Some organizations are required to use FIPS 140-3 validated authenticators for advanced authentication: a security key or passkey whose cryptographic module has passed testing under the NIST Cryptographic Module Validation Program. Knowing that a user has such a key is easy to assert and hard to prove. Lavawall® proves it, at registration and again at every login, and can refuse anything that does not meet the bar.
What FIPS 140-3 is, and the date on the calendar
FIPS 140-3 is the current US federal standard for cryptographic modules, published by NIST and based on the international standard ISO/IEC 19790. A certificate covers the module that performs the cryptography, for a security key, the chip inside it, not the application it signs into. On 21 September 2026, NIST moves every FIPS 140-2 validation to its historical list, so a program still resting on 140-2 hardware is on borrowed time and new procurements should specify FIPS 140-3.
How the enforcement works
In the console you set the minimum authenticator standard to FIPS 140-3 validated. From then on, every passkey or security key is checked against the maintained list of NIST CMVP validated authenticators.
| Step | What happens |
|---|---|
| Checked at registration | When a key is enrolled, its attestation is read and matched to a current CMVP FIPS 140-3 certificate, for example the YubiKey 5 FIPS Series under certificate 5291, valid to 2031. A model with no such certificate is not accepted at this level. |
| Re-checked at every login | The standard is enforced on each sign-in, not just once, so a key cannot slip below the bar unnoticed. |
| A PIN or biometric is required | User verification is required, which on most keys is what puts the device into its FIPS-approved mode. |
| Report-only first | Run the control in report-only mode to see which users would be blocked, issue compliant keys, then turn on enforcement once everyone is covered. |
What this is, and what it is not
It is an authentication control. It enforces the FIPS 140-3 status of the hardware your people sign in with, and gives an auditor evidence that every login uses a validated key. Where FIPS 140-3 validated authenticators are required, under CJIS advanced authentication and in high-assurance environments generally, this is the control that proves it.
It is not a claim that everything else is FIPS-validated. Lavawall does not represent that its own data cryptography, or your wider environment, runs through FIPS 140-3 validated modules. Requirements about data in transit, such as CJIS control SC-13, concern the cryptographic modules protecting the data itself, which is a property of the infrastructure carrying it and separate from this login control. We would rather tell you exactly where the line sits than blur it.
Frequently asked
- What does Lavawall actually do for FIPS 140-3?
- Lavawall enforces the authenticators. The console can require that every passkey or security key used to sign in be a FIPS 140-3 validated model, verified against the NIST CMVP certificate list by the key's attestation. It is an authentication control. It is not a claim that Lavawall's data cryptography, or your wider environment, is FIPS 140-3 validated.
- Does this satisfy the CJIS SC-13 encryption requirement?
- No, and no login control does. CJIS control SC-13 is about criminal justice information in transit being protected by FIPS 140-3 validated cryptographic modules, which is a property of the infrastructure carrying the data. What Lavawall covers is the separate requirement to use FIPS 140-3 validated authenticators for advanced authentication.
- Which keys qualify, and what happens on 21 September 2026?
- Models covered by a current NIST CMVP FIPS 140-3 certificate qualify, for example the YubiKey 5 FIPS Series under certificate 5291, valid to 2031. A PIN or biometric must be set, which is what puts most keys into their FIPS-approved mode. On 21 September 2026 NIST moves FIPS 140-2 validations to its historical list, so new work should be on FIPS 140-3 validated hardware.