Artifact GuideGLOBALFIPS 140-3

FIPS 140-3 vs ISO/IEC 19790 and ISO/IEC 24759

A comparison of the FIPS 140-3 validation layer with the ISO/IEC cryptographic module requirements and test standards behind it.

Use it to separate CMVP validation evidence from an ISO standards citation and to identify the edition that a claim actually uses.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use FIPS 140-3 and the certificate when the question is whether a specific cryptographic module is validated for a claimed use. Use for the international module requirements and for the test requirements. Always name the edition: FIPS 140-3 and current CMVP guidance still identify ISO/IEC 19790:2012 with its 2015 correction and ISO/IEC 24759:2017, while ISO published ISO/IEC 19790:2025 and ISO/IEC 24759:2025 as the current standalone editions and withdrew the older editions.

Side-by-side comparison

FIPS 140-3 vs ISO/IEC 19790 and ISO/IEC 24759: practical differences

This side-by-side view helps distinguish validation claims from the ISO/IEC requirements and test standards referenced by FIPS 140-3.

Review all sources
First framework
FIPS 140-3 and CMVP

The validation and federal-use side: use it for certificate scope, federal procurement claims, security levels, approved algorithms, module evidence, and program guidance.

Second framework
ISO/IEC 19790 and ISO/IEC 24759

The international standard-reference side: use it for cryptographic module security requirements and test-requirements framing, not as a standalone certificate.

Comparison row 1

Scope and covered activity

FIPS 140-3 and CMVP

FIPS 140-3 covers cryptographic modules used in security systems and validation of those modules, including the defined module boundary, security level, interfaces, roles, services, and operational environment.

ISO/IEC 19790 and ISO/IEC 24759

covers security requirements for cryptographic modules; covers test requirements for cryptographic modules. The public ISO cited sources support this scope-level distinction, not a detailed clause mapping.

Comparison row 2

Who uses the result

FIPS 140-3 and CMVP

Vendors, CST laboratories, reviewers, federal buyers, and Canadian federal users rely on the FIPS/CMVP result to evaluate validated cryptographic modules.

ISO/IEC 19790 and ISO/IEC 24759

Standards, assurance, procurement, and lab teams may cite or to describe the requirement or test basis behind cryptographic module assessment work.

Comparison row 3

When the comparison matters

FIPS 140-3 and CMVP

The FIPS side matters when a product claim, federal procurement response, system authorization, customer contract, or module release depends on FIPS 140-3 validation or approved cryptography evidence.

ISO/IEC 19790 and ISO/IEC 24759

The ISO side matters when a customer, lab, or policy asks which international cryptographic module requirements or test requirements sit behind the FIPS 140-3 work.

Comparison row 4

Work products

FIPS 140-3 and CMVP

FIPS/ work products include module specification, security policy, service and approved-mode descriptions, operational-environment details, algorithm validation evidence, test reports, entropy and self-test support, and change-impact records.

ISO/IEC 19790 and ISO/IEC 24759

and references support the requirements and test-method vocabulary, but this page does not assert unsupported one-to-one ISO clause deliverables.

Operational implication

Build the deliverable list from guidance for a FIPS claim, then use ISO references only where the source material or customer request actually cites them.

Comparison row 5

Evidence and records

FIPS 140-3 and CMVP

Keep certificate scope, module version, boundary diagrams, security levels, service tables, approved algorithm certificates, security policy text, lab test evidence, and change decisions together.

ISO/IEC 19790 and ISO/IEC 24759

Keep ISO references as standards support: the requirements citation, the test-requirements citation, and any separately reviewed ISO text or procurement crosswalk.

Comparison row 6

Timing and updates

FIPS 140-3 and CMVP

FIPS 140-3 superseded FIPS 140-2, became effective after approval, and is supported by guidance that changes over time; validation evidence should track the guidance version used for the submission or change review.

