CARVIEW |
This is a potential security issue, you are being redirected to https://csrc.nist.gov.

An official website of the United States government
Here’s how you know
Official websites use .gov
A
.gov website belongs to an official government
organization in the United States.
Secure .gov websites use HTTPS
A
lock (
) or https:// means you’ve safely connected to
the .gov website. Share sensitive information only on official,
secure websites.
Security Testing, Validation and Measurement STVM
Mission Statement
Overview
Federal agencies, industry, and the public rely on cryptography for the protection of information and communications used in electronic commerce, critical infrastructure, and other application areas. When protecting their sensitive data, federal government agencies require a minimum level of assurance that cryptographic products meet their security requirements. Federal agencies are also required to use only tested and validated cryptographic modules. Adequate testing and validation of the cryptographic module and its underlying cryptographic algorithms against established standards is essential to provide security assurance.
The Security Testing, Validation, and Measurement (STVM) Group’s testing-focused activities include validating cryptographic algorithm implementations, cryptographic modules, and Security Content Automation Protocol (SCAP)-compliant products; developing test suites and test methods; providing implementation guidance and technical support to industry forums; and conducting education, training, and outreach programs. All of the STVM's validation programs work together with independent Cryptographic and Security Testing laboratories that are accredited by the NIST National Voluntary Laboratory Accreditation Program (NVLAP). Based on the independent laboratory test report and test evidence, the Validation Program then validates the implementation under test. The validations awarded to vendor implementations are publicly posted on the NIST website.
Staff Listing and Profiles
STVM Projects
Automated Cryptographic Validation Testing
Cryptographic Algorithm Validation Program
Cryptographic Module Validation Program
Entropy as a Service
FIPS 140-3 Development
FIPS 140-3 Transition Effort
Measuring Security Risk in Enterprise Networks
National Checklist Program
National Vulnerability Database
SCAP Validation Program
Security Content Automation Protocol
U.S. Government Configuration Baseline