FIPS 140-2 Expiration: September 2026 Changes
Mon - Fri: 8:00 - 17:00 PST

FIPS 140-2 Expiration Date: What Changes After September 21, 2026?

fips 140-2 transition

Is FIPS 140-2 expiring? People commonly refer to September 21, 2026, as the FIPS 140-2 expiration date. After that date, NIST will move FIPS 140-2 validation certificates from the Cryptographic Module Validation Program (CMVP) Active list to the Historical list. This change affects how organizations evaluate cryptographic modules for new systems, but it does not automatically make every existing FIPS 140-2 deployment unusable.

Although “FIPS 140-2 expiration,” “FIPS 140-2 end of life” and “sunset” are common ways to describe the approaching deadline, the official change is a transition from Active to Historical status. Procurement, engineering and compliance teams should use the remaining time to identify affected projects and review which standard each agency, program or contract requires.

Quick answer: FIPS 140-2 does not suddenly stop working on September 22, 2026. According to NIST, its validation certificates remain Active through September 21 and then move to the Historical list. Organizations may continue using Historical FIPS 140-2 modules in existing systems, subject to applicable requirements. They may use active FIPS 140-3 validations for new and existing systems.

What Does the FIPS 140-2 Expiration Date Mean?

Not in the usual product-lifecycle sense. The NIST Cryptographic Module Validation Program currently recognizes Active validations under both FIPS 140-2 and FIPS 140-3. That overlap ends after September 21, 2026, when the remaining FIPS 140-2 certificates move to the Historical list.

  • Through September 21, 2026: Organizations may still use Active FIPS 140-2 modules for new systems.
  • Beginning September 22, 2026: FIPS 140-2 validation certificates move from the Active list to the Historical list.
  • For new systems: Organizations should determine whether the applicable requirements call for an active FIPS 140-3 validated module.
  • For existing systems: NIST permits the continued use of Historical FIPS 140-2 modules, subject to the requirements of the applicable agency, program or contract.

NIST also advises agencies to continue using FIPS 140-2 modules until suitable FIPS 140-3 replacements become available. Teams should therefore treat the transition as a procurement and system-planning issue—not as a claim that all FIPS 140-2 technology suddenly becomes insecure on one date.

Why the FIPS 140-2 Sunset Date Matters Now

The practical risk is waiting until a new project reaches procurement or qualification before addressing its FIPS requirements. If a design specifies a FIPS 140-2 module that reaches Historical status before the organization acquires the system, the team may need to locate an active FIPS 140-3 alternative and repeat technical or compliance work.

Organizations with projects scheduled for late 2026 or beyond should review their approved vendor lists, bills of materials, product specifications and replacement-part strategies now. Starting early provides more time to compare interfaces, capacities and environmental requirements without turning validation status into a last-minute sourcing problem.

FIPS 140-2 Transition Guidance by Deployment Type

Deployment situationWhat to review
New system after September 21, 2026Determine whether the system requires an active FIPS 140-3 validated module.
Existing system using FIPS 140-2Applicable agency, contract and program requirements may allow organizations to continue using Historical FIPS 140-2 modules in existing systems.
Replacement component for an existing systemReview whether applicable rules treat the purchase as maintenance of the existing deployment.
Product containing a validated moduleDetermine whether the applicable requirements address the complete product or the cryptographic module contained within it.
Encrypted but non-validated productEncryption or an approved algorithm alone does not establish FIPS 140-2 or FIPS 140-3 validation.

What Is the Difference Between FIPS 140-2 and FIPS 140-3?

Both standards define security requirements for cryptographic modules used to protect sensitive information. FIPS 140-3 supersedes FIPS 140-2 and aligns the validation framework with international standards. FIPS 140-3 references ISO/IEC 19790 for security requirements and ISO/IEC 24759 for testing requirements.

The change does not simply replace one encryption algorithm with another. The standards address the design, implementation and operation of a cryptographic module across multiple security areas, including:

  • Cryptographic module specifications and interfaces
  • Roles, services and authentication
  • Software and firmware security
  • Physical security
  • Management of sensitive security parameters
  • Self-tests and lifecycle assurance
  • Mitigation of other attacks

FIPS validation applies to a defined cryptographic module rather than to a general statement that a product supports encryption.

What Does the CMVP Historical List Mean?

CMVP previously validated every module on the Historical list, but those modules no longer appear on the Active list. For the September 2026 transition, NIST states that agencies may continue using Historical FIPS 140-2 modules for existing systems.

Historical status differs from revocation. CMVP requirements no longer permit the use of a revoked module. Historical modules may remain relevant to existing deployments depending on agency, contract and program-specific rules.

What Teams Should Consider During the Transition

Organizations planning secure storage deployments around the transition should consider the following project requirements:

  • Whether the deployment is a new or existing system
  • The FIPS standard and validation status required by the agency, program or contract
  • Storage form factor and interface
  • Capacity, performance and endurance requirements
  • Commercial- or industrial-temperature operation
  • Qualification, procurement and deployment deadlines

Addressing these requirements before September 21 provides more time to compare available form factors and complete any required system qualification.

Need FIPS Storage? Contact AMP

If your project requires a FIPS 140-validated SSD, AMP can help identify and source selected configurations from our manufacturing partners. Contact us with your form factor, interface, capacity, performance, operating-temperature and delivery requirements.

FIPS 140-2 Expiration Frequently Asked Questions

Is FIPS 140-2 expiring or reaching end of life?

FIPS 140-2 is not expiring in the usual product-lifecycle sense. After September 21, 2026, its validation certificates move from the CMVP Active list to the Historical list. Historical modules may continue in existing systems, subject to applicable requirements.

Can organizations still use FIPS 140-2 modules in existing systems?

Yes. NIST permits organizations to continue using Historical FIPS 140-2 modules in existing systems. Organizations should still review the requirements of the applicable agency, program or contract.

What changes for new systems after September 21, 2026?

After September 21, 2026, the remaining FIPS 140-2 validations move to the Historical list. Organizations planning new systems should determine whether their applicable requirements call for an active FIPS 140-3 validated module.

Can AMP help source a FIPS-validated SSD?

Yes. AMP can help identify and source selected FIPS 140-validated SSD configurations from manufacturing partners based on the project’s form factor, interface, capacity, performance, operating-temperature and delivery requirements.


This article provides general information about the CMVP transition. Review the requirements of your agency, contract, compliance team and specific application before selecting or deploying a cryptographic module.

Recent Posts
Recent Posts