FIPS 140-2 FAQ

    What is FIPS 140-2?

    FIPS 140-2 is a Federal Information Processing Standard that spells out the cryptographic requirements for products used in the Federal Government.

    How much does a FIPS 140-2 Validation Cost?

    The cost associated with a FIPS 140-2 validation can vary depending on the following variables:

    • The type of Cryptographic module – Software, Hardware, Firmware, or Hybrid
    • The overall Security Level of the Cryptographic Module – 1, 2, 3, or 4

    Additionally, the cost of the NIST recovery can vary depending on the Security Level:

    • Level 1 – $2750
    • Level 2 – $3750
    • Level 3 – $5250
    • Level 4 – $7250

    Typically, a revalidation can cost less then a new module that has not been FIPS 140-2 validated before.

    For additional information regarding costs, please use our contact form or call our FIPS 140-2 Laboratory at (301) 498-0150.

    How long does FIPS 140-2 Testing Take?

    Obtaining a FIPS 140-2 Certification can take up to eight (8) months once all required documentation has been developed and submitted to the lab for review. If we feel that your product is not yet ready for validation testing, we will help you determine what the appropriate steps are to prepare for validation testing. FIPS 140-2 Validation Phases:

    • Module Testing
      • Documentation Review
      • Cryptographic Algorithm Testing through CAVP
      • Functional and Physical Testing (if applicable)
      • Source Code Review
    • Report Submission and CMVP Review
    • Coordination between CMVP and COACT
    • Certificate Finalization

    Click here for a list of COACT FIPS Services