In 140-2 a vendor affirmation was allowed under Implementation Guidance G.5. In our case our appliances are GPC. Implementation Guidance for FIPS 140-2
FIPS 140-3 Management Manual similarly says the following that allows a vendor affirmation to porting to another appliance: FIPS-140-3-CMVP Management Manual.pdf
7.9.1 Vendor 2554
1. A vendor may perform post-validation recompilations of a software, firmware, or hybrid 2555
module and affirm the modules continued validation compliance. By adding vendor support 2556
of non-tested configurations to the validated module security policy, the vendor bears all 2557
responsibility. These non-tested configurations versions may be considered by the user at 2558
their risk, provided the following is maintained: 2559
a) Software modules do not require any source code modifications (e.g., changes, additions, 2560
or deletions of code) to be recompiled and ported to another OE and must: 2561
i) For Level 1 OE, a software cryptographic module can be considered compliant with 2562
the FIPS 140-3 validation when operating on any general-purpose platform/processor 2563
that supports the specified operating system as listed on the validation entry or 2564
another compatible4 operating system, or 2565
ii) For Level 2 OE, a software cryptographic module can be considered compliant with 2566
the FIPS 140-3 validation when operating on any general-purpose platform/processor 2567
that supports the same level 2 operational environment settings specified on the 2568
validation entry. 2569
b) Firmware modules do not require any source code modifications (e.g., changes, additions, 2570
or deletions of code) to be recompiled, and its identified unchanged tested operating 2571
system (i.e., same version or revision number) may be ported together from one platform 2572
to another platform while maintaining the module’s validation. 2573
Level 2 and above Firmware modules cannot be ported and maintain their validation, 2574
since Physical Security must be retested.
Section 7.9 of the FIPS Cryptographic Module Validation Program (CMVP) Management Manual covers Vendor or User Affirmation of Modules. This section
details the conditions under which a vendor or system user can formally affirm that a validated software or firmware cryptographic module will operate correctly and maintain compliance when ported or used in an operational environment (OE) similar to, but not explicitly tested during, the original lab validation.
[1, 2]