FIPS 140-3 is not a security guarantee, and auditors know it
This analysis argues that FIPS 140-3 certification is often misunderstood as a comprehensive security guarantee rather than a narrow validation of cryptographic modules. The author notes that many organizations purchase certified hardware but fail to operate it in the validated configuration, rendering the certification ineffective.
Why it matters
It challenges the industry reliance on compliance certifications as a substitute for actual security engineering and rigorous risk management.
A sales engineer at one of the major HSM vendors told me recently that over 90 percent of their customers who buy FIPS-enabled HSMs run them with FIPS mode disabled . They pay a premium for the certificate, then switch off the configuration it describes. By the end of this article you will understand why that is often the correct engineering decision.
On September 21, 2026, every remaining FIPS 140-2 certificate moves to NIST's historical list , and modules on that list should no longer be included in new federal procurements . Procurement teams are spending this summer chasing vendors for FIPS 140-3 paper, and vendors are spending it in a validation queue. A lot of money and attention is flowing toward a certificate.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in