Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Automation of the NIST Cryptographic Module Validation Program: April 2025 Status Report

Published

Author(s)

Christopher Celi, Alexander Calis, William Barker, Ayayidjin Gabiam, Karen Kent, Shawn Geddis, Barry Fussell, Andrew Karcher, Douglas Boldt, Stephan Mueller, Yi Mao, Kyle Vitale

Abstract

The Cryptographic Module Validation Program (CMVP) validates third-party assertions that cryptographic module implementations satisfy the requirements of Federal Information Processing Standards (FIPS) Publication 140-3, Security Requirements for Cryptographic Modules. The current cryptographic module validation process is heavily manual and out of sync with the pace of technology industry development and deployment. Thus, the NIST National Cybersecurity Center of Excellence (NCCoE) has undertaken the Automated Cryptographic Module Validation Project (ACMVP) to support improvement in the efficiency and timeliness of CMVP operations and processes. The goal is to demonstrate a suite of automated tools that make the FIPS 140-3 validation process more efficient and provide higher assurances that test findings reported for modules meet FIPS 140-3 requirements. This is the second status report for the project, describing progress made between September 2024 and April 2025 and planned next steps. A prior update of work accomplished can be found in the September 2024 status report. This document outlines progress across each of the three workstreams: the Test Evidence (TE) Workstream, the Protocol Workstream, and the Research Infrastructure Workstream. Each has its own scope and focus area. The combined impact of these workstreams will result in improvements to the overall automation of the CMVP.
Citation
NIST Cybersecurity White Papers (CSWP) - 37B
Report Number
37B

Citation

Celi, C. , Calis, A. , Barker, W. , Gabiam, A. , Kent, K. , Geddis, S. , Fussell, B. , Karcher, A. , Boldt, D. , Mueller, S. , Mao, Y. and Vitale, K. (2026), Automation of the NIST Cryptographic Module Validation Program: April 2025 Status Report, NIST Cybersecurity White Papers (CSWP), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.CSWP.37B , https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=962190 (Accessed October 1, 2026)
Additional citation formats

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

Created September 30, 2026
Was this page helpful?