U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

This is an archive
(replace .gov by .rip)

Cryptographic Module Validation Program CMVP

Modules In Process


DISCLAIMER: The Cryptographic Module Validation Program (CMVP) Modules In Process and Implementation Under Test (IUT) Lists are provided for information purposes only. Participation on the list is voluntary and is a joint decision by the vendor and Cryptographic Security and Testing (CST) laboratory. Modules are listed alphabetically by vendor name. Posting on the list does not imply guarantee of final validation.
The MIP and IUT lists have been updated. Each entry now indicates whether it being tested to meet FIPS 140-2 or FIPS 140-3 requirements.

 

The status of each cryptographic module in the process is identified below.

Modules In Process List

  • Review Pending
    • Complete set of testing documents submitted to NIST and CSE for review. The set includes: draft certificate, summary module description, detailed test report, nonproprietary security policy, web-site information. In addition, some CST labs include a separate physical testing report.
    • Signed letter from laboratory stating recommendation for validation received by NIST and CSE.
  • In Review
    • NIST and CSE reviewers assigned.
    • NIST and CSE perform a review of the test documents.
    • Comments coordinated by NIST and CSE reviewers and a consolidated set of comments sent to the CST laboratory.
  • Coordination (this process may be iterative)
    • Comments received by the CST laboratory from NIST and CSE for resolution.
    • Additional testing (if required).
    • Additional documentation (if required).
    • Comments resolution developed for resubmission to NIST and CSE.
    • Testing documents updated for resubmission to NIST and CSE.
    • Responses to comments and revised test documents submitted to NIST and CSE.
  • Finalization
    • Final resolution of validation review comments submitted to NIST and CSE.
    • Testing documents updated based on resolutions and submitted to NIST and CSE.
    • Certificate number assigned.
    • Certificate posting.

Implementation Under Test List

  • Implementation Under Test (IUT)
    • There exists a viable contract between the vendor and CST laboratory for the testing of the cryptographic module.
    • The cryptographic module is resident at the CST laboratory.
    • All of the required documentation is resident at the CST laboratory. (Note: if the vendor requires the CST lab personnel to test the cryptographic module onsite, all documents must be onsite with the module. 

If the module report was submitted to the CMVP but placed on HOLD by request from the CST Laboratory, the status is reflected as IUT.

Created October 11, 2016, Updated November 17, 2021