In the previous lesson you saw VALIDATED status illustrated with a Thales HSM certificate. This lesson shows the same CAVP/CMVP distinction in a non-HSM example, a software crypto library. The goal is to make clear that this discipline is not a hardware-specific rule but a general habit to apply to any claim about a crypto product. In M9 you will see the distinction again with much more detailed, HSM-specific examples; this lesson lays the general foundation for that one.
CAVP and CMVP: a reminder, the general frame
CAVP (Cryptographic Algorithm Validation Program) verifies with test vectors that an algorithm is implemented mathematically correctly. CMVP (Cryptographic Module Validation Program) takes CAVP as a prerequisite and independently validates the whole module (physical and logical security, key management, production process control). A product saying “we got CAVP” is a real achievement, but it does not substitute for CMVP; for a production decision, CMVP is usually what is really needed.
A concrete example: OpenSSL’s own FIPS provider
In M0 you actually tested OpenSSL 3.5’s PQC support (ML-KEM, ML-DSA, SLH-DSA) in your own Docker or native environment; that support is real and works. But “OpenSSL supports PQC” and “OpenSSL’s FIPS module is certified for PQC” are different claims. The OpenSSL Corporation’s own announcement (9 October 2025) separates them clearly: “all included algorithms have successfully passed NIST testing and independent laboratory review” (CAVP complete), but “the final CMVP review and certificate issuance remain as the last step in the process” (CMVP not finished). This lesson carries that forward to today (September 2026) with the “verify live” discipline: NIST’s own CMVP Modules In Process list shows the OpenSSL FIPS Provider’s current status as CAVP passed, CMVP pending (Comment Resolution - CMVP)SOURCED (as of 21 August 2026), so there has been progress since the vendor’s 2025 announcement, but there is no completed certificate.
This example follows exactly the same pattern as the Entrust/Utimaco HSM example you will see in M9 (CAVP only, CMVP pending); the difference is that it is not a hardware module but the most widely used open-source crypto library in the world. The discipline is the same: whatever the product, ask whether a “we support PQC” claim implies CAVP or CMVP, and verify the answer from an independent source (NIST’s own list, not a vendor blog).
The general rule, in two steps
When a vendor or open-source project says “we support it” about a crypto feature: (1) Does the claim imply CAVP or CMVP, or neither (just “we implemented it, we didn’t test it”)? (2) Can it be verified from an independent source (the CAVP/CMVP search pages), or does it rest only on the vendor’s word? These two questions apply the same way to every crypto product claim, from HSMs to software libraries, from cloud KMS to smart cards; in M9 you will see this general discipline applied in a much more detailed, HSM-specific way.
Numbers to know
CAVP: is the algorithm's math right (with test vectors). CMVP: has the whole module (physical and logical security, production process control included) been independently validated. CAVP is a prerequisite for CMVP, but not a substitute
OpenSSL FIPS Provider today (September 2026): CAVP algorithm tests passed (including ML-KEM, ML-DSA, SLH-DSA), but no CMVP certificate yet; on NIST's live list it is at the "Comment Resolution - CMVP" stage (as of 21 August 2026)
Lab: Check the CMVP Modules In Process list live
[not run] This is a live verification exercise, not a runnable command
# Open csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in-process/modules-in-process-list and search for 'OpenSSL'
Recorded output
Several OpenSSL-based modules (Canonical Ubuntu, Oracle, the OpenSSL Corporation's own provider) are listed at different stages; the order runs roughly: lab testing and comments ("Comment Resolution - Lab") -> NIST's own review ("Comment Resolution - CMVP", past the lab stage, the second-to-last step) -> certificate. None of them has an 'Active' certificate number yet
At the table
How to say this in a bank meeting.
To an executive
The difference between a software vendor saying 'we are FIPS 140-3 compliant' and that being independently validated is as critical as it is for HSMs; we apply this distinction to software crypto libraries with the same rigour.
To an architect
OpenSSL 3.5's PQC support (ML-KEM, ML-DSA, SLH-DSA) is real and CAVP-tested, but there is no CMVP certificate. That may mean it is not possible today to use a PQC-capable OpenSSL install as a certified FIPS 140-3 module in production (for example under certain regulatory requirements); this should be made explicit.
Objection
“"OpenSSL 3.5 already supports PQC, so let's assume it is FIPS approved."”
Answer
Those are separate claims: OpenSSL 3.5's PQC support is real (you tested it in your own Docker or native lab in M0), but 'FIPS approved' means a CMVP certificate, and that does not exist yet today (September 2026); NIST's own live list shows OpenSSL's FIPS provider at the 'Comment Resolution - CMVP' stage, so the process is moving but not complete. If a regulatory requirement demands a FIPS 140-3 certificate, this gap directly affects the production decision.
The OpenSSL Corporation, 2025. Evidence, in the vendor's own words, of the CAVP-complete/CMVP-pending distinction in a non-HSM example (a software crypto module)
whole text, a short announcement / 5 min
Commercial stake: The OpenSSL Corporation is announcing its own product's validation process; the claim can be verified (checked live on the CMVP list) but is still about its own product
NIST CSRC, 2026. The source of the OpenSSL FIPS Provider's current, live, independent CMVP processing status (beyond the vendor's own claim)
OpenSSL FIPS Provider row / 5 min
Checkpoint
Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.
01Recall
What is the difference between CAVP and CMVP, and which is a prerequisite for which?
Model answer
CAVP verifies with test vectors that an algorithm is implemented mathematically correctly. CMVP takes CAVP as a prerequisite and independently validates the whole module (physical and logical security, key management, production process control included). CAVP is a prerequisite for CMVP but not a substitute.
02Recall
Which CMVP stage is OpenSSL's FIPS provider at today, and where can you check it directly?
Model answer
Today (as of 21 August 2026) the OpenSSL FIPS Provider has passed CAVP algorithm testing but has no CMVP certificate yet; it is at the 'Comment Resolution - CMVP' stage. You can check this directly on NIST's live CMVP Modules In Process list (csrc.nist.gov).
03Scenario
A development team is building a production system on OpenSSL 3.5's PQC support, and a regulatory requirement calls for a FIPS 140-3 certified module. What do you say about this plan?
Model answer
As of today the plan is risky: OpenSSL 3.5's PQC support (ML-KEM, ML-DSA, SLH-DSA) is real and CAVP-tested, but its FIPS provider has no CMVP certificate; NIST's live list shows the 'Comment Resolution - CMVP' stage. If the regulatory requirement calls for a FIPS 140-3 certified module, this gap directly affects the production decision and needs to be made explicit.
A complete answer includes
Your score: 0/3
04Hostile
An auditor asks: 'You say your library supports PQC. How did you verify that?' Using the CAVP/CMVP distinction, and without mentioning HSMs at all, how do you answer?
Model answer
I would tell the auditor that we distinguish whether a 'we support it' claim implies CAVP or CMVP: the library's PQC algorithms have passed CAVP test vectors, which is an independently verified fact. But the whole module has no CMVP certificate yet; NIST's own Modules In Process list shows it at the 'Comment Resolution - CMVP' stage. We verified this from NIST's own live list, not a vendor blog.
A complete answer includes
Your score: 0/3
Project linkA prerequisite for the M9 lesson `hsm-validation-reality` (applying CAVP/CMVP to HSMs); the general CAVP/CMVP check step in Project 4's (capstone) vendor assessment rubric.