iGamerKnow the game.
18+ --:--:-- UTC

FIPS 140-3

Cryptographic module validationissuer NIST (US National Institute of Standards and Technology)version FIPS 140-3verified 2026-08

FIPS 140-3, 'Security Requirements for Cryptographic Modules', is the current federal standard governing the design and testing of cryptographic modules. It is validated through the Cryptographic Module Validation Program (CMVP), run jointly by NIST and the Canadian Centre for Cyber Security, and it superseded FIPS 140-2. Unlike its predecessor, FIPS 140-3 is built on the international standards ISO/IEC 19790:2012 and ISO/IEC 24759:2017. In gaming and lottery contexts it is referenced where certified crypto modules, HSMs or RNG hardware must meet a recognised security bar rather than as a whole-system gaming standard.

Current version

RNG / crypto methodology

FIPS 140-3

FIPS 140-3 (approved March 2019, effective September 2019)

What it covers
Cryptographic module specification and interfacesRoles, services and authenticationSoftware/firmware securityPhysical security and tamper resistanceSelf-tests and lifecycle assuranceMitigation of other attacksFour increasing security levels (Level 1 to Level 4)
Applies to
Validation of cryptographic modules (hardware, software, firmware) used to protect sensitive dataCrypto modules and HSMs embedded in gaming/lottery systems where they are requiredSecure key management, encryption and self-testing in cryptographic implementations
Key facts
IssuerNIST (US National Institute of Standards and Technology)
CategoryRNG / crypto methodology
Where it’s usedUS and Canada (federal requirement); widely recognised internationally and referenced by gaming labs for crypto-module assurance.
StatusCurrent standard; supersedes FIPS 140-2Approved 22 March 2019, effective 22 September 2019
Validation programCMVP (NIST + Canadian Centre for Cyber Security)CMVP stopped accepting new FIPS 140-2 submissions in 2021
Security levels4 levels (1-4)Increasing physical and logical security requirements
BasisISO/IEC 19790:2012 and ISO/IEC 24759:2017First US crypto-module standard aligned to international standards
Related standards
FIPS 140-2ISO/IEC 19790NIST SP 800-22GLI-19
Related terms

A standard is a ruleset, not a promise. A certificate against FIPS 140-3 attests that a game or system met it at test time — it does not change the house edge or guarantee a session outcome. This is a teaching summary; confirm against the issuer (NIST (US National Institute of Standards and Technology)).