FIPS 140-3 Certificate Not a Security Guarantee, Experts Warn
As FIPS 140-2 certificates move to NIST's historical list, experts caution that FIPS validation is not a guarantee of overall product security. Many customers disable FIPS mode despite paying a premium for the certificate. This highlights the need for a broader understanding of security beyond certification.
Key points
- FIPS 140-2 certificates will be moved to NIST's historical list on September 21, 2026, affecting federal procurements.
- Over 90% of FIPS-enabled HSM customers disable FIPS mode, despite paying a premium for the certificate.
- FIPS validation only ensures a module implements approved algorithms correctly, not overall product security.
- Experts warn treating FIPS certificates as a proxy for overall security can lead to incidents.
- The FIPS program has helped eliminate snake-oil cryptography, but a broader understanding of security is needed.
The upcoming change to FIPS 140-2 certificates has sparked a flurry of activity in the industry. As of September 21, 2026, these certificates will be moved to NIST's historical list, affecting federal procurements. This has led to a surge in demand for FIPS 140-3 certificates, with many vendors scrambling to meet the new requirements.
However, experts warn that FIPS validation is not a guarantee of overall product security. In fact, a recent survey found that over 90% of FIPS-enabled HSM customers disable FIPS mode, despite paying a premium for the certificate. This highlights the need for a broader understanding of security beyond certification.
FIPS validation only ensures that a specific cryptographic module, at a specific firmware version, in a specific configuration, implements approved algorithms correctly and meets certain design requirements. It does not attest that the product around the module is secure, that the module will be operated in its validated configuration, or that the keys inside it were generated and managed in a way that can be defended.
Treating the FIPS certificate as a proxy for overall security can lead to incidents. The FIPS program has helped eliminate snake-oil cryptography, but a broader understanding of security is needed. As the industry moves forward, it's essential to recognize the limitations of FIPS validation and focus on a more comprehensive approach to security.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.