
When "Validated" Stops Meaning "Usable for New Systems": FIPS 140-2 Certificates Move to the Historical List on September 21
September 21, 2026
NIST's Cryptographic Module Validation Program transition schedule moves all FIPS 140-2 certificates to the Historical List on September 21, 2026. Existing systems may continue to procure and use those modules; new systems should move to FIPS 140-3. NIST separately issued SP 1352, a non-binding small business primer on CUI assessment, and Draft NIST IR 8623, an initial public draft O-RAN profile for federal agencies open for comment until November 2, 2026, which imposes no certification or market-access requirement today. Three developments, three distinct legal statuses.
All three developments this period come from the U.S. National Institute of Standards and Technology, and none of them is a new regulation. That is worth stating up front. They fall into three different categories — an administrative status transition within a validation program, non-binding guidance, and a draft open for public comment — and their force differs accordingly. Treating all three as "new requirements" spends effort where none is needed and misjudges the timing where a real date exists.
1. FIPS 140-2 Certificates Move to the Historical List
Legal status: an administrative status transition under the Cryptographic Module Validation Program. Not a rule, not a final rule, not a rulemaking of any kind. Effective September 21, 2026.
The core fact is simple: as of September 21, 2026, all FIPS 140-2 certificates move to the Historical List.
The mechanism is the FIPS 140-3 transition schedule published by NIST CMVP, under which FIPS 140-2 validations remain active for five years after validation, or until September 21, 2026.
The term invites misreading, so the effect needs stating precisely. Moving to the Historical List does not mean a module has been found insecure, and it is not a prohibition on use. CMVP is explicit: even on the Historical List, CMVP supports the purchase and use of these modules for existing systems.
What changes is the other side of the line. For new systems and new deployments, federal agencies are directed toward FIPS 140-3 validated modules.
One practical condition should not be skipped. CMVP itself notes that the selection of FIPS 140-3 modules will remain limited for several years, and advises purchasers to consider all modules on the Validated Modules Search Page that meet their requirements, whether validated against 140-2 or 140-3. The direction is clear; the supply side is not yet there. This is a transition, not a clean switchover.
What This Means for Taiwan Manufacturers
This matters because what changes is not the technical security of a product but whether that product still counts as the compliance answer on a given piece of business. The device has not gotten worse. Whether it can be written into a new federal deployment may now need confirming.
The exposure sits with Taiwan suppliers of cryptography-bearing products into U.S. federal and defense channels: routers, firewalls, VPN appliances, wireless communications modules, endpoint devices, hardware security modules, and the firmware and cloud services around them. The risk is most concentrated among suppliers whose current product and firmware versions map only to FIPS 140-2 certificates.
The dividing line is not in the product. It is in whether a given piece of business is classified as continuation of an existing system or as a new system or new deployment. The same device with the same certificate may be fine under the first and require rework under the second.
That classification is generally not the manufacturer's to make. It depends on how the procuring agency or prime contractor characterizes the program — which makes it something to confirm in writing rather than assume.
What can be done first, and should be, is establishing the facts. Inventory the cryptographic modules used across product lines, active bids, and planned deployments, and record against each one the CMVP certificate number, module version, operational environment, and whether the validation is 140-2 or 140-3.
This sounds elementary, but most manufacturers do not actually have it. The information is scattered across engineering, procurement, quality, and outsourced suppliers, at inconsistent levels of detail and version currency. When a U.S. customer asks, the ability to produce an auditable certificate mapping within a reasonable time is itself read as a signal of supplier maturity.
The same demand needs to travel upstream. Chip, firmware, and module suppliers should be asked for a traceable mapping between product versions and valid CMVP certificates. Without that layer, any inventory stops at your own assembly level and cannot support an external compliance explanation.
For federal opportunities currently in flight, the conservative position is this: until a FIPS 140-3 replacement module is confirmed, or a written determination on existing-system classification is obtained from the procuring party, do not commit a 140-2-only configuration as the compliance answer for a new system.
Primary sources:
2. NIST SP 1352: Small Business Primer for SP 800-171A, Revision 3
Legal status: non-binding guidance. Not a regulation. It adds no control, no contract clause, and no compliance deadline. Published September 16, 2026.
The core fact: on September 16, NIST published SP 1352, a primer written for small businesses. It is not a new requirement.
The full title is Assessing Security Requirements for Controlled Unclassified Information (CUI): NIST SP 800-171Ar3 (Revision 3) Small Business Primer. Its purpose is to restate the assessment approach of SP 800-171A Rev. 3 in terms a small business owner or operator can read.
What it does not do deserves equal emphasis. It does not add to or modify any security requirement in SP 800-171. It does not change CMMC, SPRS, or DFARS implementation timelines. It sets no filing or compliance date. It lowers the cost of understanding; it does not raise the bar.
