Crypto Algorithm Compliance Checker
Paste the cipher suites, hashes and key sizes your systems use and see which are FIPS-approved, which NIST has deprecated or disallowed, and which PCI DSS no longer accepts.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Approved, deprecated and disallowed are three different states
NIST SP 800-131A distinguishes algorithms that may be used, algorithms that may still be used to process previously protected data but not to apply new protection, and algorithms that may not be used at all. Treating this as a binary approved-or-not question produces the wrong answer for the middle category, which is where most real systems sit. SHA-1 for signature generation is disallowed while SHA-1 inside HMAC remains acceptable, and a checklist that does not distinguish the two will flag working systems and miss broken ones.
Key size changes the answer more than the algorithm name
RSA is approved and RSA-1024 is not. Triple DES was withdrawn entirely for new encryption after 2023. AES is approved at 128, 192 and 256 bits but a specific mode may not be, and ECB is not approved for any key size because it leaks structure in the plaintext. The algorithm name alone is never enough to answer the question, which is why a policy that lists algorithms without parameters cannot be assessed.
PCI moved before NIST did on TLS
PCI DSS required the retirement of TLS 1.0 in 2018 and treats TLS 1.1 as no longer providing strong cryptography, while NIST guidance took longer to reach the same position. An organisation reading only one of the two will be late on the other. This tool reports each source separately for that reason, and it evaluates cipher suites down to their component parts, since a suite can pair an approved cipher with an unapproved key exchange.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
What is the difference between deprecated and disallowed?
Deprecated means the algorithm may still be used to process data protected earlier, but not to apply new protection. Disallowed means it may not be used at all. SP 800-131A defines both, and treating the question as binary gives the wrong answer for the middle category.
Is SHA-1 banned?
For digital signature generation, yes. SHA-1 inside HMAC and some key-derivation uses remains acceptable, because the collision attacks that broke signatures do not apply the same way there.
Why is AES-ECB flagged when AES is approved?
Because ECB encrypts identical plaintext blocks to identical ciphertext blocks, so it leaks structure regardless of key size. The mode matters as much as the cipher.
Does FIPS approval mean the implementation is validated?
No. An approved algorithm implemented in an unvalidated module is not FIPS-validated. Approval covers the algorithm; validation covers the module, and only the module can be certified.
Where do the PCI dates come from?
PCI DSS required TLS 1.0 to be retired in 2018 and does not treat TLS 1.1 as strong cryptography. The dates and positions differ from NIST guidance, which is why both are reported separately.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your algorithm list or cipher suites and review the status of each.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.