# FIPS (Federal Information Processing Standards) | Secureframe

> FIPS 140-2 vs FIPS 140-3, the four security levels, and why using AES-256 is not the same as using FIPS-validated AES-256. Practical notes on cryptography requirements.

canonical: https://secureframe.com/glossary/fips

FIPS are mandatory NIST-issued standards that federal agencies and their contractors must follow. For defense and cloud compliance, the standards you will actually encounter are FIPS 140-2 and FIPS 140-3 (cryptographic module validation) and FIPS 199 (security categorization). FIPS 140-3 took effect September 2019. NIST stopped accepting new FIPS 140-2 validations in April 2022.

### Which FIPS Standards Come Up in Practice

- **FIPS 140-2 / 140-3: **Security requirements for cryptographic modules. Four levels. This is the one you need for encryption compliance.
- **FIPS 199: **How to categorize a federal information system as Low, Moderate, or High impact. FedRAMP uses this.
- **FIPS 200:** Minimum security requirements. Points to NIST SP 800-53 for the actual controls.

### FIPS 140-2/140-3 Security Levels

- **Level 1:** At least one approved algorithm. No physical security requirements. Most software libraries fall here.
- **Level 2:** Tamper-evidence required. Role-based authentication. Common for enterprise hardware.
- **Level 3:** Tamper-resistance required. Identity-based authentication. Common for HSMs.
- **Level 4:** Complete envelope of protection. Rare outside of defense and intelligence hardware.

### FIPS 140-2 vs 140-3: The Transition

FIPS 140-3 aligns with ISO/IEC 19790. It became effective on September 22, 2019. The Cryptographic Module Validation Program (CMVP) stopped accepting new 140-2 submissions on April 1, 2022. Existing 140-2 validations stay on the active list until their sunset date, then move to historical. If you are specifying new cryptography today, you want a 140-3 validated module.

### Where FIPS-Validated Crypto Is Required

NIST SP 800-171 requirement 3.13.11 says to use FIPS-validated cryptography when protecting the confidentiality of CUI. This covers VPN tunnels, disk encryption, email encryption, database encryption, and wireless. FedRAMP requires FIPS-validated cryptography at every impact level.

### Why 'FIPS-Compliant' Is Not 'FIPS-Validated'

Using AES-256 is not the same as using a FIPS-validated AES-256 implementation. Validation means a specific module was tested by an accredited lab and appears on the CMVP validated modules list at csrc.nist.gov. An assessor will ask for the certificate number. 'We use strong encryption' is not an answer.
