Your company signs that its encryption meets the rules. Can you prove it?
Defense contracts require encryption (the way your computers scramble sensitive information) that the government has tested and approved. We show which of your systems use approved encryption, which do not, and give you the proof behind what your company signs.
Under CMMC’s self-check, the person who signs is your own senior manager, not an outside inspector. And the approvals keep changing: on 21 September 2026 a large group of older approvals moves to the government’s “Historical” list. It is not the last: 53 more follow through 2027.
No installer. No agent. No service. Nothing sent. Unzip a folder, read the scripts, run them, delete the folder.
Plain words used on this page
- Encryption
- Scrambling information so only the right people can read it.
- FIPS certificate
- The U.S. government’s official record that a piece of encryption software (or hardware) was tested by an approved lab. FIPS is the name of the government’s encryption standard.
- NIST
- The National Institute of Standards and Technology — the government agency that issues FIPS certificates.
- Historical list
- Where NIST moves certificates that are no longer active. Your systems keep working, but federal agencies are told not to include that software in new purchases.
- CUI
- Controlled Unclassified Information: sensitive government information, such as some contract drawings, that is not secret but must be protected.
- CMMC Level 2 (Self)
- The Defense Department’s cybersecurity check where your company checks itself against the rules and a senior manager signs.
- Plan of action
- Your company’s written to-do list of security gaps: what the gap is, who fixes it, and by when.
What the government requires, what your company must do, and what we provide
1 — What the government requires
If your company receives CUI on a Defense Department job, your contract’s cybersecurity clause requires those files to be protected with encryption that holds a FIPS certificate whenever they are sent or stored outside your company’s protected systems.
2 — What your company must do
- Meet the rules, and sign for them. Every contract with the cybersecurity clause requires your company to follow the security rules. Where your contract includes CMMC, your company also scores itself, posts the score in SPRS (the Defense Department’s supplier database), and a senior manager signs that it is true — and renews that signature every year.
- Check whether your contract asks for it. U.S. Army Corps of Engineers (USACE) construction job postings now include CMMC Level 2 (Self) — the level where your company checks itself. Check whether yours does. If it does, your own senior manager signs the statement.
- Hand the signature up the chain. Where the CMMC clause is in the contract, the prime contractor above you must get that signed statement from you before awarding your subcontract, and every year after.
- Be ready to show it. The government can still come and check what you signed.
- Write down any gap, with proof. If some of your encryption has no certificate, the rules let you put it in your plan of action as a temporary deficiency — a gap that is being fixed. But only when three things are true: the problem is small (“isolated use”), a real fix is on the way (“known fix is in process”), and the plan has steps, dates and progress (“milestones” and “show progress”).
“Isolated use of non-FIPS validated cryptography, with an associated Plan of Action, should be treated as a temporary deficiency…”
3 — What we provide
The proof behind what your company signs:
- Which of your systems use encryption that holds a FIPS certificate, which do not, and what each certificate’s government record says.
- How big any problem is, out of all your systems.
- For each gap, where a fix stands — and the letter asking the software maker to confirm it in writing, with a place to record the answer.
- Draft entries for your plan of action, for you to finish and approve.
- Your progress, the next time you run it.
- Every certificate number, so anyone can look it up on NIST’s website.
Knowing these rules is the easy part. The hard part is matching every program and version your company runs to the right government record — among thousands of records that keep changing. That is what our tool does.
What we never do: tell you that you are compliant, or how an inspector will score you. Those are the inspector’s decision and your company’s signature. And a draft only counts once your company finishes and approves it.
Sources: DFARS 252.204-7012 and NIST SP 800-171, requirement 3.13.11; the Defense Department’s CMMC Level 2 Assessment Guide (version 2.13), which limits the certificate requirement to information sent or stored outside the protected environment; 32 CFR 170.22 (the CMMC signature, renewed yearly) and DFARS 252.204-7021(d)(4) (the prime collects it), both only where the contract includes CMMC; the Defense Department’s scoring guide, NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (June 2020), used for contracts with the older clauses DFARS 252.204-7019 and 7020; and for CMMC, the 2024 rule, which says software makers’ approval problems “could be considered enduring exceptions or temporary deficiencies” (89 FR 83130–31).
The situation
On 21 September 2026, NIST moves every remaining FIPS 140-2 certificate to its Historical list. Certificates that are active today lose their standing for new federal procurement.
