# CMU-CSO-UVM — Using Validated Cryptographic Modules

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/cmu-cso-uvm

Cryptographic Module Use (`CMU`) · group all · subset CSO
Force: none stated

## Statement

_No statement text is recorded for this requirement._

## Who it binds

- Providers

## Certification classes

- class A
- class B
- class C
- class D

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

- {"text":"List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.","scope":"all","class":"a","source":"requirement"}
- {"text":"List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.","scope":"all","class":"b","source":"requirement"}
- {"text":"List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.","scope":"all","class":"c","source":"requirement"}
- {"text":"List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.","scope":"all","class":"d","source":"requirement"}

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
