FIPS 140-3, FIPS 140-2 and FIPS 197: Which Encryption Certification UAE and GCC Regulations Actually Require
FIPS 140-3 is the current NIST standard for cryptographic modules. Level 3 adds physical tamper resistance and identity-based authentication on top of Level 2 tamper evidence. On an encrypted USB drive it means the cryptographic controller is physically protected, so removing it destroys the data.
Three different marks appear on encrypted drive datasheets, and they are routinely treated as interchangeable. They are not. This guide separates them, shows how to check any vendor's claim against the NIST register yourself, and maps the result onto the UAE Information Assurance Standard, NCA ECC-1:2018, ADHICS, the CBUAE framework and the UAE PDPL. Written by PRO TECHnology in Dubai, Kanguru's exclusive MENA partner since September 2021.
- Current standard
- FIPS 140-3, aligned to ISO/IEC 19790 and ISO/IEC 24759
- Transition date
- FIPS 140-2 validations move to the CMVP historical list on 21 September 2026
- What Level 3 adds
- Physical tamper resistance and identity-based authentication
- What FIPS 197 is not
- It certifies the AES algorithm only, never the module or the drive
- How to verify
- NIST CMVP validated modules search, by certificate number
- UAE control
- IA Standard T1.4.1, management of removable media
- Saudi control
- NCA ECC-1:2018, restriction and secure handling of external storage media
- UAE PDPL exposure
- AED 50,000 to AED 5 million, plus suspension of processing
- Supplied from
- Dubai stock, across the UAE, the GCC and the wider Middle East
- Contact
- +971 4 343 5501, sales@protech.ae, Sheikh Zayed Road, Dubai

What does FIPS 140-3 Level 3 certification actually mean?
FIPS 140-3 Level 3 certification means an accredited laboratory has tested a product's cryptographic module against the current NIST standard and confirmed that it resists physical attack, rather than merely showing evidence that an attack happened.
FIPS 140 defines four security levels, and the gap between them is mostly physical, not mathematical. All four use the same approved algorithms.
- Level 1. The algorithms are approved and correctly implemented. No physical security requirements beyond production-grade components. A software library typically sits here.
- Level 2. Adds tamper evidence. Seals or coatings make it visible that a module has been opened, and authentication is role-based, so the module knows an operator's role but not their identity.
- Level 3. Adds tamper resistance and identity-based authentication. The module is built to prevent access to keys rather than just record that someone tried, and it zeroises plaintext keys if the boundary is breached.
- Level 4. Adds environmental attack response, detecting and reacting to voltage and temperature conditions outside the module's normal operating range.
The distinction buyers miss most often is scope. FIPS 140 certifies the cryptographic module, not the whole product and certainly not the company selling it. A certificate tells you a defined boundary was tested, which is why the number matters more than the logo.
Kanguru's own description of the Defender 3000 shows what Level 3 physical protection looks like in a flash drive: "built-in brute-force protection with a rugged alloy casing and a water-resistant epoxy compound containing the cryptographic controller which prevents physical access. Any subversive attempt to remove the epoxy compound destroys the flash chip, rendering it unusable and inaccessible."
One point of context for Gulf buyers. FIPS is a United States federal standard, and no UAE, Saudi or Qatari regulation mandates it by name. What regional frameworks do, repeatedly, is require "approved", "strong" or "appropriate" cryptography without defining it. FIPS 140 filled that vacuum, and it is now the default tender wording in the region because it is the only widely recognised, independently tested benchmark available. For why the encryption sits in hardware at all, see our page on hardware encrypted storage in the UAE.
FIPS 140-2 vs FIPS 140-3: is an older certificate still valid?
Yes, a FIPS 140-2 certificate remains valid and listed, but FIPS 140-3 is the current standard and no new FIPS 140-2 certificates are being issued, so a 140-2 drive has a finite compliance runway.
