Short answer: yes, but only where you're protecting the confidentiality of CUI — and only if the cryptography you're using has actually been through NIST's formal validation process. Not "FIPS-compliant." Not "uses AES-256 encryption." Validated.

This is one of the most confusing — and most expensive to get wrong — requirements in CMMC Level 2. It's also about to get more urgent. A NIST deadline on September 21, 2026 changes which validated modules still count for new purchases, landing just seven weeks before CMMC Phase 2 begins on November 10, 2026.

What "FIPS-Validated" Actually Means

Cryptography has two pieces that people constantly conflate: the algorithm (like AES-256, the math) and the module (the specific hardware or software that implements that math). CMMC doesn't care whether you used a respected algorithm. It cares whether the module — the actual product running on your laptop, firewall, or cloud service — has been tested and certified by an accredited lab under NIST's Cryptographic Module Validation Program (CMVP).

If it has, the vendor has a certificate number. If they don't have one, it isn't validated — no matter what the marketing page says.

Term What It Actually Means
FIPS-validated Tested by an accredited lab under CMVP and issued a certificate number. The only term that satisfies CMMC.
FIPS-compliant / FIPS-approved Marketing language. Usually means the product uses an approved algorithm, but the implementation was never independently tested.
FIPS-certified Not an official NIST term. Vendors use it loosely — always ask for the certificate number before trusting it.
"Uses AES-256 encryption" Describes the algorithm, not the module. The algorithm can be correct while the implementation has never been validated.
⚠️ Ask for the certificate number. If a vendor claims FIPS validation, they can point you to a specific CMVP certificate in seconds — the testing process is expensive enough that vendors who've actually done it are eager to prove it. Hesitation is your answer.

Which CMMC Controls Actually Require It?

One control carries the headline requirement, and three more extend it into specific situations:

Control What It Covers
SC.L2-3.13.11 Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. The headline requirement.
SC.L2-3.13.8 Cryptographic protection of CUI in transit — email, file transfer, web traffic.
SC.L2-3.13.16 Cryptographic protection of CUI at rest — laptops, servers, backups, cloud storage.
AC.L2-3.1.13 Cryptographic protection of remote access sessions — VPN connections, remote desktop.
SC.L2-3.13.11 is the only control in all of NIST SP 800-171 with the word "FIPS" in its text — and it only applies when you're protecting the confidentiality of CUI, not your entire IT environment.

You Don't Need to FIPS-Validate Your Whole Company

This is the part that saves small contractors real money. The requirement is scoped to CUI, not to every system you own. If you haven't already nailed down exactly where CUI lives in your environment, that's the prerequisite — not the encryption shopping list.

ℹ️ Isolate before you upgrade. Many small contractors discover that only a handful of laptops, one file share, and one email flow ever touch CUI. Isolating that footprint — sometimes called an enclave — can mean FIPS-validated cryptography only has to live in a small, contained part of your environment instead of across the whole company.

Where This Actually Shows Up for a Small DoD Sub

In practice, the requirement tends to land on the same handful of touchpoints:

How to Check If Something Is Actually Validated

NIST publishes the answer for free. Go to the CMVP's validated modules search, look up the vendor or product name, and confirm there's an active certificate that matches the exact version you're running. Don't take a vendor's word for it when the source of truth is a public government database.

One practical wrinkle: turning on "FIPS mode" can occasionally interfere with other software. Test it in a controlled rollout before flipping it on company-wide, and document what you tested.

Don't guess which controls apply to you

CMMC Map walks you through SC.L2-3.13.11 and every other control in plain English, and helps you document exactly where your CUI flows — so you know precisely where FIPS-validated cryptography actually needs to live.

Start Your Free 7-Day Trial

The September 2026 Deadline Hiding Inside This Requirement

Here's the part most small contractors haven't heard yet: on September 21, 2026, NIST's Cryptographic Module Validation Program moves every remaining active FIPS 140-2 certificate to its Historical List. Modules you already have in service can keep running. But FIPS 140-3 becomes the only standard for new active validation going forward.

In practice, that means anything you procure between now and your assessment — a new firewall, a new disk-encryption rollout, a new cloud service — should carry a 140-3 certificate, not a 140-2 one, if you want it to hold up cleanly for the long term. And it lands just weeks before Phase 2 makes third-party C3PAO assessments mandatory for Level 2 contracts, so this isn't a deadline to file away for later.

Common Mistakes Small Contractors Make

⚠️ A reminder while you're researching this: never paste actual CUI, system credentials, or configuration secrets into an AI assistant or public chatbot — including ours — while you're working through encryption questions. Describe your setup generically and keep the real data out of any tool that isn't authorized to hold it.

Get the scoping right first, document which modules protect which CUI flows in your System Security Plan, and FIPS validation stops being a mystery requirement and becomes a short, specific checklist — instead of a panic six months before your assessment.