AGILICRYPT™ · FIPS CertStanding™
Not because anything breaks. Because the certificates behind it move to NIST’s Historical list — and federal buyers are told not to select what is no longer validated.
21 September 2026
This page is the whole argument, in the order it matters. It takes about six minutes to read, and the last section tells you how to find out in two whether any of it reaches you.
Cryptographic products are validated by NIST’s Cryptographic Module Validation Program. A laboratory tests one specific version of one specific product, and NIST issues a certificate for it. That certificate is what a federal buyer, a prime contractor or an assessor accepts as proof.
There have been two revisions in service: FIPS 140-2, and the current FIPS 140-3. On 21 September 2026 every remaining 140-2 certificate moves to the Historical list.
Active today
1,189
certificates active in the CMVP record.
Active on 22 Sept
~702
the FIPS 140-3 certificates. The rest have moved.
The difference
41%
of the active catalog, in a single day.
Counted from the CMVP record we ship, version 2026.08-full, fetched 30 August 2026: 5,494 certificates, of which 1,189 are active — 487 under FIPS 140-2 and 702 under FIPS 140-3. Check it against the copy in your own bundle. Two details worth knowing: 481 of the 487 sunset on the 21st and six sunset earlier, from the 6th; and six active 140-3 certificates also sunset on or before that date, so 140-3 is not permanent cover either.
Said early, because the alternative is that you discover we overstated it later. No system stops working on 21 September. Nothing is disabled, no vendor pushes anything, and continued use in systems already deployed is permitted on a documented assessment of where and how each module is used.
What changes is procurement standing: agencies are directed not to include modules that are no longer validated in new acquisitions. So it does not bite on the date. It bites at your next contract action — a bid, a renewal or option year, an assessment, or a prime’s questionnaire.
That is precisely what makes it easy to miss. A deadline that breaks something announces itself. This one is silent until somebody asks a question you cannot answer.
There is no penalty for this. No fine arrives, nothing is revoked, and nobody sends a letter. You are simply not selected — and that is worse, because you are not told.
Federal buyers are directed not to include modules that are no longer validated in new acquisitions. Primes carry that duty down to the companies they buy from. So the cost lands in four places, and every one of them is a piece of business rather than a compliance event:
A new contract, task order or bid
The requirement is checked at selection. This is where it costs work directly — you are competing against firms that can answer the question.
A renewal or option year
Treated as a new selection. Work you already have, and expect to keep, is re-decided on the same basis.
An assessment or a score
Requirement 3.13.11 is scored against you and the score is visible to the people deciding awards. A gap here is not a private matter.
A prime’s questionnaire
The most common one, and the quietest. A prime assembling its own evidence asks its suppliers for certificate numbers. The ones who cannot produce them stop appearing in the next bid.
Two firms get the same questionnaire six weeks before an award. One answers it in a day with certificate numbers. The other starts finding out what its VPN and its servers actually run.
Only one of them is still in the bid. Nothing was breached, nothing failed, and nobody was penalised — the second firm just became the harder supplier to include, at the moment somebody was deciding who to include.
For a subcontractor this compounds. Your answers become part of your prime’s evidence, so a gap on your systems is a gap in their package. Being the reason a prime’s submission is incomplete is how a supplier quietly stops being called.
Stated as procurement rather than enforcement, deliberately. Not being selected needs no enforcement action at all, and it is the outcome that reaches most companies. There is, however, a second exposure, and it is not hypothetical.
To win the work you sign something. A representation of compliance, a score posted to SPRS, an answer on a prime’s questionnaire. Those statements are made to the government, or to somebody relaying them to the government — and since October 2021 the Department of Justice has run a Civil Cyber-Fraud Initiative that treats misstatements about cybersecurity compliance as False Claims Act matters.
Aerojet Rocketdyne agreed to pay $9 million to resolve allegations that it misrepresented its compliance with cybersecurity requirements in federal contracts — the requirements described in DFARS 252.204-7012, the same clause set out further down this page.
Two details are worth more than the number. The case began as a qui tam action brought by a former employee, who received $2.61 million of the recovery — so it did not start with an audit, and it did not need one. And it settled on the second day of trial with no admission of fault or liability, which is how these resolve and is part of the public record.
Source: US Department of Justice, Eastern District of California, 8 July 2022.
The exposure there is not weak encryption. It is saying something that turns out not to be true. A company can hold an entirely defensible position — a gap, documented, with a plan and a date — and be fine. The difficulty arrives when somebody affirms compliance they cannot evidence, usually because nobody in the building actually knew.
