808bits

Virtual TPM

FIPS 140-2 certificate #4686 · Microsoft Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode with the modules Kernel Mode Cryptographic Primitives Library validated to FIPS 140-2 under Cert. #4670 operating in FIPS mode and Code Integrity validated to FIPS 140-2 under Cert. #4602 operating in FIPS mode or Secure Kernel Code Integrity validated to FIPS 140-2 under Cert. #4640 operating in FIPS mode

Certificate

Certificate number4686
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorMicrosoft Corporation · website
Software versions10.0.17763.10021 and 10.0.17763.10127
Hardware versionsIntel Xeon Silver 4114, Intel Xeon Gold 6230, Intel Xeon Platinum 8260 and Intel Xeon D-1559

Module description

The Virtual Trusted Platform Module (Virtual TPM or VTPM) is a dynamically linked library, TPMEngUM.dll, that provides TPM 2.0 cryptographic services to virtual machines that are running in guest partitions on the host Windows operating system.

Security level exceptions

  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AESC1577, C1587, C2044, C2053
CKGvendor affirmed
CVLC1585, C2051
DRBGC1577, C1587, C2044, C2053
ECDSAC1585, C1587, C2051, C2053
HMACC1587, C2053
KASC1587, C2053
KBKDFC1587, C2053
KTSvendor affirmed
RSAC1577, C1585, C1587, C2044, C2051, C2053
SHSC1577, C2044

Allowed algorithms

NDRNG

Tested configurations

  • Windows Server 2019 Datacenter Core (x64) running on a Dell PowerEdge R640 Server with an Intel Xeon Gold 6230 with PAA
  • Windows Server 2019 Datacenter Core (x64) running on a Dell PowerEdge R840 Server with an Intel Xeon Platinum 8260 with PAA
  • Windows Server 2019 Datacenter Core (x64) running on a Dell XR2 with an Intel Xeon Silver 4114 with PAA
  • Windows Server 2019 Datacenter Core (x64) running on a Rugged Mobile Appliance with an Intel Xeon D-1559 with PAA (single-user mode)

Validation history

DateTypeLab
2024-04-03InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-04-03

Source documents