What This Means for Taiwan Manufacturers
The value here is not novelty — it is provenance. For Taiwan small and mid-sized manufacturers carrying CUI-bearing work in the U.S. defense supply chain without dedicated compliance staff, a citable document from the standards body supplies an official shared vocabulary, and what that saves in communication usually exceeds what the content itself teaches.
The most common source of waste in CUI assessment preparation is not a technical gap but an interpretive one. The U.S. customer, the outside advisor, and the internal engineering team each carry a different account of what an assessment examines, what evidence looks like, and what counts as done. Reconciling those accounts often costs more than the remediation work itself. A primer issued by the standards body, written for small organizations, collapses that reconciliation onto a baseline all parties can cite.
In practice it folds into existing preparation: scoping narratives at assessment kickoff, evidence-preparation checklists, and training material for internal teams and suppliers. This is improvement work with no deadline attached, absorbed at your own pace without disturbing current schedules.
Primary sources:
3. Draft NIST IR 8623: CSF 2.0 Profile for Federal Agency O-RAN Deployment
Legal status: Initial Public Draft, open for comment, not final and not binding. It imposes no equipment certification or market-access requirement at this time. Draft published September 17, 2026; the public comment period closes November 2, 2026.
The core fact: NIST released the initial public draft of IR 8623 on September 17, with comments open until November 2. It is a draft, and nothing in it requires compliance today.
The full title is Cybersecurity Framework 2.0 Community Profile for Federal Agency Open Radio Access Network (O-RAN) Deployment. It establishes a CSF 2.0 community profile for federal agencies deploying O-RAN: assessing relevant threats and resources, describing how O-RAN components can support CSF 2.0 outcomes, and referencing O-RAN ALLIANCE security specifications and related guidance.
Its audience is federal agencies, not equipment suppliers, and it remains a draft. Those two facts set the appropriate response: nothing requires compliance today, but there is a defined window in which to anticipate.
What This Means for Taiwan Manufacturers
Why should a supplier spend time on a draft written for federal agencies? Because a federal agency profile can reasonably be expected to propagate down the supply chain through procurement terms and technical specifications — though that has not happened yet.
For Taiwan suppliers of O-RAN and RAN equipment, software, or components, the practical use of this draft is advance visibility into the kind of security evidence federal customers are likely to ask for.
The value at the draft stage lies not in compliance but in comparison. Measure it against the security documentation and controls your products can currently evidence, and identify the gaps. Gap analysis done without deadline pressure costs far less than the same work compressed into a bid window.
November 2 is the only window in which this document is open to outside input. If your product architecture, existing security design, or field experience diverges from the assumptions in the draft, this is the point at which that view can be placed on the record before the document is finalized. Whether to comment is a commercial judgment, not an obligation — but if the answer is yes, the schedule has to be worked backward from that date, because the same channel does not reopen after the draft is finalized.
Primary sources:
- Draft NIST IR 8623 (Initial Public Draft, September 17, 2026)
- NIST announcement and comment deadline
Conclusion
There is no new regulation this period, but there is one substantive change taking effect now.
Only one item requires immediate handling: as of September 21, 2026, FIPS 140-2 certificates are on the Historical List. It prohibits nothing, and existing systems continue. But it draws a line at "new systems," and which side of that line a given program sits on is usually not yours to decide.
The response is inventory and written confirmation, not panic replacement — particularly while FIPS 140-3 module availability remains limited, where committing prematurely to a replacement schedule may carry more risk than confirming the classification carefully.
The other two are not urgent. SP 1352 is a tool available for immediate use with no deadline attached. IR 8623 is a draft whose only date is the November 2 comment deadline, and that is an opportunity rather than an obligation.
It is also worth recording what did not happen. Within this observation period there were no new additions to the FCC Covered List, no new router conditional approvals, and no formal announcement of a CMMC Phase II restart or a change to SPRS or DFARS timelines. For companies tracking the Covered List, the position established by DA 26-957 in the prior period is unchanged.
About This Briefing
Vantikon tracks U.S. regulatory and standards developments that reach Taiwan manufacturers, their product lines, and their supply chains. We translate those developments into product-level preparation: identifying the affected products and versions, inventorying and organizing technical and supply-chain evidence, and defining a sensible scope of response, so that subsequent dealings with qualified advisors or regulators rest on organized facts.
We are a readiness and advisory partner — not a law firm, not a certification body, and not a testing laboratory. We do not file on your behalf and we do not render legal opinions. If this period's developments touch your product lines or your U.S. market plans, get in touch.
This briefing is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel regarding your specific circumstances.