Which is the practical reason to know where you stand before the question is put to you, rather than after. We do not tell you that you are compliant — that is your assessor’s determination and your own affirmation. What we do is make sure the affirmation you sign is one you can evidence.
This is a description of a public enforcement record, not legal advice, and not a statement about your exposure. If any of it looks close to your situation, that is a conversation for your counsel.
The contract does not mention certificates, and the certificate list does not mention your contract. They are connected, but by four steps — which is why so few people have followed it all the way down.
The contract
DFARS 252.204-7012. You agreed to implement NIST SP 800-171 on any system that touches Controlled Unclassified Information.
One line of the 110
Requirement 3.13.11 — “Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.” Not strong. Not modern. Validated.
What validated means
A certificate on the CMVP list naming the exact product and the exact version. Not on it, not validated — however good the software is.
21 September 2026
The certificate moves to Historical. The module on the machine does not change. Its standing does, and meeting 3.13.11 then turns on whether you can document the gap.
Stated precisely, because a compliance buyer will check: nothing audits “Active versus Historical” and no clause mentions certificate status at all. An assessor scores 3.13.11, and a module without a current validation is the reason that score is lost.
“We pour concrete, we are not a cyber company” is the first thing said on most of these calls, and it sounds like common sense. It is also the one idea standing between a firm and a problem it already has.
The clause does not look at your trade. It looks at the information. A construction firm, a mechanical contractor, an architect or a facilities manager is not covered because of what they build. They are covered when the drawings, specifications, site layouts, utility routing, security-system plans or personnel lists they receive are covered defense information.
If that material arrives in your email, sits in your file share, goes home on a laptop, or is passed to your own subcontractors, the systems holding it are in scope. The concrete is not the point. The site plan of the building the concrete goes into is.
Under paragraph (m) of 252.204-7012, a prime that passes covered information to a supplier passes the same obligations with it — and that supplier does the same again. So a firm can carry every duty on this page without ever having spoken to a contracting officer.
You do not find out from the government. You find out when a prime sends a questionnaire, six weeks before an award, asking which certificate covers your encryption.
Picture a contractor doing work for Defense and Justice. A few hundred machines — servers, workstations, firewalls, switches. Somebody asks:
“Which of these still hold FIPS standing after the twenty-first?”
Nobody can answer. Not because they are careless — because the answer lives in a NIST database, spread across thousands of certificates each naming exact products and exact versions, and nothing they own reads it. The inventory tools say what software is installed. None of them says whether its certificate is still current.
That contractor is illustrative and described as such deliberately. AGILICRYPT has no customers yet, and a named case study implying a real engagement is the one thing a company selling assurance cannot be caught doing.
We read the public NIST record against the software you actually run, and report where each system stands: holding a validation, losing one on the September date, already without one, or genuinely unverified. Where a question can only be settled by the company that sold you the software, we write the letter for you to send — addressed, with your products and versions already filled in.
The refusals are worth as much as the answers. An assessor who catches one row claiming coverage the record does not support stops trusting the whole document, and is right to.
Open a contract or subcontract agreement and search the text for 252.204-7012. In a federal prime contract it sits in Section I, Contract Clauses. In a subcontract or purchase order it is usually in the terms and conditions or a flow-down attachment.
NIST SP 800-171 applies, and requirement 3.13.11 with it. Any system you use to store, send or work on those files needs cryptography holding a current validation — and from 21 September, a module resting on a FIPS 140-2 certificate no longer holds one.
Then on that contract, this probably does not reach you. Two things to check before relying on it: contracts routinely incorporate clauses by reference rather than printing them, so search the whole agreement and its attachments; and this answers the DoD question only — FedRAMP, CJIS and healthcare-adjacent terms impose FIPS-validated cryptography under their own authority.
It is a per-contract answer, not a company-wide one. One contract carrying the clause is enough to put the requirement on the systems that touch its data.
If you want to see it on your own machine before deciding anything, the trial is $100: one computer, one report, everything the full tool produces. A twelve-month license is $5,000.
One thing that cuts against us, said here rather than left for you to find: CMMC Phase 2 was suspended on 13 July 2026. The mandatory third-party assessment due to appear in contracts from 10 November is not arriving on that date, and a reform task force reports on or about 13 September 2026. What did not change is everything the FIPS date touches — Phase 1 self-assessment, DFARS 252.204-7012 and NIST SP 800-171 all remain in force. Checked 1 September 2026.