- Key Takeaways
- What Actually Changed Between FIPS 140-2 and FIPS 140-3?
- What is the September 21, 2026 Deadline, Exactly?
- What Does "Historical" Status Mean in Practice?
- How Should Organizations Plan the FIPS 140-2 to 140-3 Migration?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Migrate to FIPS 140-3 Before the Deadline
FIPS 140-2 and FIPS 140-3 are successive NIST standards for validating cryptographic modules; FIPS 140-3, based on the international ISO/IEC 19790 standard, is now the only standard accepting new module submissions, and existing FIPS 140-2 certificates move to historical status on September 21, 2026.
FIPS 140-3 replaces FIPS 140-2 as NIST’s cryptographic module validation standard, aligning U.S. requirements with the international ISO/IEC 19790 standard. NIST stopped accepting new FIPS 140-2 submissions in September 2021, and every FIPS 140-2 validation certificate, regardless of level, moves to historical status on September 21, 2026, meaning organizations must migrate to FIPS 140-3 validated modules before that date.
Key Takeaways
- FIPS 140-3 is based on ISO/IEC 19790, aligning the U.S. standard with the international standard for the first time and easing cross-border recognition of validated modules.
- NIST stopped accepting new FIPS 140-2 module submissions in September 2021; all new validations since then have been issued against FIPS 140-3.
- September 21, 2026 is the hard deadline: every FIPS 140-2 certificate, at every security level, moves to historical status on that date.
- A “historical” validation is not automatically invalid for existing deployments, but federal procurement and many regulated industries treat historical status as non-compliant for new purchases.
- FIPS 140-3 adds non-invasive attack testing requirements and updated software/firmware security requirements not present in FIPS 140-2.
What Actually Changed Between FIPS 140-2 and FIPS 140-3?
| Aspect | FIPS 140-2 | FIPS 140-3 |
|---|---|---|
| Base standard | U.S.-specific (NIST-authored) | Aligned to ISO/IEC 19790 (international) |
| New submissions accepted | Closed September 2021 | Only standard currently accepting submissions |
| Non-invasive attack testing | Not required | Added as a testable requirement at higher levels |
| Software/firmware security | Original 2001-era requirements | Updated to reflect modern module architectures |
| Four security levels | Yes (1-4) | Yes (1-4), same conceptual structure, updated test requirements |
What is the September 21, 2026 Deadline, Exactly?
September 21, 2026 is the date every remaining FIPS 140-2 validation certificate moves to historical status on NIST’s Cryptographic Module Validation Program (CMVP) list, regardless of which security level it was validated at or when it was originally issued. This is a hard NIST-set date, not a rolling expiration tied to each individual certificate’s issue date, which is why organizations still relying on FIPS 140-2 validated modules need a clear migration plan well ahead of it.
What Does “Historical” Status Mean in Practice?
A historical validation means the module is no longer actively tracked as current on the CMVP list, though systems already deployed with it do not stop functioning overnight. The practical impact falls mainly on procurement: federal agencies and many regulated buyers require currently validated (not historical) modules for new purchases, and some compliance frameworks explicitly reference active FIPS 140-3 validation as a control requirement, making historical status a real blocker for new contracts even if existing deployments continue to run.
How Should Organizations Plan the FIPS 140-2 to 140-3 Migration?
- Inventory every HSM, cryptographic library, and embedded module currently running under a FIPS 140-2 validation.
- Check each vendor’s FIPS 140-3 validation status and roadmap for the specific hardware or software version in use.
- Prioritize migration for anything tied to federal procurement, active compliance audits, or contracts requiring current validation.
- Plan hardware refresh cycles and software updates around the September 2026 deadline rather than treating it as a distant date.
- Validate the migrated environment end to end, confirming the new module’s FIPS 140-3 certificate number and security level match what compliance documentation requires.
How Encryption Consulting Helps
How Encryption Consulting Helps HSM-as-a-Service runs on FIPS 140-3 validated hardware today, and our HSM Services and FIPS Advisory teams help organizations inventory FIPS 140-2 dependencies and plan a migration ahead of the September 2026 deadline. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
When do FIPS 140-2 certificates expire?
Every FIPS 140-2 validation certificate moves to historical status on September 21, 2026, a single NIST-set deadline that applies regardless of the module’s original validation date or security level.
Can I still buy FIPS 140-2 validated hardware?
New FIPS 140-2 submissions stopped being accepted by NIST in September 2021, so any hardware or software still marketed as FIPS 140-2 validated was validated before that cutoff. Organizations purchasing new cryptographic modules should confirm current FIPS 140-3 validation instead.
What is the main technical difference between FIPS 140-2 and FIPS 140-3?
FIPS 140-3 is based on the international ISO/IEC 19790 standard, adds non-invasive attack testing requirements, and updates software and firmware security requirements to reflect modern module architectures, compared to FIPS 140-2’s original 2001-era requirements.
Does my organization need to migrate immediately?
It depends on your compliance obligations and procurement requirements, but every organization relying on FIPS 140-2 validated modules should have a migration plan in place well before September 21, 2026, since historical status affects new federal procurement and many regulated-industry requirements.
Migrate to FIPS 140-3 Before the Deadline
Take the next step HSM-as-a-Service runs on FIPS 140-3 validated hardware today. Our HSM Services team helps you inventory FIPS 140-2 dependencies and plan your migration well ahead of September 2026. Explore HSM-as-a-Service to get started.
- Key Takeaways
- What Actually Changed Between FIPS 140-2 and FIPS 140-3?
- What is the September 21, 2026 Deadline, Exactly?
- What Does "Historical" Status Mean in Practice?
- How Should Organizations Plan the FIPS 140-2 to 140-3 Migration?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Migrate to FIPS 140-3 Before the Deadline
