Hi ala,
Welcome to Vault by EC, your monthly roundup of the trends, technologies, and best practices shaping enterprise cryptography.
On September 7, the OpenSSL 3.0 series reaches end of life. Two weeks later, on September 21, every remaining FIPS 140-2 validation moves to the CMVP Historical list.
For anyone whose compliance rests on a validated module, those two dates are the same event arriving twice. The OpenSSL FIPS Provider that ships with 3.0 is validated under 140-2, so when 3.0 stops receiving security fixes and 140-2 goes Historical, a module that quietly underpins a large share of federal and regulated infrastructure stops counting.
The catch is the one that runs through every issue of this newsletter. You cannot move off a module you cannot see. Most organizations do not keep a current list of where the FIPS 140-2 OpenSSL provider actually runs, so the work starts with discovery.
The stakes are concrete. Only FIPS 140-3 modules will satisfy new federal procurements and compliance checks after September 21, and both FedRAMP and CMMC require 140-3 validation. FedRAMP has published a transition path for a module still moving through the validation queue, but it only helps if the module is genuinely in process.
CMMC Level 2 enforcement begins November 10, roughly seven weeks later. And the validation pipeline is congested. As of July, more than 500 modules were still in FIPS 140-3 testing, so a plan that depends on a lab queue clearing in time, or on a module being in it at all, is not a plan.
Two clocks, one blind spot: the validated module no one is tracking. This issue is about what comes next: finding every affected module and getting off it before the date arrives.