<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FIPS again, and FedRAMP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281079#M46697</link>
    <description>&lt;P&gt;I've searched SK and the community and seen lots of bits on FIPS support for the gateways. &amp;nbsp;Looks like the available information is a bit thin on details, even in the admin guides I pulled. &amp;nbsp;I saw some URLs for the NIST reference sites and I see R81.20 has FIPS 140-2 certification. &amp;nbsp;However, the list also specifies a specific appliance model. &amp;nbsp; Does this mean that hardware platform (9300 in this case) is the only appliance certified for FIPS?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in-process/modules-in-process-list" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in-process/modules-in-process-list&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Can someone make an SK article to cover all this in one place? That'd be fantastic! &amp;nbsp;Similarly, can this include FedRAMP support, too? &amp;nbsp;I see the R82.20 EA release notes mention FedRAMP; is that the only version?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2026 18:31:16 GMT</pubDate>
    <dc:creator>Duane_Toler</dc:creator>
    <dc:date>2026-08-13T18:31:16Z</dc:date>
    <item>
      <title>FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281079#M46697</link>
      <description>&lt;P&gt;I've searched SK and the community and seen lots of bits on FIPS support for the gateways. &amp;nbsp;Looks like the available information is a bit thin on details, even in the admin guides I pulled. &amp;nbsp;I saw some URLs for the NIST reference sites and I see R81.20 has FIPS 140-2 certification. &amp;nbsp;However, the list also specifies a specific appliance model. &amp;nbsp; Does this mean that hardware platform (9300 in this case) is the only appliance certified for FIPS?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4264&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in-process/modules-in-process-list" target="_blank"&gt;https://csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in-process/modules-in-process-list&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Can someone make an SK article to cover all this in one place? That'd be fantastic! &amp;nbsp;Similarly, can this include FedRAMP support, too? &amp;nbsp;I see the R82.20 EA release notes mention FedRAMP; is that the only version?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2026 18:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281079#M46697</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-08-13T18:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281084#M46698</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18467"&gt;@Malcolm_Levy&lt;/a&gt;&amp;nbsp;recently posted about FIPS 140-3&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/FIPS-140-3/td-p/279085" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-and-Security-Management/FIPS-140-3/td-p/279085&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2026 05:20:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281084#M46698</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-08-14T05:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281097#M46701</link>
      <description>&lt;P&gt;I updated the referenced post.&lt;/P&gt;
&lt;P&gt;We are listed under the Modules In Process for 140-3 and we tested on all current modules Smart-1, Quantum GWs, MHO. The list is given under the separate Entropy certification certificate&amp;nbsp;&lt;A id="cert-number-link-1" href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/entropy-validations/certificate/309" target="_blank"&gt;&lt;SPAN&gt;E&lt;/SPAN&gt;309&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2026 13:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281097#M46701</guid>
      <dc:creator>Malcolm_Levy</dc:creator>
      <dc:date>2026-08-14T13:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281098#M46702</link>
      <description>&lt;P&gt;Thanks! I saw that post as well. &amp;nbsp;Does this mean that ONLY those appliance hardware models qualify? Or is the specified software version enough, regardless of the underlying hardware (or VM/cloud) platform?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2026 13:24:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281098#M46702</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-08-14T13:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281099#M46703</link>
