FIPS 140-3 certificate #5404 · Microsoft Corporation · data as of 2026-09-01
Active.
Sunset date 2031-08-30, 1823 days away.
Caveat: When installed, initialized and configured as specified in Section 11 of the Security Policy. When operated in approved mode with module Kernel Mode Cryptographic Primitives Library (cng.sys) validated to FIPS 140-3 under Cert. #5408 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
The Windows Boot Manager module is a multi-chip standalone software-hybrid cryptographic module. Boot Manager is the first Windows OS component to load when the computer powers up. When Secure Boot is enabled, the integrity of Boot Manager is validated before loading by the computer’s UEFI firmware. Along with other startup and initialization tasks, Boot Manager loads and cryptographically validates the integrity of Winload.efi (the Windows OS Loader), the next module in the startup sequence. The Boot Manager, which includes parts of BitLocker disk encryption, collects authorization factors, known as “protectors”, by reading data or interacting with the user. BitLocker uses these protectors to encrypt entire disk volumes.