808bits

Apple CoreCrypto Kernel Module v9.0 for ARM

FIPS 140-2 certificate #3438 · Apple Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS Mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3438
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorApple Inc. · website
Software versions9.0

Module description

The Apple CoreCrypto Kernel Module v9.0 for ARM is a software cryptographic module running on a multi-chip standalone hardware device and provides services intended to protect data in transit and at rest.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • iOS 12 running on iPad Air 2 with Apple A8X CPU with PAA
  • iOS 12 running on iPad Air 2 with Apple A8X CPU without PAA
  • iOS 12 running on iPad Pro with Apple A10X Fusion CPU with PAA
  • iOS 12 running on iPad Pro with Apple A10X Fusion CPU without PAA
  • iOS 12 running on iPad Pro with Apple A12X Bionic CPU with PAA
  • iOS 12 running on iPad Pro with Apple A12X Bionic CPU without PAA
  • iOS 12 running on iPad Pro with Apple A9X CPU with PAA
  • iOS 12 running on iPad Pro with Apple A9X CPU without PAA
  • iOS 12 running on iPhone 5S with Apple A7 CPU with PAA
  • iOS 12 running on iPhone 5S with Apple A7 CPU without PAA
  • iOS 12 running on iPhone 6 (iPhone 6 and iPhone 6 Plus) with Apple A8 CPU with PAA
  • iOS 12 running on iPhone 6 (iPhone 6 and iPhone 6 Plus) with Apple A8 CPU without PAA
  • iOS 12 running on iPhone 6S (iPhone 6S and iPhone 6S Plus) with Apple A9 CPU with PAA
  • iOS 12 running on iPhone 6S (iPhone 6S and iPhone 6S Plus) with Apple A9 CPU without PAA
  • iOS 12 running on iPhone 7 (iPhone 7 and iPhone 7 Plus) with Apple A10 Fusion CPU with PAA
  • iOS 12 running on iPhone 7 (iPhone 7 and iPhone 7 Plus) with Apple A10 Fusion CPU without PAA
  • iOS 12 running on iPhone 8 (iPhone 8, iPhone 8 Plus) and iPhone X with Apple A11 Bionic CPU with PAA
  • iOS 12 running on iPhone 8 (iPhone 8, iPhone 8 Plus) and iPhone X with Apple A11 Bionic CPU without PAA
  • iOS 12 running on iPhone XS (iPhone XR, iPhone XS and iPhone XS Max) with Apple A12 Bionic CPU with PAA
  • iOS 12 running on iPhone XS (iPhone XR, iPhone XS and iPhone XS Max) with Apple A12 Bionic CPU without PAA
  • tvOS 12 running on Apple TV 4K with Apple A10X Fusion CPU with PAA
  • tvOS 12 running on Apple TV 4K with Apple A10X Fusion CPU without PAA
  • TxFW 16P374 running on Apple iMac Pro with Apple T2 with PAA
  • TxFW 16P374 running on Apple iMac Pro with Apple T2 without PAA
  • TxFW 16P374 running on Apple MacBook Pro with Apple T2 with PAA
  • TxFW 16P374 running on Apple MacBook Pro with Apple T2 without PAA (single-user mode)
  • watchOS 5 running on Apple Watch Series 1 with Apple S1P CPU with PAA
  • watchOS 5 running on Apple Watch Series 1 with Apple S1P CPU without PAA
  • watchOS 5 running on Apple Watch Series 3 with Apple S3 CPU with PAA
  • watchOS 5 running on Apple Watch Series 3 with Apple S3 CPU without PAA
  • watchOS 5 running on Apple Watch Series 4 with Apple S4 CPU with PAA
  • watchOS 5 running on Apple Watch Series 4 with Apple S4 CPU without PAA

Validation history

DateTypeLab
2019-04-23Initialatsec information security corporation
2021-03-11Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-04-23, 2021-03-11

Source documents