Who decides what
Whether your cryptography survives an assessment is settled by four parties, and we are only one of them. Buyers are right to ask which, so here it is in full — including the questions we will not answer, which are the reason you can rely on the ones we do.
Decides whether a module is validated
NIST CMVP and the accredited laboratories
The Cryptographic Module Validation Program issues the certificate, sets its sunset date, and maintains the Modules In Process queue. Nobody else can validate a cryptographic module, and no assessment, opinion or tool — including ours — can substitute for one. We read that record. We never opine on it. Every certificate number we print links back to NIST so you can check us against the source rather than take our word.
Decides whether your organization meets the requirement
Your assessor
Under CMMC, that is either your own self-assessment or a certification assessment by an accredited C3PAO, depending on the level and the contract; the highest level is assessed by the government. They decide whether your implementation satisfies the control, whether your documentation is adequate, and whether a gap can be carried as a temporary deficiency.
We are not a C3PAO and we do not intend to become one. An organization that assessed you could not also sell you the preparation without a conflict, and we would rather be useful to both sides of that table.
Makes the affirmation, and carries the consequence
You
The score, the affirmation and the plan are yours. So is the judgment about which gaps are acceptable to carry and which need budget this quarter. Nobody can sign that for you, and any supplier who implies otherwise is selling you something they cannot deliver.
You also hold the one input nothing else in the chain has: what is actually deployed. CMVP does not know your estate, and your assessor does not inventory it for you.
Produces the evidence, upstream of all three
Us
We take the inventory you already export, join every component to the public CMVP record, and tell you which certificate each one rests on, when that certificate’s standing ends, whether a successor names the exact version you run, and what class of work the fix is — a paragraph, a patch, or a purchase order.
Then we hand you the evidence in the form an assessor asks for, with the rule that produced each claim and the snapshot it came from, so the finding can be checked rather than believed.
Question by question
| The question | Who settles it | Do we answer? |
|---|---|---|
| Is this module FIPS validated? | CMVP and the testing laboratory | We report theirs |
| When does its standing end? | CMVP, on the certificate | Yes — and when it moves |
| Does the certificate cover the version we actually run? | The certificate names versions; the join is ours | Yes, or we say we cannot |
| Is a replacement in progress? | CMVP’s Modules In Process list | We report the phase |
| How long will that phase take? | The vendor. NIST publishes no durations | No |
| Does this satisfy SP 800-171 3.13.11? | Your assessor | No |
| Is the gap carryable as a temporary deficiency? | Your assessor, on your documentation | We supply the evidence |
| Are you compliant? | Your assessment and your affirmation | No |
| Has this vendor abandoned the product? | The vendor, in writing, to you | No |
| Should you buy this product? | You | No |
The refusals are the product
It would be easy to answer all ten. Plenty of tools do — they collapse “we could not determine this” into a clean red or green, because a dashboard with unknowns in it looks unfinished.
That is exactly what gets a report discarded. An assessor who finds one row claiming coverage the record does not support does not discount that row; they stop trusting the document, and reasonably so. Five hundred correct rows buy nothing back. So the tool treats unknown, ambiguous and contradictory as real answers, and roughly a quarter of its automated tests exist to prove it still refuses when it should.
One example, because it is the difference in miniature
Windows cryptography rests on two modules. One is called Cryptographic Primitives Library; the other is Kernel Mode Cryptographic Primitives Library. The first name is contained inside the second, and Microsoft currently has exactly one of the two in the CMVP queue.
A tool that matches on names finds the queue entry for both and reports that a fix is in process for a module nobody has submitted. The customer files a plan promising a certificate that is not coming, and finds out at the assessment. We split them, and we have a test whose only job is to keep them split.
What this means when you buy
You are not buying a compliance determination, and you should be wary of anyone selling one. You are buying the measurement and the evidence behind it — produced independently, reproducibly, and early enough to act on, so that the assessment finds a documented gap with a plan attached rather than an undocumented one.
That difference is the whole thing. Two organizations with identical estates get different assessment outcomes depending on whether the gap was found, classified and written down before anyone came to look.
Nothing is installed, nothing is scanned, and the tool has no networking code in it at all — how that is checked.