FIPS 140-3 is not a rewrite of the security levels. It keeps the same four-level structure and instead changes what sits underneath: the standard now points at ISO/IEC 19790 for the requirements and ISO/IEC 24759 for the test methods, which aligns the American standard with the international one. It tightens the module specification, sharpens the rules on what must be documented, and adds explicit requirements around non-invasive attack mitigation, meaning side-channel techniques that read a key without ever opening the device.
The dates matter for procurement. The Cryptographic Module Validation Program stopped accepting new FIPS 140-2 submissions in September 2021, and all remaining FIPS 140-2 validations move from the CMVP active list to the historical list on 21 September 2026.
Be careful how you read that, because a lot of vendor marketing overstates it. NIST's own transition guidance says the CMVP "supports the purchase and use of these modules for existing systems" even after they move to the historical list, and that individual agencies decide when they move to FIPS 140-3 only. Historical means superseded, not revoked and not banned.
The practical consequence for a tender written today: accept FIPS 140-2 Level 3, but score FIPS 140-3 Level 3 higher, and if the award is a three or five year framework, require the supplier to state a migration path rather than leaving you holding a historical-list fleet in year four.
Two dated examples make the transition concrete. Kanguru states that "In June 2026 the Kanguru Defender 3000 achieved FIPS 140-3, Level 3 Certification" under Cert #5364, having previously carried FIPS 140-2 Level 3. The iStorage datAshur PRO+C, described as "the world's first encrypted flash drive with validation for FIPS 140-3 Level 3 certification", dates to December 2024. Expect channel listings and reseller datasheets to lag by months in both cases, which is the single best argument for checking the certificate number rather than the product page.
| What FIPS 140-2 already covered | What FIPS 140-3 adds or changes |
|---|---|
| Four security levels, from algorithm correctness up to environmental attack response | Same four levels, so a Level 3 drive is still a Level 3 drive |
| A US-specific standard written and maintained by NIST | Built on ISO/IEC 19790 requirements and ISO/IEC 24759 test methods, aligning US and international practice |
| Physical security, key management, self-tests and role or identity-based authentication | Tightened module specification and documentation, with clearer boundary definition |
| Limited treatment of attacks that do not open the device | Explicit non-invasive attack mitigation requirements, covering side-channel techniques |
| Certificates issued until September 2021 | The only standard new certificates are issued against; 140-2 entries move to the historical list on 21 September 2026 |
FIPS 197 is not FIPS 140: the line most buyers misread
FIPS 197 certifies the AES algorithm. FIPS 140 certifies the module that runs it. A drive advertised as FIPS 197 Certified AES 256-bit has no FIPS 140 certification at all, and will fail a tender that asks for one.
FIPS 197 is the publication that defines AES itself. A FIPS 197 claim, properly made, means the implementation computes AES correctly and was checked against known test vectors. That is a real and worthwhile thing. It is also an extremely narrow thing.
Nothing in FIPS 197 tests how the key is generated, where it is stored, whether it ever leaves the controller, what happens on the tenth failed password attempt, whether the housing resists being opened, or whether the device can tell one authenticated user from another. Every one of those questions belongs to FIPS 140. A drive can hold flawless AES 256-bit encryption and still hand its key to anyone who decaps the chip.
Being specific about our own range is the point here, because a compliance page that inflates its own products is worthless. Within the Kanguru Defender line, the Defender Elite30, Defender SSD 35 and Defender HDD 35 carry FIPS 197 Certified AES 256-bit XTS hardware encryption and no FIPS 140-2 or FIPS 140-3 certification whatsoever. The Defender SED30 sits in the same tier, described by Kanguru as AES 256-bit hardware encryption with no FIPS 140 certification. Kanguru positions the Elite30 for "SMBs and commercial organizations that do not require strict government security compliance", which is the correct and legitimate use for it.
Watch for the adjacent phrasing too. iStorage describes the diskAshur M2 as its "most rugged FIPS compliant encrypted portable SSD" and says it "encrypts data using FIPS PUB 197 validated, AES-XTS 256-bit hardware encryption". Read carefully, that is a FIPS 197 statement wearing a FIPS-shaped coat. It is accurate, but a procurement officer skimming for the word FIPS will misfile it.
