Identify requirements
- Last Updated: February 11, 2026
- 1 minute read
- OpenEdge
- Version 13.0
- Documentation
Your application may or may not have to adhere to a particular FIPS standard. Your application may benefit from using NIST-approved algorithms or may require full FIPS certification, which requires CMVP validation and certification from a third-party, NIST-accredited lab. Identify your requirements and next steps.
| Security requirement | Next steps |
|---|---|
| Use stronger encryption algorithms | No additional license required.
|
| Use FIPS mode | Requires Progress® OpenEdge Advanced Security (OEAS) license.
|
| Become FIPS compliant | Enabling FIPS mode does not make your application FIPS compliant. Application code, as well as all external dependencies like OS, hardware, and third-party libraries, must follow the FIPS 140 standard. Compliant states adherence to the FIPS 140 standard but does not have third-party CMVP validation. |
| Certify your application | FIPS compliant applications may opt to complete the CMVP certification process. |