When can vendor affirmation be used under FIPS 140-3?
is available only for specific cases described in CMVP Implementation Guidance. For SP 800-208 , IG C.O permits it only when the implementation performs the required cryptographic algorithm self-tests, the underlying operations and parameter sets have the required CAVP certificates, and the verifies each supported HSS operation through source-code review. The same IG preserves the separate state-management requirements in Section 8 of SP 800-208.
Do not describe as a general validation status. The FIPS 140-3 standard says cryptographic modules are validated through CMVP, with testing by accredited CST laboratories, while CAVP addresses approved security function and sensitive security parameter generation and establishment method testing.
- Confirm the exact IG section that allows the claim, such as IG C.O for SP 800-208 or IG D.H for SP 800-133 key generation.
- Keep CAVP certificate numbers for the underlying algorithms that the IG requires, including the operations used by an implementation.
- Make sure the Security Policy places the claim in the correct table or disclosure location required by the applicable IG.
Supports the specific IG C.O conditions for SP 800-208 HSS vendor affirmation, including CASTs, LMS CAVP certificates, CSTL source-code review, Security Policy placement, and transition when CAVP testing becomes available.
Supports the distinction between CMVP module validation, accredited CST laboratory testing, and the procurement role of validated modules.
Public NIST search page for checking algorithm-validation certificate evidence that an IG may require before a vendor-affirmed claim is usable.