808bits

AWS Link Encryption Module

FIPS 140-3 certificate #5256 · Amazon Web Services, Inc. · data as of 2026-08-28
Active. Sunset date 2031-05-04, 1709 days away.
Caveat: When operated with module AWS-LC Cryptographic Module (dynamic) validated to FIPS 140-3 under Cert. #5146 operating in approved mode, No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs

Certificate

Certificate number5256
StandardFIPS 140-3
Statusactive
Sunset date2031-05-04
Overall level1
Module typeSoftware-hybrid
EmbodimentMultiChipStand
VendorAmazon Web Services, Inc. · website

Module description

MACsec and DWDM link encryption is used by AWS networking infrastructure to secure traffic across its core network consisting of long-distance and large-scale data communications across the globe. Traffic flowing across the AWS global network is protected by strong cryptography and meets regulatory requirements.

Security level exceptions

  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Validation history

DateTypeLab
2026-05-05InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2026-05-05

Source documents