Q: Will FedRAMP provide guidance on the sunsetting of FIPS 140-2? What do I do if our planned 140-3 Module is not yet approved.
A: Short Answer: We acknowledge the backlog for CMVP approval, but this is a NIST process and issues. If you are required to leverage a CMVP validated crypto module and your planned module is in process, either transition to the in process Module early and track this as a risk/vulnerability, or don't transition and track the use of a historical module as a risk/vulnerability.
Long Answer: All FIPS 140-2 will be set to historical on 21 September 2026. There is a big 140-3 backlog awaiting certification. As of Jul 2026, there are 285 Modules in active review and 234 in Laboratory testing. This means there are 521 Modules within a FIPS 140-3 testing pipeline and only 614 vendors who have achieved full FIPS 140-3 Certification. All that to be said if this is more of a process issue then a certification issue. CSPs who have modules that face moving into historical status while their 140-3 counterpart s not approved have three options.
- Transition to an approved 140-3 Module, leveraging your Significant Change processes.
- Stay on the historical legacy FIPs Module until the 140-3 version is available. This carries risk and should be tracked as an open vulnerability
- Transition early to the 140-3 compliant version before it completes certification. This carries risk and should be tracked as an open vulnerability.
All of these options carry different risks and technical complexity. It is your job as the CSP to manage those risks. FedRAMP cannot and will not help you make a decision here.