Federal Information Processing Standard 140-2 is the U.S. government’s security standard for cryptographic modules, setting the requirements that hardware, software, and firmware encryption components must meet before federal agencies can use them to protect sensitive data. Published by the National Institute of Standards and Technology in June 2001, FIPS 140-2 defines four escalating security levels and evaluates modules across eleven requirement areas. It has been superseded by FIPS 140-3, and all remaining FIPS 140-2 validation certificates will move to NIST’s Historical List on September 21, 2026.1National Institute of Standards and Technology. FIPS 140-3 Transition Effort
The Four Security Levels
FIPS 140-2 organizes its requirements into four security levels, each building on the one below it. A software encryption library running on a desktop faces different threats than a hardware security module bolted inside an ATM, so the standard scales its demands to match.2National Institute of Standards and Technology. FIPS 140-2 – Security Requirements for Cryptographic Modules
Level 1
Level 1 is the baseline. The module must use at least one NIST-approved cryptographic algorithm, but there are no specific physical security requirements beyond basic production-grade equipment. A purely software-based encryption library running on a general-purpose computer can qualify. Organizations that need validated encryption without specialized hardware typically operate at this level.
Level 2
Level 2 adds tamper-evidence on top of everything in Level 1. The module must include features like tamper-evident coatings, seals, or pick-resistant locks on removable covers or doors, so that any physical attempt to reach the cryptographic keys inside leaves visible evidence. Level 2 also requires role-based authentication: the module must verify that a user is authorized for a particular role before granting access to its services.3National Institute of Standards and Technology. FIPS 140-2 – Security Requirements for Cryptographic Modules
Level 3
Level 3 shifts from passive evidence to active defense. The module must include tamper-response circuitry that detects a physical breach and immediately erases all plaintext secret and private keys. The enclosure itself must be hardened, built from materials like hard epoxy potting or strong enclosures designed so that any attempt at removal or penetration will likely destroy the module. Data centers and financial institutions frequently rely on Level 3 modules because a successful physical attack still yields nothing usable.3National Institute of Standards and Technology. FIPS 140-2 – Security Requirements for Cryptographic Modules
Level 4
Level 4 is the ceiling. It adds environmental failure protection: circuitry that continuously monitors operating temperature and voltage. If either measurement falls outside the module’s normal operating range, whether by accident or deliberate attack, the protection circuitry must either shut the module down or immediately erase all keys and critical security parameters. NIST’s environmental failure testing procedures require testing across a temperature range of −100°C to +200°C and across voltage ranges designed to induce electronic failure. This level exists for modules deployed in physically unprotected or hostile environments where an attacker might try to force errors by heating, cooling, or voltage-spiking the device.3National Institute of Standards and Technology. FIPS 140-2 – Security Requirements for Cryptographic Modules
The Eleven Requirement Areas
Every module is evaluated against eleven distinct requirement areas regardless of the target level. The demands within each area become more stringent at higher levels, but all eleven apply at every level.4National Institute of Standards and Technology. Cryptographic Module Validation Program – FIPS 140-2
- Cryptographic module specification, including an explicitly drawn cryptographic boundary that separates security-relevant components from everything else.3National Institute of Standards and Technology. FIPS 140-2 – Security Requirements for Cryptographic Modules
- Cryptographic module ports and interfaces, with all physical and logical access points identified and controlled.
- Roles, services, and authentication, requiring at minimum a user role for general cryptographic operations and a crypto-officer role for administrative tasks like initialization and key management.3National Institute of Standards and Technology. FIPS 140-2 – Security Requirements for Cryptographic Modules
- Finite state model, describing every operational and error state, including power-on, self-test, user, crypto-officer, key-entry, and error states, so the module can never slip into a condition where cryptographic protections are bypassed.3National Institute of Standards and Technology. FIPS 140-2 – Security Requirements for Cryptographic Modules
- Physical security, ranging from none at Level 1 to full environmental failure protection at Level 4.
- Operational environment, covering the operating system and platform for software modules; at Level 2 and above, the operating system must meet specific access-control standards.
- Cryptographic key management across generation, distribution, entry, storage, and destruction.
- Electromagnetic interference and compatibility, with hardware modules required to meet FCC requirements.
- Self-tests, including power-up and conditional tests that verify cryptographic algorithms and internal components are functioning correctly.
