808bits

Secure Kernel Code Integrity

FIPS 140-2 certificate #3651 · Microsoft Corporation · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #3615. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module Windows OS Loader validated to FIPS 140-2 under Cert. #3615 operating in FIPS mode

Certificate

Certificate number3651
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorMicrosoft Corporation · website
Software versions10.0.17763[1] and 10.0.17763.107[2]

Module description

Secure Kernel Code Integrity (SKCI) running in the Virtual Secure Mode (VSM) of the Hyper-V hypervisor will only grant execute access to physical pages in the kernel that have been successfully verified. Executable pages will not have write permission outside of Hyper-V. Therefore, only verified code can be executed.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
RSAC211, C349, C2047
SHSC211, C2047

Tested configurations

  • Azure Data Box Edge (x64) running on a Microsoft Azure Data Box with an Intel Xeon Silver without PAA[1]
  • Windows 10 Education October 2018 Update (x64) running on a Microsoft Surface Laptop with an Intel Core i5 without PAA[1]
  • Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Book 2 with an Intel Core i7 without PAA[1]
  • Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Laptop with an Intel Core i5 without PAA[1]
  • Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Pro LTE with an Intel Core i5 without PAA[1]
  • Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Studio with an Intel Core i7 without PAA[1]
  • Windows 10 Enterprise October 2018 Update (x64) running on a Samsung Galaxy Book 12" with an Intel Core i5 without PAA[1]
  • Windows 10 Enterprise October 2018 Update (x64) running on an HP EliteBook x360 1030 G2 with an Intel Core i7 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on a Dell Latitude 12 Rugged Tablet with an Intel Core i5 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on a Dell Latitude 5290 with an Intel Core i7 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Book 2 with an Intel Core i7 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Go with an Intel Pentium without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Laptop with an Intel Core i5 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Pro LTE with an Intel Core i5 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on a Samsung Galaxy Book 10.6" with an Intel Core m3 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on an HP Elite x2 1013 G3 Tablet with an Intel Core i7 without PAA[1]
  • Windows 10 Pro October 2018 Update (x64) running on an HP Slimline Desktop with an Intel Pentium with PAA[1]
  • Windows Server 2019 Core (x64) on Hyper-V on Windows Server 2016 running on a Dell PowerEdge R740 Server with an Intel Xeon Gold without PAA[1]
  • Windows Server 2019 Core (x64) on Hyper-V on Windows Server 2019 running on a Dell Precision Tower 5810MT with an Intel Xeon E5 without PAA[1]
  • Windows Server 2019 Core (x64) running on a Dell PowerEdge R740 Server with an Intel Xeon Gold without PAA[1]
  • Windows Server 2019 Datacenter Core (x64) on Hyper-V on Windows Server 2019 running on a Dell Precision Tower 5810MT with an Intel Xeon E5 without PAA[1]
  • Windows Server 2019 Datacenter Core (x64) running on a Dell PowerEdge R740 Server with an Intel Xeon Gold without PAA[1]
  • Windows Server Core Datacenter 2019 RTM (x64) running on an HPE Edgeline EL8000 / ProLiant e910 Server Blade with PAA[2] (single-user mode)

Validation history

DateTypeLab
2020-05-07InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2022-10-05UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-05-07, 2022-10-05

Source documents