808bits

STARCOS SPK 2.4 CHIP

FIPS 140-2 certificate #372 · Giesecke & Devrient · data as of 2026-09-12

STARCOS SPK 2.4 CHIP, from Giesecke & Devrient, holds FIPS 140-2 certificate #372 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number372
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentSingle-chip
VendorGiesecke & Devrient · website
Software versionsCP5WxSPKI24-01-3-S_V0330
Hardware versionsP8WE 5032 M5.1

Module description

Quoted from the NIST CMVP entry for this certificate.

Giesecke & Devrient (G&D) Smart Card Chip Operating System Standard Version with Public Key Extension 2.4 (STARCOS SPK 2.4) is a scaleable multi-application operating system for smart cards and provides functionality that is necessary for public key infrastructure.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Design Assurance: Level 2

Approved algorithms (4)

AlgorithmCAVP certificates
RSAvendor affirmed
SHA-1137
Triple-DES154
Triple-DES MACvendor affirmed

Other algorithms

DES (Cert. #200); DES MAC (Cert. #200, vendor affirmed)

Validation history

DateTypeLab
2003-12-29InitialCYGNACOM SOLUTIONS INC
2008-03-19Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2003-12-29, 2008-03-19

Source documents