Crypto Soup in CMMC (L03a)
CMMC level 2 (and level 3) require the use of FIPS validated module for secure communication and storage. CMMC level-2 Assessment guide references FIPS 140 requirements in several practices. FIPS 140 and Algorithm testing is mentioned in eight practices. This talk will introduce the audience to the FIPS 140 certification terminologies, basics of the CMVP program, cover the differences and relationship between FIPS 140 certificates and algorithm certificates, explain how to verify the FIPS certificates at the NIST website and decipher FIPS certificates for CMMC use. This talk will be useful to the RPs, CCPs, CCAs, Lead Assessors, Quality Assurance Professional and the contractors targeting CMMC Level-2 and Level-3. The speaker is a FIPS140 lab Director with over 15 years of FIPS 140 experience. The author is a RP, CCP, CCA and PA.