Why the Revalidation Path You Choose Determines Your Cost, Effort and Timeline! Achieving an initial FIPS validation is a major milestone, but it may not be a one-time exercise! As products evolve through patches, new platforms, or branding updates, your cryptographic module must be revalidated to stay on the CMVP Active List. The challenge is not the update itself but choosing …
FIPS Validation Pitfalls—and How to Avoid Costly Delays
A Practical Guide for Security, Engineering, and Compliance Teams Achieving FIPS validation is often viewed as a final checkpoint—something to address once development is complete. In practice, this mindset is one of the most common reasons organizations encounter delays, rework, …
CMVP Transitions Update (July 2023)
CMVP algorithm transitions can be a great source of anxiety for vendors who seek to attain or maintain compliance to the FIPS 140-2 and 140-3 standards. A great deal of diligence, patience and persistence are required to continually review and …
ACVP Vector Test Harness for OSSL 3.x
Lightship has released, as open source, an ACVP vector test harness for OpenSSL 3.x. The code can be found in our GitHub repository at https://github.com/lightshipsec/ls-acvp-harness. The README.md contains the current capabilities which we expect to update and maintain. At the …
FIPS 140-3 Is Here!
The countdown is on. As of September 22, 2021, FIPS 140-2 will be sunset and only FIPS 140-3 validations can be submitted to the Cryptographic Module Validation Program (CMVP). In this latest post, we cover the key differences in the …





