What does an algorithm certificate prove under FIPS 140-3?
A supports the algorithm part of a FIPS 140-3 evidence package. It shows that the named implementation was tested for the algorithm capabilities and operational environments recorded by CAVP. An accredited CST laboratory separately tests the cryptographic module that integrates and uses that implementation, and reviews and validates the submission.
That distinction matters in public claims. A product team should not describe a product as FIPS 140-3 validated merely because one embedded algorithm has a certificate. The module still needs its own validation record and Security Policy for the claimed module boundary.
- Use the certificate to identify the tested algorithm implementation, implementation version, and operational environment.
- Use the module certificate and Security Policy to support a FIPS 140-3 module-validation claim.
- Keep customer and procurement wording separate: -tested algorithm implementation is not the same claim as -validated cryptographic module.
Supports the distinction between CAVP testing for algorithm implementations and CMVP validation for cryptographic modules.
Explains that CMVP validates cryptographic modules and that validated modules are the procurement metric for agencies.
Public NIST search page for checking algorithm validation records used as supporting evidence.