      <description>&lt;P&gt;In 140-2 a vendor affirmation was allowed under Implementation Guidance G.5. In our case our appliances are GPC.&amp;nbsp;&lt;A href="https://csrc.nist.gov/CSRC/media/Projects/Cryptographic-Module-Validation-Program/documents/fips140-2/FIPS1402IG.pdf" target="_blank"&gt;Implementation Guidance for FIPS 140-2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;FIPS 140-3 Management Manual similarly says the following that allows a vendor affirmation to porting to another appliance:&amp;nbsp;&lt;A href="https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS-140-3-CMVP%20Management%20Manual.pdf#7.9%20Vendor%20or%20User%20Affirmation%20of%20Modules" target="_blank"&gt;FIPS-140-3-CMVP Management Manual.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;7.9.1 Vendor 2554 &lt;BR /&gt;1. A vendor may perform post-validation recompilations of a software, firmware, or hybrid 2555 &lt;BR /&gt;module and affirm the modules continued validation compliance. By adding vendor support 2556 &lt;BR /&gt;of non-tested configurations to the validated module security policy, the vendor bears all 2557 &lt;BR /&gt;responsibility. These non-tested configurations versions may be considered by the user at 2558 &lt;BR /&gt;their risk, provided the following is maintained: 2559 &lt;BR /&gt;a) Software modules do not require any source code modifications (e.g., changes, additions, 2560 &lt;BR /&gt;or deletions of code) to be recompiled and ported to another OE and must: 2561 &lt;BR /&gt;i) For Level 1 OE, a software cryptographic module can be considered compliant with 2562 &lt;BR /&gt;the FIPS 140-3 validation when operating on any general-purpose platform/processor 2563 &lt;BR /&gt;that supports the specified operating system as listed on the validation entry or 2564 &lt;BR /&gt;another compatible4 operating system, or 2565 &lt;BR /&gt;ii) For Level 2 OE, a software cryptographic module can be considered compliant with 2566 &lt;BR /&gt;the FIPS 140-3 validation when operating on any general-purpose platform/processor 2567 &lt;BR /&gt;that supports the same level 2 operational environment settings specified on the 2568 &lt;BR /&gt;validation entry. 2569 &lt;BR /&gt;b) Firmware modules do not require any source code modifications (e.g., changes, additions, 2570 &lt;BR /&gt;or deletions of code) to be recompiled, and its identified unchanged tested operating 2571 &lt;BR /&gt;system (i.e., same version or revision number) may be ported together from one platform 2572 &lt;BR /&gt;to another platform while maintaining the module’s validation. 2573 &lt;BR /&gt;Level 2 and above Firmware modules cannot be ported and maintain their validation, 2574 &lt;BR /&gt;since Physical Security must be retested.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV class="OZ9ddf WAUd4" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 14px; font-weight: 400; margin: -8px 0px 0px; text-decoration: none; border-bottom: 0px rgb(31, 31, 31);"&gt;
&lt;DIV class="nk9vdc GYaNDc" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 14px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(31, 31, 31);"&gt;
&lt;DIV class="Fzsovc cwYVJe RJPOee" role="heading" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 14px; font-weight: 500; margin: 0px; text-decoration: none; border-bottom: 0px rgb(31, 31, 31);" aria-level="2"&gt;AI Overview&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 14px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(31, 31, 31);" data-ved="2ahUKEwjSvIn3pKCWAxUnQUEAHWvxMOoQ2b4KegQIAhAF" data-hveid="CAIQBQ" data-ve-view=""&gt;
&lt;DIV class="Pqkn2e" data-copy-service-computed-style="font-family: Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(31, 31, 31);" data-ved="2ahUKEwjSvIn3pKCWAxUnQUEAHWvxMOoQ274KegQIAhAG"&gt;
&lt;DIV class="jloFI GkDqAd rJweXb" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(0, 29, 53);"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(0, 29, 53);" data-complete="true" data-ved="2ahUKEwjSvIn3pKCWAxUnQUEAHWvxMOoQ7uAMegQIAhAH" data-hveid="CAIQBw"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(0, 29, 53);" data-complete="true"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(0, 29, 53);"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(0, 29, 53);"&gt;
&lt;DIV class="LT6XE" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);"&gt;
&lt;DIV class="RJPOee EIJn2" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);"&gt;
&lt;DIV class="pOOWX" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-rl="en"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);"&gt;
&lt;SECTION data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-complete="true" data-sc="1" data-host-wiz-contract-name="gws_wizbind"&gt;
&lt;DIV id="_lCB_atKiIKeChbIP6-LD0Q4_2" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);"&gt;
&lt;DIV class="qRuFed" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);"&gt;
&lt;DIV class="CKgc1d" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-sfc-root="ep" data-scope-id="turn"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-sfc-root="c" data-sfc-cp="" data-subtree="aimc"&gt;
&lt;DIV class="FkX2oe" dir="ltr" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-sfc-inited="2" data-hveid="CAIIAAgACAIQAA" data-ved="2ahUKEwiJ_P_2pKCWAxX0efEDHdGNBWAQ2O0OegoIAggACAAIAhAA" data-ctx-provider="[[[&amp;quot;tsCKD&amp;quot;,&amp;quot;3&amp;quot;],[&amp;quot;dMtGDc&amp;quot;,&amp;quot;[false]&amp;quot;]]]" data-wiz-uids="tJkpVd_2" data-sfc-root="ep"&gt;
&lt;DIV class="pWvJNd" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-sfc-root="ep"&gt;
