Skip to Content
FIPS 140-3 ComplianceFIPS Certification Status

FIPS Certification Status

Cryptographic module status

Every RLC Pro cryptographic module is CMVP-validated except the RLC Pro 9.6 kernel, which is currently in process (MIP). The tables below track current status.

Status definitions

  • CMVP (Validated/Certified): The module has completed NIST validation and holds an active FIPS 140-3 certificate. It can be used to meet FIPS 140-3 requirements when deployed and operated in the module's approved mode per its security policy.
  • MIP (Modules In Process): The module has been approved by the testing lab and submitted to NIST for validation. The NIST review process typically takes at least 12 months. MIP modules have completed lab testing but are awaiting final NIST certification.

Certified modules (CMVP)

The following modules have completed NIST validation and hold active FIPS 140-3 certificates.

Certificate #Module NameRLC Pro VersionsValidation DateSunset
5350Rocky Linux 8 and 9 GnuTLS Cryptographic Module8.6, 8.10, 9.2, 9.6June 23, 2026June 22, 2031
5337Rocky Linux 8 and 9 NSS Cryptographic Module8.6, 8.10, 9.2, 9.6June 17, 2026June 16, 2031
5200Rocky Linux 8 OpenSSL Cryptographic Module8.6, 8.10March 18, 2026March 17, 2031
5117Rocky Linux 8 and 9 libgcrypt Cryptographic Module8.6, 8.10, 9.2, 9.6January 6, 2026January 5, 2031
5116Rocky Linux 9 OpenSSL FIPS Provider9.2, 9.6January 6, 2026January 5, 2031
5113Rocky Linux 9 Kernel Cryptographic API9.2December 18, 2025December 17, 2030
5095Rocky Linux 8 Kernel Cryptographic API8.6, 8.10November 24, 2025November 23, 2030

Modules In Process (MIP)

The following modules have completed testing and have been submitted to NIST for validation.

ModuleRLC Pro VersionsSubmitted to NIST
Kernel9.6October 2025

Coverage by version

ModuleRLC Pro 8.6RLC Pro 8.10RLC Pro 9.2RLC Pro 9.6
KernelCertifiedCertifiedCertifiedMIP
OpenSSLCertifiedCertifiedCertifiedCertified
libgcryptCertifiedCertifiedCertifiedCertified
GnuTLSCertifiedCertifiedCertifiedCertified
NSSCertifiedCertifiedCertifiedCertified

Last updated: July 13, 2026. For authoritative, real-time status, use the CMVP Validated Modules Search and the Modules In Process List.

Entropy source validation

FIPS 140-3 requires validated entropy sources for random number generation (SP 800-90B). CIQ's entropy sources have been independently validated by NIST:

CertificateEntropy SourceAvailabilityValidation Date
E117Kernel CPU Time Jitter RNGRocky 8 and 9February 9, 2024
E205Kernel CPU Time Jitter RNGRocky 8 and 9November 4, 2024
E208OpenSSL 3 CPU Time Jitter RNGRocky 9November 15, 2024
E210Userspace CPU Time Jitter RNGRocky 8 and 9November 18, 2024
E219OpenSSL 1 CPU Time Jitter RNGRocky 8December 13, 2024

All entropy sources are validated to SP 800-90B, provide 256-bit full entropy output, and are classified as non-physical noise sources using CPU timing jitter.