Buying this quarter? Read the sunset date, not the standard
There are 703 active FIPS 140-3 certificates held by 311 vendors. 651 of them still run past September 2028. 52 do not — and a specification that says only “must be FIPS 140-3 validated” cannot tell the two apart.
- 703active FIPS 140-3 certificates
- 311vendors holding one
- 52end within two years of the cliff
If you are buying Windows machines
This is the most common version of the question, and it has an uncomfortable answer. A Windows build’s FIPS posture rests on two modules — bcryptprimitives.dll and cng.sys. A build with other modules validated but not those two is not the same as a covered build.
| Release | Build | Core modules | Other Microsoft modules |
|---|---|---|---|
| Windows 11 26H1 Build 28000 (latest 28000.2954 on 8 September 2026) per Microsoft's Windows 11 release information page, read 14 September 2026. Offered on new devices only, not as an in-place update, and not supported for IoT Enterprise. Microsoft's Windows 11 validations page (ms.date 2026-09-02) lists no entry for it. | 10.0.28000 | none | none |
| Windows 11 25H2 Build 26200 (latest 26200.9445 on 8 September 2026) per Microsoft's Windows 11 release information page, read 14 September 2026. Microsoft's Windows 11 validations page (ms.date 2026-09-02) lists no entry for it. | 10.0.26200 | none | none |
| Windows 11 24H2 | 10.0.26100 | none | none |
| Windows Server 2025 No certificate in the CMVP record names this build. The gap is present-tense and is not created by the 21 September transition. | 10.0.26100 | none | none |
| Windows 11 23H2 | 10.0.22631 | none | none |
| Windows 11 22H2 FIPS 140-3 #5410 and #5408, validated 31 August 2026, sunset 30 August 2031 - issued the day after the 30 August refresh, so this entry read "no validation" until 14 September 2026. The vendor's two documents disagree on the build: Microsoft's Windows 11 page says "Build: 10.0.22621.1"; section 2.2 of both security policies says "Windows 11 version 22H2 10.0.22621.30001". The tool matches only the version the security policy names, so a 22H2 machine on any other revision is not reported as covered - and, because Microsoft did validate this release, it is no longer reported as "no validation published" either. It reads as not determined, which is the honest state of a revision neither document names. Both named builds are listed above. | 10.0.22621.1, 10.0.22621.30001 | 2 active #5408 #5410 | 5 active |
| Windows 11 21H2 In the record, the only Windows 11 release a FIPS 140-2 primitives certificate names. Since 31 August 2026, 22H2 also holds a FIPS 140-3 pair (#5410, #5408); Microsoft's Windows 11 page (ms.date 2026-09-02) lists no entry for 23H2, 24H2, 25H2 or 26H1. | 10.0.22000 | 2 active #4766 #4825 | 1 active |
| Windows Server 2022 (FIPS 140-3 validation) FIPS 140-3 #5410 and #5408, validated 31 August 2026, sunset 30 August 2031, Standard and Datacenter only (not Datacenter: Azure). The vendor's two documents disagree on the build: Microsoft's page (ms.date 2026-09-02) says "Build: 10.0.20348.1668"; section 2.2 of both security policies says "Windows Server 2022 10.0.20348.30000 (including the March 2023 updates)". Both are listed. The tool matches only the version the security policy names (data/security-policy-versions.json), so a machine on any other revision is NOT reported as covered by this pair - our conservative reading of a conflict between the vendor's documents, not a determination that it is uncovered. | 10.0.20348.1668, 10.0.20348.30000 | 2 active #5408 #5410 | 7 active |
