Canadian buyers sometimes assume FIPS 140-3 is an American requirement they can set aside. It is not. The Canadian Centre for Cyber Security (CCCS), Canada’s national cyber authority and part of the Communications Security Establishment, jointly manages the Cryptographic Module Validation Program (CMVP) with the United States National Institute of Standards and Technology (NIST), and is the Canadian certification authority for it. The same certificate that satisfies a US rule is recognised in Canada.
One programme, both countries
Under the CMVP, cryptographic modules are tested by accredited laboratories and validated against the Federal Information Processing Standard 140-3, which is aligned with the international standard ISO/IEC 19790. Because CCCS and NIST run the programme together, a module on the CMVP validated list carries weight for a Canadian federal department and a US agency alike. FIPS 140-2 validations move to NIST’s historical list on 21 September 2026, so Canadian procurements, like American ones, should specify FIPS 140-3.
Primary source: the CCCS Cryptographic Module Validation Program page.
Who this applies to in Canada
If your obligations point at CMVP-validated cryptography, FIPS 140-3 is the version to specify. That reaches further than most people expect:
| Sector | Why FIPS 140-3 comes up |
|---|---|
| Federal government and suppliers | CCCS guidance points departments and their contractors to CMVP-validated modules for protecting sensitive and protected information. |
| Law enforcement | Village, town, county, and municipal police services, and the providers that support them, handle criminal justice information and align to CJIS-style controls for information in transit. |
| Health | Custodians under provincial health-privacy law, such as Ontario’s PHIPA and Alberta’s HIA, are expected to use strong, validated cryptography for personal health information. |
| Finance | Federally regulated financial institutions under OSFI expectations, and firms under IIROC-successor oversight, treat validated cryptography as a baseline. |
| Defence supply chain | The Canadian Programme for Cyber Security Certification (CPCSC) and US CMMC work for Canadian defence suppliers both lean on FIPS-validated cryptography. |
What Lavawall® meets that others may not
Several remote-access and RMM tools have a FIPS story, but for a Canadian regulated buyer the combination is what matters, and it is uncommon:
| Requirement | Lavawall® |
|---|---|
| Current FIPS 140-3 module for data in transit | The remote session runs through a FIPS 140-3 validated module, NIST CMVP Certificate #5247, recognised in Canada through the CCCS-NIST programme. A current 140-3 validation, not a 140-2 one on its way to the historical list. |
| Enforced FIPS 140-3 validated login keys | Logins can be restricted to FIPS 140-3 validated security keys, checked against the CMVP list at registration and every sign-in. |
| Canadian data residency | Your data and its AI processing run in Canada by default, on AWS in Montréal and Calgary. See Canadian data residency. |
| One platform, not a separate edition | The FIPS-mode cryptography, patching, remote support, and GRC run in one console, so the evidence lands in one place. |
The YubiKey 5C NFC FIPS (140-3) is US$95 on Amazon, or US$88 direct from Yubico. Prices last checked: Amazon 2026-09-03, Yubico 2026-09-03. Check the retailer for the current figure.
Frequently asked
- Is FIPS 140-3 a US-only standard?
- No. The Canadian Centre for Cyber Security (CCCS), Canada’s national cyber authority, jointly manages the Cryptographic Module Validation Program with the U.S. National Institute of Standards and Technology, and is the Canadian certification authority. The same CMVP certificate that satisfies a US requirement is recognised in Canada, and FIPS 140-3 is aligned with the international standard ISO/IEC 19790.
- Which Canadian organizations need FIPS 140-3 validated cryptography?
- Federal departments and their suppliers under CCCS guidance, law-enforcement bodies that touch criminal justice information, and organizations in health, finance, and defence supply chains that handle sensitive or protected information. If your obligations point at CMVP-validated modules, FIPS 140-3 is the current version to specify.
- Does Lavawall keep Canadian data in Canada?
- Yes, by default. Your data and its AI processing run in Canada, on AWS in Montréal and Calgary, and can be placed elsewhere only on request. The remote session Lavawall carries is protected in transit by a FIPS 140-3 validated module, NIST CMVP Certificate #5247.