FIPS 140-2
U.S. government cryptographic standard

The Federal Information Processing Standard Publication 140-2, (FIPS PUB 140-2), is a U.S. government computer security standard used to approve cryptographic modules. The title is Security Requirements for Cryptographic Modules. Initial publication was on May 25, 2001, and was last updated December 3, 2002.
Its successor, FIPS 140-3, was approved on March 22, 2019, and became effective on September 22, 2019. FIPS 140-3 testing began on September 22, 2020, and the first FIPS 140-3 validation certificates were issued in December 2022. FIPS 140-2 testing was still available until September 21, 2021 (later changed for applications already in progress to April 1, 2022), creating an overlapping transition period of more than one year. FIPS 140-2 test reports that remain in the CMVP queue will still be granted validations after that date, but all FIPS 140-2 validations will be moved to the Historical List on September 21, 2026 regardless of their actual final validation date.
Purpose
The National Institute of Standards and Technology (NIST) issued the FIPS 140 Publication Series to coordinate the requirements and standards for cryptography modules that include both hardware and software components. Protection of a cryptographic module within a security system is necessary to maintain the confidentiality and integrity of the information protected by the module. This standard specifies the security requirements that will be satisfied by a cryptographic module.
The public source identifies “FIPS 140-2” as u.S. government cryptographic standard. This brief keeps that definition visible, then builds a research path around FIPS, 140-2 and government.
Why this record matters
A short description can identify a subject without explaining its stakes. For “FIPS 140-2”, the useful work is to connect “u.S. government cryptographic standard” to the records capable of establishing context and consequence.
Chronology, provenance and viewpoint should be read together before a broad social or political interpretation is accepted. The source revision retrieved here is dated Apr 24, 2026. The linked authority identifier is Q5425845. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2001, 2002, 2019 and 2020.
Later summaries often reconcile disputed chronology or motive more neatly than the contemporary record permits. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Compare institutional narratives with records created by participants and affected communities. Dates and formal titles are useful anchors, but not substitutes for context.
- Event chronology
- Institutional context
- Locating named record creators
Contemporary correspondence, government or organizational records, oral histories and cited historical scholarship.
Three-step research path
- Establish the record: confirm the title “FIPS 140-2”, its source revision and the description used here.
- Expand the search: follow FIPS 140-2 primary sources, FIPS 140-2 archive and FIPS research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “FIPS 140-2”?
- Who created the surviving record, and for what administrative purpose?
- What chronology connects this entry to wider political or social change?
Search terms from this dossier
This entry incorporates text from “FIPS 140-2” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.