The decision rule is blunt and worth writing into your policy: if your control framework or tender names FIPS 140, a FIPS 197 drive does not qualify, however strong its encryption is. Conversely, if your data is internal commercial material with no regulatory tier attached, insisting on FIPS 140-3 Level 3 is money spent on an audit you will never face.
Certified, validated or pending? How to check a FIPS claim yourself
Every genuine FIPS 140 certification has a certificate number you can look up on the NIST Cryptographic Module Validation Program list. If a datasheet gives no number, treat the claim as unverified until the vendor supplies one.
Four phrasings turn up on encrypted drive datasheets, and they mean four different things to an auditor. Real examples from the range we supply, so you can see the pattern rather than the theory.
| Wording you see | What it actually means | Real example | Tender status |
|---|---|---|---|
| Certified, with a number | An accredited lab tested the module and NIST issued a certificate you can look up | Kanguru Defender 3000, Cert #5364 (140-3 Level 3); Defender Elite300, Certificate #2442; iStorage datAshur PRO, Certificate 2688 | Qualifies |
| FIPS Inside | The certificate attaches to the embedded cryptographic module, not the finished drive. The module is validated; the enclosure around it was not part of the tested boundary | Kanguru Defender SSD350 and HDD350, both Cert #4228, described by Kanguru as "FIPS 140-2 Inside" | Usually qualifies, but declare it |
| Pending | Testing is under way or submitted. Not certified. Supporting CAVP algorithm certificates may exist, which validate the algorithms, not the module | iStorage diskAshur PRO3 and diskAshur DT3, "pending the new FIPS 140-3 Level 3 validation standard" | Does not qualify |
| Compliant or compatible | A self-assessed statement with no certification behind it. Sometimes it describes an option rather than the product as shipped | Kanguru FlashTrust, where "FIPS 140-2 Level 2 compliant physical epoxy security encapsulation may be added" | Does not qualify |
The "FIPS Inside" distinction is the one that catches people in an audit. It is a legitimate and common arrangement, but the tested boundary is the embedded module, so an auditor asking "what exactly was validated" deserves a straight answer rather than a certificate waved from across the room. Declare it in the bid response and it is a non-issue.
Also flag the case where a certification is claimed but no number is published. The Kanguru Defender SED300, in both its M.2 NVMe and SATA versions, is described as "FIPS 140-2 Certified, Level 2" with no certificate number on the product page. That is not evidence of a bad claim, it is evidence of an incomplete datasheet, and the fix is to ask us for the number before the purchase order rather than after.
The four-step check to run before signing a purchase order
- Get the certificate number in writing. Not the word "certified", not a logo, a number. If a bidder cannot produce one within a day, that tells you something.
- Look it up on the CMVP validated modules search at csrc.nist.gov, which lets you search by certificate number, vendor or module name across FIPS 140-2 and FIPS 140-3, including the historical and revoked lists.
- Read the module name on the certificate against the product you are buying. This is where FIPS Inside, superseded models and renamed products surface. The certificate should describe the thing in the box.
- Check the standard, the level and the status. Confirm it says 140-3 or 140-2 as you expect, confirm the level, and confirm whether the entry sits on the active or the historical list. Then record the number in your asset register, so the next audit is a lookup rather than a project.
TAA compliance, Common Criteria EAL5+ and CMMC explained
TAA compliance is about where a drive was made, not how strongly it encrypts. It is now the sharpest filter in GCC government and defence procurement, and it is a separate question from FIPS.
Three more marks share space on the same datasheets, and all three get conflated with FIPS.
TAA, the Trade Agreements Act
A country-of-origin and trusted supply chain requirement, not a security test. It restricts procurement to goods made or substantially transformed in the United States or a designated country. Buyers increasingly ask it as a plain question: where was this assembled, and who touched the firmware?
