What is FIPS 140-3 certification of USB token?

FIPS(Federal Information Processing Standards) 140-3 is a U.S. government computer security standard used to approve cryptographic modules. 

The National Institute of Standards and Technology (NIST) issued the FIPS 140 Publication Series to coordinate the requirements and standards.

FIPS 140-3 certification is becoming an important term for anyone using or supplying USB cryptographic tokens for Digital Signature Certificates (DSCs). But what does it actually mean, and why is the DSC industry moving toward it?

The Controller of Certifying Authorities (CCA), Ministry of Electronics and Information Technology (MeitY), has specified security requirements for cryptographic devices used for digital signatures in India. Its August 2026 document also records the transition from FIPS 140-2 to FIPS 140-3. Now what are these 2 and 3 levels?

FIPS 140 series uses four increasing tiers of security rules:

  • Level 1: Uses basic production-grade equipment and tested algorithms.

  • Level 2: Adds physical tamper-evidence clues and role-based login checks.

  • Level 3: Adds physical tamper-resistance blocks and strict identity-based logins.

  • Level 4: Requires maximum physical protection and advanced defense against environmental attacks.

So a token does not become FIPS 140-3 certified simply by changing its firmware or adding a new chip. FIPS validation applies to a defined cryptographic module, including its hardware, firmware/software, security boundary, algorithms, interfaces and security controls. The exact changes therefore depend on the OEM and the specific module being validated.

Hence USB Tokens are switched to FIPS 140-3 certification from earlier 140-2 Certification as per CCA guidelines.

Also, FIPS 140-3 and SHA-2 are two different things.

How should I choose a FIPS 140-3 certified token?

Tags: No tags

Comments are closed.