Secure Controls Framework
Download The SCF

When do FIPS 140-2 validations expire and what happens after September 2026?

Direct Answer

Under the NIST CMVP transition schedule, remaining active FIPS 140-2 validated cryptographic modules were set to move to the Historical list on September 21, 2026. Historical status means the CMVP no longer lists these modules as actively validated for procurement verification purposes. Organizations relying on FIPS 140-2 validated products should now confirm the status of each module on the CMVP validated modules search, check whether their agency or contract still accepts Historical-status modules for existing deployments, and specify FIPS 140-3 validated modules for new procurements.

Detailed Answer

September 21, 2026 was the transition date set by NIST's Cryptographic Module Validation Program (CMVP). On that date, cryptographic modules still holding an active FIPS 140-2 validation were scheduled to move to Historical status in the CMVP module database. Historical status does not mean the product is insecure or defective - it means the CMVP no longer considers the validation active for new procurement verification. What this means in practice varies by context.

 

Federal agencies: OMB and agency-specific guidance determines whether Historical-status modules can remain in production. Agencies should confirm their position with their IT security teams.

 

DoD and national security systems: Given the intersection with CNSA 2.0 requirements, most classified and national security use cases will require FIPS 140-3 or higher-assurance products.

 

Commercial and contractual requirements: Many contracts and audit frameworks reference FIPS 140-2 compliance without specifying Historical vs. active status - review specific contracts and consult legal counsel if needed.

 

New procurements: Any organization procuring new cryptographic modules or products with embedded cryptographic functions should require FIPS 140-3 validation going forward.

 

Organizations should check the NIST CMVP module search at csrc.nist.gov to verify current validation status of specific products they rely on.