AGILICRYPT™ FIPS CertStanding™. Four steps, at your own pace: read your estate across the domain,
build the report with its four honest answers, and prove the tool never touches the network. The
colours, the buttons and the checks are the real ones.
AGILICRYPTFIPS CERTIFICATE STANDING
Which of your modules lose federal standing on 21 September 2026.
21 September 2026
THIS FOLDER
11 inventory files
THIS MACHINE
WORKSTATION-01
REPORT ENGINE
Ready
Every action is a read. Nothing is installed and nothing is sent anywhere.
COLLECT
Read this machine
The software installed here, into one CSV.
1
Read several machines over the network
A domain controller, servers — machines you name.
2
Combine inventory files in this folder
For when you have dropped several files here.
3
ASSESS
Check whether these files can answer the question
No report, just checks. What each file can and cannot show.
4
Build the report
The assessment, with the certificate each finding rests on.
5
AGILICRYPTFIPS CERTIFICATE STANDING
Which of your modules lose federal standing on 21 September 2026.
21 September 2026
THIS FOLDER
11 inventory files
THIS MACHINE
WORKSTATION-01
REPORT ENGINE
Ready
Every action is a read. Nothing is installed and nothing is sent anywhere.
COLLECT
Read this machine
The software installed here, into one CSV.
1
Read several machines over the network
A domain controller, servers — machines you name.
2
Combine inventory files in this folder
For when you have dropped several files here.
3
ASSESS
Check whether these files can answer the question
No report, just checks. What each file can and cannot show.
4
Build the report
The assessment, with the certificate each finding rests on.
5
FIPS Certificate Standing — domain estate
167 components across 24 machines · each finding carries the certificate it rests on
LOSES STANDING
dc-01 · bcryptprimitives.dll
Domain controller — Windows CNG moves to Historical 21 Sep 2026
#4825 · 140-2
NO VALIDATED CRYPTO
edge-fw-01 · SRX345
Certified firewall on firmware its certificate does not name
outside validated
UNVERIFIED
app-04 · custom service
Standing could not be established from this input
unknown
NO CRYPTO FOUND
print-svc-02
Inventory shows no cryptographic component at all
none
HOLDS — 140-3
app-11 · openssl 3.0.13
Already on FIPS 140-3 — unaffected by the cliff
#4985 · 140-3
AGILICRYPTFIPS CERTIFICATE STANDING
Which of your modules lose federal standing on 21 September 2026.
21 September 2026
THIS FOLDER
11 inventory files
THIS MACHINE
WORKSTATION-01
REPORT ENGINE
Ready
Every action is a read. Nothing is installed and nothing is sent anywhere.
COLLECT
Read this machine
The software installed here, into one CSV.
1
Read several machines over the network
A domain controller, servers — machines you name.
2
Combine inventory files in this folder
For when you have dropped several files here.
3
ASSESS
Check whether these files can answer the question
No report, just checks. What each file can and cannot show.
4
Build the report
The assessment, with the certificate each finding rests on.
5
Four honest answers — and the last two are the point
On a compliance cliff, the dangerous answer is a false all-clear.
LOSES STANDING
A validated module that goes to the NIST Historical list on 21 September.
NO VALIDATED CRYPTO
A certified product, but not in its validated configuration — so the certificate does not cover it.
UNVERIFIED
Standing could not be established from what you gave it — often the export never captured the crypto library. The tool says so. Not a pass.
NO CRYPTO FOUND
The inventory shows no cryptographic component. Reported as exactly that — never as a clean bill of health.
Every free scanner collapses “unknown” into “no problem.” That is why they get uninstalled. AGILICRYPT never does.
One window on the customer’s own machine.
Five numbered steps. Most customers already have an inventory export —
ServiceNow, Intune, SCCM, Tanium or a spreadsheet — and drop it in the
folder. Step 2 reads several machines across the domain —
a domain controller, file servers — using Windows’ own remote
management, reaching only the machines you name.
Step 4 checks what the files can answer; step 5
builds the report. A domain controller loses standing on the cliff date,
and the finding names the certificate it rests on — #4825 —
so an assessor checks it at NIST directly. A certified firewall is running
firmware its certificate does not name, so it is not actually covered.
Four answers, and the last two are the point.Unverified means standing could not be established from the input
— not a pass. No crypto found means the inventory showed none
— not a clean bill of health. Every free scanner turns those two into
“you’re fine”, and every one of those is wrong.
Then prove it never phoned home. The first
command is not a check — it is the question that has to come first,
because a search of source files “passes” on a compiled bundle
for the wrong reason, and we would rather tell you that than let you find
it. Then: the collectors are plain text in every build, so read them. And
block the engine at the firewall, or pull the cable, and the report comes
out identical — which is stronger proof than any line of code we
could show you. You verify it, not us.
What you just saw
One window, five numbered steps. Drop an inventory export in the
folder — ServiceNow, Intune, SCCM, Tanium, or a spreadsheet — or use
step 2 to read a domain controller and servers over your own network,
reaching only the machines you name. Then Check, then Build the
report.
Four answers, and it never fakes an all-clear. A module that
loses standing; a certified device not in its validated
configuration; an input the tool cannot verify; and a machine
with no cryptography found. Each real finding carries the certificate
number it rests on, so an assessor checks it at NIST directly.
And it never phones home. In about a minute, on the copy in your
hands: the collectors are plain text in every build we ship, so read them —
and block the engine at the firewall, or pull the cable, and the report comes
out identical. We tell you which build you are holding first, because a check
that passes for the wrong reason is worse than no check.
Check it yourself.