808bits

Cryptographic Primitives Library

FIPS 140-3 certificate #5410 · Microsoft Corporation · data as of 2026-09-15

Cryptographic Primitives Library, from Microsoft Corporation, holds FIPS 140-3 certificate #5410 at overall level 1. The validation is active, with a sunset date of 2031-08-30. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2031-08-30, 1809 days away.
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode with module Kernel Mode Cryptographic Primitives Library validated to FIPS 140-3 under Cert. #5408 operating in approved mode and Code Integrity validated to FIPS 140-3 under Cert. #5406 operating in approved mode or Secure Kernel Code Integrity validated to FIPS 140-3 under Cert. #5407 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. No assurance of FIPS 140-3 requirements met for the components of the RBG construct that are external to the module boundary (e.g., DRBG, ESV) except for SP 800-90C compliance and security strength of the provided random bits
This caveat mentions binding. A bound module inherits the earliest sunset of the modules it binds to, so the sunset date above can be optimistic.

Certificate

Certificate number5410
StandardFIPS 140-3
Statusactive
Sunset date2031-08-30
Overall level1
Module typeSoftware-hybrid
EmbodimentMultiChipStand
VendorMicrosoft Corporation · website

Module description

Quoted from the NIST CMVP entry for this certificate.

The Cryptographic Primitives Library is a cryptographic module that provides cryptographic services to user-mode applications running on Windows through the set of exported functions described in section 3 Cryptographic Module Interfaces. The module includes a set of algorithm providers for the Cryptography Next Generation (CNG) framework in Windows. Each provider represents a single cryptographic algorithm or a set of closely related cryptographic algorithms.

Security level exceptions

  • Non-invasive security: N/A

Approved algorithms (44)

AlgorithmCAVP certificates
AES-CBCA4008, A4009
AES-CCMA4008, A4009
AES-CFB128A4008, A4009
AES-CFB8A4008, A4009
AES-CMACA4008, A4009
AES-CTRA4008, A4009
AES-ECBA4008, A4009
AES-GCMA4008, A4009
AES-GMACA4008, A4009
AES-KWA3763, A3764
AES-XTS Testing Revision 2.0A4008, A4009
Counter DRBGA4008, A4009
DSA KeyGen (FIPS186-4)A4008, A4009
DSA PQGGen (FIPS186-4)A4008, A4009
DSA PQGVer (FIPS186-4)A4008, A4009
ECDSA KeyGen (FIPS186-4)A4008, A4009
ECDSA KeyVer (FIPS186-4)A4008, A4009
ECDSA SigGen (FIPS186-4)A4008, A4009
ECDSA SigVer (FIPS186-4)A4008, A4009
HMAC-SHA-1A4008, A4009
HMAC-SHA2-256A4008, A4009
HMAC-SHA2-384A4008, A4009
HMAC-SHA2-512A4008, A4009
KAS-ECC Sp800-56Ar3A4008, A4009
KAS-ECC-SSC Sp800-56Ar3A4008, A4009
KAS-FFC Sp800-56Ar3A4008, A4009
KAS-FFC-SSC Sp800-56Ar3A4008, A4009
KDA HKDF SP800-56Cr2A4008, A4009
KDF IKEv1A4008, A4009
KDF IKEv2A4008, A4009
KDF SP800-108A3763, A3764
KDF TLSA4008, A4009
PBKDFA4008, A4009
RSA Decryption PrimitiveA4008, A4009
RSA KeyGen (FIPS186-4)A4008, A4009
RSA SigGen (FIPS186-4)A4008, A4009
RSA Signature PrimitiveA4008, A4009
RSA SigVer (FIPS186-4)A4008, A4009
Safe Primes Key GenerationA4008, A4009
SHA-1A4008, A4009
SHA2-256A4008, A4009
SHA2-384A4008, A4009
SHA2-512A4008, A4009
TLS v1.2 KDF RFC7627A4008, A4009

Validation history

DateTypeLab
2026-08-31InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-09-01: first observed by this tracker, status active
  • Validation dates on record: 2026-08-31

Source documents