{"id":5946,"date":"2026-10-08T09:57:17","date_gmt":"2026-10-08T09:57:17","guid":{"rendered":"https:\/\/signmycode.com\/blog\/?p=5946"},"modified":"2026-10-08T09:57:19","modified_gmt":"2026-10-08T09:57:19","slug":"fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules","status":"publish","type":"post","link":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/","title":{"rendered":"FIPS 140 2 End of Life: Impact on HSMs and Cryptographic Modules"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The shift from the <a href=\"https:\/\/signmycode.com\/blog\/what-is-fips-detailed-guide-on-fips-140-2\/\">FIPS 140-2 standard<\/a> is significant for organizations making use of HSMs, software-based cryptographic modules, VPN equipment, secure communications, and other items depending on validated crypto.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-small-font-size wp-block-paragraph\"><strong>As of September 21, 2026<\/strong>, FIPS 140-2 validation will remain active on the CMVP list. <strong>Starting September 22, 2026<\/strong>, the remaining FIPS 140-2 validations will move to the Historical list, and FIPS 140-3 validations will become active.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That being said, it does not mean that the existing FIPS 140-2 modules will start malfunctioning or will become insecure. The transition has implications for how businesses will be appraising validated crypto devices, especially when purchasing or employing them in the new systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Does FIPS 140-2 End of Life Mean?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u201c<a href=\"https:\/\/postquantum.com\/security-pqc\/fips-140-2-sunset-what-changes\/\">FIPS 140-2 end of life<\/a>\u201d refers to the transition that occurs in September 2026, but does not signify the end of FIPS 140-2 technology.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key aspect is the CMVP validation status.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FIPS 140-2 modules will remain on the list of &#8220;CMVP Active&#8221; until September 21, 2026, and starting from September 22, 2026, the validation status is going to change to &#8220;Historical&#8221;. <a href=\"https:\/\/csrc.nist.gov\/projects\/fips-140-3-transition-effort\">NIST made<\/a> a specific note concerning the importance of the &#8220;Historical&#8221; status compared to the &#8220;revoked&#8221; status, as the former indicates that the validation has been granted and the latter means that the information cannot be qualified as valid.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why the FIPS 140-2 Sunset Date Matters Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The main problem is waiting until a new project has gone through procurement or qualification to deal with FIPS issues. If the design calls for a FIPS 140-2 module that is already in Historical status when the company takes ownership of the system, it may be necessary to find a <a href=\"https:\/\/signmycode.com\/blog\/fips-140-3-certification-and-levels-fips-140-2-vs-140-3\/\">FIPS 140-3<\/a> alternative and redo the necessary work for compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies with initiatives that will kick off in late 2026 or later should be reviewing their lists of approved vendors, bills of materials, product specifications, and replacement strategies now. Starting now allows for more time to match interfaces, capabilities, and environmental specifications and avoid having the validation status become an urgent sourcing problem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Happens to a FIPS 140-2 Module After It Becomes Historical?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As soon as a FIPS 140-2 validation is moved to the Historical list, its status in the CMVP database gets altered. <strong>However, this doesn&#8217;t imply that the following has happened:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The <a href=\"https:\/\/signmycode.com\/blog\/what-is-a-hardware-security-module-role-of-hsms-for-digital-signing\/\">HSM<\/a> stops working.<\/li>\n\n\n\n<li>Available encryption keys go void automatically.<\/li>\n\n\n\n<li>Available certificates expire right away.<\/li>\n\n\n\n<li>Algorithms like AES become less secure all of a sudden.<\/li>\n\n\n\n<li>The organization has to detach the module.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, it is the responsibility of the organization to check the possibility of using the module based on specific requirements applicable to this system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the existing module is already used, the entity has a right to continue the module operation but consider planning its move to the corresponding FIPS 140-3 validated option whenever needed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>FIPS 140-2 Transition Guidance by Deployment Type<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The consequences of the FIPS 140-2 transition depend on whether the module is applied in a new, existing, or replacement system. The table below explains what organizations need to check according to each possible case.