808bits

Trellix Core Cryptographic Module (user)

FIPS 140-2 certificate #4221 · Trellix · data as of 2026-09-13

Trellix Core Cryptographic Module (user), from Trellix, holds FIPS 140-2 certificate #4221 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2026-09-21, 7 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number4221
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorTrellix · website
Software versions2.2.0.17.0

Module description

Quoted from the NIST CMVP entry for this certificate.

The Trellix Core Cryptographic Module provides cryptographic functionality for Trellix's Endpoint Encryption product range.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (6)

AlgorithmCAVP certificates
AESA1555, A1556
CKGvendor affirmed
DRBGA1556
HMACA1555, A1556
RSAA1556
SHSA1555, A1556

Allowed algorithms

RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • BIOS Preboot running on Dell Inspiron 5558 with Intel i5-5250U with PAA
  • BIOS Preboot running on Dell Inspiron 5558 with Intel i5-5250U without PAA
  • UEFI 64-bit Preboot running on Microsoft Surface 3 with Intel i5-520M with PAA
  • UEFI 64-bit Preboot running on Microsoft Surface 3 with Intel i5-520M without PAA
  • Windows 10 64-bit running on Microsoft Surface 3 with an Intel i5-520M with PAA
  • Windows 10 64-bit running on Microsoft Surface 3 with an Intel i5-520M without PAA
  • Windows 7 32-bit running on Dell Latitude E7270 with Intel i5-6300U with PAA
  • Windows 7 32-bit running on Dell Latitude E7270 with Intel i5-6300U without PAA (single-user mode)

Validation history

DateTypeLab
2022-05-09InitialAcumen Security
2024-03-13UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-05-09, 2024-03-13

Source documents