Corsec Corsec is a private company which guides organizations through the security certification & validation process.

For 27+ years we have guided companies through FIPS 140-3, Common Criteria, CSfC, & DoD requirements (STIGs, DoDIN APL, UC APL, etc.). Corsec provides its clients with exceptional consulting and critical expertise to meet their most important business challenges in attaining third-party certifications and security validations and accessing new markets and revenue streams. We draw from our global n

etwork of carefully-vetted third-party accredited laboratories and our internal team of highly qualified professionals in the fields of information security and interoperability to help our clients get through the security certification process for FIPS 140, Common Criteria, and the DoDIN APL. While Corsec traces our roots to our founding in a FIPS 140 laboratory, we have grown significantly since then to become a global partner in enabling market access through a combination of offerings, competencies and expertise in a number of practice areas for our clients across the globe. At the same time, we have become a top career option for the best graduates and security professionals worldwide, with varied career growth paths. Corsec is committed to investing what it takes โ€“ in our all-star team and our systems and processes โ€“ to help our clients stay at the top of their game. We have built a world-class firm that enables product vendors to tap into new revenues and markets and drive improvements to their bottom line.

๐Ÿ” Your August roundup of key updates from NIST, DISA, & NIAP, including updates relevant to FIPS 140, Common Criteria, &...
09/01/2026

๐Ÿ” Your August roundup of key updates from NIST, DISA, & NIAP, including updates relevant to FIPS 140, Common Criteria, & DoD STIGs:
https://www.corsec.com/fed-aug26/

Stay informed with the latest federal cybersecurity news, certification updates, and insights from August 2026 in this blog post.

Myth  #5: FIPS 140-3 validation isn't worth the cost or time.Reality: The cost of not being validated may be far greater...
08/26/2026

Myth #5: FIPS 140-3 validation isn't worth the cost or time.
Reality: The cost of not being validated may be far greater.

Read the final installment of our FIPS Myths & Realities series:
๐Ÿ“– https://www.corsec.com/fips-myths-5/

Explore the true costs and timelines of FIPS 140-3 validation and why early planning can make compliance more predictable and worthwhile.

๐Ÿšจ New Blog Alert! ๐ŸšจThink your FIPS 140-2 validation means youโ€™re covered for FIPS 140-3? Think again.FIPS 140-2 and FIPS...
08/12/2026

๐Ÿšจ New Blog Alert! ๐Ÿšจ

Think your FIPS 140-2 validation means youโ€™re covered for FIPS 140-3? Think again.

FIPS 140-2 and FIPS 140-3 are different standards, and an existing FIPS 140-2 certificate does not automatically become a FIPS 140-3 validation. With the September 21, 2026, sunset date approaching for remaining FIPS 140-2 validations, now is the time to understand where your product stands.

In our latest blog, we break down this common misconception and what organizations should consider when transitioning from FIPS 140-2 to FIPS 140-3.

Read the full blog here๐Ÿ‘‰ https://www.corsec.com/fips-myth-4/

๐Ÿ” Your July roundup of key updates from NIST, DISA, & NIAPโ€” including updates relevant to FIPS 140, Common Criteria, & D...
08/04/2026

๐Ÿ” Your July roundup of key updates from NIST, DISA, & NIAPโ€” including updates relevant to FIPS 140, Common Criteria, & DoD STIGs:
https://www.corsec.com/fed-july26/

Stay informed with the latest federal cybersecurity news, certification updates, and insights from July 2026 in this blog post.

**Myth  #3:** FIPS validation is just a documentation exercise.**Not true! Documentation is important, but validation al...
08/03/2026

**Myth #3:** FIPS validation is just a documentation exercise.**

Not true! Documentation is important, but validation also requires technical testing, engineering effort, and careful planning. Understanding what's involved can help you avoid costly delays and rework.

Read the blog: https://www.corsec.com/myth-3/

Many organizations assume FIPS 140-3 validation is mostly documentation. Learn why engineering, testing, and implementation drive success.

**Myth  #2: Using FIPS-approved algorithms means your product is FIPS 140-3 compliant.**Not quite.While approved algorit...
07/22/2026

**Myth #2: Using FIPS-approved algorithms means your product is FIPS 140-3 compliant.**

Not quite.

While approved algorithms are a critical part of the process, FIPS 140-3 validation evaluates much more than the algorithms themselves. Understanding the difference can help organizations avoid delays, unexpected costs, and compliance challenges.

Learn what's really required in our latest FIPS Myths blog:

๐Ÿ“– https://www.corsec.com/fips-myth-2/

Think you understand FIPS 140-3?Many organizations rely on cryptography to protect sensitive information, but common mis...
07/15/2026

Think you understand FIPS 140-3?

Many organizations rely on cryptography to protect sensitive information, but common misconceptions about FIPS 140-3 validation can create confusion around compliance, product readiness, and market access.

Our Deconstructing FIPS 140-3: 5 Myths and Realities blog series explores the most common myths and explains what organizations should know when planning for validation.

๐Ÿ“– Read the series: https://www.corsec.com/fips-myths/

Explore five common misconceptions about FIPS 140-3 validation and learn how they impact compliance, product development, and market access.

Our Common Criteria Myth series has officially come to a close!If you've been following along, our final blog brings tog...
07/08/2026

Our Common Criteria Myth series has officially come to a close!

If you've been following along, our final blog brings together the key lessons from the series and explains what organizations should keep in mind when planning for Common Criteria certification.

Want a quick summary instead? We've also created a downloadable Common Criteria Myths One-Pager that compiles all of the myths and realities into one convenient resource.

๐Ÿ“– Read the final blog: https://www.corsec.com/cc-myths-lessons-learned/

๐Ÿ“„ Download the one-pager: https://ww3.corsec.com/myths-common-criteria

A breakdown of Common Criteria misconceptions and lessons learned, including cost, scope, maintenance, and global certification realities.

A new White House EO accelerates federal PQC requirements. Learn what it means for product vendors and the areas of comp...
07/02/2026

A new White House EO accelerates federal PQC requirements.

Learn what it means for product vendors and the areas of compliance they must address.
https://www.corsec.com/eo-pqc/

๐Ÿ” Your June roundup of key updates from NIST, DISA, & NIAPโ€” including updates relevant to FIPS 140, Common Criteria, & D...
07/01/2026

๐Ÿ” Your June roundup of key updates from NIST, DISA, & NIAPโ€” including updates relevant to FIPS 140, Common Criteria, & DoD STIGs
https://www.corsec.com/fed-june26/

Stay informed with the latest federal cybersecurity news, certification updates, and insights from June 2026 in this blog post.

Address

12600 Fair Lakes Circle, Suite 210
Fairfax, VA
22003

Opening Hours

Monday 8am - 6pm
Tuesday 8am - 6pm
Wednesday 8am - 6pm
Thursday 8am - 6pm
Friday 8am - 6pm

Telephone

(703) 267-6050

Alerts

Be the first to know and let us send you an email when Corsec posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Corsec:

Shortcuts

Share