Cryptographic Primitives Library
Cryptographic Primitives Library, from Microsoft Corporation, holds FIPS 140-3 certificate #5410 at overall level 1. The validation is active, with a sunset date of 2031-08-30. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode with module Kernel Mode Cryptographic Primitives Library validated to FIPS 140-3 under Cert. #5408 operating in approved mode and Code Integrity validated to FIPS 140-3 under Cert. #5406 operating in approved mode or Secure Kernel Code Integrity validated to FIPS 140-3 under Cert. #5407 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. No assurance of FIPS 140-3 requirements met for the components of the RBG construct that are external to the module boundary (e.g., DRBG, ESV) except for SP 800-90C compliance and security strength of the provided random bits
This caveat mentions binding. A bound module inherits the earliest sunset of the modules it binds to, so the sunset date above can be optimistic.
Certificate
| Certificate number | 5410 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-08-30 |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | MultiChipStand |
| Vendor | Microsoft Corporation · website |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Cryptographic Primitives Library is a cryptographic module that provides cryptographic services to user-mode applications running on Windows through the set of exported functions described in section 3 Cryptographic Module Interfaces. The module includes a set of algorithm providers for the Cryptography Next Generation (CNG) framework in Windows. Each provider represents a single cryptographic algorithm or a set of closely related cryptographic algorithms.
Security level exceptions
- Non-invasive security: N/A
Approved algorithms (44)
| Algorithm | CAVP certificates |
|---|---|
| AES-CBC | A4008, A4009 |
| AES-CCM | A4008, A4009 |
| AES-CFB128 | A4008, A4009 |
| AES-CFB8 | A4008, A4009 |
| AES-CMAC | A4008, A4009 |
| AES-CTR | A4008, A4009 |
| AES-ECB | A4008, A4009 |
| AES-GCM | A4008, A4009 |
| AES-GMAC | A4008, A4009 |
| AES-KW | A3763, A3764 |
| AES-XTS Testing Revision 2.0 | A4008, A4009 |
| Counter DRBG | A4008, A4009 |
| DSA KeyGen (FIPS186-4) | A4008, A4009 |
| DSA PQGGen (FIPS186-4) | A4008, A4009 |
| DSA PQGVer (FIPS186-4) | A4008, A4009 |
| ECDSA KeyGen (FIPS186-4) | A4008, A4009 |
| ECDSA KeyVer (FIPS186-4) | A4008, A4009 |
| ECDSA SigGen (FIPS186-4) | A4008, A4009 |
| ECDSA SigVer (FIPS186-4) | A4008, A4009 |
| HMAC-SHA-1 | A4008, A4009 |
| HMAC-SHA2-256 | A4008, A4009 |
| HMAC-SHA2-384 | A4008, A4009 |
| HMAC-SHA2-512 | A4008, A4009 |
| KAS-ECC Sp800-56Ar3 | A4008, A4009 |
| KAS-ECC-SSC Sp800-56Ar3 | A4008, A4009 |
| KAS-FFC Sp800-56Ar3 | A4008, A4009 |
| KAS-FFC-SSC Sp800-56Ar3 | A4008, A4009 |
| KDA HKDF SP800-56Cr2 | A4008, A4009 |
| KDF IKEv1 | A4008, A4009 |
| KDF IKEv2 | A4008, A4009 |
| KDF SP800-108 | A3763, A3764 |
| KDF TLS | A4008, A4009 |
| PBKDF | A4008, A4009 |
| RSA Decryption Primitive | A4008, A4009 |
| RSA KeyGen (FIPS186-4) | A4008, A4009 |
| RSA SigGen (FIPS186-4) | A4008, A4009 |
| RSA Signature Primitive | A4008, A4009 |
| RSA SigVer (FIPS186-4) | A4008, A4009 |
| Safe Primes Key Generation | A4008, A4009 |
| SHA-1 | A4008, A4009 |
| SHA2-256 | A4008, A4009 |
| SHA2-384 | A4008, A4009 |
| SHA2-512 | A4008, A4009 |
| TLS v1.2 KDF RFC7627 | A4008, A4009 |
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-31 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-09-01: first observed by this tracker, status active
- Validation dates on record: 2026-08-31