New Publication: Automation of the NIST Cryptographic Module Validation Program

https://www.nist.gov/themes/custom/nist_www/img/homepage/nist_mark.png

The NIST Cryptographic Module Validation Program (CMVP) is essential for organizations required to use validated cryptography – ensuring that hardware and software cryptographic implementations meet standard security requirements. The NCCoE has published the draft NIST SP 1800-40B, Automation of the NIST Cryptographic Module Validation Program to demonstrate how structured test evidence, standardized submission protocols, and modernized computing infrastructure can streamline the submission and review process.

This publication is open for public comment through June 1, 2026.

NIST established the CMVP to ensure that hardware and software cryptographic implementations conform to specified security requirements. Since CMVP was established, the volume, complexity, and speed-to-market of cryptographic modules seeking validation have steadily increased. The rapid pace of innovation is exceeding the capacity of vendors, labs, and validation authorities to keep up with testing and validation.

The NCCoE, in collaboration with the CMVP, is demonstrating the value of automation to improve the efficiency and...

Copyright of this story solely belongs to nist.gov. To see the full text click HERE

Read more