elastic / elastic/roadmap

FIPS 140-3 support for Elasticsearch and Kibana

Open
#250 0 comments 0 reactions 1 assignee Claimed by @bytebilly View on GitHub
Component: Elasticsearch Component: Kibana product-area:platform v9.4.0
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**Value proposition**

Organizations in **regulated and public-sector** environments must run workloads that use **FIPS-validated cryptography**. As the ecosystem moves from **FIPS 140-2** toward **FIPS 140-3**, customers need a **clear, supported path** on the Elastic Stack so they can **stay compliant** and **reduce reliance on exceptions**.

**Expected outcome**

- **Broader eligibility** for Elastic in **government, defense, finance, healthcare**, and other sectors with strict cryptographic baselines.
- **Reduced friction** for security, platform, and compliance stakeholders: alignment with **industry timelines** for 140-2 sunset and 140-3 adoption.
- Customers who **must** run in **FIPS 140-3** mode can do so on **supported stack versions**, including a path for teams not yet on the latest major (**8.19.x** as well as **9.x**).
- **FIPS 140-2** remains available where needed for **backward compatibility** during migration; we do not force an immediate breaking change for existing 140-2 deployments.

**Key user stories / use cases**

1. **As a security or compliance lead**, I need our Elasticsearch and Kibana deployment to operate with **FIPS 140-3-validated cryptography** so our **assessors and authorizing officials** accept the stack under current and upcoming requirements.

1. **As a platform architect**, I need **first-class FIPS 140-3 support** in Elasticsearch and Kibana so I can **standardize on Elastic** in a **FIPS-enforced** environment without unsupported workarounds.

1. **As a federal or regulated program**, I need the stack to align with **FIPS 140-3** expectations so we can **renew authorizations**, pass **crypto reviews**, and **de-risk** dependency on **sunsetting 140-2** modules and programs.

1. **As a customer still on FIPS 140-2**, I need **140-2 to remain available** until we complete testing and cutover, so we can **migrate on our schedule** without losing backward compatibility.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.