After that date, federal agencies are directed not to include those modules in new procurements. Your systems keep running — nothing switches off, and continued use is permitted on a documented assessment of where and how each module is used. What changes is your standing at the next contract action.
Most organizations find out during that contract action, because nobody maintains a map from deployed software to CMVP certificate numbers. It changes every time a vendor re-validates.
Source: NIST CMVP FIPS 140-3 Transition Effort. The date appears on every FIPS 140-2 certificate as its Sunset Date.
Why this is a contract problem, not a curiosity
A Department of Defense contract involving CUI carries DFARS 252.204-7012, which requires NIST SP 800-171, which requires FIPS-validated cryptography. On 21 September the certificates behind that cryptography move to the Historical list.
Most companies in the defense industrial base need CMMC Level 2, which is built on 800-171. CMMC Phase 1 is running now — November 2025 to November 2026 — so the FIPS deadline lands in the middle of it. Organizations are self-assessing against 800-171, and posting the score to SPRS, at the moment the validations they depend on stop counting for new procurement.
In fairness, the part of this that cuts against us: CMMC Phase 2 was suspended on 13 July 2026, so the third-party assessment that was due to appear in contracts from 10 November is not coming on that date. On 3 September DoD’s class deviation 2026-O0025 (Revision 3) let contracts require CMMC Level 1 or Level 2 (Self) and suspended the November Phase 2 transition, and a reform task force is expected to report in late September or early October. What did not change is everything the FIPS date touches: self-assessment, DFARS 252.204-7012 and NIST SP 800-171 all remain in force. Checked 15 September 2026 — reporting, DoD CIO — CMMC.
Free, instant, and nothing is sent to us — the lookup runs in your browser against USAspending.gov.
The other exposure: what you sign to win the work
Not being selected is the common outcome. It is not the only one. To win federal work you make statements — a representation of compliance, a score posted to SPRS, an answer on a prime’s questionnaire — and those statements go to the government, or to somebody passing them to the government.
The enforcement changed too. Since 2021 the Department of Justice has been pursuing defense contractors over cybersecurity misrepresentations under the False Claims Act — one settled for $9 million in 2022, over this same clause. It started with a former employee, not an audit.
Source: US Department of Justice, Eastern District of California, 8 July 2022. The settlement included no admission of fault or liability.
The exposure there is not weak encryption. It is affirming something that turns out not to be true — usually because nobody in the building actually knew. Of the eight Justice Department cybersecurity settlements we read, all concerned security requirements that were not met or were misrepresented, and none was about encryption itself. The risk is in what gets signed without proof. A documented gap, with a plan and a date, is a defensible position. An affirmation nobody can evidence is a different thing entirely.
Which is why we will not tell you that you are compliant. That is your assessor’s determination and your own affirmation. What we do is make sure the affirmation you sign is one you can evidence — and say plainly where the record does not settle it.
A description of a public enforcement record — not legal advice, and not a statement about your exposure. If any of it looks close to your situation, that is a conversation for your counsel.
What you get
A verdict, for your estate
Not “check your certificates”. Something like: 2 of your 5 systems rely on modules that lose standing on 21 September. Every affected certificate named and numbered — and named against your own systems, wherever the list you send identifies them.
The proof behind each plan line
Draft entries for your plan of action, letters to send your software makers, and a place to record their answers — for you to finish. Every certificate number can be looked up on NIST’s website, and we re-check each one before the report reaches you.
What we could not determine
Every report states its limits and its coverage gaps. If we could not tell, it says so rather than guessing.
What a report actually says
There are three honest answers, and we give whichever is true.
1 — You have exposure
2 of your 5 systems rely on cryptographic modules that lose federal procurement standing on 21 September 2026.
Each one named, with its certificate number and what to ask the vendor.
2 — You have no validated cryptography at all
No FIPS-validated cryptographic module was identified in this estate.
Nothing expires, because nothing currently holds standing. If a contract requires validated cryptography, that gap is live today rather than in September — a larger problem, and a different conversation.
3 — Your input cannot answer the question
This inventory cannot answer the question.
Some inventories structurally cannot show the exposure. We tell you that instead of returning a clean-looking result that means nothing.
Rather than take our word for any of that — here is a complete report, produced by the actual tool, with the columns of input that produced it. The estate is invented; the certificate records behind it are not.