Explicit TAA statements appear on the Kanguru Defender 3000, Defender Elite300, Defender SSD350, Defender SSD 35, Defender HDD 35, Defender SED300 in both versions, Defender SED30, the UltraLock range, and on the iStorage datAshur PRO+C, datAshur PRO+A, diskAshur3, diskAshur PRO3 and diskAshur DT3. To be straight about it, no TAA statement appears on the Defender Elite30 or the Defender HDD350 product pages. If TAA is a scored requirement for you, those two need a written confirmation before they go into a bid.
Common Criteria EAL5+
An international hardware certification, and on these products it certifies the secure microprocessor inside the drive rather than the drive as a whole. Kanguru names the iStorage datAshur PRO2, diskAshur3, diskAshur DT3, diskAshur M2 and diskAshur PRO3 as incorporating a Common Criteria EAL5+ hardware certified secure microprocessor. It is a useful independent signal about the chip, and it is not a substitute for FIPS 140 when a tender asks for FIPS 140.
One honest caveat. Kanguru also references Common Criteria EAL2+ under Germany's BSI, but its own wording ties that to "predecessor models of Defender devices and remote management", not to the current range. Do not carry it into a bid as a current certification.
CMMC
Kanguru's statement is that "Kanguru aligns with CMMC Level 1 foundational cybersecurity practices to protect Federal Contract Information". Read it precisely: that is an alignment statement about how the company operates, not a certification of any product. Separately, the iStorage datAshur PRO+C and PRO+A are described as supporting CMMC compliance.
Where this bites in the Gulf is on US-linked programmes. If your work touches Controlled Unclassified Information, CMMC Level 2 control MP.L2-3.8.6 and its parent, NIST SP 800-171 control 3.8.6, both require FIPS-validated cryptography to protect CUI on portable storage media during transport. That is a direct, named requirement for FIPS 140, and a FIPS 197 drive does not meet it. ITAR obligations frequently sit alongside on the same defence and aerospace contracts, which is why TAA and FIPS tend to appear together in the same clause.
What UAE regulation requires for removable media
No UAE regulation names a brand of drive, but the UAE Information Assurance Standard, Dubai Data Law and the PDPL together require classified and personal data on portable media to be encrypted, inventoried and controlled, which in practice rules out consumer flash drives.
The UAE Information Assurance Standard
The IA Standard sets out 188 controls, and the one that governs this subject directly is T1.4.1, management of removable media. It requires organisations to have a defined procedure for how removable media is authorised, handled, stored, transported and disposed of, rather than leaving it to individual judgement. Originally published by NESA, the standard now sits under the UAE Cyber Security Council and the Signals Intelligence Agency, and version 2 was refreshed during 2025.
The bigger shift is the National Cyber Accreditation Programme, rolling out through 2026. It moves the UAE from largely voluntary compliance towards mandatory resilience, and it pulls suppliers to government entities into scope alongside the entities themselves. If you sell to a federal or emirate-level body, this is the mechanism that makes your removable media policy someone else's business.
Dubai Data Law
Law No. 26 of 2015 classifies data into four tiers: Open, Shared-Confidential, Sensitive and Secret. The practical consequence sits at the top tier, where Secret data moves strictly on a need-to-know basis. In day-to-day operations that usually means it does not travel over a network at all, it is hand-carried, and the medium it is hand-carried on becomes the control.
The UAE PDPL
Federal Decree-Law No. 45 of 2021 has been in force since January 2022, with Executive Regulations under Cabinet Decision 111/2023. It requires appropriate technical and organisational measures for personal data, and it carries administrative fines running from AED 50,000 up to AED 5 million, alongside the power to suspend processing altogether, which is frequently the more damaging outcome for an operating business. Separately, the UAE Public Prosecution has publicly warned of penalties up to AED 500,000 for the illegal possession and use of personal data.
The practical translation is two lines long. Classify the data first, then match the classification to a certification tier. Buying one drive specification for the whole organisation either overspends on marketing material or underprotects the personnel file, and it is the second of those that ends up in front of a regulator.
