808bits

Intel® Offload and Crypto Subsystem (OCS)

FIPS 140-2 certificate #4025 · Intel Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-08, 10 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: None

Certificate

Certificate number4025
StandardFIPS 140-2
Statusactive
Sunset date2026-09-08
Overall level2
Module typeHardware
EmbodimentSingle Chip
VendorIntel Corporation · website
Hardware versions4.0
Firmware versions4.0[1], 4.1[2], 4.2[3] and 4.3[4]

Module description

The Intel® Offload and Crypto Subsystem (OCS) is classified as a single-chip hardware cryptographic module for FIPS 140-2 purpose.

Approved algorithms

AlgorithmCAVP certificate
AESA668
ECDSAA668
HMACA668
SHSA668

Tested configurations

  • Lakemont 3.7 embedded in Intel Elkhart Lake with Lakemont 3.7 with CSME OS running firmware version 15.40.10.2204 [4]
  • Lakemont 3.7 embedded in Intel Rocket Lake-S with Lakemont 3.7 with CSME OS running firmware version 15.0.22.1571 [2]
  • Lakemont 3.7 embedded in Intel Tiger Lake-H with Lakemont 3.7 with CSME OS running firmware version 15.0.30.1716 [3]
  • Lakemont 3.7 embedded in Intel Tiger Lake-U with CSME OS running firmware version 15.0.20.1648 [1]

Validation history

DateTypeLab
2021-09-09Initialatsec information security corporation
2022-08-23Updateatsec information security corporation
2023-04-19Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2021-09-09, 2022-08-23, 2023-04-19

Source documents