How it works
- Check that it applies to you. Run the free lookup above, and read the sample report — a complete one, produced by the actual tool. The only question that matters is whether any contract you work under requires FIPS-validated cryptography. If none does, this is not for you and we would rather say so here than on a call.
- Confidentiality is already in force. Our terms contain a mutual NDA that binds us from the moment you accept them — nothing to sign, and no week waiting on two legal teams.
- You get the tool. Collectors, the assessment tool and a dated copy of the NIST record, licensed to you for the year. Run it on your own machines and nothing leaves your network. If you would rather we did it, send an export from whatever you already run — ServiceNow, Intune, SCCM, Tanium — or a spreadsheet. Three columns is enough.
- You produce the report. Run the tool and it is written in minutes, on your own machine. Prefer us to do it? Send the list and we return it in one to three business days, re-checked against the live NIST record before it leaves us.
- We walk you through it on a call. Including the limits page. It comes with pre-written language for your contracting officer.
What we don’t do
- We don’t install anything. No installer, no service, no scheduled task, nothing written to Program Files or the registry, and no administrator rights needed to produce the report. The bundle is a folder: unzip it, run it, delete it. Nothing is left behind and nothing keeps running afterwards.
- We don’t scan your network. No agents, no credentials, no connections in.
- You can read the collectors before you run them. They are plain PowerShell, a few hundred lines, and they collect a software list — package name, version, machine. Nothing else: no certificates, no keys, no user data. Your administrator should read them, and we wrote them expecting exactly that.
- We don’t keep your data. Your inventory is deleted on delivery, in writing. We can promise this because the report is reproducible from its recorded snapshot and assessment date.
- We don’t tell you that you are compliant. We assess certificate standing. Compliance is your contracting officer’s determination.
- We don’t publish accuracy figures. We give you numbered certificate records instead, each traceable to the public register.
- We don’t ask you to take our word for it. The assessment is deterministic: the same inventory, assessed against the same dated NIST record, produces the same report — the same document, months later. It records the exact version of every input it used, so an auditor can reproduce the result rather than trust it. That is unusual, and it is the reason we can delete your data and still stand behind the findings.
Run it yourself
Many organizations cannot release an asset inventory. For a defense contractor it is often CUI, and DFARS 252.204-7012 requires CUI to stay in systems meeting NIST SP 800-171. Asking you to upload it to an ordinary website could put you in breach of your own contract.
So there is a second route, and it is not a lesser one — or a cheaper one. It is the same assessment at the same price, run on your side of the boundary instead of ours.
We send you the collectors, the assessment tool and a dated copy of the NIST record. You run all of it on your own machines. Nothing leaves your network. If you want a second read afterwards, send us the finished report — it names certificates, not every version of everything you run.
Why this is the opposite of the usual approach
Tools in this category generally work by deploying something into your estate: a sensor installed from a package, an appliance stood up as a virtual machine with a port open back to a collection hub, or an analyser that attaches to running processes to watch which cryptographic calls they make. Those are capable products and this is not a criticism of them — but each is a thing your security team has to approve, deploy, monitor and eventually decommission, and none of them is something they can read first.
We are not a lighter version of that. We are the other posture. You already have an inventory, and the assessment is a calculation over it. So there is nothing to deploy, nothing to watch, and nothing to remove afterwards. If you have no inventory to hand, the collectors write one, and you can read every line of them before they run.
To be straight about it: open-source scanners are readable too. They probe a server and report which post-quantum algorithms it will negotiate, which is a different question from which of your deployed components rely on a certificate that loses standing on 21 September. We know of no other tool that is readable, installs nothing, sends nothing, and answers that second question.
About the collectors
There are three — one for Linux and Unix, one for a single Windows machine, and one your administrator points at a list of Windows hosts. Each writes the same CSV.
They are deliberately unsophisticated, and that is the point:
- Nothing is ever sent to us. None of the three contains any code capable of reaching the internet. They write a file; you decide what happens to it.
- The two single-machine collectors make no network connection at all. Not restricted, not sandboxed — absent. The multi-machine one necessarily reaches the hosts your administrator names, using Windows’ own remote management, inside your own network.
- No agent, no service, no install. Nothing is left running and nothing persists after they exit.
- No credentials stored, and no changes made. They read; they do not write to your systems.
- Short enough to read before you run them. Plain text, a couple of minutes each. Your security team should read them — we wrote them expecting exactly that.