Saudi NCA ECC-1:2018 and removable media across the GCC
Saudi Arabia's Essential Cybersecurity Controls, NCA ECC-1:2018, require organisations to restrict and securely handle external storage media, which is why encrypted drives now appear as a line item in Kingdom tenders rather than an IT preference.
The ECC is mandatory for government bodies and for organisations operating critical national infrastructure in Saudi Arabia, and it has become the de facto baseline well beyond that group because it is what large Saudi buyers audit their suppliers against. Its storage media provisions require restriction of external media use, secure handling while in use, and secure disposal at end of life. In a Kingdom tender this typically surfaces as a requirement to state the encryption standard, the certification, and the erasure method, in that order.
For a regional business, the layering is the real problem. A Dubai company selling into Riyadh has to satisfy the UAE IA Standard at home and the NCA ECC in the Kingdom, with different auditors and different reporting. Running two device fleets to match two frameworks is expensive and, in practice, unenforceable once staff start travelling. Standardising on the higher certification tier and documenting it once is almost always cheaper than maintaining two standards.
Free zone entities carry a second layer on top. DIFC Data Protection Law and the ADGM data protection regulations apply their own obligations to organisations registered there, independently of the federal PDPL, and VARA adds requirements for virtual asset firms. Regional headquarters ask about this constantly, and the answer is that the free zone regime sits alongside the federal one rather than replacing it.
| Framework | Where it applies | What it requires on removable media | Practical tier |
|---|---|---|---|
| UAE IA Standard | UAE government entities, critical infrastructure and their suppliers | Control T1.4.1, defined procedures for managing removable media through its life | FIPS 140-3 or 140-2 Level 3 for classified, Level 2 for sensitive |
| NCA ECC-1:2018 | Saudi government and critical national infrastructure, widely applied to suppliers | Restriction, secure handling and secure disposal of external storage media | FIPS 140 certified with documented erasure |
| CBUAE Cybersecurity Framework | UAE licensed banks, exchange houses, finance companies, payment providers | Inventory and control of devices that can leave the premises, with evidence | FIPS 140 certified plus central management and audit logging |
| SAMA Cyber Security Framework | Saudi banking, insurance and financing institutions | Equivalent asset and media controls, drawing on NIST, ISO 27001 and PCI DSS | FIPS 140 certified plus central management |
| ADHICS | Every healthcare provider in Abu Dhabi | Encryption of patient information at rest and in transit, across 11 control domains | Hardware encryption, FIPS 140 certified, with remote disable |
| UAE PDPL | All organisations processing personal data in the UAE | Appropriate technical measures; fines to AED 5 million plus suspension | Hardware encryption as the minimum defensible position |
Healthcare: what ADHICS requires of drives holding patient data
ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard issued by the Department of Health, mandates encryption of patient information at rest and in transit across 11 control domains, and it applies to every hospital, clinic, pharmacy and diagnostic centre in the emirate.
ADHICS sits within the Department of Health's wider AAMEN programme for health sector cyber security, and it is enforced as a condition of operating rather than offered as guidance. On top of it, MOHAP and the DHA apply their own health data rules in their respective jurisdictions, and the federal PDPL applies above all of them. A private clinic in Dubai treating an Abu Dhabi patient can be inside three regimes at once.
Most search traffic on this subject asks about HIPAA, so it is worth stating the comparison plainly. HIPAA does not ban USB drives. What it does is make a lost unencrypted one a reportable breach, while a lost encrypted one falls under safe harbour and generally is not. That single distinction is the whole economic argument, and the numbers are unkind: the average healthcare data breach reached 7.42 million dollars in 2025, roughly 67 per cent above the global all-sector average.
Which brings us to the question people actually type. Is a password protected USB drive HIPAA compliant? No. A password on a folder, a zip file or a partition is access control, not encryption. The data is still sitting in readable form on the flash chip, and anyone willing to read the chip directly does not need the password. Only a drive that encrypts in hardware, with the key held inside the controller, moves lost data out of breach-notification scope.
