Features > Transfer Security > FIPS 140-3 Validation
Cerberus FTP Server
FIPS 140-3 Compliant File Transfer
Cerberus FTP Server 2026.1 and higher uses an embedded FIPS 140-3-validated cryptographic module (Certificate #4985 using the OpenSSL 3 FIPS Provider Module) for all cryptographic operations and meets federal cryptographic requirements with FIPS 140-3 validated cryptography up to 256-bit AES encryption over SSL and SSH.
Meets all FIPS 140-3 cryptographic requirements
Certified by NIST/CSEC’s Cryptographic Module Validation Program
What is FIPS 140-3 Compliance?
NIST‘s Federal Information Processing Standard (FIPS) publications establish a security standard for cryptographic modules used by the U.S. federal government in the collection, storage, transfer, sharing and dissemination of sensitive information. FIPS 140-3 is the most current standard, and most federal agencies and regulated industries must comply with the FIPS 140-3 standard by law. All products sold to the federal government that use cryptographic modules must be FIPS 140-3 validated by September 1, 2026 (when the older FIPS 140-2 standard sunsets).
What Organizations Require FIPS-Compliant File Transfer?
The organizations below are required to use FIPS-compliant cryptography by law:
- U.S. federal and state government agencies that deal with citizens’ private information
- The U.S. military and its vendors working with sensitive but unclassified data
- Vendors, suppliers and third parties selling cryptographic modules to the federal government or using these modules in support of their services
Industries that deal with sensitive data requiring high levels of privacy for regulatory or security reasons will often require the FIPS 140-3 standard as well. These industries include:
- Financial institutions
- Information-processing vendors
- Healthcare-related organizations that fall under HIPAA regulation
- Educational institutions
- Utilities
However, the FIPS 140-3 standard can be used any organization that wishes to transfer files securely, safeguard business data, and protect its most critical information.
What Does it Mean to be FIPS 140-3 Compliant?
FIPS-validated solution must use cryptographic algorithms and hash functions that meet the FIPS requirements. Specifically, a FIPS-validated solution must:
- Use algorithms and hash functions approved under FIPS 140-3 requirements
- Be validated by the joint NIST/CSEC Cryptographic Module Validation Program (CMVP)
Try Cerberus FTP Server free for 25 days
- Live US-based phone & email support
- Bulletproof reliability
- Built for complete data control
- Trouble-free enterprise deployment
Full Cerberus FTP Server Feature List
Protocols
FTP, FTP/S, SFTP, SCP, HTTP/S
Advanced Security
SSH, SSL, FIPS 140-3
MFT Automation
Event, Alert & Sync Tools
Environments
Windows Server, Cloud & Virtual
Access Protection
IP, User & Protocol Restriction Tools
Account Management
AD, LDAP, 2FA, SSO & More
Auditing and Reporting
File Access, User and Admin Logging
Administration Tools
API, Sync Manager, & Other Tools
HTTPS Web Portal
Browser-Based Transfer from Any Device
Monitoring & Testing
Automated Network, Load and Access Testing
Regulatory Compliance
Auditing, Retention, & Encryption Tools
Award-Winning Support
Phone, Email, & 24/7/365
Industry-Focused Solutions
Cerberus FTP Server supports a wide range of industry and professional needs. Enhance data security, streamline operations, and ensure compliance with regulations.
Uncompromising Commitment To Customer Satisfaction
G2
4.8 / 5
Capterra
4.8 / 5
CNET Download
4.8 / 5
Recognized as an industry-leading secure FTP server
Trusted by Companies Like Yours
Uncompromising Customer Satisfaction
Latest News
Cerberus FTP Server 12.5 Introduces “Zip and Download” For Multiple Files
Save clicks and time with this new and efficiency-improving feature - download multiple files and folders by bundling them together in a single downloadable file. About the new feature Users have frequently requested a faster way to download multiple files and folders...
Zip/Unzip permission bypass vulnerability fixed in Cerberus FTP Server versions 11.0.3 and 10.0.18
Security Advisory Description Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 are vulnerable to a permissions bypass when a user has zip/unzip permission. When zipping, users could zip files and folders that weren't visible to them; and...
SFTP Two-Factor Authentication
Note: Cerberus FTP Server 2024.2 includes an enhancement to these configuration settings, detailed in this post. In Cerberus FTP Server 2024.1, we have added Two-Factor Authentication (2FA) support for SFTP and SCP. We support both time-based one-time password (TOTP)...
Explore what Cerberus FTP Server can do for you
- 25 Day Free Trial
- No Credit Card Required
- Up and running in less than 15 mins