You are never obliged to run one. An export from ServiceNow, Intune, SCCM, Tanium or Jamf works as it comes, and so does a spreadsheet.
Check it yourself, in about a minute
Every vendor says their tool sends nothing home. Here is how to check ours,
on the copy in your hands, without an account, a call with us, or anything to
install. Open a Command Prompt in the folder holding RUN-ME.cmd.
First, which bundle are you holding?
dir agilicrypt-cmvp.exe
If that file is listed you have the compiled build, and the three source searches below will return nothing because the folder they search does not exist — which proves nothing at all. Skip to “If you have the compiled build”. If it says File Not Found you have the source build and every check below applies as written.
We put that question first because a check that appears to pass for the wrong reason is worse than no check.
Is there any code here that can open a connection?
findstr /S /I /M /C:"urllib.request" /C:"import socket" /C:"http.client" /C:"import requests" tool\*.py
Nothing comes back. Every route Python has to the network goes through one
of those, and none of them is in the bundle. We do have a module that
fetches the public NIST record — it is how we build the dated snapshot in
data\ — and it is removed from every bundle before it ships.
Confirm with dir /s /b tool\*fetch*: File Not Found. The
certificate data was assembled before the bundle was made, so there is nothing
to look up and no way to look it up.
Is there an address of ours to call?
findstr /S /I /M /C:"//agilicrypt" tool\*.py collect\*.ps1
Nothing. Not “we choose not to” — there is no address in there to contact.
Can the collectors reach the internet?
findstr /S /I /M /C:"Invoke-WebRequest" /C:"Invoke-RestMethod" /C:"WebClient" /C:"DownloadString" collect\*.ps1
Nothing. Those are how PowerShell fetches something from the internet, and none appears in any collector.
And afterwards — did it install anything? This is the claim on this page that is easiest to make and least often checked, so check it. Run the tool, produce a report, then ask Windows:
reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall /s /f AGILICRYPT
sc query AGILICRYPT
schtasks /query /tn AGILICRYPT
dir "%ProgramFiles%\AGILICRYPT*"
0 match(es) found, the specified service does not exist, cannot find the file specified, File Not Found. Nothing in Add or Remove Programs, no service, no scheduled task, nothing under Program Files, and no Run key. The whole product is the folder you unzipped. Delete it and the machine is exactly as it was — not uninstalled, because nothing was installed.
That is not restraint on our part; there is no installer to restrain. It is also why a hardened estate can block the collectors outright — execution policy, AppLocker, constrained language mode — and why we state that as a limitation rather than hide it: a tool that installs nothing has nothing to fall back on.
Two things a looser search will turn up, and we would rather tell
you first. support@agilicrypt.com appears in two files
— an address printed on screen for a person to read; the tool sends no
mail and contains no mail code. And the word “socket” appears once,
inside a comment showing an example line of dpkg output that reads
Secure Sockets Layer toolkit. You will also find
urllib.parse imported, which is Python’s string handling for
URL text — it decodes file:/// paths inside SBOM documents
and opens nothing. The module that opens connections is
urllib.request, which is what the first check looks for.
If you have the compiled build. The engine is
agilicrypt-cmvp.exe, native code with its own runtime inside it.
You cannot read it, and we are not going to pretend otherwise.
Three things are still true and all three are checkable.
- The collectors are unchanged, and they are what actually runs on your servers. They are plain PowerShell in every build, and the third check above works exactly as written.
- Prove the behavior instead of reading the code. Pull the
network cable, or run it on an air-gapped machine, and produce a full report
— it works, because nothing in the assessment needs a network. Or add an
outbound firewall rule denying
agilicrypt-cmvp.exeand watch the report come out identical. For a binary that is stronger evidence than reading imports: it tests what the program does rather than what its source suggests. - One thing you will find, and we would rather say it first.
The bundled runtime includes
_socket.pyd, the standard Python networking extension. Every Python runtime on Windows ships it. It is there because the interpreter is bundled whole, not because our code uses it — the module that does reach the network is excluded at compile time, so it was never built in rather than merely left unused.
Why compiled at all? To make our component-to-certificate mapping harder to lift wholesale — the one part of this that took years rather than weeks. Not to hide anything from you, and the distinction is worth being exact about: the collectors are what run on your servers, they are plain PowerShell in every build, and you can read every line of them. What is compiled is the engine that reads the result afterwards.
