The encryption requirement is the second-most-fail-prone control in my assessment experience, after scoping. The trap is the difference between 'uses encryption' and 'uses FIPS-validated cryptography.'
The requirement: SC.L2-3.13.11
"Employ FIPS-validated cryptography when used to protect the confidentiality of CUI."
This is the practice text from NIST SP 800-171 Rev 2 § 3.13.11. Two key terms:
- FIPS-validated — the cryptographic module has been independently tested and validated under the NIST Cryptographic Module Validation Program (CMVP). Validation produces a certificate listing the module, the validated cryptographic algorithms, the operating environment, and the configuration.
- To protect the confidentiality of CUI — the requirement applies wherever CUI is being protected from disclosure, both at rest (storage) and in transit (network).
FIPS 140-2 vs FIPS 140-3
| Standard | Status | Validation status |
|---|---|---|
| FIPS 140-2 | Superseded by FIPS 140-3 | Existing validations remain valid until they expire (5 years from issue) or sunset; no new FIPS 140-2 validations after September 2021. |
| FIPS 140-3 | Current standard | New cryptographic module validations are issued under FIPS 140-3. |
For NIST SP 800-171 Rev 2, both FIPS 140-2 and FIPS 140-3 validations are acceptable. The CMMC Hashing Guide on the DoW CIO documentation index also addresses cryptography expectations.
Where to verify
The authoritative source is the CMVP Validated Modules list at csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules. Search by:
- Vendor name — for example, "Microsoft" returns Windows cryptographic providers.
- Module name — for example, "OpenSSL FIPS Object Module."
- Certificate number — if the vendor provides one.
Verify three things per module: (1) the certificate is active, (2) the operating environment matches yours, and (3) the configuration matches how you're using the module (FIPS mode enabled, approved algorithms only).
Common at-rest implementations
- BitLocker on Windows — BitLocker uses Windows cryptographic providers, which are FIPS-validated when FIPS mode is enabled and the validated configuration is used.
- FileVault on macOS — uses Apple cryptographic providers; verify current FIPS validation status against CMVP.
- Azure / AWS storage encryption — the FedRAMP authorization documentation and the Customer Responsibility Matrix specify which storage encryption is FIPS-validated.
- SQL Server / database encryption — verify the specific TDE / Always Encrypted module against CMVP.
Common in-transit implementations
- TLS — the TLS implementation must use a FIPS-validated cryptographic module. Most modern OSs and browsers can be configured for FIPS mode.
- VPN — validate the IPsec or TLS-based VPN's cryptographic module on CMVP.
- SSH — the SSH server's underlying crypto library must be FIPS-validated.
- Email encryption (S/MIME) — the email client and underlying crypto provider must be FIPS-validated.
Common errors
- Treating "uses AES-256" as FIPS-validated. The algorithm being approved doesn't make the module validated. The module itself must hold a CMVP certificate.
- Treating "FIPS-compliant" as FIPS-validated. Vendor marketing language; not equivalent.
- Using a validated module in a non-validated configuration. The CMVP certificate specifies the validated configuration; using the module differently breaks the validation.
- Failing to enable FIPS mode at the OS level. Many OSs ship with FIPS mode disabled by default; non-FIPS algorithms can run unless explicitly disabled.
- Letting validation certificates expire. CMVP certificates are valid for a defined period; check the expiration date and the post-validation status.
Sources
Track every cryptographic module against its CMVP certificate.
The CMMC Compliance Engine includes the POL-FIPS-01_FIPS_Cryptographic_Standards_Policy, the PRO-FIPS-01_FIPS_Cryptographic_Implementation_Procedure, and the CMVP-TRK-01_FIPS_Certificate_Reference_and_Tracker.
Get the CMMC Compliance Engine