FIPS Cryptographic Modules

FIPS Cryptographic Modules delivers FIPS 140-3 Level 1 validated cryptography across your device — from the Wi-Fi radio through to application-layer TLS — without requiring you to source, integrate, or maintain your own validated modules. It is the only globally recognized cryptographic testing and validation program, making it a mandatory requirement for US and Canadian federal agencies, defense, and medical device manufacturers. Ezurio ships this as a turnkey, lifecycle-maintained capability: available today on the 60 Series SOM, with Carbon AM62L in active development.

FIPS-Icon-White-Outline.png

What is FIPS 140?

FIPS 140 (Federal Information Processing Standard 140) is a U.S. government security standard for cryptographic modules. Validation is performed by accredited laboratories under the NIST Cryptographic Module Validation Program (CMVP). FIPS 140-3 is the current active standard; FIPS 140-2 validations remain in effect under a transition period.

FIPS 140-3 Level 1 Validated Modules

Designed for US and Canadian Government Agencies — including Veterans Affairs Hospitals, Department of Defense, and Military — and enterprises with the most stringent cryptographic requirements.

Wi-Fi Data-in-Transit

  • WPA3-Personal & Enterprise
  • WPA3-Enterprise CNSA 192-bit mode
  • Auth: SAE, EAP-TLS/TTLS/PEAP

TLS Data-in-Transit

  • TLS 1.3 validated
  • Works with any transport protocol using OpenSSL TLS APIs
  • Secures application-layer data if required

Lifecycle Coverage

  • Regular validation updates as NIST guidance and FIPS standards evolve
  • BSP updates with updated validations included
  • Non-cryptographic updates to address bug fixes and known CVEs in code

FIPS is the only true cryptographic testing & validation program in the world. Turnkey FIPS coverage — from Wi-Fi radio to application layer (TLS) — maintained across your product's full lifecycle.

Built on international standards — ISO/IEC 19790:2012 (security requirements for cryptographic modules) and ISO/IEC 24759:2017 (test methods for conformance). Available today on select Ezurio SOMs — shipping on the 60 Series SOM now; in development on Carbon AM62L with IF513, with additional SOMs under evaluation.

Now Certified for FIPS 140-3!

Ezurio is the first vendor to provide a validated FIPS 140-3 Level 1 module that includes Wi-Fi data-in-transit which is pre-engineered to integrate into highly sensitive device designs. Our 60 Series SOM is that offering, validated by NIST's Cryptographic Module Validation Program for the most stringent software requirements in today's data-sensitive applications.

Cert #5090

60-SOM Render 333 - FIPS 140-3
Chain of Trust icon

Chain of Trust

  • Device security framework using secure boot with hardware root of trust and secure device storage
  • Production-Grade Image Signing - Secure signing service for generating signed firmware and certificates, backed by AWS
  • Manufacturing Provisioning -Mass programming of hardware root of trust and secure image programming with optional provisioning of customer-specific application keys, certificates, and credentials
Security BSP Releases icon

Security BSP Releases

  • LTS Linux kernel, Yocto, and Buildroot releases out of our normal cycle to address CVEs
  • Ezurio QA re-tests the BSP/hardware combination to preserve features
  • Customer outsources the burden of retesting core BSP functionality
  • Yocto & Buildroot generate SBOMs for use in customer’s CVE scanner or each build system’s built in CVE scanner.
  • Supports EU CRA, EO 14028 & NTIA SBOM compliance
FIPS Cryptographic Modules icon

FIPS Cryptographic Modules

  • FIPS 140-3 Level 1 certified
  • Wi-Fi data-in-transit
  • TLS data-in-transit
  • Currently on 60 Series SOM
  • In design for Carbon AM62L
  • Required for medical, government, defense
Loop

Ready to Get Started? 

Get in touch with our sales and engineering team to find the SOM that best meets your needs, powered by our comprehensive EZ BSP. 

Browse Ezurio SOMs

View Support Documentation

Contact Sales and Support