808bits

Secure Kernel Code Integrity

FIPS 140-2 certificate #4640 · Microsoft Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode with module Windows OS Loader validated to FIPS 140-2 under Cert. #4545 operating in FIPS mode

Certificate

Certificate number4640
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorMicrosoft Corporation · website
Software versions10.0.17763.10021 and 10.0.17763.10127

Module description

Secure Kernel Code Integrity (SKCI) running in the Virtual Secure Mode (VSM) of the Hyper-V hypervisor will only grant execute access to physical pages in the kernel that have been successfully verified. Executable pages will not have write permission outside of Hyper-V. Therefore, only verified code can be executed.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
RSAC1577, C1586, C2044, C2052
SHSC1577, C2044

Tested configurations

  • Windows Server 2019 Datacenter Core (x64) running on a Dell PowerEdge R640 Server with an Intel Xeon Gold 6230
  • Windows Server 2019 Datacenter Core (x64) running on a Dell PowerEdge R840 Server with an Intel Xeon Platinum 8260
  • Windows Server 2019 Datacenter Core (x64) running on a Dell XR2 with an Intel Xeon Silver 4114
  • Windows Server 2019 Datacenter Core (x64) running on a Rugged Mobile Appliance with an Intel Xeon D-1559 (single-user mode)

Validation history

DateTypeLab
2023-10-23InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-10-23

Source documents