threat_intelligence649 wordsRead on Arc Codex

Announcing Chainguard’s industry-first validated FIPS 140-3 module delivering post

Announcing Chainguard’s industry-first validated FIPS 140-3 module delivering post-quantum readiness - View all articles Zayn Lohit Senior Product Manager Chainguard - View all articles Katie Campisi Staff Product Marketing Manager Chainguard Zayn Lohit Senior Product Manager + 1 other Today, we are announcing that the Chainguard FIPS Provider for OpenSSL v3.6 has received validation from the NIST Cryptographic Module Validation Program (CMVP) under the FIPS 140-3 standard (Certificate #5523). This makes Chainguard the first and only provider to deliver an approved hybrid post-quantum key exchange as a validated service inside a FIPS 140-3 module. With the Commercial National Security Algorithm Suite (CNSA) 2.0 requiring post-quantum algorithm support starting in January 2027, organizations governed by federal and international compliance frameworks, including FedRAMP, EO 14409, DORA, PCI DSS v4.0, and the CRA, will no longer have to navigate impossible tradeoffs. Chainguard gives you immediate, out-of-the-box post-quantum compliance, zero known CVEs, and strict FIPS validation. Eliminate the tradeoff between FIPS compliance and quantum readiness For engineering, security, and compliance teams in regulated sectors, managing cryptographic foundations has historically required tough trade-offs: Meeting FIPS 140-3 requires strict algorithmic verification, often locking teams into legacy cryptographic modules. Revalidating cryptographic modules at NIST takes time, which often leaves organizations forced to run outdated modules with accumulated CVEs. The US government's CNSA 2.0 directive sets a hard January 2027 deadline for adopting quantum-safe algorithms to protect against "harvest-now, decrypt-later" attacks. Adopting post-quantum cryptography (PQC) used to mean stepping outside of FIPS-approved boundaries or undertaking massive, risky infrastructure redesigns. Chainguard FIPS Provider for OpenSSL v3.6 solves this dilemma by delivering a drop-in upgrade that combines government-validated post-quantum key exchange with zero-CVE guarantees. Chainguard delivers out-of-the-box post-quantum compliance Chainguard owns the validated module and its lifecycle. We can submit security fixes, algorithm updates, and patch CVEs inside the validated boundary itself. This lets us carry the certificate forward, rather than waiting for an upstream module owner or deferring remediation to a future revalidation. In practice, that ownership gives customers durable advantages: 1. First Approved Hybrid Post-Quantum Key Exchange Our OpenSSL v3.6 module is validated under NIST Certificate #5523 and covers all three standardized post-quantum TLS hybrids, which are approved FIPS services. By combining proven classical key exchanges with post-quantum ML-KEM algorithms, hybrid key exchange lets you maintain current CNSA 1.0 regulatory compliance today while instantly shielding your workloads against future quantum threats. Chainguard enables you to achieve out-of-the-box PQC compliance that no other vendor can deliver under FIPS 140-3. 2. Full Post-Quantum & Classical Algorithm Coverage The module supports the complete suite of standardized post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) alongside classical FIPS primitives like AES, SHA-2/3, ECDSA, and RSA. It also integrates a NIST-validated software entropy source (Cert E191) directly within the module boundary, ensuring full 256-bit cryptographic strength for every generated key. 3. Zero CVEs in the Module Boundary Organizations shouldn't have to compromise safety for compliance. Rather than deferring vulnerability fixes to a future revalidation, the v3.6 validation bakes remediations for active high-profile CVEs directly into the module boundary, delivering zero known CVEs out of the box. Rollout & availability Beginning October 1, 2026, Chainguard will roll out the validated FIPS 3.6 module to our FIPS container images on an opt-in basis. Because adoption is opt-in, engineering teams can migrate workloads to quantum-safe hybrid key exchange on their own schedule without breaking existing applications or risking downtime. To learn more about migrating your workloads to validated FIPS 3.6 images or preparing your organization for CNSA 2.0, reach out to our team. Share this article Related articles - product Announcing the Sovereign Artifacts beta - product Announcing Chainguard container images for Go 1.27 - product Introducing the Guardener GitHub App - product Chainguard Libraries now available on AWS Security Hub Extended - product Everything we announced during AI Readiness Innovation Week - product Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.