Does CMMC require FIPS-validated encryption, or is FIPS-compliant enough?

CMMC unequivocally requires the use of FIPS-validated cryptographic modules, not merely FIPS-compliant ones, for protecting Controlled Unclassified Information (CUI). This mandate stems directly from NIST SP 800-171, which forms the technical foundation for CMMC Level 2 and above. FIPS validation, conducted by the NIST Cryptographic Module Validation Program (CMVP), ensures that cryptographic modules have undergone rigorous testing and certification against FIPS 140-2 or FIPS 140-3 standards, providing a higher assurance level than self-attestation.

Practitioners must ensure that any cryptographic module used to protect CUI is listed on the NIST Cryptographic Module Validation Program (CMVP) website. This means organisations cannot simply rely on a vendor's claim of "FIPS compliance" or a product having a "FIPS mode." Instead, they must verify the specific module's validation certificate number and ensure it is actively maintained. This requirement applies to all cryptographic functions protecting CUI, including data at rest, data in transit, and cryptographic key management. Procurement processes should explicitly demand evidence of FIPS validation for relevant components.

A common pitfall is confusing vendor self-attestation of "FIPS compliance" with official "FIPS validation." While a product might incorporate FIPS-compliant algorithms, only a FIPS-validated module has undergone the stringent testing and certification process by NIST and the Canadian Centre for Cyber Security. During a CMMC assessment, assessors will specifically look for evidence of this validation, such as CMVP certificate numbers associated with the cryptographic modules in use. Failure to demonstrate the use of FIPS-validated cryptography for CUI protection will result in a finding during the assessment, impeding CMMC certification.

Sources

  • NIST SP 800-171 Rev. 2, Requirement 3.13.11
  • CMMC Model v2.0, Level 2, Practice SC.L2-3.13.11

Related