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Deployment Situation<\/strong><\/td><td><strong>What to Review<\/strong><\/td><\/tr><tr><td><strong>New system after September 21, 2026<\/strong><\/td><td>It is strictly prohibited to incorporate Historical FIPS 140-2 modules into new systems. Where FIPS is required, applicable Active FIPS 140-3 validated modules should be utilized.<\/td><\/tr><tr><td><strong>Existing system using FIPS 140-2<\/strong><\/td><td>Certain agency, program, and contract requirements may permit organizations to use Historical FIPS 140-2 modules in their existing systems.<\/td><\/tr><tr><td><strong>Replacement component for an existing system<\/strong><\/td><td>Make sure that applicable classification regimes classify the acquisition as maintenance of existing implementations.<\/td><\/tr><tr><td><strong>Product containing a validated module<\/strong><\/td><td>Make sure the appropriate requirements concern the whole product or the encryption module inside it.<\/td><\/tr><tr><td><strong>Encrypted but non-validated product<\/strong><\/td><td>Encryption and the use of an accepted algorithm are insufficient to achieve compliance with FIPS 140-2 or FIPS 140-3.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Difference Between FIPS 140-2 and FIPS 140-3<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">FIPS 140-3 replaces FIPS 140-2 with updated cryptographic module requirements and testing. The table below highlights the key differences between the two standards.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Aspect<\/strong><\/td><td><strong>FIPS 140-2<\/strong><\/td><td><strong>FIPS 140-3<\/strong><\/td><\/tr><tr><td><strong>Status<\/strong><\/td><td>Superseded by FIPS 140-3<\/td><td>Current successor to FIPS 140-2<\/td><\/tr><tr><td><strong>Published<\/strong><\/td><td>2001<\/td><td>2019<\/td><\/tr><tr><td><strong>Effective Date<\/strong><\/td><td>May 25, 2002<\/td><td>September 22, 2019<\/td><\/tr><tr><td><strong>Validation Program<\/strong><\/td><td>Cryptographic Module Validation Program (CMVP)<\/td><td>Cryptographic Module Validation Program (CMVP)<\/td><\/tr><tr><td><strong>Primary Standard Basis<\/strong><\/td><td>FIPS 140-2 requirements<\/td><td>Based on ISO\/IEC 19790 with testing aligned to ISO\/IEC 24759<\/td><\/tr><tr><td><strong>Security Levels<\/strong><\/td><td>Four security levels: 1\u20134<\/td><td>Four security levels: 1\u20134<\/td><\/tr><tr><td><strong>Cryptographic Module Requirements<\/strong><\/td><td>Defines security requirements for cryptographic modules<\/td><td>Updates and modernizes requirements for cryptographic modules<\/td><\/tr><tr><td><strong>Physical Security<\/strong><\/td><td>Requirements for physical protection based on the module&#8217;s security level<\/td><td>Updated physical-security requirements aligned with the newer framework<\/td><\/tr><tr><td><strong>Non-Invasive Attack Mitigation<\/strong><\/td><td>More limited requirements<\/td><td>Provides updated requirements for mitigation of non-invasive attacks, including applicable side-channel protections<\/td><\/tr><tr><td><strong>Entropy Requirements<\/strong><\/td><td>Entropy requirements were less comprehensive<\/td><td>Places greater emphasis on entropy sources and their documentation and validation<\/td><\/tr><tr><td><strong>Software\/Firmware Security<\/strong><\/td><td>Defines requirements for software and firmware components<\/td><td>Updates software and firmware security requirements and testing<\/td><\/tr><tr><td><strong>Sensitive Security Parameters<\/strong><\/td><td>Defines requirements for management and protection<\/td><td>Provides updated requirements for sensitive security parameter management<\/td><\/tr><tr><td><strong>Testing Requirements<\/strong><\/td><td>FIPS 140-2 testing framework<\/td><td>Testing requirements are aligned with ISO\/IEC 24759<\/td><\/tr><tr><td><strong>International Alignment<\/strong><\/td><td>Primarily U.S. federal standard<\/td><td>Greater alignment with international cryptographic-module standards<\/td><\/tr><tr><td><strong>Current CMVP Status<\/strong><\/td><td>FIPS 140-2 validations moved to the Historical list beginning September 22, 2026<\/td><td>Applicable FIPS 140-3 validations remain on the CMVP Active list<\/td><\/tr><tr><td><strong>New Federal Procurements<\/strong><\/td><td>Historical modules should not be included where the applicable requirements require an active validation<\/td><td>Active FIPS 140-3 validation can be used where FIPS validation is required<\/td><\/tr><tr><td><strong>Existing Deployments<\/strong><\/td><td>Historical modules may continue to be used depending on applicable requirements<\/td><td>Active validation provides the current validation path<\/td><\/tr><tr><td><strong>Impact on HSMs<\/strong><\/td><td>Existing FIPS 140-2 HSMs may require migration planning<\/td><td>New HSM procurements can evaluate applicable Active FIPS 140-3 validated modules<\/td><\/tr><tr><td><strong>Overall Direction<\/strong><\/td><td>Legacy validation standard<\/td><td>Current validation framework for cryptographic modules<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>FIPS 140-2 to FIPS 140-3 Migration Checklist<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations can use the following checklist to prepare their cryptographic infrastructure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inventory all HSMs and cryptographic modules.<\/li>\n\n\n\n<li>Record each CMVP certificate number.<\/li>\n\n\n\n<li>Check whether each certificate is Active, Historical or Revoked.