Announcing Chainguard’s industry-first validated FIPS 140-3 module delivering post
Announcing Chainguard’s industry-first validated FIPS 140-3 module delivering post-quantum readiness
- View all articles
Zayn Lohit
Senior Product Manager
Chainguard
- View all articles
Katie Campisi
Staff Product Marketing Manager
Chainguard
Zayn Lohit Senior Product Manager + 1 other
Today, we are announcing that the Chainguard FIPS Provider for OpenSSL v3.6 has received validation from the NIST Cryptographic Module Validation Program (CMVP) under the FIPS 140-3 standard (Certificate #5523).
This makes Chainguard the first and only provider to deliver an approved hybrid post-quantum key exchange as a validated service inside a FIPS 140-3 module.
With the Commercial National Security Algorithm Suite (CNSA) 2.0 requiring post-quantum algorithm support starting in January 2027, organizations governed by federal and international compliance frameworks, including FedRAMP, EO 14409, DORA, PCI DSS v4.0, and the CRA, will no longer have to navigate impossible tradeoffs. Chainguard gives you immediate, out-of-the-box post-quantum compliance, zero known CVEs, and strict FIPS validation.
Eliminate the tradeoff between FIPS compliance and quantum readiness
For engineering, security, and compliance teams in regulated sectors, managing cryptographic foundations has historically required tough trade-offs:
Meeting FIPS 140-3 requires strict algorithmic verification, often locking teams into legacy cryptographic modules.
Revalidating cryptographic modules at NIST takes time, which often leaves organizations forced to run outdated modules with accumulated CVEs.
The US government's CNSA 2.0 directive sets a hard January 2027 deadline for adopting quantum-safe algorithms to protect against "harvest-now, decrypt-later" attacks.
Adopting post-quantum cryptography (PQC) used to mean stepping outside of FIPS-approved boundaries or undertaking massive, risky infrastructure redesigns. Chainguard FIPS Provider for OpenSSL v3.6 solves this dilemma by delivering a drop-in upgrade that combines government-validated post-quantum key exchange with zero-CVE guarantees.
Chainguard delivers out-of-the-box post-quantum compliance
Chainguard owns the validated module and its lifecycle. We can submit security fixes, algorithm updates, and patch CVEs inside the validated boundary itself. This lets us carry the certificate forward, rather than waiting for an upstream module owner or deferring remediation to a future revalidation. In practice, that ownership gives customers durable advantages:
1. First Approved Hybrid Post-Quantum Key Exchange
Our OpenSSL v3.6 module is validated under NIST Certificate #5523 and covers all three standardized post-quantum TLS hybrids, which are approved FIPS services.
By combining proven classical key exchanges with post-quantum ML-KEM algorithms, hybrid key exchange lets you maintain current CNSA 1.0 regulatory compliance today while instantly shielding your workloads against future quantum threats. Chainguard enables you to achieve out-of-the-box PQC compliance that no other vendor can deliver under FIPS 140-3.
2. Full Post-Quantum & Classical Algorithm Coverage
The module supports the complete suite of standardized post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) alongside classical FIPS primitives like AES, SHA-2/3, ECDSA, and RSA. It also integrates a NIST-validated software entropy source (Cert E191) directly within the module boundary, ensuring full 256-bit cryptographic strength for every generated key.
3. Zero CVEs in the Module Boundary
Organizations shouldn't have to compromise safety for compliance. Rather than deferring vulnerability fixes to a future revalidation, the v3.6 validation bakes remediations for active high-profile CVEs directly into the module boundary, delivering zero known CVEs out of the box.
Rollout & availability
Beginning October 1, 2026, Chainguard will roll out the validated FIPS 3.6 module to our FIPS container images on an opt-in basis. Because adoption is opt-in, engineering teams can migrate workloads to quantum-safe hybrid key exchange on their own schedule without breaking existing applications or risking downtime.
To learn more about migrating your workloads to validated FIPS 3.6 images or preparing your organization for CNSA 2.0, reach out to our team.
Share this article
Related articles
- product
Announcing the Sovereign Artifacts beta
- product
Announcing Chainguard container images for Go 1.27
- product
Introducing the Guardener GitHub App
- product
Chainguard Libraries now available on AWS Security Hub Extended
- product
Everything we announced during AI Readiness Innovation Week
- product
Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.