What happens after 21 September
The FIPS 140-2 sunset is the biggest date on the calendar. It is not the last one. 48 more certificates lose standing between 22 September 2026 and the end of 2027 — including modules in laptops, firewalls, HSMs and SSDs that most estates are still buying today.
- 48certificates, cliff to end 2027
- 42on a two-year certificate
- 10with a submission in the CMVP queue
Why these exist: not every FIPS 140-3 certificate is a five-year certificate
The usual life of an active FIPS 140-3 certificate is exactly five years, and most of them are. But 42 were issued with a two-year life instead. They begin in August 2024, stop in April 2025, and ran alongside normal five-year certificates in the same months — in November 2024, thirteen modules were validated for two years and fifteen for five.
We do not know why, and we are not going to guess in public. What matters for a reader is narrower and firmer: “it is FIPS 140-3 validated” is not a single fact. It is a certificate with its own end date, and on 42 of the rows below that date arrives before the end of next year. The sunset date is the thing to read, not the standard.
The calendar
Every active certificate whose standing ends after the 21 September 2026 cliff and before 31 December 2027, in date order. Certificate numbers link to NIST.
September 2026 — 2 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 23 Sep 2026 | #4812 | Outset Medical, Inc. | Tablo Medical Informatics System 2-year certificate | nothing found at the snapshot date |
| 30 Sep 2026 | #4817 | Apple Inc. | Apple corecrypto Module v12.0 [Apple silicon, User, Software, SL1] 2-year certificate | in the CMVP queue — Review |
October 2026 — 4 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 10 Oct 2026 | #4829 | Palo Alto Networks, Inc. | PAN-OS 11.0 running on PA-400 Series, PA-800 Series, PA-1400 Series, PA-3200 Series, PA-3400 Series, PA-5200 S… 2-year certificate | nothing found at the snapshot date |
| 20 Oct 2026 | #4846 | Red Hat, Inc. | Red Hat Enterprise Linux 9 gnutls 2-year certificate | in the CMVP queue — Comment Resolution - CMVP |
| 27 Oct 2026 | #4854 | Apple Inc. | Apple corecrypto Module v12.0 [Apple silicon, Kernel, Software, SL1] 2-year certificate | in the CMVP queue — Review |
| 30 Oct 2026 | #4860 | Nokia of America Corporation (Nokia) | Nokia 1830 Photonic Service Switch (PSS) & Nokia 1830 Photonic Service Interconnect- Line (PSI-L) 2-year certificate | in the CMVP queue — Review |
November 2026 — 9 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 12 Nov 2026 | #4875 | Geotab Inc. | Geotab Cryptographic Module 2-year certificate | in the CMVP queue — Review |
| 12 Nov 2026 | #4876 | Hewlett Packard Enterprise | Hewlett Packard Enterprise OpenSSL 3 Provider 2-year certificate | nothing found at the snapshot date |
| 13 Nov 2026 | #4879 | Samsung Electronics Co., Ltd. | Samsung NVMe TCG Opal SSC SEDs PM1743/PM1745 Series 2-year certificate | in the CMVP queue — Comment Resolution - Lab |
| 13 Nov 2026 | #4880 | Advanced Micro Devices (AMD), Microsoft Corporation | Pluton Security Processor ROM 2-year certificate | nothing found at the snapshot date |
| 14 Nov 2026 | #4881 | Broadcom Inc. | VMware’s VPN Crypto Module 2-year certificate | nothing found at the snapshot date |
| 17 Nov 2026 | #4882 | Juniper Networks, Inc. | Juniper Networks QFX10002, QFX10008 and QFX10016 2-year certificate | nothing found at the snapshot date |
| 17 Nov 2026 | #4883 | F5, Inc. | F5OS-A Cryptographic Module 2-year certificate | a similar module exists — ask which |
| 17 Nov 2026 | #4884 | Amazon Web Services, Inc. | AWS Key Management Service HSM 2-year certificate | nothing found at the snapshot date |
| 20 Nov 2026 | #4897 | Corsec Security, Inc. | CorSSL 2-year certificate | a similar module exists — ask which |
December 2026 — 12 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 2 Dec 2026 | #4907 | AudioCodes Ltd. | Mediant 800 Session Border Controller/Media Gateway, Mediant 2600/4000B/9080B Session Border Controllers, and… 2-year certificate | nothing found at the snapshot date |
