Compliance

Crypto Algorithm Compliance Checker

Paste the cipher suites, hashes and key sizes your systems use and see which are FIPS-approved, which NIST has deprecated or disallowed, and which PCI DSS no longer accepts.

Last reviewed by the Radiatus Cloud team

Status appears here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Approved, deprecated and disallowed are three different states

NIST SP 800-131A distinguishes algorithms that may be used, algorithms that may still be used to process previously protected data but not to apply new protection, and algorithms that may not be used at all. Treating this as a binary approved-or-not question produces the wrong answer for the middle category, which is where most real systems sit. SHA-1 for signature generation is disallowed while SHA-1 inside HMAC remains acceptable, and a checklist that does not distinguish the two will flag working systems and miss broken ones.

Key size changes the answer more than the algorithm name

RSA is approved and RSA-1024 is not. Triple DES was withdrawn entirely for new encryption after 2023. AES is approved at 128, 192 and 256 bits but a specific mode may not be, and ECB is not approved for any key size because it leaks structure in the plaintext. The algorithm name alone is never enough to answer the question, which is why a policy that lists algorithms without parameters cannot be assessed.

PCI moved before NIST did on TLS

PCI DSS required the retirement of TLS 1.0 in 2018 and treats TLS 1.1 as no longer providing strong cryptography, while NIST guidance took longer to reach the same position. An organisation reading only one of the two will be late on the other. This tool reports each source separately for that reason, and it evaluates cipher suites down to their component parts, since a suite can pair an approved cipher with an unapproved key exchange.

Related tools

Frequently Asked Questions

What is the difference between deprecated and disallowed?

Deprecated means the algorithm may still be used to process data protected earlier, but not to apply new protection. Disallowed means it may not be used at all. SP 800-131A defines both, and treating the question as binary gives the wrong answer for the middle category.

Is SHA-1 banned?

For digital signature generation, yes. SHA-1 inside HMAC and some key-derivation uses remains acceptable, because the collision attacks that broke signatures do not apply the same way there.

Why is AES-ECB flagged when AES is approved?

Because ECB encrypts identical plaintext blocks to identical ciphertext blocks, so it leaks structure regardless of key size. The mode matters as much as the cipher.

Does FIPS approval mean the implementation is validated?

No. An approved algorithm implemented in an unvalidated module is not FIPS-validated. Approval covers the algorithm; validation covers the module, and only the module can be certified.

Where do the PCI dates come from?

PCI DSS required TLS 1.0 to be retired in 2018 and does not treat TLS 1.1 as strong cryptography. The dates and positions differ from NIST guidance, which is why both are reported separately.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste your algorithm list or cipher suites and review the status of each.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.