Reference Source

What changed — FIPS 140 validated cryptographic modules: active, historical or revoked

The change history of FIPS 140 validated cryptographic modules: active, historical or revoked: The current validation status of every cryptographic module certificated by the NIST/CCCS Cryptographic Module Validation Program (CMVP). Each record is one certificate number with the vendor, the module name, the module type, the validation date and whether the certificate is Active, Historical or Revoked, quoted from the CMVP listing it was read from. Answers 'is FIPS 140-2 certificate #4536 still valid', 'has my FIPS module moved to the historical list', 'which FIPS 140-2 certificates are still active', and 'FIPS 140-2 vs 140-3 certificate status'. The status is a value that changes silently: CMVP moves a certificate to the Historical list when it is more than five years old or on a programmatic transition, and publishes no notice per certificate, so an assistant answering from memory reports certificates as Active months after they were retired. 503 FIPS 140-2 certificates are Active as of 2026-08-05 and carry a sunset date of 9/21/2026. Coverage: the complete CMVP register as published on 2026-08-05 — every certificate on every list. 1,165 Active (503 against FIPS 140-2, 662 against FIPS 140-3), 4,259 Historical (287 against FIPS 140-1, 3,914 against FIPS 140-2, 58 against FIPS 140-3) and 25 Revoked (21, 3 and 1), 5,449 in all. That is 22 fewer than the 5,471 rows the list pages print between them, because CMVP's Historical query returns revoked certificates as well as historical ones and those 22 rows name a certificate the Revoked list already named.

Change dates1
Tracked since
Last change

No changes yet since the initial snapshot of . This register is re-checked against its sources on a schedule; a date appears below only when records were added or their values changed, so a quiet stretch means the register itself was quiet, not that nobody looked.

We keep the current verified state of each record, not the value it replaced — so each entry says which records changed and what they now state, never what they said before. Machine subscribers: poll changes.xml (Atom) or changes.json instead of re-fetching the dataset.

— Initial snapshot — 5,449 records

The first verified snapshot: every record was new on this date. The full register is on the dataset page.

… and 5,429 more records on this date. The full current state of every record is in data.json.