What is FIPS 140

FIPS 140, which is the United States government standard developed by NIST for securing cryptographic modules. The standard focuses on the security requirements for the hardware and software that implement cryptographic functions, defining four hierarchical security levels ranging from basic software integrity (Level 1) to active tamper-detection designed for high-risk physical environments (Level 4). Crucially, the text details the evolution of the standard, noting that the prevalent FIPS 140-2 is actively sunsetting and being replaced by the current FIPS 140-3, which is significant because it harmonizes the standard with international ISO/IEC requirements to create a unified global marketplace. Finally, the source outlines the rigorous validation process, where third-party laboratories test modules before they receive a certificate from the CMVP program.