Code Integrity
Caveat: When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode with module Windows OS Loader validated to FIPS 140-3 under Cert. #5405 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
Certificate
| Certificate number | 5406 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-08-19 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | MultiChipStand |
| Vendor | Microsoft Corporation · website |
Module description
The Code Integrity module is a multi-chip standalone software cryptographic module that verifies the integrity of Windows executable files as they are loaded into memory from storage.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-20 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-08-20