holds FIPS 140-2 certificate #2832 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2832
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorApple Inc. · website
Software versions7.0

Module description

Quoted from the NIST CMVP entry for this certificate.

The Apple macOS CoreCrypto Module is a software cryptographic module running on a multi-chip standalone mobile device and provides services intended to protect data in transit and at rest.

Security level exceptions

  • Physical Security: N/A

Approved algorithms (10)

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 160 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength; non-compliant less than 112 bits of encryption strength); AES (non-compliant); ANSI X9.63 KDF; Blowfish; CAST5; DES; ECDSA (non-compliant); Ed25519; Hash_DRBG (non-compliant); Integrated Encryption Scheme on elliptic curves; KBKDF (non-compliant); MD2; MD4; MD5; OMAC (One-Key CBC MAC); RC2; RC4; RFC6637 KDF; RIPEMD; RSA (non-compliant); SP800-56C KDF (non-compliant); Triple-DES (non-compliant)

Tested configurations

  • macOS Sierra v10.12.2 running on Mac mini with i5 CPU with PAA
  • macOS Sierra v10.12.2 running on Mac mini with i5 CPU without PAA
  • macOS Sierra v10.12.2 running on MacBook Pro with i7 CPU with PAA
  • macOS Sierra v10.12.2 running on MacBook Pro with i7 CPU without PAA
  • macOS Sierra v10.12.2 running on MacBook with Core M CPU with PAA
  • macOS Sierra v10.12.2 running on MacBook with Core M CPU without PAA (single-user mode)
  • macOS Sierra v10.12.2 running on MacPro with Xeon CPU with PAA
  • macOS Sierra v10.12.2 running on MacPro with Xeon CPU without PAA

Validation history

DateTypeLab
2017-02-02Initialatsec information security corporation
2021-03-11Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-02-02, 2021-03-11

Source documents