<\/li>\n\n\n\n<li>Verify the exact validated module version.<\/li>\n\n\n\n<li>Document the validated operating environment.<\/li>\n\n\n\n<li>Identify systems using FIPS 140-2 modules.<\/li>\n\n\n\n<li>Separate existing deployments from new projects.<\/li>\n\n\n\n<li>Review agency, regulatory and contractual requirements.<\/li>\n\n\n\n<li>Identify FIPS 140-3 replacement options.<\/li>\n\n\n\n<li>Test application compatibility.<\/li>\n\n\n\n<li>Plan cryptographic-key migration.<\/li>\n\n\n\n<li>Update procurement requirements.<\/li>\n\n\n\n<li>Document the migration roadmap.<\/li>\n\n\n\n<li>Maintain evidence for audits and assessments.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Impact on Existing HSM Deployments<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The transition <strong>does not automatically require<\/strong> every existing FIPS 140-2 HSM to be removed or replaced on September 22, 2026.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">For existing systems, organizations should review:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The CMVP status of the HSM&#8217;s cryptographic module.<\/li>\n\n\n\n<li>The exact module version and configuration.<\/li>\n\n\n\n<li>The applicable agency or regulatory requirements.<\/li>\n\n\n\n<li>Contractual requirements.<\/li>\n\n\n\n<li>Internal security policies.<\/li>\n\n\n\n<li>Whether the system is considered an existing deployment or a new system.<\/li>\n\n\n\n<li>Whether the vendor provides a FIPS 140-3 validated replacement.<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote has-normal-font-size is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-small-font-size wp-block-paragraph\"><strong>According to NIST recommendations<\/strong>, federal entities could still utilize FIPS 140-2 modules that fall under the historical category in existing systems. Thus, organizations should not act as if this transition will require them to &#8220;<strong>swap out every single HSM straight away<\/strong>&#8220;. On the contrary, this should be a part of a well-organized process of changing the cryptographic infrastructure.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Impact on New HSM Procurements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The situation differs for the case of a new acquisition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When FIPS validation is necessary, it is far better to choose a valid FIPS 140-3 module than a module that has a status of historical <a href=\"https:\/\/signmycode.com\/blog\/fips-140-2-validation-vs-compliance\/\">FIPS 140-2 validation<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For instance, organizations trying to implement a new PKI system should not consider an HSM only because \u201c<strong>it has a FIPS 140-2 certification<\/strong>\u201d written in its product description.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Procurement Team should verify:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CMVP certificate number<\/li>\n\n\n\n<li>FIPS version<\/li>\n\n\n\n<li>Validation status<\/li>\n\n\n\n<li>Module version<\/li>\n\n\n\n<li>Approved operating environment<\/li>\n\n\n\n<li>Security level<\/li>\n\n\n\n<li>Validated algorithms<\/li>\n\n\n\n<li>Validated configurations<\/li>\n\n\n\n<li>Vendor lifecycle\/support status<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A product may have multiple models or <a href=\"https:\/\/signmycode.com\/blog\/what-is-firmware-signing-best-practices-for-firmware-signing-and-security\/\">firmware<\/a> versions, and not every version is necessarily covered by the same validation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>HSM Migration: What Organizations Should Check<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations with existing HSM infrastructure should begin with an inventory.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Identify Every Cryptographic Module<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations are advised to start by compiling a full inventory of their hardware security modules (HSMs) and other crypto modules that are present throughout their system. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The inventory should comprise not only hardware HSMs but also software crypto modules, cloud crypto services that are used, and modules that have been embedded into security appliances or software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For each of the modules, the information that should be recorded includes product name, product manufacturer, product model, version of software or firmware, CMVP certificate number, FIPS version, level of security, installation location, operating environment, and name of the owner. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended:<\/strong> <a href=\"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures\/\">NIST Announces Third Round Candidates for Post-Quantum Digital Signatures<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Having a detailed inventory helps organizations identify whether they still use FIPS 140-2 modules or whether any of the modules have a valid FIPS 140-3 approval.