A validation deadline with a long shadow
On 21 September 2026, NIST's Cryptographic Module Validation Program moves all remaining FIPS 140-2 validated certificates to the Historical list. From that point, only FIPS 140-3 validated implementations are accepted for new US federal procurement.
For vendors selling into the US federal market, this is a hard commercial date and the work has been in progress for years. For everyone else, it is easy to read as somebody else's problem.
It is worth a second look, because the sunset is a useful prompt for a question most enterprises cannot currently answer: which cryptographic primitives do your compliance evidence and integrity records actually depend on, and what happens to those records when a primitive is deprecated?
Evidence has a longer life than the cryptography that protects it
This is the structural problem, and it is unusual because it runs the opposite way from most security lifecycle questions.
When an encryption algorithm weakens, you re-encrypt. The data is still there, you protect it differently, and the old ciphertext becomes irrelevant. Painful at scale, conceptually simple.
Integrity evidence does not work like that. A record that says 'this document existed in this state on 14 March 2024' derives its force from a cryptographic operation performed in 2024. You cannot re-perform it later - re-hashing today only proves the document existed today. If the primitive used in 2024 is later broken, the proof does not silently degrade in the background where nobody notices. It fails at exactly the moment someone relies on it, which is typically years later, in an audit or a dispute.
Regulatory retention periods make this concrete. Financial records held for seven or ten years, AI system logs held for the lifetime of the system, medical records held for decades. Every one of those is a bet that the cryptography underneath the integrity claim outlives the retention obligation.
What a cryptographic inventory needs to record
- Where each primitive is used, distinguishing confidentiality uses from integrity and signature uses, because their migration paths differ fundamentally
- The retention obligation on the data each use protects, so the mismatch between primitive life and record life is visible
- Which validations the implementation holds and when they expire or move to historical status
- Whether an integrity claim can be re-anchored under a new primitive without losing its original date, or whether re-anchoring resets the clock
- The dependency direction: which systems would need to change first, and which claims would be orphaned if a primitive were withdrawn tomorrow
Why federal deadlines matter to European buyers
The CMVP transition affects US federal procurement directly, but the ripple reaches further than the procurement rules suggest.
European vendors selling into US federal supply chains inherit the requirement through their customers. Vendors who validated modules for the federal market generally ship the same modules everywhere, so the transition changes what is available commercially regardless of buyer. And European procurement frameworks and certification schemes routinely reference FIPS validation as an acceptable assurance baseline, which means the reference point shifts even where the rule does not.
For organisations already tracking US requirements - anyone in the defence supply chain, for instance, whose situation we covered in CMMC Phase 2 is suspended, not cancelled - the crypto inventory work overlaps almost entirely with the CUI boundary work. Doing them together is materially cheaper than doing them apart.
The post-quantum connection
The FIPS 140-2 sunset is a validation transition, not a post-quantum one. But it lands in the middle of a much larger migration, and the two share an inventory.
Every federal agency was required to name a post-quantum migration lead by late July 2026, with full migration plans due to OMB by late October. On the industry side the picture is thinner: roughly 13% of organisations have post-quantum cryptography in production and around 60% have not begun meaningful migration, against transition timelines that large enterprises estimate at eight to fifteen years.
The organisations that will handle both transitions well are not the ones that started earliest. They are the ones that know what they have. An inventory built now serves the FIPS transition, the post-quantum migration, and every future deprecation, which is a rare thing in compliance work.
- Separate integrity and signature uses from confidentiality uses in your inventory - they have different migration mechanics
- Check the retention obligation against the primitive for your longest-lived evidence first
- Confirm whether your integrity records can be re-anchored without losing their original timestamps
- Do the FIPS transition inventory and the post-quantum inventory as one exercise
If you want to see how integrity anchoring handles primitive transitions without invalidating existing proofs, the ROOTKey platform page covers the verification model, and you can test it against your own long-retention records.
Recevez nos analyses sur la cyber-résilience par e-mail
Des conseils pratiques et prêts pour l'audit sur l'intégrité des données, la conformité et la continuité - dès leur publication.





