808bits

Broadcom Inc.

18 FIPS 140 certificates · 10 active · data as of 2026-09-08

Broadcom Inc. holds 18 FIPS 140 certificates in NIST's Cryptographic Module Validation Program, covering BCM, VMware’s and VMware's. 10 are still active, 8 have moved to the historical list.

2 certificates on the 140-2 sunset list. Every FIPS 140-2 validation still active moves to the historical list on 2026-09-21. What that means and the full list.
CertModuleStandardStatusLevelValidated
5286VMware’s Linux Kernel Cryptographic ModuleFIPS 140-3active · sunsets 2029-11-0412026-05-21
5258Symantec Messaging Gateway Cryptographic ModuleFIPS 140-3active · sunsets 2029-08-2612026-05-07
5147VMware’s OpenSSL FIPS Provider based on the OpenSSL FIPS ProviderFIPS 140-3active · sunsets 2030-03-1012026-01-27
5007BCM58202B0FIPS 140-3active · sunsets 2030-04-2032025-04-21
4986VMware's BC-FJA (Bouncy Castle FIPS Java API)FIPS 140-3active · sunsets 2029-07-2812025-03-14
4973VMware's BoringCrypto ModuleFIPS 140-3active · sunsets 2029-07-2212025-02-26
4952PrismPlus Cryptographic ModuleFIPS 140-3active · sunsets 2030-01-2612025-01-27
4881VMware’s VPN Crypto ModuleFIPS 140-3active · sunsets 2026-11-1412024-11-15
4861VMware’s OpenSSL FIPS ProviderFIPS 140-2active · sunsets 2026-09-2112024-11-04
4694VMware's BoringCrypto ModuleFIPS 140-2active · sunsets 2026-09-2112024-04-24
4865VMware’s Linux Kernel Cryptographic ModuleFIPS 140-3historical12024-11-05
4550Symantec Messaging Gateway Cryptographic ModuleFIPS 140-2historical12023-07-12
4104CAPKI for ServerFIPS 140-2historical12021-12-13
3941Broadcom FIPS Object Module for OpenSSLFIPS 140-2historical12021-06-02
3920BCM58200 Series: BCM58201, BCM58202FIPS 140-2historical32021-05-03
3436BCM58200 Series: BCM58201, BCM58202FIPS 140-2historical32019-04-19
2654BCM58100B0 Series: BCM58101B0, BCM58102B0, BCM58103B0FIPS 140-2historical32016-06-07
1266BCM5880 Cryptographic ModuleFIPS 140-2historical32010-03-29

NIST records the vendor as free text, so one company can appear under several spellings. Those are grouped here. Corporate families are not: a product line can change owner, and the certificates stay with the registration that earned them. The nShield modules run from nCipher Corporation through Thales to Entrust, and this tracker keeps those as three vendors because that is how NIST holds them.