Curity Adds FIPS 140-3 Compliant Mode to Identity Server Ahead of NIST's September Deadline

Curity Adds FIPS 140-3 Compliant Mode to Identity Server Ahead of NIST's September Deadline

Curity announces the release of the Curity Identity Server 11.4, introducing an FIPS-compliant mode ahead of the September 21 deadline for the use of FIPS 140-2 validated modules in new federal systems.

National Institute of Standards and Technology (NIST) will move all remaining FIPS 140-2 certificates to the historical list. Existing deployments can continue using them, but from that date, a FIPS 140-2 validation will no longer meet the requirements for new federal procurement. Anything acquired after that will need an active FIPS 140-3 validation.

Beyond federal procurement, FIPS validation is also regularly used as a benchmark for cryptographic assurance in highly regulated environments, including defense, financial services and critical infrastructure.

With the Curity Identity Server 11.4, Curity customers can configure the platform to run in FIPS-compliant mode, so only NIST-approved cryptographic algorithms are permitted and non-compliant algorithms are automatically rejected. The mode is built on pre-certified cryptographic modules, giving organizations a validated foundation without additional certification work on their own. For environments requiring an even higher level of assurance, Curity also supports the use of Hardware Security Modules (HSMs). FIPS-compliant mode ships as a Docker image, available through Curity's FIPS support add-on.

"The September deadline is an immediate reason for organizations to look at this, but the bigger shift is that strong cryptographic assurance is increasingly expected well beyond US federal procurement. Organizations in regulated industries want to know that the security infrastructure they depend on is using validated, modern cryptography, and that they can demonstrate that to their customers," said Jacob Ideskog, CTO at Curity.

Additional capabilities in the Curity Identity Server 11.4:

  • Extended DPoP binding: Demonstrating Proof of Possession (DPoP) token binding now extends across the OAuth endpoints. This means a token only works for the client that earned it, so a stolen one is worth nothing on its own. The added protection is particularly relevant as more tokens are issued to autonomous API clients and AI agents.
  • Database Scopes in the Admin UI: Teams managing large or fast-moving scope catalogs can make changes without redeploys, right where they already work.

Curity recommends organizations that supply federal agencies or operate in regulated industries review the cryptographic modules used across their identity infrastructure ahead of the September deadline, particularly where FIPS requirements form part of procurement, compliance or customer assurance processes.

The Curity Identity Server 11.4, including FIPS-compliant mode, is available today. Learn more and get started here: https://curity.io/blog/curity-identity-server-11-4/