| Windows Server 2022 The FIPS 140-2 validation: the bare build 10.0.20348 (Standard, Datacenter, Datacenter: Azure), moving to Historical on 21 September 2026. Server 2022 also holds a FIPS 140-3 validation of narrower scope, kept as its own entry - one pair per entry, as for Server 2019. | 10.0.20348 | 2 active #4766 #4825 | 7 active |
| Windows 10 22H2 The terminal Windows 10 release, and the one most fleets run. No certificate in the record names this build for the primitives libraries. | 10.0.19045 | none | none |
| Windows 10 21H2 | 10.0.19044 | none | none |
| Windows 10 21H1 | 10.0.19043 | 2 active #4766 #4825 | none |
| Windows 10 20H2 | 10.0.19042 | 2 active #4766 #4825 | none |
| Windows 10 2004 | 10.0.19041 | 2 active #4515 #4536 | 8 active |
| Windows 10 1909 | 10.0.18363 | 2 active #4515 #4536 | 8 active |
| Windows 10 1903 | 10.0.18362 | 2 active #4515 #4536 | 7 active |
| Windows Server 2019 The narrowest scope in the index, on both axes: two exact revisions and Core only. A Server 2019 on any other revision, or with the desktop experience installed, is outside these certificates. | 10.0.17763.10021, 10.0.17763.10127 | 2 active #4670 #4687 | 6 active |
Read the Core modules column. The newest releases with an active core pair are Windows 11 22H2 (10.0.22621) and Windows Server 2022 (10.0.20348), which gained FIPS 140-3 certificates on 31 August 2026 for the exact builds those certificates name. Windows 11 22H2 is past Microsoft’s end of servicing (Enterprise and Education ended 14 October 2025), so no Windows 11 release Microsoft still services is named on a certificate; Server 2022 is supported to 14 October 2031. Windows 10 21H2 and 22H2, Windows 11 23H2, 24H2, 25H2 and 26H1, and Server 2025 have no active core certificate in this snapshot. That is not a reason to avoid them; it is a reason to know before you write the specification, because “latest” and “validated” are currently pulling in opposite directions and the gap has to be documented either way.
An active core pair is not the end of the question — read the scope too. Windows Server 2019 is the sharpest example on this table: its certificates name two exact revisions and cover Server Core only, so a Server 2019 on any other revision, or with the desktop experience installed, sits outside them. A certificate number on its own cannot tell you that, which is why the notes are here.
The table starts at the oldest release that still carries an active core certificate and shows everything newer; older releases are assessed in full by the report rather than listed here.
Search any vendor
Every active FIPS 140-3 certificate, with its end date. Type a vendor or a product name.
The 52 to look at twice
These are validated today and their standing ends within two years of the cliff. Buying one is not a mistake — it is a decision that should be made knowingly, with the end date written into the risk register next to it rather than discovered later.
| Standing ends | Cert | Vendor | Module |
|---|---|---|---|
| 23 Sep 2026 | #4812 | Outset Medical, Inc. | Tablo Medical Informatics System 2-year certificate |
| 30 Sep 2026 | #4817 | Apple Inc. | Apple corecrypto Module v12.0 [Apple silicon, User, Software, SL1] 2-year certificate |
| 10 Oct 2026 | #4829 | Palo Alto Networks, Inc. | PAN-OS 11.0 running on PA-400 Series, PA-800 Series, PA-1400 Series, PA-3200 Series, PA-3400 Series, PA-5200 S… 2-year certificate |
| 20 Oct 2026 | #4846 | Red Hat, Inc. | Red Hat Enterprise Linux 9 gnutls 2-year certificate |
| 27 Oct 2026 | #4854 | Apple Inc. | Apple corecrypto Module v12.0 [Apple silicon, Kernel, Software, SL1] 2-year certificate |
| 30 Oct 2026 | #4860 | Nokia of America Corporation (Nokia) | Nokia 1830 Photonic Service Switch (PSS) & Nokia 1830 Photonic Service Interconnect- Line (PSI-L) 2-year certificate |