| 2 Dec 2026 | #4908 | AudioCodes Ltd. | Mediant Virtual Edition SBC and Cloud Edition SBC 2-year certificate | nothing found at the snapshot date |
| 2 Dec 2026 | #4910 | Digital.ai Software, Inc. | Digital.ai Key & Data Protection Module 2-year certificate | nothing found at the snapshot date |
| 8 Dec 2026 | #4913 | Ciena Corporation | WaveLogic 5 Extreme Encryption Modem 2-year certificate | in the CMVP queue — Finalization |
| 11 Dec 2026 | #4916 | Aruba, a Hewlett Packard Enterprise company | AP-514, AP-515, AP-534, AP-535, AP-584, AP-585, AP-587, AP-635 and AP-655 Access Points 2-year certificate | nothing found at the snapshot date |
| 12 Dec 2026 | #4917 | Palo Alto Networks, Inc. | WildFire 11.0 WF-500 and WF-500-B 2-year certificate | nothing found at the snapshot date |
| 17 Dec 2026 | #4920 | Ciena Corporation | Waveserver 5 Control Processor Module 2-year certificate | in the CMVP queue — Comment Resolution - CMVP |
| 17 Dec 2026 | #4921 | Hewlett Packard Enterprise | Bootloader Module 2-year certificate | nothing found at the snapshot date |
| 18 Dec 2026 | #4927 | Palo Alto Networks, Inc. | Panorama 11.0 M-200, M-300, M-600 and M-700 2-year certificate | nothing found at the snapshot date |
| 19 Dec 2026 | #4929 | Hewlett Packard Enterprise | Aruba OpenSSL Module 2-year certificate | a similar module exists — ask which |
| 19 Dec 2026 | #4931 | Fortinet Technologies Inc. | FortiClient Crypto Library 2-year certificate | a similar module exists — ask which |
| 26 Dec 2026 | #4934 | Samsung Electronics Co., Ltd. | Samsung SAS TCG Enterprise SSC SEDs PM1653/PM1655 Series 2-year certificate | in the CMVP queue — Pending Resubmission |
January 2027 — 7 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 1 Jan 2027 | #4935 | Palo Alto Networks, Inc. | Panorama Virtual Appliance 11.0 2-year certificate | nothing found at the snapshot date |
| 5 Jan 2027 | #4936 | Silvus Technologies, Inc. | SC4000 Series Mesh Radio 2-year certificate | nothing found at the snapshot date |
| 6 Jan 2027 | #4938 | Ampex Data Systems Corporation | TuffServ® Encryption Module (TSEM) 2-year certificate | nothing found at the snapshot date |
| 8 Jan 2027 | #4940 | Hewlett Packard Enterprise | Aruba Crypto Module 2-year certificate | a similar module exists — ask which |
| 16 Jan 2027 | #4943 | Legion of the Bouncy Castle Inc. | BC-FJA (Bouncy Castle FIPS Java API) 2-year certificate | in the CMVP queue — Review |
| 26 Jan 2027 | #4951 | Apple, Inc. | Apple corecrypto Module v12 [Intel, User, Software] 2-year certificate | nothing found at the snapshot date |
| 29 Jan 2027 | #4956 | Apple, Inc. | Apple corecrypto Module v12 [Intel, Kernel, Software] 2-year certificate | nothing found at the snapshot date |
February 2027 — 4 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 6 Feb 2027 | #4959 | Juniper Networks, Inc. | Juniper Networks EX4300-48MP Ethernet Switch 2-year certificate | nothing found at the snapshot date |
| 6 Feb 2027 | #4960 | Juniper Networks, Inc. | Juniper Networks PTX1000 Packet Transport Router 2-year certificate | nothing found at the snapshot date |
| 6 Feb 2027 | #4961 | Juniper Networks, Inc. | Juniper Networks PTX10008 and PTX10016 Packet Transport Routers 2-year certificate | nothing found at the snapshot date |
| 6 Feb 2027 | #4962 | Thales | Thales Luna G7 Cryptographic Module 2-year certificate | nothing found at the snapshot date |
March 2027 — 3 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 23 Mar 2027 | #4991 | Icom Inc. | UT-125 FIPS #31 and #41 Cryptographic Module 2-year certificate | nothing found at the snapshot date |
| 24 Mar 2027 | #4992 | Utimaco Inc. | Atalla Cryptographic Subsystem (ACS) 2-year certificate | nothing found at the snapshot date |
| 30 Mar 2027 | #4995 | SonicWall, Inc. | SonicWall NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700 2-year certificate | a similar module exists — ask which |
April 2027 — 1 certificate
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 16 Apr 2027 | #5000 | Pure Storage, Inc. | FlashBlade Data Encryption Module 2-year certificate | nothing found at the snapshot date |