The Gulf use cases that actually drive purchases are consistent: DICOM imaging studies moved between a hospital and an imaging centre when the network link will not carry them, consultants who work across three or four facilities in a week, and clinical trial data moving under a sponsor's chain of custody rules.
One nuance worth building into policy. A lost drive becomes a notifiable incident only if you cannot demonstrate the data was inaccessible. Certification gives you the first half of that argument, and the ability to disable the drive remotely and show the log gives you the second. We cover the remote management detail on our hardware encrypted storage page rather than repeating it here.
Banking and finance: CBUAE, SAMA and PCI DSS v4.0
For a UAE bank, exchange house, finance company or payment service provider, the buying trigger is rarely the drive itself, it is the audit. The CBUAE Cybersecurity Framework and Saudi SAMA's Cyber Security Framework both expect an inventory of every device that can leave the building, plus evidence of control over it.
The CBUAE framework applies across licensed financial institutions in the UAE, and SAMA's framework does the equivalent job across the Kingdom for banking, insurance and financing companies. Neither was written from scratch: both draw on NIST, ISO 27001 and PCI DSS, which is why an institution that satisfies one is usually most of the way to the others. PCI DSS v4.0 adds its own requirement for continuous control over any media holding cardholder data, including how it is classified, stored, transported and destroyed.
What separates finance from other sectors is that certification alone stops being sufficient. An examiner will ask for four things, and only the first is about the drive:
- An asset inventory of every encrypted device issued, to whom, and its current status.
- File-level audit logs showing what was copied to and from a device, and when.
- Proof of remote disable, meaning a demonstrated capability and a log, not a feature bullet on a datasheet.
- Enforced password policy applied centrally rather than trusted to the user.
That evidence layer is what the Kanguru Remote Management Console exists to provide, and it is the reason finance buyers rarely buy unmanaged drives. Full feature detail sits on our hardware encrypted storage page, so one caveat is all that belongs here, and it is a caveat a finance buyer needs before specifying a form factor. Kanguru states plainly: "The Defender HDDs and SSDs do not support File Auditing in KRMC-Hosted or KRMC On-Premise, PREMIUM Accounts." If file-level auditing is mandatory for your examiner, that requirement constrains you to flash form factors. Discovering it after the fleet arrives is an expensive way to learn it.
Institutions licensed in the DIFC or ADGM carry the free zone data protection regime as a second layer, which in practice means the same controls documented against two frameworks rather than different controls.
Oil, gas and OT: IEC 62443 and moving files into an air-gapped plant
IEC 62443-3-3 SR 2.3 requires enforced usage restrictions on portable and mobile devices in each security zone, which makes removable media the one sanctioned way across an air gap and therefore the control that gets audited.
SR 2.3 is worth reading literally. It asks the control system to enforce restrictions on portable and mobile devices according to the security policy of the zone they enter, which means the restriction has to be technical, not a sign on the door. IEC 62443-2-1 supplies the policy and procedure layer above it, requiring documented rules for how media is authorised, scanned and handled.
The regional evidence is the strongest part of the case, and it is not comfortable reading. Kaspersky ICS CERT found removable-media threats blocked on Middle East industrial control system computers at 1.8 times the global average. The region ran roughly 14 OT and ICS incidents a month during 2025, against about one a month in 2018. Within those incidents, refineries accounted for 26 per cent and transport infrastructure for 49 per cent, the single largest share.
That transport figure widens this section well beyond oil and gas. Airports, port terminals, customs systems and free zone logistics operators across the UAE and Saudi Arabia are classed as critical national infrastructure, fall under the UAE IA Standard and the NCA ECC, and run the same segmented control networks as a refinery. Many are still writing their removable media policy rather than enforcing one.
Why write protection matters as much as encryption here
In an OT context the threat model inverts. The risk is usually not that data leaves on the drive, it is that something arrives on it. A drive going into a PLC, an HMI or an engineering workstation should be read-only, so that a compromised endpoint cannot write to it and ride it to the next machine. A physical write-protect switch beats a software setting here, because the engineer switches between read-only and read/write with a deliberate mechanical action rather than a policy a local administrator can override. Kanguru fits one to the Defender Elite300 and Defender Elite30, and iStorage offers an optional read-only mode on the datAshur PRO+C and PRO+A.