ISO/IEC 19790 and ISO/IEC 24759

ISO published :2025 as edition 3 and withdrew ISO/IEC 19790:2012 and Cor.1:2015. FIPS 140-3 and the April 9, 2026 implementation guidance still name the 2012 requirements edition with its 2015 corrections.

Comparison row 7

Assurance route

FIPS 140-3 and CMVP

FIPS 140-3 assurance runs through validation, with testing by accredited CST laboratories and acceptance by U.S. and Canadian federal agencies for protected information uses described in the source material.

ISO/IEC 19790 and ISO/IEC 24759

and provide standards references; the cited public sources do not show an independent enforcement or certificate route equivalent to validation.

Operational implication

When a buyer asks for validated cryptography, confirm whether they mean a -listed FIPS 140-3 module rather than a general ISO standards citation.

Comparison row 8

Overlap and reuse

FIPS 140-3 and CMVP

FIPS 140-3 incorporates and references and adds FIPS/-specific validation context, NIST SP 800-140 modifications, and implementation guidance.

ISO/IEC 19790 and ISO/IEC 24759

ISO references can explain the underlying security and test framework, but they should not absorb FIPS-specific certificate, approved-mode, CAVP, or evidence requirements.

Comparison row 9

Practical decision rule

FIPS 140-3 and CMVP

Use FIPS 140-3 and as controlling when the question is "Is this cryptographic module validated for the claimed use?"

ISO/IEC 19790 and ISO/IEC 24759

Use or as controlling only when the question is about the international requirements or test-requirements standard named in the request.

Practical decision rule

How to choose between FIPS 140-3 and ISO/IEC 19790 and ISO/IEC 24759

  • Choose FIPS 140-3 and when the visitor needs validation status, certificate scope, or a yes-or-no answer about whether the module is accepted as validated for the claimed use.
  • Choose or when the visitor needs the international requirements or test standard, and name the edition.
  • When a request mixes compliance and validation language, name both layers: the exact ISO edition for the requirement or test basis, and the FIPS/ certificate evidence for validation status.
Section 1

What is being compared?

FIPS 140-3 is the published Federal Information Processing Standard for security requirements for cryptographic modules. It applies to federal agencies using cryptography-based security systems and is the basis for validation of modules used to protect sensitive information.

FIPS 140-3 is based on :2012/Cor.1:2015 for module requirements and :2017 for testing. NIST's SP 800-140 series modifies specified ISO annexes and test sections, while implementation guidance supplies program decisions and clarifications.

:2025 and :2025 are the current standalone ISO editions, and ISO lists the 2012 requirements edition, its 2015 correction, and the 2017 test edition as withdrawn. The April 9, 2026 implementation guidance still maps to ISO/IEC 19790:2012 with the 2015 corrections and ISO/IEC 24759:2017. Do not assume that citing either 2025 edition proves conformity with the older editions and NIST modifications used for a FIPS 140-3 validation.

  • Use FIPS 140-3 when the claim is about validation, federal-agency acceptance, certificate scope, or a FIPS-labeled procurement requirement.
  • Use when the claim is about international cryptographic-module requirements, and state whether the claim concerns the 2025 edition or the 2012 edition incorporated into the current FIPS/ material.
  • Use :2017 for the test-requirements frame referenced by FIPS 140-3 and current guidance; use ISO/IEC 24759:2025 for the current standalone ISO test standard.
  • Do not describe or as a substitute for validation unless the procurement or assurance document explicitly allows that.
Section 2

Where FIPS 140-3 adds operational work

A FIPS claim requires more than a standards citation. FIPS 140-3 names four qualitative security levels and covers module specification, interfaces, roles, services and authentication, software and firmware security, operational environment, physical security, non-invasive security, sensitive security parameter management, self-tests, life-cycle assurance, and mitigation of other attacks.

guidance turns those requirements into validation operations: module boundary and service descriptions, algorithm certificate handling, approved security service indicators, operational-environment records, entropy and SSP evidence, self-test expectations, CVE management, and change-impact decisions.

