CyberSense holds an active FIPS 140-3 CMVP certificate.
Here is what you can verify, what you need to specify, and when you can deploy.
***
The CyberSense FIPS Cryptographic Module holds CMVP certificate #5316. The certificate is FIPS 140-3, Overall Level 1, listed to Index Engines Inc., and it is Active on the NIST CMVP Active Modules list.
An independent NIST-specified laboratory tested the module and the Cryptographic Module Validation Program issued the certificate.
FIPS 140-3 is the U.S. and Canadian standard for cryptographic modules. It covers hardware, software, and firmware. It defines four levels of security assurance. It is required for systems that handle Sensitive But Unclassified information.
Most compliance frameworks depend on it. FedRAMP, FISMA, CMMC, Common Criteria, HIPAA, and HITECH all reference validated cryptography. DoD and DISA STIG environments assume it. Meeting FIPS 140-3 satisfies a prerequisite that appears under all of them.
Validation is performed by one of fewer than fifteen laboratories NIST has specified for this work. That is why the process takes time and why the certificate carries weight.
Federal agencies are the clearest case. Treasury, Health and Human Services, Defense, Social Security, Veterans Affairs, and Agriculture all run large data estates with high ransomware exposure. Their procurement processes will not open a serious evaluation of a data integrity platform without validated cryptography.
The same requirement appears outside the federal space. Healthcare systems under HIPAA and HITECH, financial institutions, and defense contractors all face auditors who ask the same question. A CMVP certificate number is the answer in every one of those conversations.

The CyberSense FIPS Cryptographic Module covers:
The module is a rebrand of KeyPair Consulting’s validated OpenSSL 3 FIPS Provider, CMVP #4724, under FIPS 140-3 Management Manual §7.1.8. KeyPair authored the implementation. Index Engines holds the listing. The module is deployed without modification on Ubuntu 24.04 LTS on binary-compatible Intel Xeon-based hardware.
Cryptography that routes through OpenSSL inherits coverage from the validated module. This includes CyberSense application crypto and the system services that call libcrypto. Paths that do not route through OpenSSL are tracked separately under their own certificates.
A complete FIPS data-at-rest posture uses three validated modules.
Multiple validated boundaries is the ideal architectural pattern. Each certificate is independently verifiable on the NIST CMVP Active Modules list. Every step in the passkey lifecycle happens inside a validated module. Between modules the passkey is briefly held in userspace by the orchestration process and cleared on a best-effort basis. It is outside the validated module boundaries and is never written to disk in the clear.
FIPS-mode deployments require SED and TPM components from the CyberSense FIPS Hardware Compatibility Matrix. Each entry lists the vendor and model, the current CMVP certificate number and listing URL, the certificate sunset date and FIPS 140 revision, and the configuration steps needed to run the part in FIPS-approved mode.
FIPS 140-2 sunsets on September 21, 2026. Any SED or TPM on a 140-2 certificate without a 140-3 path stops being viable after that date. Specify 140-3 parts now.
Certificate #5316 is active. Validation finished ahead of the product integration work. The FIPS-validated CyberSense appliance image (Ubuntu 24.04, module #5316) is targeted for the November 17, 2026 release.
Validation was the unpredictable part of this work. Laboratory queues and CMVP review cycles run on their own schedule. That step is complete, and integration is the remaining work targeted for the November 17, 2026 release.
Look up certificate #5316 on the NIST CMVP Active Modules list.
↑