Short answer: yes, but only where you're protecting the confidentiality of CUI — and only if the cryptography you're using has actually been through NIST's formal validation process. Not "FIPS-compliant." Not "uses AES-256 encryption." Validated.
This is one of the most confusing — and most expensive to get wrong — requirements in CMMC Level 2. It's also about to get more urgent. A NIST deadline on September 21, 2026 changes which validated modules still count for new purchases, landing just seven weeks before CMMC Phase 2 begins on November 10, 2026.
What "FIPS-Validated" Actually Means
Cryptography has two pieces that people constantly conflate: the algorithm (like AES-256, the math) and the module (the specific hardware or software that implements that math). CMMC doesn't care whether you used a respected algorithm. It cares whether the module — the actual product running on your laptop, firewall, or cloud service — has been tested and certified by an accredited lab under NIST's Cryptographic Module Validation Program (CMVP).
If it has, the vendor has a certificate number. If they don't have one, it isn't validated — no matter what the marketing page says.
| Term | What It Actually Means |
|---|---|
| FIPS-validated | Tested by an accredited lab under CMVP and issued a certificate number. The only term that satisfies CMMC. |
| FIPS-compliant / FIPS-approved | Marketing language. Usually means the product uses an approved algorithm, but the implementation was never independently tested. |
| FIPS-certified | Not an official NIST term. Vendors use it loosely — always ask for the certificate number before trusting it. |
| "Uses AES-256 encryption" | Describes the algorithm, not the module. The algorithm can be correct while the implementation has never been validated. |
Which CMMC Controls Actually Require It?
One control carries the headline requirement, and three more extend it into specific situations:
| Control | What It Covers |
|---|---|
| SC.L2-3.13.11 | Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. The headline requirement. |
| SC.L2-3.13.8 | Cryptographic protection of CUI in transit — email, file transfer, web traffic. |
| SC.L2-3.13.16 | Cryptographic protection of CUI at rest — laptops, servers, backups, cloud storage. |
| AC.L2-3.1.13 | Cryptographic protection of remote access sessions — VPN connections, remote desktop. |
SC.L2-3.13.11 is the only control in all of NIST SP 800-171 with the word "FIPS" in its text — and it only applies when you're protecting the confidentiality of CUI, not your entire IT environment.
You Don't Need to FIPS-Validate Your Whole Company
This is the part that saves small contractors real money. The requirement is scoped to CUI, not to every system you own. If you haven't already nailed down exactly where CUI lives in your environment, that's the prerequisite — not the encryption shopping list.
Where This Actually Shows Up for a Small DoD Sub
In practice, the requirement tends to land on the same handful of touchpoints:
- Laptop and disk encryption — BitLocker has a FIPS-validated mode, but it has to be the validated module and it has to actually be turned on, not just available.
- VPN and firewall appliances — many business-grade SonicWall and Fortinet models have FIPS-validated firmware, but only specific versions, and only when FIPS mode is enabled.
- Cloud email and file storage — this is where the GCC High question comes in. (We cover the tradeoffs in our GCC High vs. commercial M365 guide.)
- Backups — if a backup ever contains CUI, the encryption protecting it needs the same validation.
- Password managers — if you store credentials to CUI systems in one, the vault's encryption is in scope too.
How to Check If Something Is Actually Validated
NIST publishes the answer for free. Go to the CMVP's validated modules search, look up the vendor or product name, and confirm there's an active certificate that matches the exact version you're running. Don't take a vendor's word for it when the source of truth is a public government database.
One practical wrinkle: turning on "FIPS mode" can occasionally interfere with other software. Test it in a controlled rollout before flipping it on company-wide, and document what you tested.
Don't guess which controls apply to you
CMMC Map walks you through SC.L2-3.13.11 and every other control in plain English, and helps you document exactly where your CUI flows — so you know precisely where FIPS-validated cryptography actually needs to live.
Start Your Free 7-Day TrialThe September 2026 Deadline Hiding Inside This Requirement
Here's the part most small contractors haven't heard yet: on September 21, 2026, NIST's Cryptographic Module Validation Program moves every remaining active FIPS 140-2 certificate to its Historical List. Modules you already have in service can keep running. But FIPS 140-3 becomes the only standard for new active validation going forward.
In practice, that means anything you procure between now and your assessment — a new firewall, a new disk-encryption rollout, a new cloud service — should carry a 140-3 certificate, not a 140-2 one, if you want it to hold up cleanly for the long term. And it lands just weeks before Phase 2 makes third-party C3PAO assessments mandatory for Level 2 contracts, so this isn't a deadline to file away for later.
Common Mistakes Small Contractors Make
- Trusting "AES-256 encrypted" marketing copy without checking whether the actual module is validated.
- Assuming GCC High is required everywhere when only the CUI-touching pieces actually need it.
- Enabling FIPS mode without testing — and finding out a critical line-of-business app breaks.
- Storing CUI-related credentials in a password manager that's never been FIPS-validated.
- Leaving it for "later" because it's confusing — which is exactly what makes an assessor write it up as not implemented when nobody on staff can name the certificate number.
Get the scoping right first, document which modules protect which CUI flows in your System Security Plan, and FIPS validation stops being a mystery requirement and becomes a short, specific checklist — instead of a panic six months before your assessment.