December 2027 — 6 certificates
| Standing ends | Cert | Vendor | Module | In the record |
|---|---|---|---|---|
| 6 Dec 2027 | #4389 | Apple Inc. | Apple corecrypto Module v11.1 [Intel, User, Software] | nothing found at the snapshot date |
| 6 Dec 2027 | #4390 | Apple Inc. | Apple corecrypto Module v11.1 [Intel, Kernel, Software] | nothing found at the snapshot date |
| 6 Dec 2027 | #4391 | Apple Inc. | Apple corecrypto Module v11.1 [Apple silicon, User, Software] | nothing found at the snapshot date |
| 6 Dec 2027 | #4392 | Apple Inc. | Apple corecrypto Module v11.1 [Apple silicon, Kernel, Software] | nothing found at the snapshot date |
| 29 Dec 2027 | #4401 | Advanced Micro Devices (AMD) | AMD Ryzen PRO 5000 Series PSP Cryptographic CoProcessor | a similar module exists — ask which |
| 29 Dec 2027 | #4402 | Advanced Micro Devices (AMD) | AMD Ryzen PRO 4000 Series PSP Cryptographic CoProcessor | nothing found at the snapshot date |
What the right-hand column means
in the CMVP queue The vendor has a submission for this module on the CMVP Modules In Process list, at the phase shown. That is a fix in process, and under 32 CFR 170.4 that distinction is the one that decides whether a gap can be carried as a temporary deficiency. NIST publishes no expected duration for any phase and directs enquiries to the vendor, so a queue position is not a delivery date.
successor #… A longer-dated certificate for the same module is already on the record. Worth knowing that a certificate is not a patch: when one issues it names versions, and machines already running a named version become covered without being touched. The question to put to the vendor is whether the successor names the exact version you run.
a similar module exists The vendor holds an active certificate whose name strictly contains, or is contained by, this one. That cannot be settled from a name in either direction — “Kernel Mode Cryptographic Primitives Library” contains every word of “Cryptographic Primitives Library” and is a different module, while a renamed product looks identical. So we do not decide it. Ask the vendor which one covers you.
nothing found at the snapshot date No successor and no queue entry matched at the date below. Read that as a question, not a verdict. It is the absence of a record in one snapshot — a certificate may have issued since, or been filed under a name this did not join to the retiring one. The honest action is to ask the vendor, in writing, whether a FIPS 140-3 submission exists for the product you own. That written answer is itself evidence, and it is worth more to an assessor than anything we could infer.
Why a one-off check is not enough
Take one row. AWS Key Management Service HSM standing ends on 17 November 2026 — fifty-seven days after the cliff, by which point the September assessments are filed and nobody is looking again. Nothing about that machine changes on the day. What changes is whether the evidence behind it still stands.
That is the shape of the whole list: the answer is not wrong when you get it, it goes stale afterwards, and there is no signal when it does. Which is why we sell a report you re-run rather than a document you file.
The tool reads inventory you already export. It has no networking code in it at all — see how that is checked.
Buying rather than checking?
The same record answers the procurement question: what is still validated when it arrives — 703 active FIPS 140-3 certificates across 311 vendors, with the sunset date on every row.
Where this comes from. The NIST CMVP validated-module list, snapshot 2026.09-full, fetched 2026-09-14; and the CMVP Modules In Process list retrieved 2026-09-14.
What it cannot tell you. A certificate issued after that date is not in here. A module validated under a name our matching did not join to the retiring one will read as having no successor when it has one. So a blank on this page means nothing was found in a snapshot taken on that date — it is not a finding about the vendor, and we do not publish it as one. Every row links to NIST so you can check the current position rather than take ours.