Zscaler Mobile Cryptographic Module
Caveat: When operated in FIPS mode. The module makes no assurance of the minimum strength of random strings and generated keys. This validation entry is a non-security-relevant modification to Cert. #1938.
Certificate
| Certificate number | 3154 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Zscaler Inc. · website |
| Software versions | 2.1 |
Module description
The Zscaler Mobile Cryptographic Module offloads functions for secure key management, data integrity, data at rest encryption, and secure communications to a trusted implementation.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 2125, 2126 |
| CKG | vendor affirmed |
| DRBG | 233, 234 |
| DSA | 666, 667 |
| ECDSA | 319, 320 |
| HMAC | 1296, 1297 |
| RSA | 1094, 1095 |
| SHS | 1849, 1850 |
| Triple-DES | 1351, 1352 |
Tested configurations
- Android 4.0 running on a Galaxy Nexus
- iOS 5.1 running on a iPad 3
- iOS 6 running on a iPad 3
- iOS 7 running on a iPad 3 (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2018-03-19 | Initial | Acumen Security |
| 2022-03-09 | Update | AEGISOLVE, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2018-03-19, 2022-03-09