
Table of Contents
If your organization sells to the federal government, supports a government contractor, or operates in a regulated industry like healthcare or finance, you have probably heard the term FIPS 140-3 coming up more often lately. There is a good reason for that. On September 21, 2026, NIST moves every FIPS 140-2 certificate to the Historical List, and FIPS 140-3 becomes the only game in town for new validations and new federal procurements. If you buy, deploy, or recommend cellular routers, now is the time to understand what FIPS 140-3 actually is, how a product earns it, and which manufacturers are ready.
What Is FIPS 140-3?
FIPS stands for Federal Information Processing Standard, a family of publicly announced standards developed by the National Institute of Standards and Technology (NIST). FIPS 140-3, titled “Security Requirements for Cryptographic Modules,” is the U.S. and Canadian government standard for approving the cryptographic modules that encrypt and protect sensitive data. It was published in March 2019, took effect in September 2019, and NIST began accepting validation submissions under the new scheme in September 2020.
In plain English: when a router claims to protect your VPN tunnel or management traffic with encryption, FIPS 140-3 validation is the government’s way of independently verifying that the encryption is implemented correctly. It is not a marketing checkbox. Validation is administered through the Cryptographic Module Validation Program (CMVP), a joint effort between NIST in the United States and the Canadian Centre for Cyber Security. You can browse every validated module on the official NIST CMVP validated modules list.
Like its predecessor, FIPS 140-3 defines four increasing security levels. Level 1 covers software modules with at least one approved algorithm and basic requirements. Level 2 adds tamper evidence and role-based authentication. Levels 3 and 4 add physical tamper resistance and environmental protections typically found in hardware security modules rather than network routers. Most cellular router validations land at Level 1, which is exactly what federal agencies require for network equipment handling sensitive but unclassified data.
How Does a Product Get FIPS 140-3 Validated?
Earning a FIPS 140-3 certificate is a long, expensive, multi-stage process, which is why so few vendors complete it. Here is how it works:
- Build the cryptographic module. The vendor isolates its cryptographic functions into a defined module boundary, whether software, firmware, or hardware, and documents every algorithm, key, and security parameter it handles.
- Algorithm testing (CAVP). Each individual algorithm (AES, SHA, RSA, ECDSA, and so on) must first pass the Cryptographic Algorithm Validation Program to prove the math is implemented correctly.
- Independent lab testing. The vendor contracts an accredited third-party Cryptographic and Security Testing Laboratory. The lab tests the module against ISO/IEC 24759 procedures, reviews source code, runs operational testing, and verifies the security policy documentation.
- CMVP submission and review. The lab submits its test report to the CMVP, where NIST and Canadian reviewers scrutinize the results. Back-and-forth questions are common and the queue can take many months.
- Certificate issuance. Once approved, the module receives a numbered certificate listed publicly on the NIST website, along with a sunset date. The vendor must maintain the module carefully, because even small code changes can trigger retesting.
The whole journey routinely takes one to two years and six figures in cost. That investment is exactly what separates “FIPS compliant” marketing language from a true “FIPS validated” certificate. Compliant means a vendor believes it follows the rules. Validated means an accredited lab and the U.S. government confirmed it.
How FIPS 140-3 Differs From FIPS 140-2
FIPS 140-2 served as the standard for over two decades, but FIPS 140-3 modernizes it in several important ways:
International alignment. Rather than spelling out its own requirements, FIPS 140-3 adopts the international standards ISO/IEC 19790 for module requirements and ISO/IEC 24759 for testing. This harmonizes U.S. and Canadian validation with global security practices.
Stricter integrity and self-testing. FIPS 140-3 tightens integrity test requirements and adds a mandatory service allowing a module to report its own name and version, so operators can map running firmware directly to a validation certificate.
Broader key zeroization. Under FIPS 140-3, all unprotected Sensitive Security Parameters must be zeroized at every level, including public keys, closing gaps that existed under 140-2.
Enforcement in code, not policy. Requirements around roles, services, and authentication must now be met by the module’s actual implementation rather than through written policy or operational rules. Password restrictions, for example, must be enforced by the software itself.
Lifecycle assurance and non-invasive attack considerations. Vendors must demonstrate sound development lifecycle practices, and the standard introduces a framework for addressing non-invasive attacks such as side-channel analysis.
The transition deadline. The most practical difference is timing. New FIPS 140-2 submissions are no longer accepted, and on September 21, 2026, all existing FIPS 140-2 certificates move to the Historical List. Existing 140-2 equipment does not stop working and certificates are not revoked, but federal agencies will increasingly require FIPS 140-3 validation for new procurements and new deployments.
Which Router Manufacturers Support FIPS 140-3?
At 5Gstore we carry seven major cellular router brands: Peplink, Cradlepoint, Teltonika, Semtech, Inseego, Digi, and Katalyst. Here is where each stands on FIPS 140-3 as of June 2026.
Digi: Validated Across the Portfolio
Digi announced FIPS 140-3 validation in April 2026 for its entire Digi Accelerated Linux (DAL OS) based portfolio, including the Enterprise (EX), Industrial (IX), and Transportation (TX) router lines. Digi positioned itself as the first provider in the cellular connectivity space to achieve portfolio-wide FIPS 140-3 validation, and notably, FIPS functionality is enabled through simple configuration on standard hardware rather than requiring special product variants. We covered the announcement in detail in our Digi FIPS 140-3 validation post. New products like the Digi IX25 ship with FIPS 140-3 in the spec sheet from day one.
