📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Buyer’s guide

Best FIPS 140-3 RMM and remote support for MSPs

FIPS mode tells you the algorithms are approved. It does not tell you who can read the session. This guide covers what FIPS 140-3 actually requires, the deadline most buyers have not heard about, and the one question that sorts a real answer from a marketing sentence.

Start free, no credit card See our modules and certificates

What FIPS 140-3 requires, in plain language

FIPS 140-3 is the current US federal standard for cryptographic modules. It is validated jointly by the US National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security under the Cryptographic Module Validation Program, or CMVP, and it is aligned with the international standard ISO/IEC 19790. A validated module appears on the CMVP list with a certificate number.

A compliance rule that references FIPS does not ask whether your tool uses good encryption. It asks whether a validated module performs the encryption. CJIS control SC-13 is the clearest example: criminal justice information in transit has to be protected by a FIPS-validated module, and an assessor checks the certificate.

The date most buyers have not heard is 21 September 2026. On that day NIST moves every FIPS 140-2 validation to its historical list. A historical certificate is not cancelled, but NIST's own note on those entries says the module should not be included by federal agencies in new procurements. If you are choosing a tool now, choose one whose validation is 140-3.

Three sentences that get blurred

Almost every confusing FIPS claim comes from collapsing three different statements into one word. Pull them apart and the vendor conversation gets short.

A validated module has a certificate number. NIST tested it and published the result, and you can look it up.

A product that uses a validated module is relying on someone else's certificate. That is fine and normal, but the certificate belongs to the module, not to the product, so the product should name the module and the number.

A product in FIPS mode, or one that lists FIPS-approved algorithms, has told you something about its algorithm choices and nothing about a validated module. Approved algorithms with no module behind them do not meet a rule that asks for a validated module.

So the question to put to any vendor, in one line: which module, which certificate number, and which components does it cover? A vendor that can answer in a sentence is selling you a validated module. A vendor that answers with adjectives is selling you a FIPS mode.

Lavawall’s answer, by component

Here is the same question answered for Lavawall, per component, with the certificate numbers attached.

ComponentModuleCMVP certificateStandard
Relay, Windows agent, macOS agent, native viewerGo Cryptographic Module v1.0.0#5247FIPS 140-3
Passkey and hardware technician sign-inYubiKey 5 FIPS Series, firmware 5.7.x#5291FIPS 140-3

Two limits we would rather state than have you find. The console tier runs on the host operating system's OpenSSL FIPS provider, which is a validated module supplied by the platform rather than one we certify ourselves. And a session viewed in a web browser uses FIPS-approved algorithms through the browser's own cryptography: it is end-to-end encrypted, but a browser is not a validated module, so we do not call a browser-viewed session module-protected. A session viewed in the Lavawall viewer application is protected by certificate #5247 at both ends. Volunteering those two lines is the reason you can trust the rest.

Where the plaintext lives

A validated module on the wire answers a narrower question than most buyers think. Many remote-support products that advertise FIPS put an approved cipher on a connection that still terminates in plaintext at the vendor's appliance or cloud. The cryptography is real. It also stops at a box the vendor operates, and at that box the session is in the clear.

Lavawall is built the other way. Session content is encrypted between the endpoint and the technician, and the relay in the middle routes ciphertext it holds no key for. So the question “who at the vendor can read this screen?” has the answer “nobody”, by construction rather than by policy. Screen frames, keystrokes, the clipboard, file transfers, shell output, and script bodies all travel inside that channel, and the relay refuses to forward any of them in the clear. Session keys rotate during a session, so a key recovered later does not open earlier traffic.

Zero trust, as four things that actually happen

The relay sits in the middle of every session and is trusted with routing, not with content. It authenticates and authorizes; it does not decrypt.

The technician is authenticated for each session, and can be required to prove it with a hardware key rather than a logged-in browser tab.

The endpoint proves its identity with a per-device key that never leaves the device, held in the TPM on Windows or the Secure Enclave on Mac.

Nothing is granted on the strength of having reached the relay.

What to verify, and Lavawall’s answer

Take these five to any vendor. The column on the right is ours.