  • Start FIPS evidence with the module boundary, version, operating environment, security level claims, roles, services, and approved versus non-approved services.
  • Attach algorithm claims to CAVP certificate evidence where guidance requires it.
  • Keep approved-mode indicators, security policy text, test reports, entropy support, self-test behavior, and change records together with the certificate scope.
  • Rerun the comparison when the module boundary, implementation, operational environment, validated algorithms, or public claim changes.
Section 3

Where ISO/IEC 19790 and ISO/IEC 24759 fit

defines cryptographic module security requirements, and defines cryptographic module test requirements. The current standalone editions are ISO/IEC 19790:2025 and ISO/IEC 24759:2025. For the FIPS route, the baseline remains the older editions named in FIPS 140-3 and current material, together with the applicable NIST modifications, Derived Test Requirements, management manual, and implementation guidance.

An ISO citation explains the requirements or test-standard layer. It does not establish a module's validation status, certificate scope, approved services, or tested operational environments.

  • Record the exact ISO edition. Do not collapse the 2012/2015 and 2025 requirements editions, or the 2017 and 2025 test editions, into an undated claim.
  • Use FIPS and citations to support validation status, certificate scope, submission evidence, and U.S./Canadian federal acceptance claims.
  • Keep any deeper ISO clause mapping outside this page unless the source text is available and reviewed directly.
  • Flag customer requests that ask for "ISO 19790 compliant" evidence when they actually require a FIPS 140-3 validated module.
Section 4

Procurement and audit evidence to keep separate

Keep three evidence sets separate: the FIPS 140-3 validation claim, the requirements reference, and the test-requirements reference. They overlap, but the labels answer different procurement and assurance questions.

For customer-facing claims, avoid broad wording such as "ISO/FIPS compliant" unless the statement identifies the module, version, boundary, certificate status, operational environment, and the source that supports the claim.

  • FIPS claim record: module name, version, boundary, security level, certificate identifier or status, operational environment, validated algorithms, and security policy link or artifact.
  • ISO requirements record: the exact edition, the procurement language, and the requirement area being discussed. Do not silently substitute the 2025 edition for the 2012 edition named by FIPS 140-3.
  • Test-method record: the or /DTR test reference named by the lab, assessor, or customer.
  • Gap record: unsupported equivalence assumptions, missing certificate scope, expired or changed operational environments, and evidence reused from a different module.
Primary sources

References and citations

csrc.nist.gov
Referenced sections
  • Program guidance for FIPS 140-3 validation evidence, binding/embedding, approved service indicators, CAVP certificates, change impact, and CMVP operating expectations.
"CAVP addresses the testing of Approved Security Functions"
Related guides

