📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

FIPS 140-3 validated security keys, enforced

If a rule says your people must sign in with FIPS 140-3 validated hardware, Lavawall® checks each key against the NIST CMVP list and enforces it. Here is exactly what that does, and where the line is.

Some organizations are required to use FIPS 140-3 validated authenticators for advanced authentication: a security key or passkey whose cryptographic module has passed testing under the NIST Cryptographic Module Validation Program. Knowing that a user has such a key is easy to assert and hard to prove. Lavawall® proves it, at registration and again at every login, and can refuse anything that does not meet the bar.

What FIPS 140-3 is, and the date on the calendar

FIPS 140-3 is the current US federal standard for cryptographic modules, published by NIST and based on the international standard ISO/IEC 19790. A certificate covers the module that performs the cryptography, for a security key, the chip inside it, not the application it signs into. On 21 September 2026, NIST moves every FIPS 140-2 validation to its historical list, so a program still resting on 140-2 hardware is on borrowed time and new procurements should specify FIPS 140-3.

How the enforcement works

In the console you set the minimum authenticator standard to FIPS 140-3 validated. From then on, every passkey or security key is checked against the maintained list of NIST CMVP validated authenticators.

StepWhat happens
Checked at registrationWhen a key is enrolled, its attestation is read and matched to a current CMVP FIPS 140-3 certificate, for example the YubiKey 5 FIPS Series under certificate 5291, valid to 2031. A model with no such certificate is not accepted at this level.
Re-checked at every loginThe standard is enforced on each sign-in, not just once, so a key cannot slip below the bar unnoticed.
A PIN or biometric is requiredUser verification is required, which on most keys is what puts the device into its FIPS-approved mode.
Report-only firstRun the control in report-only mode to see which users would be blocked, issue compliant keys, then turn on enforcement once everyone is covered.

What this is, and what it is not

It is an authentication control. It enforces the FIPS 140-3 status of the hardware your people sign in with, and gives an auditor evidence that every login uses a validated key. Where FIPS 140-3 validated authenticators are required, under CJIS advanced authentication and in high-assurance environments generally, this is the control that proves it.

It is not a claim that everything else is FIPS-validated. Lavawall does not represent that its own data cryptography, or your wider environment, runs through FIPS 140-3 validated modules. Requirements about data in transit, such as CJIS control SC-13, concern the cryptographic modules protecting the data itself, which is a property of the infrastructure carrying it and separate from this login control. We would rather tell you exactly where the line sits than blur it.

Frequently asked

What does Lavawall actually do for FIPS 140-3?
Lavawall enforces the authenticators. The console can require that every passkey or security key used to sign in be a FIPS 140-3 validated model, verified against the NIST CMVP certificate list by the key's attestation. It is an authentication control. It is not a claim that Lavawall's data cryptography, or your wider environment, is FIPS 140-3 validated.
Does this satisfy the CJIS SC-13 encryption requirement?
No, and no login control does. CJIS control SC-13 is about criminal justice information in transit being protected by FIPS 140-3 validated cryptographic modules, which is a property of the infrastructure carrying the data. What Lavawall covers is the separate requirement to use FIPS 140-3 validated authenticators for advanced authentication.
Which keys qualify, and what happens on 21 September 2026?
Models covered by a current NIST CMVP FIPS 140-3 certificate qualify, for example the YubiKey 5 FIPS Series under certificate 5291, valid to 2031. A PIN or biometric must be set, which is what puts most keys into their FIPS-approved mode. On 21 September 2026 NIST moves FIPS 140-2 validations to its historical list, so new work should be on FIPS 140-3 validated hardware.

Data residency: We place your data and our AI processing in the region your obligations require: Canada, the United States, Europe, or Australia. How data residency works →