FIPS 140-3 validates a cryptographic module — a defined boundary containing approved algorithms, key management and self-tests — against ISO/IEC 19790 requirements, tested by an accredited lab and validated by the CMVP. Four security levels grade the demands, from correct algorithm implementation at Level 1 to tamper-responsive hardware with environmental protections at Levels 3–4. The certificate lists precisely what was validated: module version, operational environments, approved modes. Step outside any of them and you are, formally, no longer FIPS-validated.
The programme’s practical reality is the queue. CMVP review times have historically stretched to many months beyond lab testing, which makes validation timing a product-roadmap decision, not a compliance afterthought. The September 2026 move of FIPS 140-2 certificates to the historical list sharpens this: procurement frameworks that require an active validation will stop accepting 140-2-validated modules, and vendors who did not re-validate under 140-3 inherit the full queue at its most congested.
For European vendors, FIPS is rarely the whole answer but often a required ingredient: it validates the crypto boundary, while CC/EUCC, SESIP or scheme-specific evaluations cover the surrounding product security. The efficient strategies design one module boundary and one set of evidence that feeds both worlds.