Explore more topics

FIPS 140-3 algorithm certificate mapping: ACVTS certificates to module boundary
Map CAVP algorithm certificates to FIPS 140-3 module services, approved security functions, security policy tables, and validation evidence.
FIPS 140-3 Algorithm Certificates FAQ
How CAVP algorithm certificates support, but do not replace, FIPS 140-3 cryptographic module validation evidence.
FIPS 140-3 Applicability Test
Check whether FIPS 140-3 applies to a cryptographic module claim by testing agency use, module boundary, security level, approved functions, CMVP status, and procurement evidence.
FIPS 140-3 Approved and Non-Approved Mode Workflow
Classify FIPS 140-3 module services by approved security service, allowed no-security-claimed use, and non-approved service evidence.
FIPS 140-3 approved-mode evidence workflow
Collect FIPS 140-3 approved-mode evidence for a specific module service: boundary, indicator, selected CAVP capabilities, Security Policy entry, and deployment configuration.
FIPS 140-3 Certificate Maintenance FAQ
How to maintain FIPS 140-3 certificate evidence after validation by checking module status, version, caveats, Security Policy, and revalidation records.
FIPS 140-3 Change Impact Review
Review FIPS 140-3 module changes against boundary, version, operational environment, embedded module, software loading, CVE, and certificate evidence.
FIPS 140-3 CMVP Lifecycle and Status Guide
Follow a FIPS 140-3 module from scoping and CST-laboratory testing through CMVP review, publication, Active status, revalidation, and procurement checks.
FIPS 140-3 compliance guide
An official source FIPS 140-3 compliance guide for cryptographic module scope, security-level claims, CMVP validation evidence, and procurement review.
FIPS 140-3 Entropy and DRBG Evidence
FIPS 140-3 entropy and DRBG guidance for module boundary decisions, entropy caveats, Security Policy evidence, ESV references, and DRBG CSP handling.
FIPS 140-3 Entropy Evidence FAQ
How FIPS 140-3 entropy evidence should document entropy source location, GetEntropy access, SP 800-90B testing, Security Policy text, and certificate caveats.
FIPS 140-3 FAQ for Cryptographic Modules
Answers to common FIPS 140-3 questions about scope, CMVP validation, algorithm certificates, module boundaries, approved mode, and validation evidence.
FIPS 140-3 Module Boundaries FAQ
Understand how FIPS 140-3 module boundaries affect cryptographic module scope, interfaces, software and firmware components, and bound or embedded validated modules.
FIPS 140-3 Module Boundary Selector Workflow
A FIPS 140-3 workflow for selecting a cryptographic module boundary, separating embedded and bound modules, and collecting CMVP validation evidence.
FIPS 140-3 operational environments FAQ
Learn what a FIPS 140-3 operational environment means for software, firmware, and hybrid cryptographic modules, and what evidence to check before relying on a validation claim.
FIPS 140-3 security levels: how to choose and evidence them
A practical FAQ on FIPS 140-3 security levels, module scope, CMVP evidence, bound or embedded modules, and common claim mistakes.
FIPS 140-3 Security Policy Template
Draft the vendor-authored parts of a FIPS 140-3 CMVP Security Policy and prepare the structured module information that CMVP merges into the final policy.
FIPS 140-3 Validation Checklist
Checklist for preparing a cryptographic module for FIPS 140-3 validation: boundary, levels, services, approved algorithms, entropy, tests, security policy, and change evidence.
FIPS 140-3 Validation Maintenance
Decide whether a changed FIPS 140-3 module still matches its validation or needs a CMVP revalidation scenario, evidence update, or paused claim.
FIPS 140-3 Validation Maintenance Change Workflow
Triage a changed FIPS 140-3 module against current CMVP revalidation scenarios, Security Policy evidence, CAVP testing, operational environments, and CVE handling.
FIPS 140-3 Vendor Affirmation FAQ
When vendor affirmation can support a FIPS 140-3 module claim, what it does not supersede, and which Security Policy, CAVP, CSTL, and test-report evidence to keep.
FIPS 140-3: FIPS 140-2 vs FIPS 140-3
Compare FIPS 140-2 legacy references with FIPS 140-3 requirements, ISO/IEC 19790 alignment, CMVP testing evidence, and guidance mappings.
FIPS 140-3: Module Boundary and Service Mapping
Map a FIPS 140-3 cryptographic module boundary to services, approved algorithms, operational environments, and CMVP validation evidence.
FIPS 140-3: Module Boundary Selector
Select and document a FIPS 140-3 cryptographic module boundary across hardware, software, firmware, operational environment, services, and validation evidence.
FIPS 140-3: Operational Environment
FIPS 140-3 operational environment guidance for software, firmware, hybrid, CAVP certificate, EVM, and PAA/PAI validation claims.
FIPS 140-3: Security Levels Explained
Compare FIPS 140-3 Security Levels 1 through 4 by requirement area and document a level claim without extending it beyond the validated module.
FIPS 140-3: step-by-step workflow for mapping algorithm certificates to CMVP modules
Map CAVP algorithm certificates to a FIPS 140-3 module by matching the tested implementation, operational environment, service use, and CMVP Security Policy record.
How should teams handle approved mode under FIPS 140-3?
Answer the FIPS 140-3 approved-mode question with service-level indicators, Security Policy evidence, and limits on non-approved functions.