3.13 System & Communications Protection5 ptsPOA&M-eligible

3.13.11 — FIPS-validated cryptography

Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

Encryption protecting CUI must be FIPS 140-validated — not just 'on'.

What it actually means

The single most commonly failed control in real government assessments. The trap: it's not enough that CUI is encrypted — the cryptographic module doing the encrypting has to be FIPS 140-validated (listed on NIST's Cryptographic Module Validation Program). BitLocker, FileVault, and your VPN can all encrypt without running in a validated mode. A 2026 wrinkle: all FIPS 140-2 module certificates move to NIST's Historical List on Sept 21, 2026 — see FIPS 140-2 → 140-3 for what that means, especially for new deployments.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

Scoring & POA&M note: On the SPRS scale, 3.13.11 deducts the full 5 points if CUI isn't encrypted at all, but only 3 points if you do encrypt with a module that isn't FIPS-validated yet. That 3-point partial is the one higher-weight gap the CMMC program lets you place on a POA&M (most 3- and 5-point controls cannot be deferred). Full validation is still the goal — a POA&M is a clock, not a finish line.

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Communications Protection (3.13)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.