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Check the CMVP Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Having compiled the inventory, the organization must authenticate each cryptographic module with the <strong><a href=\"https:\/\/www.nist.gov\/programs-projects\/cryptographic-module-validation-program-cmvp\">NIST Cryptographic Module Validation Program (CMVP)<\/a><\/strong>. Never depend simply on any vendor\u2019s assertion that a product is \u201c<strong>FIPS certified<\/strong>\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organization must validate the exact certificate number, status of the validity, version of the module, configuration validated, operating environment, and the security level that is applicable. By doing so, it can establish the status of the module as being Active, Historical, or Revoked, with verification of this version\u2019s correspondence with that covered by the certificate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Separate Existing and New Deployments<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations must differentiate between cryptographic modules that have been used in existing systems and those that will be used in the future. A <strong>Historical FIPS 140-2 module can continue to be put to use in the existing system<\/strong>, depending on whether the pertinent agency or relevant contract, regulation, or program permits it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In any new system for which FIPS validation is required, organizations ought to investigate an Active FIPS 140-3 validated option rather than continue using a Historical FIPS 140-2 module.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended:<\/strong> <a href=\"https:\/\/signmycode.com\/blog\/fips-140-2-encryption-for-mobile-app-security\/\">FIPS 140-2 Encryption for Mobile App Security<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Identify FIPS 140-3 Alternatives<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For each FIPS 140-2 module that has finally been classified as having \u201cHistorical\u201d status, organizations should look for an appropriate FIPS 140-3 substitute.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The alternative does not just have to be picked according to the FIPS validation status.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations should also look for differences in security level, algorithms provided, interfaces, cryptographic performance, key capacity, firmware specifications, availability features, cloud integration, and support for device lifecycle.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Plan Key Migration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to substituting an HSM, an appropriate strategy is vital in relation to the cryptographic keys that are processed or protected by the HSM. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Various issues related to key generation, storage, recovery, rotation, migration, encapsulation, and destruction should be resolved in a transition plan.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote has-normal-font-size is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-small-font-size wp-block-paragraph\">The transition plan should also define entities and applications dependent on specific keys, such as certificate authorities, TLS infrastructure, code-signing systems, databases, payment systems, and other cryptographic usage. Key transitions should be performed with due diligence to ensure the absence of any interruptions and critical loss.<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">Review the Operating Environment<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It is essential to check whether the HSM or cryptographic element runs in the mode specified in its CMVP certificate. The verified module may have its own demands in terms of the firmware version, software version, operating systems used, hardware installations, and mode regulations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Updating the firmware or changing the environment can lead to the fact that the solution does not match the validated mode any longer. Thus, teams need to get acquainted with the requirements stated in the certificate relative to its security policy and configuration before they make any serious changes in the infrastructure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Evaluate Application Compatibility<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before transitioning to a new HSM, it is essential for businesses to determine if their applications will be able to connect with the new system in question. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means checking out the APIs, PKCS #11 API, vendor SDKs, protocols used for <a href=\"https:\/\/signmycode.com\/blog\/best-practices-for-cryptographic-key-management-to-avoid-failures\/\">key and certificate management<\/a>, mechanisms to authenticate users, and configurations for providing high availability of services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The process of testing compatibility should happen in a controlled environment prior to the organization migrating to production to ensure there are no unexpected downtimes in the usage of applications that rely on the older HSM device.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Review Compliance and Contractual Requirements<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations should examine relevant requirements to determine if there are any requirements that actually require them to use FIPS-validated cryptography. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These requirements may be stated in federal regulations, requirements established by contracts, requirements stated in regulatory compliance frameworks, customer agreements, or internal security policies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is not always the case that the validation of an organization&#8217;s FIPS 140-2 module has changed results in a requirement to replace the device. The actual need for the replacement will depend on the governing layer of requirements and the purpose of usage of the particular module.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Create a Migration Roadmap<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, organizations should create a documented migration roadmap for HSMs and other cryptographic modules that have moved to the Historical list. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The roadmap should identify the affected systems, module owners, replacement candidates, testing requirements, key-migration activities, target dates, dependencies, and rollback procedures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A structured roadmap allows organizations to prioritize critical infrastructure and migrate in phases rather than treating the FIPS 140-2 transition as an immediate, organization-wide hardware replacement exercise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>What Should Organizations Do Now?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The FIPS 140-2 transition must be viewed as an ongoing procedure in terms of managing cryptographic infrastructure and not just as an event where some products are replaced after a day.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first step for organizations is to manage their knowledge regarding what kind of cryptographic assets they have and which modules have been moved to the Historical list; moreover, it is important to define whether the given Historical module is part of an old system or it belongs to a new one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In case of existing systems, the organization should study the regulatory and law-enforcement requirements and create a migration plan. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the case with the new systems where the necessity for using FIPS modules is present, the organization should prioritize the purchase of those HSMs that are validated according to the FIPS 140-3 standard.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended:<\/strong> <a href=\"https:\/\/signmycode.com\/blog\/what-is-a-cloud-hardware-security-module-right-cloud-hsm-for-code-signing\/\">What is a Cloud Hardware Security Module?<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With regard to the HSM environment, the migration task should start much earlier than the HSM equipment fails. The task may be challenging because the organization must consider such factors as the migration process, compatibility of applications, availability of systems, backup process, and the process of disaster recovery.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">FIPS 140-2 transition is considered to be a major development for companies using HSMs and other encryption modules. Even though already installed FIPS 140-2 may be used depending on the requirements, those companies planning to implement a new system should check the CMVP status and choose an appropriate active FIPS 140-3 validated solution.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The shift from the FIPS 140-2 standard is significant for organizations making use of HSMs, software-based cryptographic modules, VPN equipment, secure communications, and other items depending on validated crypto. As of September 21, 2026, FIPS 140-2 validation will remain active on the CMVP list. Starting September 22, 2026, the remaining FIPS 140-2 validations will move&hellip; <a class=\"more-link\" href=\"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/\">Read More <span class=\"screen-reader-text\">FIPS 140 2 End of Life: Impact on HSMs and Cryptographic Modules<\/span><\/a> <\/p>\n","protected":false},"author":1,"featured_media":5948,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[458,457],"tags":[966,970,967,969,968],"class_list":["post-5946","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","category-developers-guide","tag-fips-140-2-end-of-life","tag-fips-140-2-historical-status-2026","tag-fips-140-2-retirement","tag-fips-140-2-sunset","tag-fips-140-3-transition","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FIPS 140-2 Sunset Sep 2026: Navigating the Shift to FIPS 140-3<\/title>\n<meta name=\"description\" content=\"FIPS 140-2 retirement affects HSMs, cryptographic modules, and compliance strategies. Learn what organizations need to know about the transition.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FIPS 140-2 Sunset Sep 2026: Navigating the Shift to FIPS 140-3\" \/>\n<meta property=\"og:description\" content=\"FIPS 140-2 retirement affects HSMs, cryptographic modules, and compliance strategies. Learn what organizations need to know about the transition.