HomeBlog › The 542-Day Wait to Sell to the Government
Defense Tech

The 542-Day Wait to Sell to the Government

Today every remaining FIPS 140-2 certificate became historical, and the replacement now takes an average of 542 days to get. In federal and defense tech, the clock is the barrier, not the code.

One signal a day. No noise. A 3-minute read when something genuinely shifts.
By Tyron Dizon · September 21, 2026 · 5 min read
Today every remaining FIPS 140-2 certificate became historical, and the replacement now takes an average of 542 days to get. In federal and defense tech, the clock is the barrier, not the code.
Source: SafeLogic, on the CMVP FIPS 140-2 to 140-3 transition.

Somewhere in a validation database today, a whole generation of certificates quietly became history. As of 21 September 2026, the Cryptographic Module Validation Program declares every remaining active FIPS 140-2 certificate historical. From today, a vendor cannot use one to support a new acquisition by a US federal organisation.

No product broke. No code changed. The cryptography inside those modules is exactly as sound as it was yesterday. What expired was permission.

The paperwork is load bearing

FIPS 140-2 is not one checkbox among many. It is the cryptography baseline that Common Criteria, FedRAMP, DoDIN APL, CMMC, CSfC, FISMA, NIST SP 800-53 and NIST SP 800-171 all quietly reference. Think of it as the electrical code that a dozen separate building inspections point back to. Change the code once, and every inspection downstream changes with it, whether or not the inspectors mention it by name.

So the interesting number is not the deadline. It is the queue behind it. Average validation time under FIPS 140-2 ran about 367 days. Under FIPS 140-3 it has risen to 542 days, a 42 percent increase. A vendor who starts the process today is realistically looking at October 2027 before it can support new federal business again.

One honesty note, because it matters. The loudest write-up of this deadline comes from SafeLogic, a company that sells a product solving exactly this problem. The transition date itself is long published CMVP policy and I would treat it as solid. The no time left urgency around it is interested commentary, and I could not pull the CMVP notice independently.

And in the same month, a gate opened

Here is the part that makes September strange. While the cryptography gate was closing, the cybersecurity assessment gate swung open.

The Department of Defense suspended CMMC Phase 2 on 13 July 2026, ahead of its scheduled 10 November start, pending a review. That was a memo. On 3 September, John Tenaglia, the Department's Principal Director for Defense Pricing, Contracting and Acquisition Policy, signed Revision 3 of DARS class deviation 2026-O0025, which turns that suspension into binding acquisition regulation. Contracting officers are now instructed to strip CMMC third party assessment requirements out of contracts and to look to the Revolutionary FAR Overhaul instead.

The distinction is the whole story. A suspension memo is policy and can be reversed by announcement. A class deviation is regulation, and undoing it requires regulatory action. Third party cybersecurity assessment was the single largest fixed cost between a small software company and a defense subcontract. Right now it is not required.

Put the two together and the picture is oddly precise. The assessment gate opened. The cryptography gate closed. Anyone treating either as permanent is making a bet on paperwork, which is the one thing in this industry that reliably changes without a press release.

Capability has become the cheap half of the problem. Permission is the expensive half, and it is priced in months.

Being better is not the same as being allowed

If you want proof that the barrier has moved from engineering to procedure, look at what happened at the Department of Homeland Security last week.

DHS finalised Anduril's addition to track one of its 1.5 billion dollar counter drone contract vehicle on 16 September. Anduril had originally won only track two in the August award. It protested the track one evaluation, DHS agreed to re-evaluate, and GAO dismissed the protest three weeks after filing. Anduril, BAE Systems' US subsidiary and Leidos are now the only three companies holding positions on both halves of the five year vehicle.

DHS received 57 proposals for the product portion and 47 for services. That is not an emerging market with room to wander into. And notice how the last position was won: not by a better demo, but by having the legal capacity and the patience to force a re-evaluation. In the same week, Oasis filed a protest over the Army's counter drone award to Parsons, alleging conflicts. Protest capability is now a competency, and it is one a ten person team does not have.

One door, and the list that moved out of it

The front door has also narrowed. A memorandum from Secretary of Defense Pete Hegseth on 29 June 2026 designated the Defense Innovation Unit as the Pentagon's primary liaison with commercial companies across all unmanned and autonomous systems programs, reportedly a portfolio in the region of 75 billion dollars. Meanwhile the Blue UAS Cleared List, which DIU created in 2020, moved to the Defense Contract Management Agency in December 2025 with 39 certified systems and 165 certified components at handoff. DIU still shapes the standards.

Standards setting and list administration are now deliberately separate organisations. One writes what good means, the other checks whether you meet it. One door genuinely lowers discovery cost for a small company. It also removes the second opinion: one door is one place to be rejected, with nowhere to shop the same product afterward.