What to verifyLavawall®
A validated module with a certificate number for the session cryptoGo Cryptographic Module v1.0.0, certificate #5247, FIPS 140-3, covering the relay, the Windows and macOS agents, and the native viewer
Who can read the session contentThe two endpoints. The relay routes ciphertext and holds no session key
Per-device keys, not a shared account keyEvery device has its own key, held in the TPM on Windows or the Secure Enclave on Mac, and it cannot be exported
Scripts signed on the endpointScripts run from a signed library inside the agent's Authenticode-signed executable. The server sends a script identifier and typed parameters, never a script body
A US-only path when you need itTenants can be pinned to US-only infrastructure, with no CDN in the session path

How the broader field compares

Based on each vendor’s own published documentation, as of September 2026. FIPS validations change and editions differ, so confirm the current CMVP certificate and configuration for any product before you rely on it. “Not published” means we did not find a vendor statement, not that a capability is impossible.

Platform Validated module for session crypto Enforces FIPS 140-3 validated login keys FIPS posture and RMM in one platform
Lavawall® Yes, FIPS 140-3, certificate #5247, covering relay, agents, and native viewer Yes, checked against the CMVP list at every login Yes, one platform: remote support, patching, and GRC
BeyondTrust (Bomgar) Own certificate #3881 is FIPS 140-2, now historical; the 140-3 statement cites no certificate Not published Separate FIPS-configured deployment; privileged-access focus
ConnectWise ScreenConnect FIPS mode using the operating system’s cryptography; no product certificate published Not published Remote tool; RMM and GRC are separate products
Kaseya VSA FIPS 140-2 validated historically; 140-3 status in progress, verify Not published RMM; FIPS scope varies by component
N-able (Take Control) FIPS 140-2 validated components Not published Remote tool within the N-able range
NinjaOne Not published for its own agent or remote session; general FIPS guidance only Not published RMM; cloud-hosted
Datto RMM Not published for the RMM path; Datto BCDR appliances offer a FIPS mode Not published RMM
Atera Not published; cloud-hosted RMM Not published RMM
Splashtop FIPS mode in the On-Prem or government edition Not published Remote tool

Sources: vendor FIPS documentation and NIST CMVP listings, accessed September 2026, including BeyondTrust’s FIPS 140-3 compliance statement, NIST CMVP certificate #3881, N-able’s FIPS 140-2 components letter, and the NIST CMVP validated-modules list.

Where Lavawall® fits

Lavawall is for the MSP or the lean public-sector IT team that has a FIPS 140-3 obligation and does not want to stand up a separate enterprise program to meet it. Remote support, patching, and GRC run in one console, so the evidence lands in one place, and the modules and certificate numbers are the ones in the table above. Data and its AI processing can sit in Canada by default, or on a US-only path when the rule calls for it.

The YubiKey 5C NFC FIPS (140-3) is US$95 on Amazon, or US$88 direct from Yubico. Prices last checked: Amazon 2026-09-17, Yubico 2026-09-20. Check the retailer for the current figure.

Frequently asked

What does FIPS 140-3 actually require?
It requires that the cryptography protecting the data be performed by a cryptographic module that NIST has validated, and listed on the Cryptographic Module Validation Program (CMVP) with a certificate number. A rule such as CJIS control SC-13 points at that list. Using strong algorithms, or running in a FIPS mode, is not the same thing: the question is whether a validated module does the work, and which certificate covers it.
What changes on 21 September 2026?
NIST moves every FIPS 140-2 validation to its historical list. A historical certificate is not withdrawn, but NIST's own note says such a module should not be included by federal agencies in new procurements. New work should specify FIPS 140-3, and a tool whose only validated module is 140-2 is worth a question.
Which module, which certificate, and which components?
That is the question to put to any vendor. Lavawall's answer: the relay, the Windows agent, the macOS agent, and the native viewer use the Go Cryptographic Module v1.0.0, certificate #5247, FIPS 140-3. Technician hardware sign-in uses the YubiKey 5 FIPS Series, certificate #5291, FIPS 140-3. The console tier runs on the host operating system's OpenSSL FIPS provider.
Is a browser-viewed session FIPS validated?
No, and we will not say it is. A session viewed in a web browser uses FIPS-approved algorithms through the browser's own cryptography, and it is end-to-end encrypted, but a browser is not a validated module. A session viewed in the Lavawall viewer application is protected by a validated module, certificate #5247, at both ends. We keep that line drawn so you know what you are relying on.

Start free →FIPS 140-3 support