AGILICRYPT™ What is safe to specify

Buying this quarter? Read the sunset date, not the standard

There are 703 active FIPS 140-3 certificates held by 311 vendors. 651 of them still run past September 2028. 52 do not — and a specification that says only “must be FIPS 140-3 validated” cannot tell the two apart.

If you are buying Windows machines

This is the most common version of the question, and it has an uncomfortable answer. A Windows build’s FIPS posture rests on two modules — bcryptprimitives.dll and cng.sys. A build with other modules validated but not those two is not the same as a covered build.

ReleaseBuildCore modulesOther Microsoft modules
Windows 11 26H1
Build 28000 (latest 28000.2954 on 8 September 2026) per Microsoft's Windows 11 release information page, read 14 September 2026. Offered on new devices only, not as an in-place update, and not supported for IoT Enterprise. Microsoft's Windows 11 validations page (ms.date 2026-09-02) lists no entry for it.
10.0.28000nonenone
Windows 11 25H2
Build 26200 (latest 26200.9445 on 8 September 2026) per Microsoft's Windows 11 release information page, read 14 September 2026. Microsoft's Windows 11 validations page (ms.date 2026-09-02) lists no entry for it.
10.0.26200nonenone
Windows 11 24H210.0.26100nonenone
Windows Server 2025
No certificate in the CMVP record names this build. The gap is present-tense and is not created by the 21 September transition.
10.0.26100nonenone
Windows 11 23H210.0.22631nonenone
Windows 11 22H2
FIPS 140-3 #5410 and #5408, validated 31 August 2026, sunset 30 August 2031 - issued the day after the 30 August refresh, so this entry read "no validation" until 14 September 2026. The vendor's two documents disagree on the build: Microsoft's Windows 11 page says "Build: 10.0.22621.1"; section 2.2 of both security policies says "Windows 11 version 22H2 10.0.22621.30001". The tool matches only the version the security policy names, so a 22H2 machine on any other revision is not reported as covered - and, because Microsoft did validate this release, it is no longer reported as "no validation published" either. It reads as not determined, which is the honest state of a revision neither document names. Both named builds are listed above.
10.0.22621.1, 10.0.22621.300012 active #5408 #54105 active
Windows 11 21H2
In the record, the only Windows 11 release a FIPS 140-2 primitives certificate names. Since 31 August 2026, 22H2 also holds a FIPS 140-3 pair (#5410, #5408); Microsoft's Windows 11 page (ms.date 2026-09-02) lists no entry for 23H2, 24H2, 25H2 or 26H1.
10.0.220002 active #4766 #48251 active
Windows Server 2022 (FIPS 140-3 validation)
FIPS 140-3 #5410 and #5408, validated 31 August 2026, sunset 30 August 2031, Standard and Datacenter only (not Datacenter: Azure). The vendor's two documents disagree on the build: Microsoft's page (ms.date 2026-09-02) says "Build: 10.0.20348.1668"; section 2.2 of both security policies says "Windows Server 2022 10.0.20348.30000 (including the March 2023 updates)". Both are listed. The tool matches only the version the security policy names (data/security-policy-versions.json), so a machine on any other revision is NOT reported as covered by this pair - our conservative reading of a conflict between the vendor's documents, not a determination that it is uncovered.
10.0.20348.1668, 10.0.20348.300002 active #5408 #54107 active
Windows Server 2022
The FIPS 140-2 validation: the bare build 10.0.20348 (Standard, Datacenter, Datacenter: Azure), moving to Historical on 21 September 2026. Server 2022 also holds a FIPS 140-3 validation of narrower scope, kept as its own entry - one pair per entry, as for Server 2019.
10.0.203482 active #4766 #48257 active
Windows 10 22H2
The terminal Windows 10 release, and the one most fleets run. No certificate in the record names this build for the primitives libraries.
10.0.19045nonenone
Windows 10 21H210.0.19044nonenone
Windows 10 21H110.0.190432 active #4766 #4825none
Windows 10 20H210.0.190422 active #4766 #4825none
Windows 10 200410.0.190412 active #4515 #45368 active
Windows 10 190910.0.183632 active #4515 #45368 active
Windows 10 190310.0.183622 active #4515 #45367 active
Windows Server 2019
The narrowest scope in the index, on both axes: two exact revisions and Core only. A Server 2019 on any other revision, or with the desktop experience installed, is outside these certificates.
10.0.17763.10021, 10.0.17763.101272 active #4670 #46876 active

Read the Core modules column. The newest releases with an active core pair are Windows 11 22H2 (10.0.22621) and Windows Server 2022 (10.0.20348), which gained FIPS 140-3 certificates on 31 August 2026 for the exact builds those certificates name. Windows 11 22H2 is past Microsoft’s end of servicing (Enterprise and Education ended 14 October 2025), so no Windows 11 release Microsoft still services is named on a certificate; Server 2022 is supported to 14 October 2031. Windows 10 21H2 and 22H2, Windows 11 23H2, 24H2, 25H2 and 26H1, and Server 2025 have no active core certificate in this snapshot. That is not a reason to avoid them; it is a reason to know before you write the specification, because “latest” and “validated” are currently pulling in opposite directions and the gap has to be documented either way.

