How should teams maintain a FIPS 140-3 certificate claim?
Treat the public CMVP certificate entry as the current reference for the validation claim. Before using it in procurement, customer trust, audit, or product-security material, verify the status, certificate number, module name, vendor, version, tested configuration, caveats, Security Policy, and validation history on the official NIST CMVP site. Record the date of that check because the public status and supporting documents can change.
Do not rely on a downloaded certificate image or a vendor slide as the only proof. FIPS 140-3 treats CMVP validation as a module-level decision after accredited-laboratory testing and CMVP review, so the public claim must continue to identify the module that was actually validated rather than the surrounding product by implication.
- Record the official CMVP URL, certificate number, validation status, module name, vendor, module version, tested configuration, and date checked.
- Compare the product or embedded module being offered with the certificate entry and the non-proprietary Security Policy.
- Re-check the CMVP entry before renewing public claims, responding to procurement questionnaires, or accepting a vendor's updated module package.
Official search page for checking certificate number, vendor, module name, validation status, and certificate details.
Explains that CMVP validates cryptographic modules and that federal agencies use validated modules as a procurement metric.