How should I choose a FIPS 140-3 certified token?

The easiest way is to verify the token through the official NIST Cryptographic Module Validation Program (CMVP) database.

The mToken CryptoID, has an active FIPS 140-3 validation.

Its official details are:

  • Module: mToken CryptoID
  • FIPS Standard: FIPS 140-3
  • CMVP Certificate: #4845
  • Security Level: Level 3
  • Status: Active

You can verify these details directly on the NIST website:

Verify mToken CryptoID — NIST CMVP Certificate #4845

When purchasing a FIPS 140-3 token, don’t rely only on a sticker, logo or seller’s claim. Always check the CMVP certificate number, module name, manufacturer and validation status.

For mToken CryptoID, Below have been verified from NIST.

FIPS 140-3 | CMVP Certificate #4845 | Active | Level 3

This allows you to independently verify that the cryptographic mToken module has been validated under FIPS 140-3.

What is FIPS 140-3 certification of USB token?

FIPS(Federal Information Processing Standards) 140-3 is a U.S. government computer security standard used to approve cryptographic modules. 

The National Institute of Standards and Technology (NIST) issued the FIPS 140 Publication Series to coordinate the requirements and standards.

FIPS 140-3 certification is becoming an important term for anyone using or supplying USB cryptographic tokens for Digital Signature Certificates (DSCs). But what does it actually mean, and why is the DSC industry moving toward it?

The Controller of Certifying Authorities (CCA), Ministry of Electronics and Information Technology (MeitY), has specified security requirements for cryptographic devices used for digital signatures in India. Its August 2026 document also records the transition from FIPS 140-2 to FIPS 140-3. Now what are these 2 and 3 levels?

FIPS 140 series uses four increasing tiers of security rules:

  • Level 1: Uses basic production-grade equipment and tested algorithms.

  • Level 2: Adds physical tamper-evidence clues and role-based login checks.

  • Level 3: Adds physical tamper-resistance blocks and strict identity-based logins.

  • Level 4: Requires maximum physical protection and advanced defense against environmental attacks.

So a token does not become FIPS 140-3 certified simply by changing its firmware or adding a new chip. FIPS validation applies to a defined cryptographic module, including its hardware, firmware/software, security boundary, algorithms, interfaces and security controls. The exact changes therefore depend on the OEM and the specific module being validated.

Hence USB Tokens are switched to FIPS 140-3 certification from earlier 140-2 Certification as per CCA guidelines.

Also, FIPS 140-3 and SHA-2 are two different things.

How should I choose a FIPS 140-3 certified token?

Blue color new mtokens which are FIPS 140-3 certified and will be useful even after 21 sep 2026

How to get class 3 digital signature certificate?

You can get a Class 3 Digital Signature Certificate (DSC) online through Official Digi Sign e services.

Class 3 in a digital signature generally represents the level of security. It represents the paperless process of getting a digital signatures.

If you want to get class 3 signing only digital signatures valid for 1,2,3 years you can reach us at our WhatsApp number i.e : 9876787172.

Documents required are as follows :
1. Original photo of Aadhar Card ( front and back )
2. Pan card
3. Mobile number linked with Aadhar card.

There are other types of digital signatures which have got specific uses.