MSSP, Governance, Risk and Compliance

The FIPS 140-2 deadline is coming. MSSPs need to find the hidden crypto gaps

COMMENTARY: The FIPS 140-2 retirement will give MSSPs a clear opportunity to move beyond compliance reminders and help clients understand where the real exposure sits. The risk is not usually the obvious HSM or security appliance. It is the older cryptographic libraries, authentication tools, and embedded modules buried inside systems that no one has reviewed in years. Clients need certificate-level visibility, not vendor assurances or product roadmaps. MSSPs that can inventory those modules, verify their status, and build a practical transition plan will turn a looming procurement problem into a valuable advisory service.


On 21 September 2026, every FIPS 140-2 certificate moves to Historical status. Modules already in place keep running, but a Historical certificate can no longer be cited to satisfy a validated-cryptography requirement in a new procurement. For any client operating under FedRAMP, HIPAA, PCI DSS, DFARS, or an equivalent regime, that turns a quiet compliance line into a live sourcing problem. MSSPs are the ones who will be asked what to replace, and by when.

SITG-Consulting reviewed FIPS 140-3 validation activity across non-hyperscaler, non-tier-1 vendors for the first half of 2026, with every certificate number, level, and date cross-referenced against the NIST Cryptographic Module Validation Program. Thirty new 140-3 certificates were issued or announced in the period across five categories. The point for anyone advising clients is not the volume. It is that readiness is uneven by category, and a blanket "our vendors are handling it" is not a defensible answer.

Readiness is uneven by category

Hardware security module vendors have largely completed their Level 3 transitions. Utimaco's u.trust Anchor (cert #5223) and Yubico's YubiHSM 2 (#5302) both validated at Level 3 in the first half. Authentication is more mixed, spanning Level 2 to 3: Yubico's YubiKey 5 FIPS Series (#5291) at Overall Level 2, HID Global applets (#5330) at Level 2, FEITIAN's ePass token (#5151) at Level 3.

Cryptographic libraries, edge/IoT, and embedded modules are the fragmented tail. They typically validate at Level 1, which is appropriate to the module type and not a quality gap, but coverage is patchy, and the timing runs late. The largest single group, seventeen of the thirty certificates, is software libraries, and edge/IoT modules were still landing certificates in July, weeks before the deadline.

The practical consequence is straightforward. A client's HSM estate is probably in good shape. The authentication tokens, the crypto libraries baked into appliances, and the embedded modules in edge and IoT devices are where gaps and last-minute vendor scrambles will concentrate. That is exactly the layer clients are least likely to have inventoried.

What to tell clients now, less than two months out

Inventory by certificate, not by vendor. Map every module in use to its actual CMVP status, 140-2 versus 140-3. Status is certificate-by-certificate: a vendor with an active 140-3 certificate for one product may still ship a legacy 140-2 module in another.

Prioritize remediation by data sensitivity. Modules protecting regulated data, federal systems, and critical infrastructure move to the front. Not everything has to be solved by 21 September, but these do.

Engage vendors with active 140-3 certificates, not pending ones. A submission in process is not a certificate. Where a vendor offers only a roadmap, treat it as a supply risk and line up alternatives.

Build 140-3 into procurement. Put validated-module requirements into RFPs and vendor evaluation criteria, and ask for signed letters that reference specific CMVP certificate numbers. Verify each one at csrc.nist.gov. It is a two-minute check that removes a whole class of disputes later.

Put post-quantum on the same roadmap. 140-3 and PQC are converging. One first-half validation, EnQuanta's QuantaCrypt (#5312), is a software module carrying the NIST post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) and aligned to CNSA 2.0. Clients replacing modules this year should favour crypto-agile vendors, so they are not repeating the exercise for the 2030 PQC transition.

The framing that matters

The deadline rewards treating validation as a supply-chain decision, not a compliance checkbox. Vendors that validated in 2026 are signalling long-term commitment to regulated markets. The ones still pointing at a roadmap are telling you something, too. For MSSPs, the value on offer over the next two months is not the reminder that a deadline exists. It is doing the certificate-level inventory and vendor triage that clients cannot easily do for themselves, and turning 21 September from an exposure into a documented, defensible transition.


MSSP Alert Perspectives columns are written by trusted members of the managed security services, value-added reseller and solution provider channels or MSSP Alert's staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].

Brian Couzens

Brian Couzens is the Founder and CEO of SITG-Consulting.

You can skip this ad in 5 seconds