Is 7-Zip Compliant With FIPS Encryption?

While 7-Zip uses strong AES-256 encryption to protect compressed files, it is not officially compliant with Federal Information Processing Standards (FIPS). This article explains why standard 7-Zip lacks FIPS validation, how its cryptographic implementation affects regulated environments, and what alternatives organizations should consider to meet federal security mandates.

Why 7-Zip Is Not FIPS Compliant

To achieve FIPS compliance—specifically under FIPS 140-2 or FIPS 140-3—a software application must have its cryptographic module evaluated, tested, and formally certified by an accredited laboratory under the Cryptographic Module Validation Program (CMVP).

Although 7-Zip implements the AES-256 cipher (which is a FIPS-approved algorithm), using a FIPS-approved algorithm is not the same as using a FIPS-validated cryptographic module. 7-Zip relies on its own built-in, open-source cryptographic implementation written by its developers rather than using an external, certified cryptographic library. Because the 7-Zip project has not submitted its internal code to the CMVP for formal validation, it cannot be considered FIPS compliant.

Behavior in FIPS-Enforced Windows Environments

When an organization enables "FIPS Mode" on a Windows operating system via Group Policy, the operating system requires applications to use validated Windows cryptographic application programming interfaces (such as Cryptography API: Next Generation, or CNG).

Because 7-Zip relies on its own internal cryptographic routines rather than calling the native Windows cryptographic APIs, it bypasses the system's FIPS enforcement checks. While this allows 7-Zip to function without crashing or throwing errors on FIPS-enabled machines, using it to encrypt sensitive data still constitutes a violation of federal compliance policies.

FIPS-Compliant Alternatives

Organizations that must adhere to FIPS requirements for data archiving and file compression should consider the following options:

  • WinZip Enterprise: Offers an administrative setting to enable FIPS 140-2 compliance, which forces the software to use the underlying Windows operating system’s certified cryptographic modules.
  • AxCrypt or 7-Zip Forks with FIPS Modules: Specialized enterprise forks of open-source archivers compiled against FIPS-validated cryptographic libraries, such as the OpenSSL FIPS Object Module.
  • Native Operating System Encryption: Encrypting files using operating system features that rely directly on FIPS-certified modules, such as Windows Encrypting File System (EFS) or BitLocker, prior to standard archiving.