FIPS 140-3
FIPS 140-3 is a U.S. government computer security standard used to validate cryptographic modules, meaning the hardware or software components that perform encryption and other cryptographic functions. It is the latest version of the FIPS 140 series and is intended to help ensure that these modules meet defined security requirements when protecting sensitive information. It applies to federal agencies that use cryptographic-based security systems, and it is often referenced in commercial security contexts as well.
FIPS 140-3, titled 'Security Requirements for Cryptographic Modules,' is a U.S. federal standard governing the security requirements for cryptographic modules. It became effective September 22, 2019, with NIST's Cryptographic Module Validation Program (CMVP) permitted to begin accepting validation submissions under the FIPS 140-3 scheme beginning September 2020. The standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and related systems. Note that FIPS 140-3 is a NIST/CMVP validation standard distinct from PCI DSS and other PCI standards; where PCI requirements reference the use of validated cryptographic modules, practitioners should confirm the applicable requirement against the current published PCI standard rather than assuming FIPS 140-3 validation alone satisfies a given PCI control.
Why it matters
Cryptographic modules are the components that actually perform encryption, key management, and related functions, and a weakness in a module can undermine the protection that an entire system depends on. FIPS 140-3 provides a defined set of security requirements and an independent validation path through NIST's Cryptographic Module Validation Program (CMVP), giving organizations a recognized reference point for judging whether a module meets baseline security expectations rather than relying on a vendor's unverified claims. This matters in payment and commerce security contexts because encryption, tokenization systems, hardware security modules, and PIN-handling components frequently rely on cryptographic modules whose trustworthiness is central to protecting sensitive data.
FIPS 140-3 is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information, and it is often referenced in commercial security contexts as well. For merchants, processors, and vendors, a module's FIPS 140-3 validation can serve as evidence during procurement, risk assessment, or customer due diligence. However, validation applies to the specific module as tested and configured, so the security benefit depends on deploying and operating the module within its validated boundary and approved mode.
It is important not to overstate what FIPS 140-3 delivers. It is a NIST/CMVP validation standard distinct from PCI DSS and the other PCI standards. Where PCI requirements reference the use of validated cryptographic modules, FIPS 140-3 validation alone does not automatically satisfy a given PCI control, and practitioners should confirm the applicable requirement against the current published PCI standard rather than assuming equivalence.
Who it's relevant to
Inside FIPS 140-3
Common questions
Answers to the questions practitioners most commonly ask about FIPS 140-3.