Certifications

FIPS 140 is a U.S. standard defining security requirements for cryptographic modules. It covers physical security, key management, roles and services, and algorithm implementation. Modules must meet these criteria to be validated for secure use.

NIST Personal Identity Verification Validation Program (NPIVP) was established to validate Personal Identity Verification (PIV) components required by Federal Information Processing Standard (FIPS) 201.

FIDO2, from the FIDO Alliance, offers phishing-resistant, password-free authentication, delivering secure, user-friendly access across desktop and mobile while addressing traditional authentication challenges for modern organizations.

CSFC uses layered commercial products to secure classified data, enabling faster deployment by leveraging multiple unclassified COTS solutions instead of traditional Type 1 government systems.

The DoDIN APL, managed by DISA, lists products certified for Defense networks, confirming they meet required cybersecurity and interoperability standards through DISA’s approval process.

NIAP oversees the U.S. program that evaluates COTS IT products for compliance with the Common Criteria. Through CCEVS, it develops Protection Profiles, evaluation methods, and policies to ensure security requirements are consistent, practical, and testable.