Cradlepoint: Active FIPS 140-3 Certificates
Cradlepoint, now part of Ericsson, holds active FIPS 140-3 certificates for the cryptographic modules inside NetCloud OS, including the Cradlepoint Cryptographic Module (certificate 4770) and the Cradlepoint Kernel Cryptographic Module (certificate 4863), both validated at Level 1. These modules ship as integrated components of NetCloud OS on Cradlepoint devices, continuing the company’s long history of federal deployments that began with FIPS 140-2 validation back in 2017.
Inseego: FIPS 140-3 Certified Hardware Shipping Now
Inseego pioneered FIPS validation in the mobile hotspot category with the FIPS 140-2 certified MiFi X PRO and has now moved to the new standard. The new MiFi PRO M4 enterprise mobile router is FIPS 140-3 certified and built from a TAA-compliant supply chain, and the FX4200 indoor router features FIPS 140-3 compliant OpenSSL alongside secure boot and IPsec/OpenVPN support. Read our full breakdown in the MiFi PRO M4 review.
Semtech: FIPS 140-3 Coming in AirLink OS 6.1
Semtech (Sierra Wireless AirLink) has committed to FIPS 140-3 for its AirLink OS based router portfolio, with the validated cryptographic module delivered in AirLink OS 6.1, targeted for release in June 2026, ahead of the September deadline. AirLink routers have long been a staple of public safety and government fleets, so this transition matters to a lot of our customers. Our earlier post on FIPS 140-3 for AirLink routers covers the model list and timeline.
Peplink: FIPS 140-2 Today, Watch This Space
Peplink currently holds an active FIPS 140-2 certificate (certificate 4763, Level 1) for the Peplink FIPS Module, available as an optional license on select Balance and MAX models. That certificate carries the September 21, 2026 sunset date along with every other 140-2 validation. Peplink has not yet announced a completed FIPS 140-3 validation, so organizations with hard FIPS 140-3 requirements for new procurements should factor that into planning. Existing Peplink FIPS deployments continue to operate normally, and we will update readers the moment Peplink announces its 140-3 path.
Teltonika and Katalyst: No FIPS Validation Announced
Teltonika builds excellent, affordable industrial routers on its OpenWrt-based RutOS platform, and Katalyst is an exciting newer entrant, but neither manufacturer has announced FIPS 140-2 or 140-3 validation. That is perfectly fine for the commercial, industrial, and IoT deployments where these brands shine. It simply means they are not the right fit for procurements that contractually require FIPS validated cryptography.
What Should You Do Before September 2026?
First, determine whether FIPS actually applies to you. If you are a federal agency, a contractor handling Controlled Unclassified Information, or subject to frameworks like FedRAMP, CMMC, or certain HIPAA and PCI DSS interpretations, FIPS validated cryptography is likely mandatory. Second, audit what you have deployed. FIPS 140-2 equipment keeps working after the deadline, but new purchases and new projects will increasingly demand 140-3. Third, when evaluating new routers, verify the actual certificate on the NIST CMVP list rather than relying on a datasheet. The difference between compliant and validated can decide an audit.
5Gstore Take
The FIPS 140-2 to 140-3 transition is one of those deadlines that sneaks up on procurement teams. We have already seen RFPs in 2026 that specify FIPS 140-3 by name, and the September 21 Historical List date will only accelerate that. The good news is that the brands we carry are in strong shape: Digi went portfolio-wide, Cradlepoint has active certificates, Inseego is shipping certified hardware, and Semtech is landing its module ahead of the deadline. If your deployment has a FIPS requirement, or you are just not sure whether it does, our team works through these compliance questions with government and enterprise customers every week. Contact us and we will help you match the right validated hardware to your project before the deadline makes the decision for you.
FAQ
Q: What is the difference between FIPS 140-2 and FIPS 140-3? A: FIPS 140-3 is the successor standard. It aligns with international ISO/IEC 19790 requirements, adds stricter integrity testing, requires zeroization of all sensitive security parameters including public keys, mandates that authentication rules be enforced in code rather than policy, and introduces lifecycle assurance and side-channel attack considerations.
Q: Does my FIPS 140-2 router stop working on September 21, 2026? A: No. Existing equipment continues to function and certificates are not revoked. They move to the NIST Historical List, which means agencies should not use them for new procurements or new deployments, and risk assessments may be required for continued use.
Q: What is the difference between FIPS compliant and FIPS validated? A: Validated means the cryptographic module passed independent accredited lab testing and holds a numbered certificate on the NIST CMVP list. Compliant typically means the vendor believes its implementation follows FIPS requirements without completing formal validation. Contracts that require FIPS usually require validation, not just compliance.
Q: Which cellular router brands offer FIPS 140-3 today? A: As of June 2026, Digi offers FIPS 140-3 validation across its DAL OS portfolio, Cradlepoint holds active FIPS 140-3 certificates for NetCloud OS modules, and Inseego ships FIPS 140-3 certified hardware including the MiFi PRO M4. Semtech is delivering its FIPS 140-3 module in AirLink OS 6.1. Peplink currently offers FIPS 140-2, while Teltonika and Katalyst have not announced FIPS validation.
Q: Do I need FIPS 140-3 if I am not a government agency? A: Possibly. Government contractors, healthcare organizations, financial institutions, utilities, and public safety agencies often face FIPS requirements through regulations, contracts, or insurance frameworks. Even without a mandate, FIPS validation provides independent assurance that encryption is implemented correctly.
Q: What security level do cellular routers typically achieve? A: Level 1, which covers software cryptographic modules with approved algorithms. Levels 2 through 4 add physical tamper protections that are more typical of dedicated hardware security modules than network routers. Level 1 satisfies federal requirements for routers handling sensitive but unclassified data.

