The case for checking before the assessment, not during it
On 21 September 2026 every FIPS 140-2 certificate moves to historical status. This is a scheduled NIST transition, not an incident. It reaches defense contracts because FIPS-validated cryptography is a contractual requirement, and it is the kind of finding that is cheap to fix early and expensive to meet for the first time in an assessment.
Why it reaches us at all
Nothing stops working on the 22nd. Deployed systems keep running, and continued use is permitted on an assessment of where and how each module is used. What changes is standing — the evidence behind the control. It bites at an assessment or a contract action, not on the date.
The part that is easy to miss
21 September is the largest date on the calendar, not the last one. Another 53 certificates lose standing between then and the end of 2027 — Amazon Web Services' Key Management Service HSM on 17 November, for one, which is 57 days after the cliff, when the assessments are filed and nobody is looking again. An answer that was correct in September is quietly wrong by November, and nothing announces it.
That calendar is published in full, free, at agilicrypt.com/renewals. Every row links to NIST so it can be checked at the source rather than taken on trust.
Two outcomes from the same estate
Two organizations running identical systems get different assessment results. The difference is not the technology — it is whether the gap was found, classified and documented before anyone came to look.
| Found early | Found in the assessment | |
|---|---|---|
| What the assessor sees | A documented gap with a plan, dates and vendor correspondence | An unknown, discovered live |
| Vendor evidence | Written answers already on file | Requested under time pressure, if at all |
| Remediation | Sequenced; purchases have lead time | Whatever can be done before the report is issued |
| Cost | Planned | Unplanned, plus the cost of a re-assessment |
What it costs to answer it properly
Doing this by hand means mapping every cryptographic component in the estate to a CMVP certificate, then checking whether that certificate names the exact version deployed. Take your own loaded rate for an engineer who can read a CMVP certificate and multiply it by two weeks. That is the comparison, and it is your number rather than ours.
It is also the optimistic version, because the traps are not obvious. Two Windows cryptographic modules have names where one contains the other word-for-word, and only one of them has a pending submission. Several hundred certificates name no version at all in the public table — the versions are in a PDF. Windows Server 2019's certificates cover two exact revisions and Server Core only. Each of those, got wrong, produces a confident answer that is false.
What is actually delivered
- Every component joined to the certificate it rests on, with the certificate number and its end date
- Each gap classified by what it costs — nothing to deploy, a software upgrade, a firmware change, or a purchase
- A drafted plan of action, with the evidence 32 CFR § 170.4 asks for where a gap is carried as a temporary deficiency
- Ready-to-send letters to each vendor asking the one question that settles their item — the written replies become part of the evidence
- A re-run that reports only what changed, so this stays answered rather than being answered once
What this is not
It is not a compliance determination, and we are careful about that. We are not a testing laboratory, we do not certify cryptographic modules, and we are not a C3PAO. Your assessor decides whether you meet the control; you make the affirmation. We produce the measurement and the evidence, independently and early enough to act on. The full boundary is published, including the questions we refuse to answer.
The decision
Check one machine for $100, or the estate for $5,000
The $100 trial produces a real report on one system — enough to see the output and judge whether the answer is worth having for everything else. The full assessment covers the estate and includes the plan, the vendor letters and the re-run.
Nothing is installed and nothing is scanned. It reads an inventory export you already produce, and the tool contains no networking code at all — which is checkable, in about a minute, on your own machine.
Questions worth asking us before you decide: what happens if the answer is that we cannot tell; what the report says when a vendor has published nothing; and what we do with your inventory afterwards. The answers are, in order: it says so and explains what would settle it; it asks rather than accuses; and nothing you send leaves your own machine unless you send it to us yourself.