Overview
FIPS 140-3 (Federal Information Processing Standard 140-3) is a cryptographic module validation standard published by NIST (National Institute of Standards and Technology). It certifies that a software module’s cryptographic implementations — encryption algorithms, key generation, hashing, and random number generation — meet federal security requirements for protecting sensitive information. FIPS 140-3 is the current version of the standard, superseding FIPS 140-2. The Maverics Orchestrator will offer FIPS-compliant builds that use a FIPS 140-3 validated cryptographic module, ensuring that all cryptographic operations meet federal standards.Current Status
The cryptographic module used by the Maverics Orchestrator is currently under review by NIST CMVP for FIPS 140-3 validation. FIPS-compliant builds are expected to be available in 2026.Who Needs FIPS 140-3
FIPS 140-3 compliant cryptography is typically required by:- Federal and government agencies — Required by FISMA (Federal Information Security Modernization Act) for all federal information systems
- Defense contractors — Organizations handling classified or sensitive government data under contracts that mandate FIPS-validated cryptographic modules
- Healthcare organizations — Those handling CUI (Controlled Unclassified Information) under NIST SP 800-171 requirements
- Financial institutions — Organizations with specific regulatory requirements mandating FIPS-validated cryptography for data protection