The same checks run in our build, so a later version cannot quietly gain the
ability to phone home. But you should not have to trust that either —
the commands above are yours, they run on your copy, and they do not depend on
us at all. Every bundle ships them as VERIFY-IT-YOURSELF.md, with
the same warning about the two bundle shapes that you just read.
Who this is for
Anyone whose obligations reach a validated cryptographic module — and that is wider than federal contracting, though federal is where it bites first and hardest.
Selling to the US federal government
- Defense subcontractors, tier 2 and 3
- Federal systems integrators
- Software vendors on GSA or SEWP schedules
- Managed service providers running federal workloads
The rule is NIST SP 800-171 control 3.13.11 — use FIPS-validated cryptography to protect CUI, the government’s term for sensitive data that is not classified. It reaches you through DFARS 252.204-7012, the clause in your contract, so it is a term you signed rather than guidance you may weigh.
Healthcare, through breach notification rather than compliance
HIPAA has a breach-notification safe harbour: if stolen patient data was properly encrypted, it is not a reportable breach. What counts as properly points at NIST-approved encryption — in practice, a validated module. The question is not whether you are fined. It is whether a lost laptop is a non-event or a notifiable breach, and that can turn on the standing of the certificate behind the encryption you already have.
Payments, at the hardware
The PCI rules — the card industry’s own security standard — let you protect PIN data with either a FIPS-validated HSM (a tamper-proof box that holds encryption keys) or a PCI-approved one. Many estates took the FIPS route, and a FIPS certificate has an end date whichever industry relies on it.
Anyone who signs code delivered into a national security system
CNSA 2.0 is the NSA’s list of approved algorithms for systems handling classified or sensitive government data. It sets 1 January 2027 for code and firmware signing to use quantum-resistant algorithms only, and expects new equipment bought for those systems to comply from the same date. A supplier who signs what it ships is inside that whether or not it thinks of itself as a defense contractor.
Anyone buying hardware or software that will outlive the transition
A firewall, an HSM or a storage array bought this year is still in service in 2030. “FIPS 140-3 validated” on a datasheet is a category, not a date — and 63 of the active certificates stop counting within two years of the September cliff. What is still validated when it arrives is free and public.
Who it is not for: anyone with no FIPS requirement at all. If nothing you sign, store or process reaches a validated module, none of this affects you — and we would rather say so on a website than on a call.
Pricing
Try it on one machine — $100
The same tool, the same engine, the same dated NIST record. It produces one real report about one of your own machines, and you keep it. Thirty days.
This is not a demo and nothing is watermarked or held back. It is the product, bounded: one report, one machine. If you point it at your whole estate it will say so and stop — and it does not spend your report doing it, so you can cut the file down and run it again.
When the trial has produced its report, that report stays readable for good. It is a file in the folder and nothing in the tool touches it. The $100 comes off the full license if you go on to buy one.
Same delivery as the full license: a private download link, sent automatically by email once your payment is confirmed. Nothing is installed and nothing is sent to us.
The full license — $5,000 for twelve months
$5,000 for twelve months. One price, whichever route you take — you run the tool yourself, or you send us an inventory. The deliverable is the same report either way, so it costs the same either way.
The year includes unlimited runs against your own estate and email support. No per-system charge, no seat count, and no price that varies with the size of your estate. Card or invoice. It does not renew automatically — we write to you before it ends.
Before you buy, four questions
If any answer is no, email us instead of paying — we would rather have the conversation than the refund.
- Does any contract or program you work under require FIPS-validated cryptography? If not, this genuinely does not affect you and we will say so.
- Can you export a list of installed software, or run a script on your own machines? Three columns is enough — package, version, and an identifier if you have one. Without one of those we have nothing to assess.
- Are you assessing servers, workstations or network devices — rather than an application’s own libraries? A list of npm or Maven dependencies structurally cannot answer this question.
- Is the inventory you would use current? The report is only ever about the estate your export describes. A list from eighteen months ago produces an accurate assessment of a network you no longer run — and the tool cannot tell, because an export does not carry the date it was taken. That one is on you, and it is worth checking before you pay rather than after. If your last export is stale, run a collector instead; it takes minutes.
There is no software prerequisite. The tool carries everything it needs: no runtime to install, no version to check, no administrator rights to produce the report. The one thing we cannot fix from our side is an inventory that does not exist, which is what the second and fourth questions are about.