An active core pair is not the end of the question — read the scope too. Windows Server 2019 is the sharpest example on this table: its certificates name two exact revisions and cover Server Core only, so a Server 2019 on any other revision, or with the desktop experience installed, sits outside them. A certificate number on its own cannot tell you that, which is why the notes are here.

The table starts at the oldest release that still carries an active core certificate and shows everything newer; older releases are assessed in full by the report rather than listed here.

Search any vendor

Every active FIPS 140-3 certificate, with its end date. Type a vendor or a product name.

The 52 to look at twice

These are validated today and their standing ends within two years of the cliff. Buying one is not a mistake — it is a decision that should be made knowingly, with the end date written into the risk register next to it rather than discovered later.

Standing endsCertVendorModule
23 Sep 2026#4812Outset Medical, Inc.Tablo Medical Informatics System 2-year certificate
30 Sep 2026#4817Apple Inc.Apple corecrypto Module v12.0 [Apple silicon, User, Software, SL1] 2-year certificate
10 Oct 2026#4829Palo Alto Networks, Inc.PAN-OS 11.0 running on PA-400 Series, PA-800 Series, PA-1400 Series, PA-3200 Series, PA-3400 Series, PA-5200 S… 2-year certificate
20 Oct 2026#4846Red Hat, Inc.Red Hat Enterprise Linux 9 gnutls 2-year certificate
27 Oct 2026#4854Apple Inc.Apple corecrypto Module v12.0 [Apple silicon, Kernel, Software, SL1] 2-year certificate
30 Oct 2026#4860Nokia of America Corporation (Nokia)Nokia 1830 Photonic Service Switch (PSS) & Nokia 1830 Photonic Service Interconnect- Line (PSI-L) 2-year certificate
12 Nov 2026#4875Geotab Inc.Geotab Cryptographic Module 2-year certificate
12 Nov 2026#4876Hewlett Packard EnterpriseHewlett Packard Enterprise OpenSSL 3 Provider 2-year certificate
13 Nov 2026#4879Samsung Electronics Co., Ltd.Samsung NVMe TCG Opal SSC SEDs PM1743/PM1745 Series 2-year certificate
13 Nov 2026#4880Advanced Micro Devices (AMD), Microsoft CorporationPluton Security Processor ROM 2-year certificate
14 Nov 2026#4881Broadcom Inc.VMware’s VPN Crypto Module 2-year certificate
17 Nov 2026#4882Juniper Networks, Inc.Juniper Networks QFX10002, QFX10008 and QFX10016 2-year certificate
17 Nov 2026#4883F5, Inc.F5OS-A Cryptographic Module 2-year certificate
17 Nov 2026#4884Amazon Web Services, Inc.AWS Key Management Service HSM 2-year certificate
20 Nov 2026#4897Corsec Security, Inc.CorSSL 2-year certificate
2 Dec 2026#4907AudioCodes Ltd.Mediant 800 Session Border Controller/Media Gateway, Mediant 2600/4000B/9080B Session Border Controllers, and… 2-year certificate
2 Dec 2026#4908AudioCodes Ltd.Mediant Virtual Edition SBC and Cloud Edition SBC 2-year certificate
2 Dec 2026#4910Digital.ai Software, Inc.Digital.ai Key & Data Protection Module 2-year certificate
8 Dec 2026#4913Ciena CorporationWaveLogic 5 Extreme Encryption Modem 2-year certificate
11 Dec 2026#4916Aruba, a Hewlett Packard Enterprise companyAP-514, AP-515, AP-534, AP-535, AP-584, AP-585, AP-587, AP-635 and AP-655 Access Points 2-year certificate
12 Dec 2026#4917Palo Alto Networks, Inc.WildFire 11.0 WF-500 and WF-500-B 2-year certificate
17 Dec 2026#4920Ciena CorporationWaveserver 5 Control Processor Module 2-year certificate
17 Dec 2026#4921Hewlett Packard EnterpriseBootloader Module 2-year certificate
18 Dec 2026#4927Palo Alto Networks, Inc.Panorama 11.0 M-200, M-300, M-600 and M-700 2-year certificate
19 Dec 2026#4929Hewlett Packard EnterpriseAruba OpenSSL Module 2-year certificate
19 Dec 2026#4931Fortinet Technologies Inc.FortiClient Crypto Library 2-year certificate
26 Dec 2026#4934Samsung Electronics Co., Ltd.Samsung SAS TCG Enterprise SSC SEDs PM1653/PM1655 Series 2-year certificate
1 Jan 2027#4935Palo Alto Networks, Inc.Panorama Virtual Appliance 11.0 2-year certificate
5 Jan 2027#4936Silvus Technologies, Inc.SC4000 Series Mesh Radio 2-year certificate
6 Jan 2027#4938Ampex Data Systems CorporationTuffServ® Encryption Module (TSEM) 2-year certificate
8 Jan 2027#4940Hewlett Packard EnterpriseAruba Crypto Module 2-year certificate
16 Jan 2027#4943Legion of the Bouncy Castle Inc.BC-FJA (Bouncy Castle FIPS Java API) 2-year certificate
26 Jan 2027#4951Apple, Inc.Apple corecrypto Module v12 [Intel, User, Software] 2-year certificate
29 Jan 2027#4956Apple, Inc.Apple corecrypto Module v12 [Intel, Kernel, Software] 2-year certificate
6 Feb 2027#4959Juniper Networks, Inc.Juniper Networks EX4300-48MP Ethernet Switch 2-year certificate
6 Feb 2027#4960Juniper Networks, Inc.Juniper Networks PTX1000 Packet Transport Router 2-year certificate
6 Feb 2027#4961Juniper Networks, Inc.Juniper Networks PTX10008 and PTX10016 Packet Transport Routers 2-year certificate
6 Feb 2027#4962ThalesThales Luna G7 Cryptographic Module 2-year certificate
23 Mar 2027#4991Icom Inc.UT-125 FIPS #31 and #41 Cryptographic Module 2-year certificate
24 Mar 2027#4992Utimaco Inc.Atalla Cryptographic Subsystem (ACS) 2-year certificate
30 Mar 2027#4995SonicWall, Inc.SonicWall NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700 2-year certificate
16 Apr 2027#5000Pure Storage, Inc.FlashBlade Data Encryption Module 2-year certificate
6 Dec 2027#4389Apple Inc.Apple corecrypto Module v11.1 [Intel, User, Software]
6 Dec 2027#4390Apple Inc.Apple corecrypto Module v11.1 [Intel, Kernel, Software]
6 Dec 2027#4391Apple Inc.Apple corecrypto Module v11.1 [Apple silicon, User, Software]
6 Dec 2027#4392Apple Inc.Apple corecrypto Module v11.1 [Apple silicon, Kernel, Software]
29 Dec 2027#4401Advanced Micro Devices (AMD)AMD Ryzen PRO 5000 Series PSP Cryptographic CoProcessor
29 Dec 2027#4402Advanced Micro Devices (AMD)AMD Ryzen PRO 4000 Series PSP Cryptographic CoProcessor
22 Feb 2028#4442VMware, Inc.VMware's ESXboot Cryptographic Module
30 Jul 2028#4555Advanced Micro Devices (AMD)AMD Ryzen PRO 5000 Series PSP Cryptographic CoProcessor (models 5475U, 5675U, 5875U)
20 Sep 2028#4603Nuvoton Technology CorporationNuvoton Cryptographic Library 2.0
20 Sep 2028#4814HP Inc.HP Endpoint Security Controller Cryptographic Library