&lt;DIV data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-sfc-root="ep"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="mZJni Dn7Fzd" dir="ltr" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-sfc-inited="2" data-ved="2ahUKEwiJ_P_2pKCWAxX0efEDHdGNBWAQ3KYQegoIAggACAAIAhAB" data-ctx-provider="[[[&amp;quot;dMtGDc&amp;quot;,&amp;quot;[false]&amp;quot;]]]" data-sfc-root="ep" data-xid="VpUvz" data-container-id="main-col"&gt;
&lt;DIV class="n6owBd awi2gc" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px 0px 16px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-hveid="CAIIAAgACAYQAA" data-sfc-root="ep" data-sfc-cp=""&gt;&lt;SPAN data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-subtree="aimfl,mfl"&gt;Section 7.9 of the FIPS Cryptographic Module Validation Program (CMVP) Management Manual covers &lt;/SPAN&gt;&lt;STRONG class="rQesXe MPyX" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 700; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);" data-sfc-root="ep" data-sfc-cp=""&gt;Vendor or User Affirmation of Modules&lt;/STRONG&gt;. This section &lt;MARK class="HxTRcb" data-copy-service-computed-style="font-family: &amp;quot;Google Sans&amp;quot;, Arial, sans-serif; font-size: 16px; font-weight: 500; margin: 0px; text-decoration: none; border-bottom: 0px rgb(0, 29, 53);" data-sfc-inited="2" data-ved="2ahUKEwiJ_P_2pKCWAxX0efEDHdGNBWAQuJAPegoIAggACAAIBhAD" data-wiz-uids="tJkpVd_q" data-sfc-root="ep"&gt;details the conditions under which a vendor or system user can formally affirm that a validated software or firmware cryptographic module will operate correctly and maintain compliance when ported or used in an operational environment (OE) similar to, but not explicitly tested during, the original lab validation&lt;/MARK&gt;.&lt;SPAN&gt; [&lt;A href="https://www.scribd.com/document/865380770/FIPS-140-3-CMVP-Management-Manual" target="_blank" rel="noopener"&gt;1&lt;/A&gt;, &lt;A href="https://www.youtube.com/watch?v=HQ2q8yRKJ-A&amp;amp;t=1375" target="_blank" rel="noopener"&gt;2&lt;/A&gt;]&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2026 08:13:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281099#M46703</guid>
      <dc:creator>Malcolm_Levy</dc:creator>
      <dc:date>2026-08-15T08:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281105#M46705</link>
      <description>&lt;P&gt;Nice! Thanks for the updates! &amp;nbsp;I also noticed your name was attached to the NIST document section, too. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2026 20:32:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281105#M46705</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-08-14T20:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281111#M46706</link>
      <description>&lt;P&gt;For possible future reference, this is NIST advice for usage of modules with updates when a CVE is remediated.&lt;/P&gt;
&lt;P&gt;Note the strong recommendation to apply patches before the update is certified.&amp;nbsp;&lt;/P&gt;
&lt;H1 id="projectName"&gt;&lt;A href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/cmvp-flow" target="_blank" rel="noopener"&gt;https://csrc.nist.gov/Projects/cryptographic-module-validation-program/cmvp-flow&lt;/A&gt;&lt;/H1&gt;
&lt;H1&gt;Cryptographic Module Validation Program&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SMALL id="project-acronym"&gt;CMV&lt;/SMALL&gt;&lt;/H1&gt;
&lt;DIV class="row"&gt;
&lt;DIV class="col-lg-8 col-sm-12"&gt;
&lt;H3 id="pageName"&gt;FIPS Validation and Updates, Patches, and CVEs&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We often get the question whether patching/updating a FIPS validation module (particularly when there is a significant security-related reason such as addressing a CVE) will invalidate that module’s FIPS status. The original version would maintain its validation but the new version that includes the patch/update would not be validated. Changing the code of the module results in that portion being untested and the CMVP is only able to make validation assurances for the tested configuration. As noted in our guidance:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The tested/validated module version, operational environment upon which it was tested, and the originating vendor are stated on the validation certificate. The certificate serves as the benchmark for the module-compliant configuration. (&lt;A href="https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/fips140-2/fips1402ig.pdf#G.5%20Maintaining%20validation%20compliance%20of%20software%20or%20firmware%20cryptographic%20modules" target="_blank" rel="noopener noreferrer"&gt;FIPS 140-2 IG G.5&lt;/A&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS-140-3-CMVP%20Management%20Manual.pdf#7.9%20Vendor%20or%20User%20Affirmation%20of%20Modules" target="_blank" rel="noopener noreferrer"&gt;FIPS 140-3 Management Manual 7.9&lt;/A&gt;)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;However, we strongly recommend patching to safeguard the security of systems and data, noting that organizations must use their own Vulnerability, Patch and Risk Management programs, policies and procedures to make those decisions within the context of their organization. Simply, this is not a decision the CMVP has either the information necessary or the authority to make.&lt;/P&gt;
