ISO/IEC 19790:2025 Selective Adoption: Join the Discussion at FIPS ‘n’ Chips

,

·

FIPS ’n’ Chips 2026 is five weeks away, and it arrives at an important moment for the Cryptographic Module Validation Program (CMVP). The program has reduced its queue of newly submitted FIPS 140-3 modules awaiting review to zero, and attention is turning to what comes next: adopting ISO/IEC 19790:2025.

Kailai Chen, the CMVP Program Manager at the Canadian Centre for Cyber Security (CCCS), explained at the September meeting of the Cryptographic Module User Forum (CMUF) that this progress allows CMVP to begin considering adoption using its existing resources, with input from the CMUF Steering Committee and members.

While no final process or timeline has been announced, one approach under discussion is gradual, selective adoption within the existing FIPS 140-3 framework, with the aim of avoiding renewed pressure on the validation queue. CMVP would define the process, while vendors, laboratories, and other community members would help identify and prioritize improvements.

Which updates in the 2025 revision of ISO/IEC 19790 deliver the greatest security benefit? And which changes best address the inherent tension between rapidly advancing technology and standards that are constantly trying to catch up? How can adoption move forward while keeping the validation queue manageable? FIPS ’n’ Chips attendees can explore these questions directly with the CMVP leadership: David Hawes and Alex Calis of the National Institute of Standards and Technology (NIST) and Kailai Chen of CCCS.

On October 27, Hawes, Calis, and Chen will take part in the CMVP Deep Dive Track panel “ISO/IEC 19790:2025 Adoption Is Not a Drop-In Replacement.” Attendees can hear directly from NIST and CCCS representatives and discuss how community experience can support a workable approach. Ryan Thomas of NVIDIA will moderate.

The discussion continues from the panel discussion with “Adopting ISO/IEC 19790:2025 in FIPS 140-3: A top 10 list for CMVP.” Thomas will present proposed changes that he has assessed for their benefits, adoption burden, and compatibility with the existing framework, drawing on his experience as both a laboratory director and a vendor guiding products through validation.

If you design, implement, or test cryptographic modules, bring your questions and practical examples. Join NIST, CCCS, and your peers in Austin to help turn the community’s recent progress into practical next steps.

Explore the conference schedule and plan your participation.