Certifications
The mountains we climb
Every certification we guide is one our SMEs have taken clients through, from Fortune 10 vendors to mid-market and startup product companies.
How a certification is earned
Requirements to certification, mapped.
Scope, framework, and timeline definition
The certifications we guide
Eight Federal programs, one accountable team.
Who needs it. Vendors whose products use cryptography to protect Controlled Unclassified Information (CUI) in the US and Canada.
Scope of work. · Initial Assessment (high level understanding of the product, scope, targeted user(s), implementation, targeted release and release date, etc.) · Gap Analysis and determination of targeted Level (1-4) for the cryptographic module (can be a software module, chip, complete hardware, firmware or software product...depends on the boundary) · Guidance on Post Quantum Cryptography (PQC), Implementation Guidance, etc. · Design consultation to close identified gaps in the architecture · Guidance to design future releases with “FIPS in mind” · Documentation preparation (Security Policy, Cryptographic Module Specification, Finite State Model, Vendor Evidence, etc.) · CAVP Algorithm Testing and Certification · Entropy Source Validation · Project Management · Testing Lab recommendations and pricing negotiations
Not sure which service you need?Start with a discovery call.
Start with a call