Buy 12 months — $5,000Invoiced, payable by transfer or cheque, with a W-9 on request — which is what most federal subcontractors’ accounts payable teams want anyway. Card payment is available too — the button above.
See it before you buy it
A complete report, produced by the actual tool, with the input that produced it and the second document that ships alongside it. The estate is invented. Every certificate number in it is real.
Including the four places the tool declined to answer — which is the part worth reading.
Four steps at your own pace: read the inventory, build the report, see the four answers the tool is allowed to give — including the two that decline — and the commands that prove it never touches the network. The sample report is the same thing as a document you can read in full.
Prefer to be walked through it? Pick a time that suits you. We will tell you plainly if this does not apply to you.
Two references, free, no sign-up
Both are built from the same public record the report is, and both answer a question that is easy to ask and currently impossible to look up.
21 September is the biggest date, not the last one. Another 53 certificates lose standing between then and the end of 2027 — AWS Key Management Service HSM on 17 November, for one, fifty-seven days after the cliff when the assessments are filed and nobody is looking again. The calendar lists all of them, with each vendor’s position in the CMVP queue.
And if you are buying rather than checking: a specification saying only “must be FIPS 140-3 validated” cannot tell a certificate that runs to 2031 from one that ends next year. The shortlist puts the end date on every row, and shows which Windows builds actually carry a core certificate.
Who decides what
Four parties settle whether your cryptography survives an assessment, and we are only one of them. We are not a testing laboratory and not a C3PAO, and we do not tell you whether you are compliant — that is your assessor’s call and your affirmation. What we do is produce the evidence, independently and early enough to act on.
The questions we refuse are worth as much as the ones we answer: an assessor who catches a single row claiming coverage the record does not support stops trusting the whole document, and is right to.
Not the person who signs?
Most people who find this page are not the one who approves the spend. There is a one-page briefing written for whoever is — what the deadline means for a contract, what it costs to meet it late, and what the decision actually is. No jargon, no certificate numbers, and it prints cleanly.
Questions
Does this mean our systems become non-compliant on 22 September?
No. Deployed systems keep operating, and NIST permits continued use based on an assessment of where and how each module is used. What changes is procurement standing — agencies are directed not to include historical modules in new acquisitions. It bites at your next contract action, not on the 22nd.
Can’t we just put the gap in our plan of action?
Often, yes — and we would not talk you out of it. The Defense Department’s scoring rules let a small gap, written into your plan of action, count as a gap that is being fixed. But the plan still needs proof behind it: that the problem is small, that a real fix exists and is on the way, and that the plan has steps, dates and progress. Getting that proof means matching everything your company runs to the right government record, and that is what our report does for you. Whether it satisfies an inspector is the inspector’s decision, not ours.
Do you need access to our network?
No. No scanning, no agents, no credentials, and no connections into your environment at any point. We work from a list you export yourself. Nothing is installed either — no installer, no service, no registry changes; the bundle is a folder you unzip, run and delete.
What if we can’t send you an inventory?
Common, and often a contractual requirement rather than a preference. In that case we send you the tool and you run it inside your own network, so nothing leaves it. Same assessment, same price.
Will you sign an NDA?
There is already one in force. A mutual NDA is built into our terms and binds us from the moment you accept them — before you send us anything, with nothing to sign and no week waiting on two legal teams.
It is mutual, it covers your inventory and your findings, and it runs for five years from each disclosure. Read it before you buy rather than after.
How do we know your numbers are right?
Every certificate we cite is numbered, and we re-check each against the live NIST record before the report leaves us. We also state explicitly what we could not determine.
What if you find nothing?
You get that in writing with the method stated, which is itself useful at audit. But be aware there are two different “nothings” — either your validations are current, or you have no validated cryptography at all. Those are very different findings and the report distinguishes them.
How long does it take?
If you run it yourself, minutes. If you send us an inventory, one to three business days from receiving something usable.
Is this the same as a FIPS audit?
No. An audit is performed by an accredited laboratory and results in a certificate. We tell you which certificates you already depend on and what happens to them. We are not a laboratory and do not certify anything.
What happens after September?
The deadline passes, but the question does not. The larger one — whether your systems keep working when the cryptography underneath them changes — is not tied to a date, and it is what we do next.
Get in touch
Email us and tell us your situation. We reply the same day.
Useful things to include: your company, whether any contract requires FIPS-validated cryptography, and roughly how many systems are in scope. Nothing sensitive — and confidentiality is already in force under our terms.