Cryptographic Primitives Library
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode with module Kernel Mode Cryptographic Primitives Library validated to FIPS 140-3 under Cert. #5408 operating in approved mode and Code Integrity validated to FIPS 140-3 under Cert. #5406 operating in approved mode or Secure Kernel Code Integrity validated to FIPS 140-3 under Cert. #5407 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. No assurance of FIPS 140-3 requirements met for the components of the RBG construct that are external to the module boundary (e.g., DRBG, ESV) except for SP 800-90C compliance and security strength of the provided random bits
This caveat mentions binding. A bound module inherits the earliest sunset of the modules it binds to, so the sunset date above can be optimistic.
Certificate
| Certificate number | 5410 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-08-30 |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | MultiChipStand |
| Vendor | Microsoft Corporation · website |
Module description
The Cryptographic Primitives Library is a cryptographic module that provides cryptographic services to user-mode applications running on Windows through the set of exported functions described in section 3 Cryptographic Module Interfaces. The module includes a set of algorithm providers for the Cryptography Next Generation (CNG) framework in Windows. Each provider represents a single cryptographic algorithm or a set of closely related cryptographic algorithms.
Security level exceptions
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A4008 |
| AES-CBC | A4009 |
| AES-CCM | A4008 |
| AES-CCM | A4009 |
| AES-CFB128 | A4008 |
| AES-CFB128 | A4009 |
| AES-CFB8 | A4008 |
| AES-CFB8 | A4009 |
| AES-CMAC | A4008 |
| AES-CMAC | A4009 |
| AES-CTR | A4008 |
| AES-CTR | A4009 |
| AES-ECB | A4008 |
| AES-ECB | A4009 |
| AES-GCM | A4008 |
| AES-GCM | A4009 |
| AES-GMAC | A4008 |
| AES-GMAC | A4009 |
| AES-KW | A3763 |
| AES-KW | A3764 |
| AES-XTS Testing Revision 2.0 | A4008 |
| AES-XTS Testing Revision 2.0 | A4009 |
| Counter DRBG | A4008 |
| Counter DRBG | A4009 |
| DSA KeyGen (FIPS186-4) | A4008 |
| DSA KeyGen (FIPS186-4) | A4009 |
| DSA PQGGen (FIPS186-4) | A4008 |
| DSA PQGGen (FIPS186-4) | A4009 |
| DSA PQGVer (FIPS186-4) | A4008 |
| DSA PQGVer (FIPS186-4) | A4009 |
| ECDSA KeyGen (FIPS186-4) | A4008 |
| ECDSA KeyGen (FIPS186-4) | A4009 |
| ECDSA KeyVer (FIPS186-4) | A4008 |
| ECDSA KeyVer (FIPS186-4) | A4009 |
| ECDSA SigGen (FIPS186-4) | A4008 |
| ECDSA SigGen (FIPS186-4) | A4009 |
| ECDSA SigVer (FIPS186-4) | A4008 |
| ECDSA SigVer (FIPS186-4) | A4009 |
| HMAC-SHA-1 | A4008 |
| HMAC-SHA-1 | A4009 |
| HMAC-SHA2-256 | A4008 |
| HMAC-SHA2-256 | A4009 |
| HMAC-SHA2-384 | A4008 |
| HMAC-SHA2-384 | A4009 |
| HMAC-SHA2-512 | A4008 |
| HMAC-SHA2-512 | A4009 |
| KAS-ECC Sp800-56Ar3 | A4008 |
| KAS-ECC Sp800-56Ar3 | A4009 |
| KAS-ECC-SSC Sp800-56Ar3 | A4008 |
| KAS-ECC-SSC Sp800-56Ar3 | A4009 |
| KAS-FFC Sp800-56Ar3 | A4008 |
| KAS-FFC Sp800-56Ar3 | A4009 |
| KAS-FFC-SSC Sp800-56Ar3 | A4008 |
| KAS-FFC-SSC Sp800-56Ar3 | A4009 |
| KDA HKDF SP800-56Cr2 | A4008 |
| KDA HKDF SP800-56Cr2 | A4009 |
| KDF IKEv1 | A4008 |
| KDF IKEv1 | A4009 |
| KDF IKEv2 | A4008 |
| KDF IKEv2 | A4009 |
| KDF SP800-108 | A3763 |
| KDF SP800-108 | A3764 |
| KDF TLS | A4008 |
| KDF TLS | A4009 |
| PBKDF | A4008 |
| PBKDF | A4009 |
| RSA Decryption Primitive | A4008 |
| RSA Decryption Primitive | A4009 |
| RSA KeyGen (FIPS186-4) | A4008 |
| RSA KeyGen (FIPS186-4) | A4009 |
| RSA SigGen (FIPS186-4) | A4008 |
| RSA SigGen (FIPS186-4) | A4009 |
| RSA Signature Primitive | A4008 |
| RSA Signature Primitive | A4009 |
| RSA SigVer (FIPS186-4) | A4008 |
| RSA SigVer (FIPS186-4) | A4009 |
| Safe Primes Key Generation | A4008 |
| Safe Primes Key Generation | A4009 |
| SHA-1 | A4008 |
| SHA-1 | A4009 |
| SHA2-256 | A4008 |
| SHA2-256 | A4009 |
| SHA2-384 | A4008 |
| SHA2-384 | A4009 |
| SHA2-512 | A4008 |
| SHA2-512 | A4009 |
| TLS v1.2 KDF RFC7627 | A4008 |
| TLS v1.2 KDF RFC7627 | A4009 |
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-31 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-09-01: first observed by this tracker, status active
- Validation dates on record: 2026-08-31