Compliance & certification
What has actually been validated by an external body, as opposed to asserted?
Requirements, evidence source, and references
This page is the citable form of this dimension — a finding elsewhere can link straight to the bar it was judged against.
Compliance & certification
7 requirementsWhat has actually been validated by an external body, as opposed to asserted?
FIPS 140-3 validation status, checked against the public CMVP Validated Modules list.
HSMLibrary / SDKPKI / CA- NIST/CCCS Cryptographic Module Validation Program (CMVP)confirmed2026-08-13Joint NIST + Canadian Centre for Cyber Security programme. Publishes a public Validated Modules search and a separate Modules In Process list; currently prioritises FIPS 140-3 submissions.
Whether a module is validated, in process, or neither — three different states, reported as such and never collapsed into “FIPS compliant”.
- NIST/CCCS Cryptographic Module Validation Program (CMVP)confirmed2026-08-13Joint NIST + Canadian Centre for Cyber Security programme. Publishes a public Validated Modules search and a separate Modules In Process list; currently prioritises FIPS 140-3 submissions.
The certificate's scope is read, not just its existence: what was validated is frequently narrower than what is marketed.
Which module, which version, and which operational environment the certificate actually covers.
Whether the PQC algorithms specifically are in scope, or only the classical ones.
- NIST/CCCS Cryptographic Module Validation Program (CMVP)confirmed2026-08-13Joint NIST + Canadian Centre for Cyber Security programme. Publishes a public Validated Modules search and a separate Modules In Process list; currently prioritises FIPS 140-3 submissions.
Common Criteria evaluation status, with protection profile and assurance level, where applicable.
HSMPKI / CABrowser and OS root-program inclusion, and standing in good order with the relevant program requirements.
PKI / CA- CA/Browser Forum — Baseline Requirementssearch-corroboratedApplies to publicly trusted CAs only. Primary text not read in this session.
Sector-specific certifications relevant to the vendor's stated market.
Where CNSA 2.0 alignment is claimed, the claim matches the suite's actual algorithm and timeline requirements.
- NSA Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)search-corroborated2026-08-12Direct PDF read was blocked (HTTP 403) when last attempted; contents corroborated across secondary sources only. Do not upgrade without reading the primary.
- NIST/CCCS Cryptographic Module Validation Program (CMVP)confirmed2026-08-13Joint NIST + Canadian Centre for Cyber Security programme. Publishes a public Validated Modules search and a separate Modules In Process list; currently prioritises FIPS 140-3 submissions.
- NSA Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)search-corroborated2026-08-12Direct PDF read was blocked (HTTP 403) when last attempted; contents corroborated across secondary sources only. Do not upgrade without reading the primary.
- NIST Automated Cryptographic Validation Protocol (ACVP) / CAVP algorithm testingsearch-corroboratedThe algorithm-level validation programme that sits beneath module validation. Primary programme text not read in the session that recorded this entry.