Field and offshore conditions add a second requirement. An IP68 rating, which Kanguru defines as completely dustproof and able to withstand submersion to one metre for one hour with the cap on, is the difference between a drive that survives a Gulf summer on a platform and one that fails in a pocket. The Defender 3000 and the iStorage datAshur PRO+C and PRO+A carry it.
For the drive-by-drive detail on moving data between separated networks, see our hardware encrypted storage page. What a plant audit asks for, though, is the policy: which media is authorised, who issued it, how it is scanned on entry, and how it is wiped on exit.
How to write the certification clause into your tender or removable media policy
A workable removable media clause specifies three things: the certification tier, the management requirement, and the disposal method. Naming a brand is what gets a tender challenged.
Map the tiers to data classification rather than to budget. The classification already exists in your policy, so this makes the specification defensible instead of arbitrary.
| Tier | Data it covers | Certification to require | Management and disposal |
|---|---|---|---|
| Tier 1 | Secret or classified government data, and Controlled Unclassified Information | FIPS 140-3 Level 3 validated hardware encryption, with the published CMVP certificate number stated in the bid, plus TAA compliance | Central management mandatory, remote disable, full asset register, NIST 800-88 conformant erasure on retirement |
| Tier 2 | Sensitive data, regulated personal data, patient records, cardholder data | FIPS 140-2 Level 3 or Level 2 accepted with a certificate number; FIPS 140-3 scored higher | Audit logging and remote disable required, password policy enforced centrally, documented erasure |
| Tier 3 | Internal commercial data with no regulatory tier attached | FIPS 197 AES 256-bit hardware encryption with digitally signed firmware | Central management optional, secure erase before reassignment |
The clauses buyers forget
- Require the certificate number in the bid response, not the word "certified". This single line does more work than the rest of the clause combined.
- State that "pending" does not satisfy a certification requirement. Otherwise you will receive compliant-looking bids offering drives that are still in evaluation.
- Specify NIST 800-88 conformant erasure for retirement and reassignment, and say who performs it and who signs the certificate of destruction.
- Require digitally signed firmware for BadUSB resistance, so that altered firmware is rejected by the device itself.
- State whether file-level auditing is mandatory, because as noted above that requirement constrains which form factors can qualify. Decide it before the tender, not during evaluation.
The objection every GCC buyer raises
"Why is this ten times the price of a consumer drive?" It is a fair question and it deserves an arithmetic answer rather than a defensive one. The honest comparison is not drive against drive, it is unit price against the cost of one reportable incident. A UAE PDPL penalty reaches AED 5 million with suspension of processing on top, and the average healthcare breach in 2025 cost 7.42 million dollars. Against a fleet of a few hundred certified drives, the break-even is a single avoided incident, and usually a fraction of one.
The reverse also holds, and it is worth saying on a page like this. If the data is genuinely unclassified internal material, a Tier 1 drive is over-specified and the money is better spent elsewhere. Tiering exists so that you can buy accurately in both directions.
Certified encrypted drives supplied and supported from Dubai
PRO TECHnology has been Kanguru's exclusive MENA partner since September 2021, supplying, stocking and supporting hardware encrypted drives across the UAE and the wider Middle East from Dubai.
