HomeControl Library › 3.13.11
3.13 System & Communications Protection5 ptsPOA&M-eligible

3.13.11 — FIPS-validated cryptography

Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

Encryption protecting CUI must be FIPS 140-validated — not just 'on'.

What it actually means

The single most commonly failed control in real government assessments. The trap: it's not enough that CUI is encrypted — the cryptographic module doing the encrypting has to be FIPS 140-validated (listed on NIST's Cryptographic Module Validation Program). BitLocker, FileVault, and your VPN can all encrypt without running in a validated mode.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

POA&M note: 3.13.11 is the one higher-weight control the CMMC program lets you place on a POA&M (most 3- and 5-point controls cannot be deferred). Full validation is still the goal — a POA&M is a clock, not a finish line.

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library