| 12 Nov 2026 | #4875 | Geotab Inc. | Geotab Cryptographic Module 2-year certificate |
| 12 Nov 2026 | #4876 | Hewlett Packard Enterprise | Hewlett Packard Enterprise OpenSSL 3 Provider 2-year certificate |
| 13 Nov 2026 | #4879 | Samsung Electronics Co., Ltd. | Samsung NVMe TCG Opal SSC SEDs PM1743/PM1745 Series 2-year certificate |
| 13 Nov 2026 | #4880 | Advanced Micro Devices (AMD), Microsoft Corporation | Pluton Security Processor ROM 2-year certificate |
| 14 Nov 2026 | #4881 | Broadcom Inc. | VMware’s VPN Crypto Module 2-year certificate |
| 17 Nov 2026 | #4882 | Juniper Networks, Inc. | Juniper Networks QFX10002, QFX10008 and QFX10016 2-year certificate |
| 17 Nov 2026 | #4883 | F5, Inc. | F5OS-A Cryptographic Module 2-year certificate |
| 17 Nov 2026 | #4884 | Amazon Web Services, Inc. | AWS Key Management Service HSM 2-year certificate |
| 20 Nov 2026 | #4897 | Corsec Security, Inc. | CorSSL 2-year certificate |
| 2 Dec 2026 | #4907 | AudioCodes Ltd. | Mediant 800 Session Border Controller/Media Gateway, Mediant 2600/4000B/9080B Session Border Controllers, and… 2-year certificate |
| 2 Dec 2026 | #4908 | AudioCodes Ltd. | Mediant Virtual Edition SBC and Cloud Edition SBC 2-year certificate |
| 2 Dec 2026 | #4910 | Digital.ai Software, Inc. | Digital.ai Key & Data Protection Module 2-year certificate |
| 8 Dec 2026 | #4913 | Ciena Corporation | WaveLogic 5 Extreme Encryption Modem 2-year certificate |
| 11 Dec 2026 | #4916 | Aruba, a Hewlett Packard Enterprise company | AP-514, AP-515, AP-534, AP-535, AP-584, AP-585, AP-587, AP-635 and AP-655 Access Points 2-year certificate |
| 12 Dec 2026 | #4917 | Palo Alto Networks, Inc. | WildFire 11.0 WF-500 and WF-500-B 2-year certificate |
| 17 Dec 2026 | #4920 | Ciena Corporation | Waveserver 5 Control Processor Module 2-year certificate |
| 17 Dec 2026 | #4921 | Hewlett Packard Enterprise | Bootloader Module 2-year certificate |
| 18 Dec 2026 | #4927 | Palo Alto Networks, Inc. | Panorama 11.0 M-200, M-300, M-600 and M-700 2-year certificate |
| 19 Dec 2026 | #4929 | Hewlett Packard Enterprise | Aruba OpenSSL Module 2-year certificate |
| 19 Dec 2026 | #4931 | Fortinet Technologies Inc. | FortiClient Crypto Library 2-year certificate |
| 26 Dec 2026 | #4934 | Samsung Electronics Co., Ltd. | Samsung SAS TCG Enterprise SSC SEDs PM1653/PM1655 Series 2-year certificate |
| 1 Jan 2027 | #4935 | Palo Alto Networks, Inc. | Panorama Virtual Appliance 11.0 2-year certificate |
| 5 Jan 2027 | #4936 | Silvus Technologies, Inc. | SC4000 Series Mesh Radio 2-year certificate |
| 6 Jan 2027 | #4938 | Ampex Data Systems Corporation | TuffServ® Encryption Module (TSEM) 2-year certificate |
| 8 Jan 2027 | #4940 | Hewlett Packard Enterprise | Aruba Crypto Module 2-year certificate |
| 16 Jan 2027 | #4943 | Legion of the Bouncy Castle Inc. | BC-FJA (Bouncy Castle FIPS Java API) 2-year certificate |
| 26 Jan 2027 | #4951 | Apple, Inc. | Apple corecrypto Module v12 [Intel, User, Software] 2-year certificate |
| 29 Jan 2027 | #4956 | Apple, Inc. | Apple corecrypto Module v12 [Intel, Kernel, Software] 2-year certificate |
| 6 Feb 2027 | #4959 | Juniper Networks, Inc. | Juniper Networks EX4300-48MP Ethernet Switch 2-year certificate |
| 6 Feb 2027 | #4960 | Juniper Networks, Inc. | Juniper Networks PTX1000 Packet Transport Router 2-year certificate |
| 6 Feb 2027 | #4961 | Juniper Networks, Inc. | Juniper Networks PTX10008 and PTX10016 Packet Transport Routers 2-year certificate |
| 6 Feb 2027 | #4962 | Thales | Thales Luna G7 Cryptographic Module 2-year certificate |
| 23 Mar 2027 | #4991 | Icom Inc. | UT-125 FIPS #31 and #41 Cryptographic Module 2-year certificate |
