Warning: The magic method WPML_Absolute_Url_Persisted::__wakeup() must have public visibility in /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php on line 30

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893
{"id":15137,"date":"2018-07-09T10:41:24","date_gmt":"2018-07-09T14:41:24","guid":{"rendered":"https:\/\/www.corsec.com\/?p=15137"},"modified":"2025-01-20T16:52:22","modified_gmt":"2025-01-20T21:52:22","slug":"fipsinside","status":"publish","type":"post","link":"https:\/\/www.corsec.com\/fipsinside\/","title":{"rendered":"FIPS Inside & FIPS Compliant: A Resource Guide"},"content":{"rendered":"

[vc_row][vc_column width=”1\/2″][vc_column_text]<\/p>\n

Implementing a FIPS 140-2<\/a> \/ FIPS 140-3<\/a>\u00a0<\/span>validation into your product is a great way to strengthen your solution, enhance your brand, and secure your bottom line. When pursuing FIPS, you will be faced with difficult and often confusing decisions; leaving you with many questions. One such question we are always asked is the difference between being FIPS Validated and FIPS Compliant (sometimes referred to as FIPS Inside). This is a critical question as there is a substantial difference between having your product achieve FIPS 140 validation and claiming your product is FIPS 140 compliant. To help, Corsec has developed a quick reference guide below as well as a FIPS Inside Whitepaper to explore this topic further:<\/p>\n

[\/vc_column_text][vc_row_inner][vc_column_inner][\/vc_column_inner][\/vc_row_inner][\/vc_column][vc_column width=”1\/2″][vc_single_image image=”21101″ img_size=”medium” alignment=”center” css=”.vc_custom_1737409903946{margin-bottom: 20px !important;}”][vc_btn title=”Download PDF” style=”outline” color=”success” size=”sm” align=”center” css=”” link=”url:https%3A%2F%2Fww3.corsec.com%2FFIPS-Validated-vs-Inside|title:FIPS%20Inside%20Whitepaper|target:_blank”][\/vc_column][\/vc_row][vc_row][vc_column][vc_separator color=”green”][vc_column_text]<\/p>\n

\n
\n
\n
\n
\n
\n
What is FIPS Inside \/ FIPS Compliant:<\/strong><\/span><\/h5>\n

\u201cFIPS Compliant\u201d or “FIPS-Inside” is a self-designated term, often used in reference to a device or appliance that employs a FIPS-validated subcomponent to provide its cryptographic services. Unfortunately, these solutions have absolutely no government backing. Vendors use this term in reference to products that uses FIPS-Approved algorithms or libraries, but have not actually gone through the necessary steps to verify and test that the product is using them in a FIPS-Approved manner.<\/p>\n

It does not hold any weight nor can it claim a completed FIPS 140 Validation. As an example, a company may incorporate another company\u2019s cryptographic module which went through the FIPS validation process for itself. Although the cryptographic module that was dropped into the product has gone through validation, the overall product still has not yet been validated; leaving concern and speculation over the product’s security.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n

[\/vc_column_text][vc_column_text]<\/p>\n

\n
\n
\n
\n
\n
\n
What is FIPS Validated:<\/strong><\/span><\/h5>\n

\u201cFIPS-validated\u201d asserts that your specific solution has gone through the rigor of the entire FIPS 140 process, resulting in the award of a certificate of your own issued by NIST. Further, this means that your product has been tested by an independent third-party laboratory and will meet the legal requirements passed by Congress, as well as the procurement requirements for the U.S. government and other industries, including: healthcare, financial services, and critical infrastructure.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n

[\/vc_column_text][vc_column_text]<\/p>\n

\n
\n
\n
\n
\n
\n
Is FIPS Compliant Right For Me:<\/strong><\/span><\/h5>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n
\n
\n
\n
\n
\n

Maybe. The FIPS Compliant approach is very convenient, and can, in fact, be a viable option in certain situations. The optimal scenario is that the vendor of the device also controls the targeted subcomponent. However, when relying on a third-party\u2019s software solution, this path also comes with its share of very real pitfalls:<\/p>\n