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/\" \/>\n<meta property=\"og:site_name\" content=\"SignMyCode - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-08T09:57:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-08T09:57:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/10\/fips-140-2-end-of-life.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"912\" \/>\n\t<meta property=\"og:image:height\" content=\"453\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/10\/fips-140-2-end-of-life.webp\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/\",\"name\":\"FIPS 140-2 Sunset Sep 2026: Navigating the Shift to FIPS 140-3\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/fips-140-2-end-of-life.webp\",\"datePublished\":\"2026-10-08T09:57:17+00:00\",\"dateModified\":\"2026-10-08T09:57:19+00:00\",\"description\":\"FIPS 140-2 retirement affects HSMs, cryptographic modules, and compliance strategies. Learn what organizations need to know about the transition.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/#primaryimage\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/fips-140-2-end-of-life.webp\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/fips-140-2-end-of-life.webp\",\"width\":912,\"height\":453,\"caption\":\"FIPS 140-2 Retirement and FIPS 140-3 Migration\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FIPS 140 2 End of Life: Impact on HSMs and Cryptographic Modules\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"name\":\"SignMyCode - Blog\",\"description\":\"Code Signing News, Updates\",\"publisher\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\",\"name\":\"SignMyCode.com\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"width\":135,\"height\":86,\"caption\":\"SignMyCode.com\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FIPS 140-2 Sunset Sep 2026: Navigating the Shift to FIPS 140-3","description":"FIPS 140-2 retirement affects HSMs, cryptographic modules, and compliance strategies. Learn what organizations need to know about the transition.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/","og_locale":"en_US","og_type":"article","og_title":"FIPS 140-2 Sunset Sep 2026: Navigating the Shift to FIPS 140-3","og_description":"FIPS 140-2 retirement affects HSMs, cryptographic modules, and compliance strategies. Learn what organizations need to know about the transition.","og_url":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/","og_site_name":"SignMyCode - Blog","article_published_time":"2026-10-08T09:57:17+00:00","article_modified_time":"2026-10-08T09:57:19+00:00","og_image":[{"width":912,"height":453,"url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/10\/fips-140-2-end-of-life.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_image":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/10\/fips-140-2-end-of-life.webp","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/","url":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/","name":"FIPS 140-2 Sunset Sep 2026: Navigating the Shift to FIPS 140-3","isPartOf":{"@id":"https:\/\/signmycode.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/#primaryimage"},"image":{"@id":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/#primaryimage"},"thumbnailUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/10\/fips-140-2-end-of-life.webp","datePublished":"2026-10-08T09:57:17+00:00","dateModified":"2026-10-08T09:57:19+00:00","description":"FIPS 140-2 retirement affects HSMs, cryptographic modules, and compliance strategies. Learn what organizations need to know about the transition.","breadcrumb":{"@id":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/#primaryimage","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/10\/fips-140-2-end-of-life.webp","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/10\/fips-140-2-end-of-life.webp","width":912,"height":453,"caption":"FIPS 140-2 Retirement and FIPS 140-3 Migration"},{"@type":"BreadcrumbList","@id":"https:\/\/signmycode.com\/blog\/fips-140-2-end-of-life-impact-on-hsms-and-cryptographic-modules\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/signmycode.com\/blog\/"},{"@type":"ListItem","position":2,"name":"FIPS 140 2 End of Life: Impact on HSMs and Cryptographic Modules"}]},{"@type":"WebSite","@id":"https:\/\/signmycode.com\/blog\/#website","url":"https:\/\/signmycode.com\/blog\/","name":"SignMyCode - Blog","description":"Code Signing News, Updates","publisher":{"@id":"https:\/\/signmycode.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/signmycode.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/signmycode.com\/blog\/#organization","name":"SignMyCode.com","url":"https:\/\/signmycode.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","width":135,"height":86,"caption":"SignMyCode.com"},"image":{"@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5946","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/comments?post=5946"}],"version-history":[{"count":4,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5946\/revisions"}],"predecessor-version":[{"id":5952,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5946\/revisions\/5952"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media\/5948"}],"wp:attachment":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media?parent=5946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/categories?post=5946"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/tags?post=5946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}