# FIPS 140-2 moves to the Historical List on September 22

Canonical: https://brew.new/templates/goteleport/fips-140-2-moves-to-the-historical-list-on-september-22

Brand: goteleport.com
Category: newsletter

![Preview of FIPS 140-2 moves to the Historical List on September 22](https://cdn.brew.new/email-preview-ccf9d63968d3d332-tracking_r57y98d6xgyrdk95r7m5y5e5d18ews2t-1790108467677.png)

## Email content

Teleport

New in Identity

Teleport — The AI Infrastructure Identity Company

Standards bodies set the calendar for infrastructure teams this fall, and the dates hold regardless of what a roadmap says. A validation program retires a generation of certificates this month, an auditor decides whether your evidence ties a control to a person and a time, and European law starts asking for incident reports on products in the field. All three demand proof that a reader outside your team accepts, so the records your access layer produces carry the weight.

Cisco and Teleport Advance Infrastructure Identity

Cisco is Teleport's largest strategic investor, and the partnership it anchors covers technology integration and licensing alongside that investment. Peter Bailey, SVP and GM of Cisco's Security Business Group, and Teleport CEO Ev Kontsevoy set out the principle behind it: no anonymous computing in critical infrastructure. The first use case is privileged access for network and infrastructure administrators, where an engineer entering a maintenance window verifies identity and requests only the access that task needs, Teleport brokers and records the session, and the privilege ends with the window. The engineer never receives a reusable credential.

Read the announcement →

FIPS 140-2 vs FIPS 140-3, Explained

By Mayur Pipaliya

On September 22, 2026, the National Institute of Standards and Technology moves every certificate under Federal Information Processing Standards 140-2 onto its Historical List, one day after those certificates lose Active status. Historical status blocks procurement for systems you have yet to build, though the Cryptographic Module Validation Program supports the purchase and use of those modules inside systems that run today. The post lays out the transition dates, the change from critical security parameters to sensitive security parameters, the requirements that cover side-channel attacks, and the way to read a certificate number on the NIST site.

Read the full post →

ISO 42001 Evidence: What Auditors Ask For

By Preet Dhatt

Organizations fail ISO 42001, the management system standard for artificial intelligence, in three ways: the control ran and nobody captured proof, the control ran and the record ties to no person or time, or the control never existed at all. Preet Dhatt sits on both sides of that table as an auditor and an auditee, and he rejects an access review when the artifact cannot say who performed it, when, and against what source. Dhatt matches the evidence he asks for to each control, and he hands you a test to run on your last three access reviews before an assessor arrives.

Read the full post →

How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate

By Maximilian Heck, Waldemar Kindler

The European Union Cyber Resilience Act applies its incident and vulnerability reporting obligations from September 2026, and the rest of the law arrives in December 2027. The European Union Agency for Cybersecurity turned that law into 22 playbooks, and five of the eight in its phase-1 baseline land on the access layer: logging and alerting, supply-chain controls, restrictive initial access, communication between components, and identity for every device. The walkthrough sets each of those five against the controls that answer them, from the certificates that stand in for passwords and keys to the audit trail an assessor reads.

Read the full post →

From the community

Aditya Soni, a Cloud Engineer III at Warner Music Group, describes an AI agent debugging a production Kubernetes issue by reading logs, checking resources, and calling APIs, then asks how far a team should trust it. Abhishek Veeramalla lists what a deployment pipeline holds to authenticate itself, from long-lived AWS keys to API keys sitting in GitHub Secrets, and asks whether it needs any of them. An agent and a pipeline arrive at the same requirement: a short-lived cryptographic identity issued at runtime that expires when the work ends.

Read Aditya Soni's X post →

Read Abhishek Veeramalla’s LinkedIn post →

Have questions or want to keep the conversation going? Join us in our Community Slack →

If you found this useful, pass it along to someone else who would, too.

Thanks for reading,

The Teleport Editorial Team

P.S. Teleport Identity Summit runs September 24 at the Computer History Museum in Mountain View and September 30 at the Lotte Palace in New York, and Cisco presents at both. Register to attend.

We'll be at these events too. Come find us.

Sept 22: DevOpsDays Rockies Denver, CO

Sept 22: Civo Navigate London

Sept 24: SRE Day London

Sept 24: (A)Identity Day London

Sept 24: PlatformCon Paris

Sept 24: FutureCon Denver, CO

Sept 24: Teleport Identity Summit Mountain View, CA

Sept 30: Teleport Identity Summit New York, NY

Find us near you: https://goteleport.com/events/

Teleport, 2100 Franklin St, Suite 400, Oakland, CA 94612

If you no longer wish to receive these emails anymore, click on the following link:

UNSUBSCRIBE

TERMS OF SERVICE | PRIVACY POLICY | SECURITY POLICY

[Open and remix this design](https://brew.new/templates/goteleport/fips-140-2-moves-to-the-historical-list-on-september-22)

[Browse email designs](https://brew.new/browse/templates)