Where the deepest benches are

Vendors by how many active FIPS 140-3 certificates they hold, and how many of those run past September 2028. A long bench is not a recommendation of any product — it says the vendor is demonstrably still in the program, which is a different and more durable fact than any single certificate.

VendorActive 140-3Running past Sep 2028
Apple Inc.2822
Cisco Systems, Inc.2121
Palo Alto Networks, Inc.2218
Juniper Networks, Inc.2016
Qualcomm Technologies, Inc.1515
Samsung Electronics Co., Ltd.1715
Motorola Solutions, Inc.1111
Amazon Web Services, Inc.1110
F5, Inc.1110
SUSE LLC1010
Ctrl IQ, Inc.99
Microsoft Corporation99
Advanced Micro Devices (AMD)118
Arista Networks, Inc.88
Google, LLC88
Ruckus Wireless LLC88
Trellix88
Canonical Ltd.77
KIOXIA Corporation77
HPE Juniper Networking66
Nuvoton Technology Corporation76
Oracle Corporation66
Cloudlinux Inc., TuxCare division55
Google, LLC.55

What this page is not

It is not a product recommendation, a security assessment, or a statement that anything absent from it is unvalidated. It is one public record, rearranged so that the end date is impossible to miss. The purchasing decision, and everything else that goes into it, stays yours.

See what expires and when Check one machine — $100

Where this comes from. The NIST CMVP validated-module list, snapshot 2026.09-full, fetched 2026-09-14; and the CMVP Modules In Process list retrieved 2026-09-14. The Windows table additionally uses our release index (2026.08), in which every build number and certificate is quoted from the vendor’s own published validation pages rather than inferred from certificate text.

What it cannot tell you. A certificate issued after that date is not in here. A module validated under a name our matching did not join to the retiring one will read as having no successor when it has one. So a blank on this page means nothing was found in a snapshot taken on that date — it is not a finding about the vendor, and we do not publish it as one. Every row links to NIST so you can check the current position rather than take ours.