90trust / 100

FIPS 140 certificate tracker

by fips.808bits.com in Other

MCP serverPassing, checked 3 h ago

Every NIST FIPS 140 certificate, plus the modules-in-process queue NIST publishes only as a page.

https://fips.808bits.com/mcp

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
229 ms typical, 229 ms slowest 5%
Last check
3 h ago
Next check
in 3 h

How to call it

Add it to any MCP client that supports remote servers.

{
  "mcpServers": {
    "fips-140-certificate-tracker": {
      "type": "http",
      "url": "https://fips.808bits.com/mcp"
    }
  }
}

6 tools

  • fips_cert

    Look up one FIPS 140 cryptographic module validation by certificate number. Returns status (active, historical or revoked), overall level, sunset date, validation history, approved algorithms and tested configurations.

  • fips_search

    Search FIPS 140 validations by module name or vendor. Use this to answer whether a given product or vendor holds a current validation, and at what level. Results are ordered by status, then how well they match, then newest first, so the current validations lead.

  • fips_in_process

    Search NIST's Modules in Process queue: submissions awaiting FIPS 140-3 validation, with the review phase each one is sitting in. Use this when a vendor claims a validation is 'coming' and you need to know whether it has actually been submitted, and how far along it is.

  • fips_vendor

    Everything one company holds, grouped across the spelling variants NIST filed it under. Cisco alone appears as three different strings. Returns a breakdown by status and standard plus the certificates themselves. Note this groups spellings of one registration, not corporate famil

  • fips_cve

    Which FIPS-validated modules are associated with a given CVE, or which CVEs are associated with a vendor's modules. Answers 'we have a validated module, is it caught up in this advisory'. The association is name-based against the product CPE, so read it as a pointer to check rath

  • fips_sunset

    List active FIPS validations by sunset date, the day each moves to NIST's historical list and stops being valid for new procurement. Answers 'what expires before date X' and 'which vendors are about to have nothing valid'. A certificate listed here may already have a 140-3 succes

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTime
3 h agoPassed200229 ms