NIST - National Institute of Standards and Technology

09/30/2026 | Press release | Distributed by Public on 10/01/2026 03:04

Automation of the NIST Cryptographic Module Validation Program: April 2025 Status Report

Published
September 30, 2026

Author(s)

Christopher Celi, Alexander Calis, William Barker, Ayayidjin Gabiam, Karen Kent, Shawn Geddis, Barry Fussell, Andrew Karcher, Douglas Boldt, Stephan Mueller, Yi Mao, Kyle Vitale

Abstract

The Cryptographic Module Validation Program (CMVP) validates third-party assertions that cryptographic module implementations satisfy the requirements of Federal Information Processing Standards (FIPS) Publication 140-3, Security Requirements for Cryptographic Modules. The current cryptographic module validation process is heavily manual and out of sync with the pace of technology industry development and deployment. Thus, the NIST National Cybersecurity Center of Excellence (NCCoE) has undertaken the Automated Cryptographic Module Validation Project (ACMVP) to support improvement in the efficiency and timeliness of CMVP operations and processes. The goal is to demonstrate a suite of automated tools that make the FIPS 140-3 validation process more efficient and provide higher assurances that test findings reported for modules meet FIPS 140-3 requirements. This is the second status report for the project, describing progress made between September 2024 and April 2025 and planned next steps. A prior update of work accomplished can be found in the September 2024 status report. This document outlines progress across each of the three workstreams: the Test Evidence (TE) Workstream, the Protocol Workstream, and the Research Infrastructure Workstream. Each has its own scope and focus area. The combined impact of these workstreams will result in improvements to the overall automation of the CMVP.
Citation
NIST Cybersecurity White Papers (CSWP) - 37B
Report Number
37B
Pub Type
NIST Pubs

Citation

Celi, C. , Calis, A. , Barker, W. , Gabiam, A. , Kent, K. , Geddis, S. , Fussell, B. , Karcher, A. , Boldt, D. , Mueller, S. , Mao, Y. and Vitale, K. (2026), Automation of the NIST Cryptographic Module Validation Program: April 2025 Status Report, NIST Cybersecurity White Papers (CSWP), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.CSWP.37B , https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=962190 (Accessed October 1, 2026)
Additional citation formats

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

NIST - National Institute of Standards and Technology published this content on September 30, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 01, 2026 at 09:04 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]