- Design assurance, meaning the vendor must demonstrate sound configuration management, secure delivery procedures, and development practices that reduce the chance of exploitable flaws.
- Mitigation of other attacks, with the vendor documenting any known attacks beyond the scope of the other ten areas and the countermeasures the module employs.
Who Needs a FIPS 140-2 Validated Module
Federal agencies are the most direct audience. FIPS 200, NIST’s minimum security requirements for federal information systems, requires the use of FIPS-validated cryptographic modules whenever encryption is used to protect federal data.5FedRAMP. FedRAMP Policy for Cryptographic Module Selection and Use
The requirement extends well beyond government offices. Cloud service providers seeking FedRAMP authorization must use FIPS-validated cryptographic modules, meaning the module has to appear on NIST’s validated modules list and the provider has to configure it to operate in FIPS mode. Simply installing a validated product without enabling FIPS mode does not satisfy the requirement.5FedRAMP. FedRAMP Policy for Cryptographic Module Selection and Use
Healthcare organizations handling electronic protected health information under HIPAA also encounter FIPS 140-2. HHS guidance has referenced the standard as a benchmark for encryption of health data, and proposed updates to the HIPAA Security Rule would strengthen encryption requirements further. Defense contractors subject to DFARS and CMMC requirements face similar obligations for controlled unclassified information. In practice, any organization that stores, processes, or transmits federal data as a contractor, grantee, or service provider should expect FIPS validation requirements to appear somewhere in its compliance obligations.
Validated vs. Compliant
A recurring source of procurement trouble is the difference between a product that is FIPS 140-2 validated and one a vendor calls “FIPS compliant.” Validated means an accredited Cryptographic and Security Testing Laboratory tested the module, NIST’s Cryptographic Module Validation Program reviewed the results, and the module appears on the CMVP validated modules list with a certificate number. Compliant, on its own, is a vendor claim without independent testing behind it. FedRAMP and other federal frameworks require validated, not compliant. If you are checking a product against a federal encryption requirement, the certificate on the CMVP list is the artifact that matters.6National Institute of Standards and Technology. Cryptographic Module Validation Program – CST Lab Accreditation and Fees
The validated module also comes with a public security policy: a non-proprietary document that describes how the module works, what security level it targets, and how an end user can verify the module is operating in its validated configuration. If you are integrating a module into a compliant system, that security policy is the reference for configuring FIPS mode correctly.
The September 2026 Transition to FIPS 140-3
NIST stopped accepting new FIPS 140-2 validation submissions in September 2021. All new validations follow FIPS 140-3. Existing FIPS 140-2 certificates remain active until September 21, 2026, after which every remaining FIPS 140-2 certificate moves to the CMVP Historical List regardless of when it was originally issued.1National Institute of Standards and Technology. FIPS 140-3 Transition Effort
Moving to the Historical List does not mean the modules stop working. Federal agencies can continue operating historical modules in existing systems. What changes is procurement: NIST guidance indicates that agencies should not include historical modules in new procurements. For vendors, this means any product still relying on a FIPS 140-2 certificate will no longer be eligible for new federal contracts after September 2026.1National Institute of Standards and Technology. FIPS 140-3 Transition Effort
What Changed in FIPS 140-3
The most significant structural change is that FIPS 140-3 no longer contains all the technical requirements in one document. It references the international standards ISO/IEC 19790 for security requirements and ISO/IEC 24759 for testing methodology, so a single validation can satisfy both U.S. and international requirements. Entropy sources must now be formally documented and validated with continuous testing, where FIPS 140-2 required minimal documentation. Self-testing expanded beyond power-up checks to include runtime and conditional tests. The new standard also provides explicit support for software and hybrid modules at all security levels, whereas FIPS 140-2 mostly treated software modules as a Level 1 concern. Approved cryptographic algorithms are now governed by NIST’s SP 800-140 series rather than being listed in annexes attached to the standard itself.1National Institute of Standards and Technology. FIPS 140-3 Transition Effort
Planning the Move
If you are still operating under FIPS 140-2 certificates, inventory every validated module in your environment and map each one to its certificate expiration or the September 2026 Historical List deadline, whichever comes first. Validation timelines under FIPS 140-3 regularly exceed a year from lab submission to certificate issuance. The gap between a 140-2 certificate going historical and a 140-3 certificate being issued can leave a product uncertified for months, which is the kind of compliance hole that derails a federal procurement.