What does an algorithm certificate prove under FIPS 140-3?
A CAVP algorithm certificate supports the algorithm part of a FIPS 140-3 evidence package. The CMVP implementation guidance says cryptographic algorithm implementations are tested and validated under CAVP, while cryptographic modules are tested and validated under CMVP.
That distinction matters in public claims. A product team should not describe a product as FIPS 140-3 validated merely because one embedded algorithm has a CAVP certificate. The module still needs its own CMVP validation record and Security Policy for the claimed module boundary.
- Use the CAVP certificate to identify the tested algorithm implementation, implementation version, and operational environment.
- Use the CMVP module certificate and Security Policy to support a FIPS 140-3 module-validation claim.
- Keep customer and procurement wording separate: CAVP-tested algorithm implementation is not the same claim as CMVP-validated cryptographic module.
Supports the distinction between CAVP testing for algorithm implementations and CMVP validation for cryptographic modules.
Explains that CMVP validates cryptographic modules and that validated modules are the procurement metric for agencies.
Public NIST search page for checking algorithm validation records used as supporting evidence.