&lt;P&gt;To reestablish those assurances as quickly as possible and minimize the risk, we also strongly recommend that vendors quickly have a CMVP certified lab test and submit an update for their module that reflects the patching/updating. The CMVP has an expedited processes in place to handle these updates when they are in response to a published CVE or a security relevant maintenance/bug fix&amp;nbsp;(see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/fips140-2/fips1402ig.pdf#G.8%20Revalidation%20Requirements" target="_blank" rel="noopener noreferrer"&gt;FIPS 140-2 IG G.8&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Scenario 3A, and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS-140-3-CMVP%20Management%20Manual.pdf#7.1.11%20Common%20Vulnerabilities%20and%20Exposures%20(CVE)" target="_blank" rel="noopener noreferrer"&gt;FIPS 140-3 Management Manual 7.1.11 CVE&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;To summarize, the CMVP would agree that quickly addressing a known risk and then following up with an expedited validation of the updated module is generally the best and recommended way to minimize the overall security risk for government agencies.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sat, 15 Aug 2026 13:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281111#M46706</guid>
      <dc:creator>Malcolm_Levy</dc:creator>
      <dc:date>2026-08-15T13:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS again, and FedRAMP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281113#M46707</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt; Thanks! I saw that post as well. &amp;nbsp;Does this mean that ONLY those appliance hardware models qualify? Or is the specified software version enough, regardless of the underlying hardware (or VM/cloud) platform?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I answered regarding other appliances in the earlier post for vendor affirmation.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regarding the software version:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The FIPS 140-3 certification relates to the OS defined as Gaia R82.10 or Gaia R82.20 (both have the same kernel).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The FIPS Security Policy shows the cryptographic boundary. For 140-3 this is defined in this table.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;&lt;STRONG&gt;Package/File Names&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;&lt;STRONG&gt;Software/ Firmware Version&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;&lt;STRONG&gt;Non-Security Relevant Distinguishing Features&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;&lt;STRONG&gt;Integrity Test Implemented&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;fips.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;arm-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Fips Provider for ARM appliances, 64-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;libjitterentropy.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;arm-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Entropy Source for ARM appliances, 64-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;fips.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;arm-32bit-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Fips Provider for ARM appliances, 32-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;libjitterentropy.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;arm-32bit-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Entropy Source for ARM appliances, 32-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;fips.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;x86-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Fips Provider for X86 appliances, 64-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;libjitterentropy.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;x86-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Entropy Source for X86 appliances, 64-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;fips.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;x86-32bit-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Fips Provider for X86 appliances, 32-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="151"&gt;
&lt;P&gt;libjitterentropy.so&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;x86-32bit-v1.0.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="75"&gt;
&lt;P&gt;Entropy Source for X86 appliances, 32-bit variant&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="151"&gt;
&lt;P&gt;HMAC SHA256&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Sat, 15 Aug 2026 13:38:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIPS-again-and-FedRAMP/m-p/281113#M46707</guid>
      <dc:creator>Malcolm_Levy</dc:creator>
      <dc:date>2026-08-15T13:38:27Z</dc:date>
    </item>
  </channel>
</rss>

