FIPS 140-2 requirements, TLS configuration, encryption at rest and in transit, cryptographic key management, and password storage. Six NIST 800-171 practices covered in one document.
What Is Included
FIPS 140-2 / FIPS 140-3 compliance requirements and approved algorithm table
TLS 1.2 / 1.3 configuration requirements and prohibited protocol list
Encryption at rest: BitLocker, FileVault, mobile devices, removable media
Encryption in transit: email (S/MIME, TLS), web, API, file transfer requirements
Password cryptographic storage and transmission requirements (3.5.10)
Roles and responsibilities matrix
Exception process and compliance assessment guidance
Document control and signature block
Practice Coverage
3.13.8Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission
3.13.10Establish and manage cryptographic keys when cryptography is employed
3.13.11Employ FIPS-validated cryptography when used to protect the confidentiality of CUI
3.13.16Protect CUI at rest
3.5.10Store and transmit only cryptographically-protected passwords
3.1.19Encrypt CUI on mobile devices and mobile computing platforms
Frequently Asked Questions
This policy covers six NIST SP 800-171 Rev 2 practices: 3.13.8 (encrypt CUI in transit), 3.13.10 (key management), 3.13.11 (FIPS-validated cryptography), 3.13.16 (encrypt CUI at rest), 3.5.10 (cryptographically protected passwords), and 3.1.19 (encrypt CUI on mobile devices).
FIPS 140-2 is the federal standard for cryptographic module validation. CMMC practice 3.13.11 requires that any cryptography used to protect CUI confidentiality must use FIPS-validated modules - meaning the specific implementations must be tested and certified by NIST's CMVP, not just any commercially available encryption. AES-256, TLS 1.2/1.3 with approved ciphers, and BitLocker are all FIPS-compatible when configured correctly.
Yes. The template includes specific guidance for Windows BitLocker with Entra ID key escrow, Intune mobile device encryption enforcement, and TLS configuration requirements applicable to M365 environments. Placeholders indicate where organization-specific implementation details should be added.
A properly completed version of this policy - with your organization's actual implementation details filled in - addresses the documentation requirement for these six practices. C3PAO assessors will also verify that the technical controls described in the policy are actually implemented. The policy is the documentation layer; the technical implementation is verified separately.