| 24 Mar 2027 | #4992 | Utimaco Inc. | Atalla Cryptographic Subsystem (ACS) 2-year certificate |
| 30 Mar 2027 | #4995 | SonicWall, Inc. | SonicWall NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700 2-year certificate |
| 16 Apr 2027 | #5000 | Pure Storage, Inc. | FlashBlade Data Encryption Module 2-year certificate |
| 6 Dec 2027 | #4389 | Apple Inc. | Apple corecrypto Module v11.1 [Intel, User, Software] |
| 6 Dec 2027 | #4390 | Apple Inc. | Apple corecrypto Module v11.1 [Intel, Kernel, Software] |
| 6 Dec 2027 | #4391 | Apple Inc. | Apple corecrypto Module v11.1 [Apple silicon, User, Software] |
| 6 Dec 2027 | #4392 | Apple Inc. | Apple corecrypto Module v11.1 [Apple silicon, Kernel, Software] |
| 29 Dec 2027 | #4401 | Advanced Micro Devices (AMD) | AMD Ryzen PRO 5000 Series PSP Cryptographic CoProcessor |
| 29 Dec 2027 | #4402 | Advanced Micro Devices (AMD) | AMD Ryzen PRO 4000 Series PSP Cryptographic CoProcessor |
| 22 Feb 2028 | #4442 | VMware, Inc. | VMware's ESXboot Cryptographic Module |
| 30 Jul 2028 | #4555 | Advanced Micro Devices (AMD) | AMD Ryzen PRO 5000 Series PSP Cryptographic CoProcessor (models 5475U, 5675U, 5875U) |
| 20 Sep 2028 | #4603 | Nuvoton Technology Corporation | Nuvoton Cryptographic Library 2.0 |
| 20 Sep 2028 | #4814 | HP Inc. | HP Endpoint Security Controller Cryptographic Library |
Where the deepest benches are
Vendors by how many active FIPS 140-3 certificates they hold, and how many of those run past September 2028. A long bench is not a recommendation of any product — it says the vendor is demonstrably still in the program, which is a different and more durable fact than any single certificate.
| Vendor | Active 140-3 | Running past Sep 2028 |
|---|---|---|
| Apple Inc. | 28 | 22 |
| Cisco Systems, Inc. | 21 | 21 |
| Palo Alto Networks, Inc. | 22 | 18 |
| Juniper Networks, Inc. | 20 | 16 |
| Qualcomm Technologies, Inc. | 15 | 15 |
| Samsung Electronics Co., Ltd. | 17 | 15 |
| Motorola Solutions, Inc. | 11 | 11 |
| Amazon Web Services, Inc. | 11 | 10 |
| F5, Inc. | 11 | 10 |
| SUSE LLC | 10 | 10 |
| Ctrl IQ, Inc. | 9 | 9 |
| Microsoft Corporation | 9 | 9 |
| Advanced Micro Devices (AMD) | 11 | 8 |
| Arista Networks, Inc. | 8 | 8 |
| Google, LLC | 8 | 8 |
| Ruckus Wireless LLC | 8 | 8 |
| Trellix | 8 | 8 |
| Canonical Ltd. | 7 | 7 |
| KIOXIA Corporation | 7 | 7 |
| HPE Juniper Networking | 6 | 6 |
| Nuvoton Technology Corporation | 7 | 6 |
| Oracle Corporation | 6 | 6 |
| Cloudlinux Inc., TuxCare division | 5 | 5 |
| Google, LLC. | 5 | 5 |
What this page is not
It is not a product recommendation, a security assessment, or a statement that anything absent from it is unvalidated. It is one public record, rearranged so that the end date is impossible to miss. The purchasing decision, and everything else that goes into it, stays yours.
Where this comes from. The NIST CMVP validated-module list, snapshot 2026.09-full, fetched 2026-09-14; and the CMVP Modules In Process list retrieved 2026-09-14. The Windows table additionally uses our release index (2026.08), in which every build number and certificate is quoted from the vendor’s own published validation pages rather than inferred from certificate text.
What it cannot tell you. A certificate issued after that date is not in here. A module validated under a name our matching did not join to the retiring one will read as having no successor when it has one. So a blank on this page means nothing was found in a snapshot taken on that date — it is not a finding about the vendor, and we do not publish it as one. Every row links to NIST so you can check the current position rather than take ours.