Is 7-Zip Compliant With FIPS Encryption?
While 7-Zip uses strong AES-256 encryption to protect compressed files, it is not officially compliant with Federal Information Processing Standards (FIPS). This article explains why standard 7-Zip lacks FIPS validation, how its cryptographic implementation affects regulated environments, and what alternatives organizations should consider to meet federal security mandates.
Why 7-Zip Is Not FIPS Compliant
To achieve FIPS compliance—specifically under FIPS 140-2 or FIPS 140-3—a software application must have its cryptographic module evaluated, tested, and formally certified by an accredited laboratory under the Cryptographic Module Validation Program (CMVP).
Although 7-Zip implements the AES-256 cipher (which is a FIPS-approved algorithm), using a FIPS-approved algorithm is not the same as using a FIPS-validated cryptographic module. 7-Zip relies on its own built-in, open-source cryptographic implementation written by its developers rather than using an external, certified cryptographic library. Because the 7-Zip project has not submitted its internal code to the CMVP for formal validation, it cannot be considered FIPS compliant.
Behavior in FIPS-Enforced Windows Environments
When an organization enables "FIPS Mode" on a Windows operating system via Group Policy, the operating system requires applications to use validated Windows cryptographic application programming interfaces (such as Cryptography API: Next Generation, or CNG).
Because 7-Zip relies on its own internal cryptographic routines rather than calling the native Windows cryptographic APIs, it bypasses the system's FIPS enforcement checks. While this allows 7-Zip to function without crashing or throwing errors on FIPS-enabled machines, using it to encrypt sensitive data still constitutes a violation of federal compliance policies.
FIPS-Compliant Alternatives
Organizations that must adhere to FIPS requirements for data archiving and file compression should consider the following options:
- WinZip Enterprise: Offers an administrative setting to enable FIPS 140-2 compliance, which forces the software to use the underlying Windows operating system’s certified cryptographic modules.
- AxCrypt or 7-Zip Forks with FIPS Modules: Specialized enterprise forks of open-source archivers compiled against FIPS-validated cryptographic libraries, such as the OpenSSL FIPS Object Module.
- Native Operating System Encryption: Encrypting files using operating system features that rely directly on FIPS-certified modules, such as Windows Encrypting File System (EFS) or BitLocker, prior to standard archiving.