AGILICRYPT™ FIPS CertStanding™

See it in action

AGILICRYPT™ FIPS CertStanding™. Four steps, at your own pace: read your estate across the domain, build the report with its four honest answers, and prove the tool never touches the network. The colours, the buttons and the checks are the real ones.

AGILICRYPTFIPS CERTIFICATE STANDING
Which of your modules lose federal standing on 21 September 2026.
21 September 2026
THIS FOLDER
11 inventory files
THIS MACHINE
WORKSTATION-01
REPORT ENGINE
Ready
Every action is a read. Nothing is installed and nothing is sent anywhere.
COLLECT
Read this machine
The software installed here, into one CSV.
1
Read several machines over the network
A domain controller, servers — machines you name.
2
Combine inventory files in this folder
For when you have dropped several files here.
3
ASSESS
Check whether these files can answer the question
No report, just checks. What each file can and cannot show.
4
Build the report
The assessment, with the certificate each finding rests on.
5
AGILICRYPTFIPS CERTIFICATE STANDING
Which of your modules lose federal standing on 21 September 2026.
21 September 2026
THIS FOLDER
11 inventory files
THIS MACHINE
WORKSTATION-01
REPORT ENGINE
Ready
Every action is a read. Nothing is installed and nothing is sent anywhere.
COLLECT
Read this machine
The software installed here, into one CSV.
1
Read several machines over the network
A domain controller, servers — machines you name.
2
Combine inventory files in this folder
For when you have dropped several files here.
3
ASSESS
Check whether these files can answer the question
No report, just checks. What each file can and cannot show.
4
Build the report
The assessment, with the certificate each finding rests on.
5
FIPS Certificate Standing — domain estate
167 components across 24 machines · each finding carries the certificate it rests on
LOSES STANDING
dc-01 · bcryptprimitives.dll
Domain controller — Windows CNG moves to Historical 21 Sep 2026
#4825 · 140-2
NO VALIDATED CRYPTO
edge-fw-01 · SRX345
Certified firewall on firmware its certificate does not name
outside validated
UNVERIFIED
app-04 · custom service
Standing could not be established from this input
unknown
NO CRYPTO FOUND
print-svc-02
Inventory shows no cryptographic component at all
none
HOLDS — 140-3
app-11 · openssl 3.0.13
Already on FIPS 140-3 — unaffected by the cliff
#4985 · 140-3
AGILICRYPTFIPS CERTIFICATE STANDING
Which of your modules lose federal standing on 21 September 2026.
21 September 2026
THIS FOLDER
11 inventory files
THIS MACHINE
WORKSTATION-01
REPORT ENGINE
Ready
Every action is a read. Nothing is installed and nothing is sent anywhere.
COLLECT
Read this machine
The software installed here, into one CSV.
1
Read several machines over the network
A domain controller, servers — machines you name.
2
Combine inventory files in this folder
For when you have dropped several files here.
3
ASSESS
Check whether these files can answer the question
No report, just checks. What each file can and cannot show.
4
Build the report
The assessment, with the certificate each finding rests on.
5
Four honest answers — and the last two are the point
On a compliance cliff, the dangerous answer is a false all-clear.
LOSES STANDING
A validated module that goes to the NIST Historical list on 21 September.
NO VALIDATED CRYPTO
A certified product, but not in its validated configuration — so the certificate does not cover it.
UNVERIFIED
Standing could not be established from what you gave it — often the export never captured the crypto library. The tool says so. Not a pass.
NO CRYPTO FOUND
The inventory shows no cryptographic component. Reported as exactly that — never as a clean bill of health.
Every free scanner collapses “unknown” into “no problem.” That is why they get uninstalled. AGILICRYPT never does.
C:\AGILICRYPT> dir agilicrypt-cmvp.exe
agilicrypt-cmvp.exe
C:\AGILICRYPT> findstr /S /I /M /C:"Invoke-WebRequest" collect\*.ps1
(nothing)
C:\AGILICRYPT> block it outbound, run it anyway
report unaffected
✓ it never wanted the network.
✓ Nothing left this machine
One window on the customer’s own machine. Five numbered steps. Most customers already have an inventory export — ServiceNow, Intune, SCCM, Tanium or a spreadsheet — and drop it in the folder. Step 2 reads several machines across the domain — a domain controller, file servers — using Windows’ own remote management, reaching only the machines you name.
Step 4 checks what the files can answer; step 5 builds the report. A domain controller loses standing on the cliff date, and the finding names the certificate it rests on — #4825 — so an assessor checks it at NIST directly. A certified firewall is running firmware its certificate does not name, so it is not actually covered.
Four answers, and the last two are the point. Unverified means standing could not be established from the input — not a pass. No crypto found means the inventory showed none — not a clean bill of health. Every free scanner turns those two into “you’re fine”, and every one of those is wrong.
Then prove it never phoned home. The first command is not a check — it is the question that has to come first, because a search of source files “passes” on a compiled bundle for the wrong reason, and we would rather tell you that than let you find it. Then: the collectors are plain text in every build, so read them. And block the engine at the firewall, or pull the cable, and the report comes out identical — which is stronger proof than any line of code we could show you. You verify it, not us.

What you just saw

One window, five numbered steps. Drop an inventory export in the folder — ServiceNow, Intune, SCCM, Tanium, or a spreadsheet — or use step 2 to read a domain controller and servers over your own network, reaching only the machines you name. Then Check, then Build the report.

Four answers, and it never fakes an all-clear. A module that loses standing; a certified device not in its validated configuration; an input the tool cannot verify; and a machine with no cryptography found. Each real finding carries the certificate number it rests on, so an assessor checks it at NIST directly.

And it never phones home. In about a minute, on the copy in your hands: the collectors are plain text in every build we ship, so read them — and block the engine at the firewall, or pull the cable, and the report comes out identical. We tell you which build you are holding first, because a check that passes for the wrong reason is worse than no check. Check it yourself.

See pricing Read the full sample report Try it on one machine — $100