FIPS PUB 140-3 specifies security requirements for cryptographic modules and defines four increasing, qualitative security levels. It covers 11 requirement areas including interfaces, roles and services, software or firmware security, operating environment, physical security, non-invasive security, SSP management, self-tests, lifecycle assurance, and mitigation of other attacks.
It is the baseline standard that federal agencies use when cryptography must provide actual protection instead of unvalidated plaintext-level assurance.