808bits

CyberArk Cryptographic Module for Java

FIPS 140-2 certificate #4693 · CyberArk Software Ltd · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in the Security Policy Section 3 and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number4693
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCyberArk Software Ltd · website
Software versions3.0.2.1

Module description

CyberArk Cryptographic Module for Java is a comprehensive cryptographic library designed to provide robust security solutions for Java and Android applications. It offers a wide range of cryptographic functions and features, including encryption, decryption, hashing, digital signatures, and key management. With CyberArk Cryptographic Module for Java, developers can easily integrate strong cryptographic capabilities into their Java applications to ensure data confidentiality, integrity, and authenticity.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA2720
CKGvendor affirmed
CVLA2720
DRBGA2720
DSAA2720
ECDSAA2720
HMACA2720
KAS-SSCvendor affirmed
KBKDFA2720
KTS
KTSvendor affirmed
KTS
PBKDFvendor affirmed
RSAA2720
SHA3A2720
SHA-3-Customizedvendor affirmed
SHSA2720
Triple-DESA2720

Allowed algorithms

NDRNG; MD5; RSA (key wrapping; key establishment methodology provides between 150 and 256 bits of encryption strength)

Tested configurations

  • VMware Photon OS 2.0 with JDK 11 on VMware ESXi 6.7 running on Dell PowerEdge R830 with Intel Xeon E5 (single-user mode)

Validation history

DateTypeLab
2024-04-16InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-04-16

Source documents