808bits

Veeam Cryptographic Module

FIPS 140-2 certificate #2872 · Veeam Software Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode. The module makes no assurance of the minimum strength of random strings and generated keys. This validation entry is a non-security relevant modification to Cert. #2038

Certificate

Certificate number2872
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorVeeam Software Corporation · website
Software versions2.1

Module description

The Veeam Cryptographic Module provides cryptographic functions for the Veeam Availability Suite and Veeam Agent for Mac. These functions are used for protecting data in transit and at rest using standards based and trusted algorithms.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2273
CKGvendor affirmed
DRBG281
DSA709
ECDSA368
HMAC1391
RSA1166
SHS1954
Triple-DES1420

Tested configurations

  • CentOS 6.3 on a Dell OptiPlex 755 with an Intel i7
  • Windows Server 2008 R2 on a Dell OptiPlex 755 with an Intel i7 (single-user mode)

Validation history

DateTypeLab
2017-03-30InitialAcumen Security
2021-08-10UpdateAEGISOLVE, Inc.
2021-12-21UpdateAEGISOLVE, Inc.
2023-11-03UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2017-03-30, 2021-08-10, 2021-12-21, 2023-11-03

Source documents