# Contractors Verify Windows FIPS Modules

Microsoft documentation lists NIST Cryptographic Module Validation Program (CMVP) FIPS 140 certificates for cryptographic modules in Windows 11 versions 21H2 and 22H2. The documentation does not establish that Windows 11 as a whole is a single validated module; contractors supporting government environments should match the deployed Windows build and cryptographic module to the applicable certificate and confirm that the module is operating in the mode specified by its security policy.

- Procurement teams evaluating Windows-based solutions can use the module-specific certificates and linked security policies to verify claims about FIPS-validated cryptography.
- Contractors should confirm that the exact build, module certificate, and required operating mode align with the security policy applicable to their government environment; validation should not be inferred from the operating system name alone.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 05, 2026

### Government Entities
- National Institute of Standards and Technology (NIST)

### Key Quotes
> The linked Security Policy document for each module provides details on the module capabilities and the policies the operator must follow to use the module in its FIPS approved mode of operation.
> — Original poster

### Sources
- [Question about FIPS](https://www.reddit.com/r/CMMC/comments/1wy98ee/question_about_fips) - reddit-cmmc