Quick answer
FIPS are NIST-published standards that federal agencies must use for information security, data processing, and cryptography in government IT systems and contracts.
Federal Information Processing Standards (FIPS) are official standards published by the National Institute of Standards and Technology (NIST) under OMB authority that establish mandatory requirements for information security, cryptographic algorithms, and data processing in federal government information systems and their contractor counterparts.
What are FIPS?
FIPS are binding standards that federal agencies must apply to non-national-security information systems. The most consequential FIPS for government contractors are FIPS 140-2 and FIPS 140-3 (security requirements for cryptographic modules), FIPS 197 (the Advanced Encryption Standard, AES), and FIPS 199/200 (security categorization and minimum security requirements). FIPS 140-2/140-3 validation is particularly critical: any cryptographic product used to protect federal sensitive information must be validated against these standards, meaning contractors offering encryption software or hardware to federal agencies must ensure their products carry FIPS 140 validation certificates. NIST maintains a Cryptographic Module Validation Program (CMVP) that tests and validates products against FIPS 140 requirements. FIPS standards are not voluntary for federal systems, agencies are required to comply, and contracts for systems that handle sensitive government information typically include FIPS compliance requirements in technical specifications and compliance matrices. Understanding which FIPS apply to a given system's data sensitivity level is foundational to any cybersecurity or IT proposal for federal customers.
Why FIPS matter for government contractors
For IT and cybersecurity contractors, FIPS compliance is a threshold requirement, not a differentiator. Proposals for federal IT systems that include non-FIPS-validated cryptographic modules will typically be found technically unacceptable. Firms must ensure that all encryption used in systems they develop, integrate, or operate for federal customers uses FIPS-validated modules.
Example
A cybersecurity firm developing a secure messaging application for a federal agency specifies FIPS 140-2 validated cryptographic modules throughout the system architecture section of its proposal. The technical evaluation confirms that the design uses only NIST-approved algorithms and validated modules, satisfying the solicitation's mandatory FIPS compliance requirement and advancing the firm to the competitive range.
Frequently Asked Questions
Are all FIPS mandatory for all federal systems?
Not all FIPS apply equally. The applicability of specific FIPS depends on the system's data sensitivity category (as determined under FIPS 199), the type of information processed, and agency-specific security requirements. Contractors should review the applicable FIPS listed in the system's security requirements document or system security plan.
What is the difference between FIPS 140-2 and FIPS 140-3?
FIPS 140-2 is the legacy cryptographic module standard while FIPS 140-3 is the current standard, which aligns more closely with ISO/IEC 19790. NIST phased out new FIPS 140-2 validations and now requires FIPS 140-3 for new submissions, but existing FIPS 140-2 certificates remain valid for a transition period.
How do I know if a product is FIPS 140 validated?
NIST maintains the Cryptographic Module Validation Program (CMVP) database at csrc.nist.gov/projects/cryptographic-module-validation-program, which lists all validated cryptographic modules with their validation certificates. Vendors should reference their CMVP certificate number in technical proposals and system documentation.
Do FIPS apply to cloud services used by federal agencies?
Yes. Cloud services that process or store federal sensitive information must use FIPS-validated cryptographic modules. FedRAMP (the federal cloud security authorization program) incorporates FIPS requirements into its control baselines, meaning FedRAMP-authorized cloud services have already been assessed for FIPS compliance.
How Bidovate helps
Bidovate puts Federal Information Processing Standards (FIPS) to work inside your capture and proposal workflow.
Proposal checklistsSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
System Security Plan (SSP)
A System Security Plan is a formal document that describes the security controls implemented in a federal information system and how they satisfy NIST requirements for authorization.
ViewNational Industrial Security Program Operating Manual (NISPOM)
The NISPOM establishes the standard requirements for protecting classified information by cleared defense contractors and their facilities under the National Industrial Security Program.
ViewInformation Security (INFOSEC)
INFOSEC refers to the policies, procedures, and technical controls used to protect government information and information systems from unauthorized access, use, disclosure, disruption, or destruction.
ViewCompliance Matrix
A tool that maps every solicitation requirement to a place in your proposal so no requirement is missed.
View