808bits

IQVIA Java Crypto Module

FIPS 140-2 certificate #4202 · IQVIA · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode. The output of the DRBG shall not be used to generate keys

Certificate

Certificate number4202
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorIQVIA · website
Software versions1.0

Module description

The cryptographic module is a single Java Archive (JAR) binary, named DvSecurityAPI.jar, that provides cryptographic and secure communication services for other applications developed by IQVIA. In this document, those applications will be referred to as the calling application. The module is a standalone cryptographic library that can be called to provide encryption, decryption, hash generation and verification, certificate generation and verification, random bit generation, and message authentication functions.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC2127
DRBGC2127
HMACC2127
RSAC2127
SHSC2127

Allowed algorithms

RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • Microsoft Windows Server 2016 with JDK v1.8 running on a ProLiant BL460c Gen8 with Intel Xeon E5-2640 (single-user mode)

Validation history

DateTypeLab
2022-04-22InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-04-22

Source documents