WinMagic Achieves FIPS 140-3 Validation, Continuing 24 Years of Unbroken Cryptographic Certification as Identity Moves to the Endpoint

PR Newswire
Today at 6:40pm UTC

WinMagic Achieves FIPS 140-3 Validation, Continuing 24 Years of Unbroken Cryptographic Certification as Identity Moves to the Endpoint

PR Newswire

Validation continuity that began with AES Certificate #1 in 2002 now spans every generation of the FIPS standard — at a moment when the endpoint, not the cloud, is becoming the foundation of online identity

TORONTO, May 5, 2026 /PRNewswire/ -- WinMagic Corp. today announced FIPS 140-3 validation for its SecureDoc and MagicEndpoint cryptographic modules (CMVP Certificates #5204 and #5214). The validation extends an unbroken 24-year record across all three generations of the FIPS standard — an engineering continuity that is, on its own, the longest in the full-disk encryption industry. It also arrives at a moment when that record matters in a new way: as passkeys, hardware-bound keys, and Zero Trust extend identity verification to the endpoint itself, the cryptographic integrity of the endpoint is becoming the foundation of online access, not just a requirement for data at rest.

Twenty-Four Years of Continuous Cryptographic Validation

WinMagic's FIPS 140-3 certification extends an unbroken record that began in 2000:

  • 2000 — Common Criteria certification. The world's first full-disk-encryption solution to achieve Common Criteria certification, presented at the inaugural global ceremony.
  • 2000 — NSA certification for SECRET level Full-Disk-Encryption with FORTEZZA PC-card. The first disk encryption certified by the NSA for US Government agencies to SECRET level.
  • March 2002 — AES Certificate #1. The first AES algorithm validation issued by NIST to any commercial vendor. The implementation was the SecureDoc Cryptographic Engine.
  • May 2002 — FIPS 140-1 Certificate (#209). Cryptographic module validation under the original FIPS 140 standard.
  • 2006 — FIPS 140-2 Levels 1 and 2. The first full-disk encryption technology to achieve FIPS 140-2 validation, and the first to certify at both Level 1 (#699) and the more demanding Level 2 (#698), which requires tamper-evidence mechanisms and role-based authentication.
  • 2006 — 2026 — Continuous FIPS 140-2 revalidation. WinMagic has maintained active FIPS 140-2 certifications continuously for 20 years.
  • 2026 — FIPS 140-3. Certificates #5204 and #5214. Continuous validation across all three generations of the FIPS standard. Achieving these validations ensure that WinMagic's products remain at the absolute forefront of modern cryptography and cryptographic compliance.

Why This Validation Matters Differently in 2026

For most of the FIPS standard's history, the question it answered was narrow: is the cryptography that protects data at rest mathematically sound and correctly implemented? That is still the question. But passkeys, hardware-bound credentials, and continuous endpoint attestation have widened what depends on the answer.

When the endpoint generates identity-bearing keys in a TPM, asserts user presence on behalf of a remote service, and continuously attests to its own posture, the cryptographic integrity of the endpoint is no longer adjacent to identity — it is identity. An endpoint that cannot prove boot integrity, cannot protect its key material, or cannot maintain verified state is not qualified to authenticate anything. FIPS 140-3, with TPM 2.0 and continuous attestation, is what "endpoint as trust anchor" looks like under the hood.

We've held FIPS validation continuously since 2002 because cryptographic rigor is an engineering discipline, not a marketing claim. The discipline mattered for data at rest. It matters more now. Passkeys, Live Key, and every hardware-bound identity scheme rest on the same assumption: that the device generating the key, protecting the key, and asserting identity is cryptographically sound. As identity moves to the endpoint, that assumption stops being adjacent to compliance and starts being the whole game.

— Thi Nguyen-Huu, Founder & CEO, WinMagic Corp.

Where the Validation Applies

  • CMMC Level 2. SecureDoc meets NIST SP 800-171 IA.L2-3.13.11 & 3.13.16 with FIPS 140-3 validation, ahead of the September 2026 transition that moves FIPS 140-2 modules to the CMVP Historical List.
  • Critical infrastructure and OT. CISA's April 2026 guidance on Zero Trust for operational technology calls for hardware-anchored, continuously-attested identity.
  • Federal and defense procurement. DOD, DOE, and federal agency requirements where FIPS 140-3 is the current standard.
  • International deployments. Common Criteria and FIPS together address the cryptographic certification requirements of European government and sovereignty-aligned procurements.
  • Endpoint-centric identity architectures. Passkeys, Live Key, and TPM-bound credentials all depend on cryptographically sound endpoints. FIPS validates that foundation.

Beyond Certification: Active Standards Work

WinMagic's engineering posture extends beyond product certification. The company is currently engaged with the standards bodies whose work will shape the next decade of identity architecture:

  • W3C — Submissions to the WebAuthn and WebAppSec working groups, March 2026.
  • IETF — Internet-Draft draft-winmagic-lit-00, published March 5, 2026.
  • DIF — Submission to the Decentralized Identity Foundation, March 25, 2026.
  • Open-source reference implementation. github.com/WinMagic/LIT

What mTLS, TPM, and passkeys started, the standards work completes — embedding identity in the secure channel itself, so there is no token to steal and no session to hijack.

— Thi Nguyen-Huu

About WinMagic

Founded in 1997 in Mississauga, Ontario, WinMagic Corp. has spent twenty-nine years advancing endpoint security and cryptographic identity. The SecureDoc platform protects endpoints in critical environments worldwide, including DOE national laboratories, defense contractors, Fortune 500 enterprises, and government agencies. MagicEndpoint extends the same hardware-anchored trust model into online authentication. WinMagic holds the industry's longest continuous record of cryptographic validation — AES Certificate #1 (2002), Common Criteria (2000, first FDE solution), FIPS 140-1 (2002), FIPS 140-2 Levels 1 and 2 (2006, first FDE solution), through FIPS 140-3 (2026).

Media Contact
WinMagic Corp.
Email: press@winmagic.com
Web: www.winmagic.com

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/winmagic-achieves-fips-140-3-validation-continuing-24-years-of-unbroken-cryptographic-certification-as-identity-moves-to-the-endpoint-302762985.html

SOURCE WinMagic