The 165 components number is the encouraging one. The list is not only about complete aircraft. Certification at the component level is a real path for a team that builds one piece well.

Why this matters even if you never touch defense

Every regulated market has a version of this clock. Capability is compressing fast. Certification is not compressing at all, and in this case it got 42 percent slower. When those two run at different speeds, the winner is rarely the team with the best technology. It is the team that designed around the calendar: shipping as a component inside somebody else's already accredited environment, rather than as a standalone product waiting 542 days for its own stamp.

The second lesson is about windows. The CMMC suspension is real, binding and temporary by construction. Building a business model on it is the same mistake as pricing your margins off a promotional API rate. Use the window. Do not depend on it.

None of this will trend. A certificate quietly going historical is not a launch. But it decides who is allowed to sell, which is a more durable fact than most of what did trend this week.

The certification clock got 42% longerAverage CMVP validation time, FIPS 140-2 compared with FIPS 140-3FIPS 140-2367 daysFIPS 140-3Bars scaled to days. A vendor starting today realistically waits until October 2027.542 daysAll remaining FIPS 140-2 certificates became historical on 21 September 2026. Source: SafeLogic.
Source: SafeLogic, on the CMVP FIPS 140-2 to 140-3 transition.

One signal a day. No noise.

A 3-minute read when something genuinely shifts in AI, automation, or defense tech. Free, most weekdays.

Free, most weekdays. No spam, unsubscribe anytime.

Sources

  1. SafeLogic - What happens on September 21, 2026 - https://www.safelogic.com/blog/what-happens-on-september-21-2026
  2. Nextgov/FCW - CMMC's Phase 2 suspension locked into binding regulation - https://www.nextgov.com/acquisition/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415890/
  3. CyberZ - Analysis of the CMMC Phase 2 class deviation - https://cyberz.pro/blog/2026/09/10/cmmc-phase-2-class-deviation/
  4. Federal News Network - Pentagon suspends CMMC Phase 2 requirements, launches review - https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/
  5. Washington Technology - Anduril now covers both halves of $1.5B DHS counter-UAS contract - https://www.washingtontechnology.com/contracts/2026/09/anduril-now-covers-both-halves-15b-dhs-counter-uas-contract/416027/
  6. Washington Technology - Oasis claims conflicts in Army's C-UAS award to Parsons - https://www.washingtontechnology.com/contracts/2026/09/oasis-claims-conflicts-armys-c-uas-award-parsons/416086/
  7. DroneXL - Pentagon names DIU as front door for drone programs - https://dronexl.co/2026/07/01/pentagon-drone-czar-drpm-uxs-diu/
  8. Spencer Fane - DIU: the Pentagon's front door for unmanned systems technology companies - https://www.spencerfane.com/insight/defense-innovation-unit-the-pentagons-front-door-for-unmanned-systems-technology-companies/
  9. DIU - Blue UAS List to transition to DCMA - https://www.diu.mil/latest/dius-blue-uas-list-to-transition-to-dcma
  10. National Defense Magazine - Pentagon's vetted drone program moves to new agency - https://www.nationaldefensemagazine.org/articles/2026/1/26/pentagons-vetted-drone-program-moves-to--new-agency

Quick answers

What actually happened on 21 September 2026?

The Cryptographic Module Validation Program declared all remaining active FIPS 140-2 certificates historical. From that date, a vendor cannot use a FIPS 140-2 certificate to support a new acquisition by a US federal organisation.

How much longer does the replacement certification take?

Average validation time has risen from about 367 days under FIPS 140-2 to about 542 days under FIPS 140-3, an increase of 42 percent. A vendor beginning the process now is realistically looking at October 2027.

Is CMMC gone?

No. CMMC Phase 2 was suspended on 13 July 2026 ahead of its scheduled 10 November start, and on 3 September that suspension was codified in Revision 3 of DARS class deviation 2026-O0025, which contracting officers must follow. A class deviation is binding but temporary, and can be rescinded or folded into the FAR.

Does this shut small companies out of federal work?

Not entirely. The barrier falls hardest on products that need their own validated cryptography. Component level paths still exist: the Blue UAS Cleared List moved to DCMA in December 2025 with 39 certified systems and 165 certified components, and DIU is now the Pentagon's primary commercial liaison for unmanned and autonomous systems.

Tyron Dizon is a Chief Product Officer, AI product builder, and Techstars-backed SaaS founder based in Baguio City, Philippines. He previously co-founded and served as CPO of SanityDesk and now builds AI products, automation systems, SaaS platforms, and rapid prototypes. About · Work · Resume · LinkedIn