<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

FIPS 140-3 Is the New Standard for Cryptographic Validation. Here Is What That Means for Your Data.

Editorial Team
By Editorial Team

TABLE OF CONTENTS

    See Virtru In Action

    On September 21, 2026, every FIPS 140-2 validation certificate moved to the Cryptographic Module Validation Program (CMVP) Historical List. Whether you operate in the public sector, a regulated industry, or anywhere that sensitive data demands serious protection, this transition matters. Here is where things stand and what Virtru is doing about it.

    A Standard Built for a Different Era Just Got Replaced

    FIPS 140-2 was published in 2001. The Federal Information Processing Standard governing cryptographic module security went largely unchanged for 25 years while the threat landscape around it transformed entirely. FIPS 140-3, which NIST formally approved in March 2019, is the long-overdue answer to that gap.

    FIPS 140-3 was substantially rewritten to address shortcomings in its predecessor and align with how modern cryptographic threats actually work. One of the most significant structural changes is that FIPS 140-3 is based on ISO/IEC 19790, the international standard for cryptographic module security. That alignment matters beyond the federal space: organizations operating across borders or working with international partners now have a single framework that maps to both U.S. federal requirements and globally recognized standards, rather than managing two separate compliance tracks.

    The technical requirements also got tighter in ways that reflect the current state of cryptographic attacks. Side-channel testing, which examines whether a module leaks information through timing, power consumption, or electromagnetic signals, is now mandatory at all security levels. Previously it was only required at the higher levels. Legacy algorithms and deprecated key lengths that FIPS 140-2 permitted in certain conditions are no longer allowed. Entropy testing requirements are more rigorous. And where FIPS 140-2 validated a module at a point in time, FIPS 140-3 requires vendors to demonstrate consistent security behavior across the full lifecycle of the module. Validation is no longer a snapshot. It is an ongoing commitment.

    Why This Touches More Than Just Government

    FIPS 140-3 validation is a hard requirement for federal agencies and defense contractors, but its reach extends well beyond the public sector. Healthcare organizations handling protected health information, financial institutions subject to regulatory scrutiny, legal firms managing privileged data, and any commercial organization that works with federal customers or bids on government contracts all operate in environments where FIPS validation is either required or expected as a baseline indicator of cryptographic quality.

    Compliance frameworks that require FIPS validation include FedRAMP, CMMC, CJIS, ITAR, and NIST SP 800-171. But even outside those mandates, FIPS validation functions as a proxy for something broader: independently verified cryptographic quality. There is an important distinction here that matters to any buyer evaluating security tools.

    FIPS-compliant is a self-declared term. An organization can call its product FIPS-compliant by virtue of using approved algorithms. FIPS-validated means an independent, NIST-accredited laboratory reviewed the module's design, implementation, and functionality and issued a certificate. No internal team, no vendor, and no marketing team can grant that. Only a third-party assessment can. For organizations making decisions about where to place their trust, that difference is not a technicality. It is the whole point.

    Now that FIPS 140-2 certificates are Historical and FIPS 140-3 is the active standard, the question for any vendor you rely on for encryption is straightforward: do they hold an active CMVP certificate, or are they still trading on a deprecated one?

    Where Virtru Stands

    Virtru is a data-centric security company. That means the integrity of the cryptography underlying our platform is not a compliance checkbox. It is foundational to everything we build and everything we promise our customers.

    The Virtru Go Cryptographic Module is an active FIPS 140-3 validated software module (CMVP certificate #5460). It covers our Go standard library and WebAssembly browser-facing applications across a growing set of Virtru encryption clients. Our FedRAMP-authorized platform runs FIPS-validated modules for data-in-transit and data-at-rest across the Virtru Data Security Platform.

    This is not where Virtru's FIPS story starts. We were the first company to achieve NIST validation for a JavaScript cryptographic module under FIPS 140-2, a milestone that demonstrated both technical depth and commitment to independently verified cryptographic quality long before the 140-3 transition was on most organizations' radar. We are updating remaining product surfaces incrementally as they transition to FIPS 140-3 validated modules. It is a deliberate, ongoing program.

    Our customers, whether they are federal agencies protecting classified workflows, healthcare organizations securing patient data, or enterprises managing sensitive intellectual property, deserve to know that the encryption protecting their data has been tested and certified by an independent authority, not just described in a datasheet. FIPS 140-3 validation is how we prove it.

    What You Should Be Asking Your Vendors Right Now

    If you rely on third-party tools for encryption, file protection, email security, or any other function that handles sensitive data, the FIPS 140-2 sunset is a reasonable prompt to ask some direct questions.

    Does the vendor hold an active FIPS 140-3 validation certificate? You can verify this yourself on the CMVP Active list at NIST. If their certificate appears on the Historical list, it means their module was validated under the old standard and has not been updated. If they cannot point to any certificate, they are compliant, not validated. In either case, that is a conversation worth having before your next audit or renewal cycle surfaces it for you.

    The validation process under FIPS 140-3 is rigorous and takes time. Organizations that are only now beginning the process are looking at many months before a new certificate is issued. That is not a reason to panic, but it is a reason to ask the question now rather than later.

    To understand which Virtru clients support FIPS 140-3 and whether FIPS mode is active in your environment, talk to our team.

    Editorial Team

    Editorial Team

    The editorial team consists of Virtru brand experts, content editors, and vetted field authorities. We ensure quality, accuracy, and integrity through robust editorial oversight, review, and optimization of content from trusted sources, including use of generative AI tools.

    View more posts by Editorial Team

    See Virtru In Action