AjakoTaja
492 FIPS 140-2 cryptographic modules remain active weeks before sunset
Trending · Score 63
1 min readUpdated 1h ago
Drafted by AI, reviewed by the Ajako Taja Editorial Team · How we use AI

AI Summary

With only 23 days left until the FIPS 140-2 sunset, 492 active certificates remain, raising questions about compliance readiness for legacy systems.

  • Analysis of NIST data by 808bits reveals 492 FIPS 140-2 security certificates remain active with only 23 days until the standard's sunset.
  • The FIPS 140-2 standard is being phased out in favor of FIPS 140-3, which requires more rigorous security testing.
  • It remains unclear how many of these active certificates belong to systems that have already reached end-of-life versus those that represent ongoing compliance gaps.

NIST records indicate 492 cryptographic modules are still operating under the FIPS 140-2 standard with less than a month before its official retirement. This transition follows the 2019 rollout of FIPS 140-3, which aligns closer with international ISO standards to address evolving cybersecurity threats. Despite the impending deadline, the persistence of these legacy certifications suggests a significant lag in enterprise-wide hardware and software migration. Whether these remaining modules will be formally revoked or grace-period extended remains the central concern for security administrators managing compliance deadlines.

Get the story before everyone else.

1-minute briefings. Zero noise. Straight to your inbox.

Join our growing community of readers

Discussion

No comments yet. Be the first to start the conversation!

Leave a comment

Comments are reviewed for community standards.