CyberArk Cryptographic Module
Caveat: When operated in FIPS mode. The module makes no assurance of the minimum strength of random strings and generated keys.
Certificate
| Certificate number | 4949 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | CyberArk Software Ltd. · website |
| Software versions | 2.1.2 |
Module description
CyberArk Cryptographic Module is a standards-based cryptographic engine for servers and appliances. The module delivers core cryptographic functions to server platforms and features robust algorithm support, including Suite B algorithms. CyberArk Cryptographic Module offloads secure key management, data integrity, data at rest encryption, and secure communications to a trusted implementation.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A4873 |
| CKG | vendor affirmed |
| DRBG | A4873 |
| DSA | A4873 |
| ECDSA | A4873 |
| HMAC | A4873 |
| RSA | A4873 |
| SHS | A4873 |
| Triple-DES | A4873 |
Tested configurations
- CentOS 7 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
- CentOS 7 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
- macOS 13 (Ventura) running on a Mac Mini M2 with an Apple M2
- Windows Server 2022 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
- Windows Server 2022 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-01-23 | Initial | DEKRA Testing and Certification S.A.U |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2025-01-23