Lightship Security, an accredited cryptographic security test laboratory and part of Applus+ Laboratories, together with the OpenSSL Corporation, has announced the submission of OpenSSL version 3.5.4 to the Cryptographic Module Validation Program (CMVP) for FIPS 140-3 validation. This submission signifies that the OpenSSL 3.5.4 codebase is complete and that all cryptographic algorithms included in the module have successfully passed both NIST testing and independent laboratory review. The FIPS 140-3 validation is a critical compliance requirement for cryptographic modules used in government and regulated industries, ensuring that the cryptographic implementations meet stringent security standards. The final step remaining in the process is the CMVP’s review and the issuance of the official FIPS 140-3 certificate. OpenSSL 3.5, which was released in April 2025, introduced support for post-quantum cryptographic (PQC) algorithms such as ML-KEM, ML-DSA, and SLH-DSA, aligning with NIST’s ongoing PQC standardization efforts. The submission of version 3.5.4 for FIPS validation is particularly significant as it represents the first move toward a FIPS-validated, PQC-ready cryptographic module, which is essential for organizations preparing for the advent of quantum computing threats. The OpenSSL 3.5.4 FIPS Object Module is designed to be open-source and standards-compliant, making it suitable for deployment across a wide range of government and industry applications. Once the FIPS 140-3 certification is granted, organizations will be able to deploy OpenSSL 3.5.4 in environments that require validated cryptographic solutions, thereby enhancing their security posture and compliance. The collaboration between Lightship Security and the OpenSSL Corporation underscores a commitment to maintaining validated, standards-based cryptography in one of the world’s most widely used open-source libraries. OpenSSL is foundational to internet infrastructure, embedded systems, and enterprise applications, making this validation effort highly impactful. The successful completion of NIST and independent laboratory testing demonstrates the robustness and reliability of the cryptographic algorithms implemented in OpenSSL 3.5.4. The FIPS 140-3 validation process is rigorous, involving detailed technical scrutiny and compliance checks, which OpenSSL 3.5.4 has now largely completed. The announcement has been recognized as a significant milestone in the ongoing effort to provide secure, compliant, and future-proof cryptographic solutions. Organizations across sectors are expected to benefit from the availability of a FIPS-validated, PQC-ready OpenSSL module. The move also supports broader industry and governmental initiatives to prepare for quantum-resistant cryptography. The final certification, once issued, will enable widespread adoption of OpenSSL 3.5.4 in regulated environments. This development is expected to influence cryptographic best practices and compliance strategies globally. The partnership between Lightship Security and the OpenSSL Corporation is anticipated to continue driving innovation and assurance in open-source cryptography.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Lightship Security and the OpenSSL Corporation submitted OpenSSL 3.5.4 for FIPS 140-3 validation. Multiple references report the same submission as the key development in the story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcehackread.com
Open sourcesecuritysenses.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.