The FIPS 140-2 sunset: 503 active certificates become Historical on 21 September 2026
On 21 September 2026, every FIPS 140-2 certificate still listed as Active is scheduled to move to the CMVP Historical list. NIST publishes no per-certificate notice when this happens — the status simply changes on the register. As of our 2026-08-05 snapshot of the complete register, 503 certificates are Active against FIPS 140-2 and carry that sunset date; certificate detail pages print it directly (for example certificate 4536, Microsoft's Cryptographic Primitives Library: "Sunset Date 9/21/2026").
The register today
The full CMVP register, snapshotted 2026-08-05 and verified row-by-row against the listing pages (method):
| Standard | Active | Historical | Revoked |
|---|---|---|---|
| FIPS 140-1 | 0 | 287 | 21 |
| FIPS 140-2 | 503 | 3,914 | 3 |
| FIPS 140-3 | 662 | 58 | 1 |
After 21 September, the FIPS 140-2 Active column goes to zero and the Historical column absorbs it — the largest single status change this register will ever have. The 503 certificates that flip are held disproportionately by the vendors federal buyers know best: Microsoft (24 certificates), Oracle (15), Google (12), Red Hat (11), Thales and Cisco (10 each), FireEye (10), Fortinet, Samsung and Entrust (8 each). By module type they split 230 software, 224 hardware, 24 software-hybrid, 16 firmware and 9 firmware-hybrid. 14 of the 503 rows carry no vendor name at all — that is NIST's own gap, published as empty cells on the register.
What Historical actually means
CMVP's own definition, from the validated-modules page:
If a validation certificate is marked as historical, Federal Agencies should not include these in new systems but can be procured for legacy systems. This does not mean that the overall FIPS-140 certificates for these modules have been revoked, rather it indicates that the certificates and the documentation posted with them are either more than 5 years old, or were moved to the Historical list because of programmatic transitions.
Two things follow from that wording. First, Historical is not Revoked — a module on the Historical list was not found deficient, and agencies "may make a risk determination on whether to continue using" it. Second, the practical bite is on new procurements: after 21 September, a product whose FIPS validation rests on a 140-2 certificate no longer satisfies a requirement for a currently-listed module in a new system. The successor path is FIPS 140-3, where 662 certificates are Active today.
Why the change is easy to miss
The status change is silent. CMVP updates the register but announces nothing per certificate, and the register itself is reachable only through advanced-search query strings — there is no stable per-certificate page carrying the status in prose an assistant can quote. An assistant answering "is certificate X still active?" from training data will keep saying yes for months after the flip. That is the gap this snapshot exists to close.
The before-state, preserved and checkable
We hold the complete register as of 2026-08-05 — all 5,449 certificates, every record carrying the CMVP listing URL it was read from and the verbatim register row as its quote, 100% of claims substring-confirmed against those pages. When the sunset lands, the changes feed on that dataset will carry the flip as data: which certificates moved, and when we verified it.
- The dataset — one page per certificate, with source and quote
- data.json — the full register, machine-readable
- changes.xml — poll this to watch the sunset happen
- How the records are made and checked
Every figure on this page is computed from those records; nothing here is estimated. If a number looks wrong, the record it came from links the page that states it — check us.