Requirements
What the regulation expects

FIPS-validated components, not a marketing label
Required for US federal work and common in financial RFPs. State the boundary clearly.
Algorithms and operations covered
AES-256, RSA 2048/4096, HMAC-SHA256, secure random generation and key zeroization procedures.
When buyers ask early
Mention FIPS component validation early with US federal and regulated financial accounts. It clears a checkbox that otherwise stalls security review.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Route key ops through FIPS-validated backends (HSM or validated software modules) according to the deployment model.
Learn moreHSM-backed custody
Pin keys to PKCS#11 HSMs where FIPS module validation is a hard requirement.
Learn moreKey themes
Where independent key control fits
Status: aligned (FIPS-validated components). Use this language in questionnaires unless a specific product module certificate number is attached to the deal.
Symmetric encryption
AES-256 (including GCM) via FIPS-validated cryptographic components.
Asymmetric operations
RSA 2048/4096 key operations on validated components where the backend supports them.
Integrity and randomness
HMAC-SHA256 for integrity; secure random number generation for key and nonce material.
Key zeroization
Documented zeroization procedures when keys are destroyed or modules are decommissioned.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
