As of November 7, 2020, the CMVP requires that all FIPS 140-2 and FIPS 140-3 module validation submissions include documentation justifying conformance to SP 800-90B if applicable. SP 800-90B, along with FIPS 140-3 Implementation Guidance documents (IGs) D.J, D.K, and D.O, outline the requirements for an entropy source to be included in a FIPS-approved cryptographic module. With the publication of SP 800-90C, the CMVP is also accepting submissions for Random Bit Generators. The associated IG is IG D.T.
The list of validated entropy sources can be found in the Entropy Source Validation Search.
The National Voluntary Laboratory Accreditation Program (NVLAP) manages the validation lab accreditation process. This is outlined in NIST Handbook 150-17. The CMVP is working to update this document with a new 17ESV accreditation scope. The 17ESV scope will allow accredited labs to submit justifications of conformance to SP 800-90B to the CMVP for entropy sources to receive an Entropy Validation Certificate, or to SP 800-90C for random bit generators to receive a Random Bit Generator Validation Certificate.
Questions may be directed to the CMVP.
Security and Privacy: cryptography, testing & validation
Technologies: hardware, software & firmware