The reference table below states each model exactly as its manufacturer states it, including the models that carry no FIPS 140 certification and the ones whose certification is still pending. Accuracy is the entire argument of this page, so nothing here is rounded up.
| Model | FIPS status | Certificate | TAA | Notes |
|---|---|---|---|---|
| Kanguru Defender 3000 | FIPS 140-3 Level 3 | Cert #5364 | Yes | USB 3.0 flash, IP68, epoxy-encapsulated controller, 16GB to 1TB |
| Kanguru Defender Elite300 | FIPS 140-2, Level 2 threshold | Certificate #2442 | Yes | USB 3.0 flash, physical write-protect switch, 16GB to 512GB |
| Kanguru Defender SSD350 / HDD350 | FIPS 140-2 Level 2, "FIPS Inside" | Cert #4228 | SSD350 yes; no statement on HDD350 | External SSD 1TB to 8TB; external HDD 2TB and 5TB |
| Kanguru Defender SED300 (M.2 NVMe and SATA) | FIPS 140-2 Level 2 | No number published | Yes | Internal self-encrypting, TCG Opal, pre-boot authentication, 500GB to 4TB |
| Kanguru Defender Elite30, SSD 35, HDD 35, SED30 | No FIPS 140 certification | FIPS 197 AES 256-bit on Elite30, SSD 35 and HDD 35; SED30 stated as AES 256-bit | SSD 35, HDD 35, SED30 yes; no statement on Elite30 | Commercial tier, correctly positioned for organisations outside strict government compliance |
| iStorage datAshur PRO+C / PRO+A | FIPS 140-3 Level 3 | Validated December 2024 | Yes | PIN-pad flash, USB-C and USB-A, IP68, 32GB to 512GB |
| iStorage datAshur PRO | FIPS 140-2 Level 3 | Certificate 2688 | Not stated | PIN-pad flash, also NLNCSA DEP-V and NATO Restricted, 4GB to 256GB |
| iStorage datAshur PRO2, diskAshur PRO2, diskAshur DT2 | FIPS 140-2 Level 3 | Number not published on product pages | Not stated | PIN-pad flash, portable SSD and HDD, desktop HDD to 30TB; PRO2 adds CC EAL5+ microprocessor |
| iStorage diskAshur PRO3 / diskAshur DT3 | Pending, not certified | CAVP algorithm certificates issued | Yes | Do not write these into a tender as certified |
Across the range, capacities run from 16GB flash drives up to 30TB desktop drives, in flash, portable SSD, portable and desktop HDD, and internal self-encrypting drive form factors.

Certified, with the number
Defender Elite300, FIPS 140-2 Certificate #2442, AES 256-bit XTS hardware encryption, physical write-protect switch and TAA compliance.

Commercial tier, stated honestly
Defender Elite30, FIPS 197 AES 256-bit hardware encryption and no FIPS 140 certification, for organisations outside strict government compliance.

The evidence layer
KRMC licensing in Hosted and On-Premise editions, plus Kanguru Local Administrator for configuring drives before they are issued.

Supported locally
Stock held in Dubai, with warranty, repairs and spare parts handled by our own service centre across the UAE, the GCC and the wider Middle East.
We supply the range with KRMC licensing and Kanguru Local Administrator for fleet setup, and we will give you the certificate number for any model before you raise a purchase order. Full catalogue on our Kanguru page, and technical detail on hardware encrypted storage. Call +971 4 343 5501 or email sales@protech.ae.
Frequently asked questions
Is a FIPS 140-2 certified drive still compliant in 2026?
Yes, a FIPS 140-2 certificate remains valid and listed, but it is the superseded standard. The Cryptographic Module Validation Program stopped accepting new FIPS 140-2 submissions in September 2021, and all remaining FIPS 140-2 validations move to the CMVP historical list on 21 September 2026. Historical means superseded, not revoked: NIST's own transition guidance states that the CMVP supports the purchase and use of these modules for existing systems, and that agencies decide when they move to FIPS 140-3 only. For a new tender, accept FIPS 140-2 Level 3 but score FIPS 140-3 Level 3 higher, and require a migration path on any multi-year framework.
Is a FIPS 197 certified drive the same as a FIPS 140-2 certified drive?
No, and this is the most costly misreading in encrypted storage procurement. FIPS 197 certifies the AES algorithm, meaning the maths is correct AES. FIPS 140 certifies the cryptographic module that runs it, covering key management, physical protection, tamper response, authentication and self-tests. A drive advertised as FIPS 197 Certified AES 256-bit has no FIPS 140 certification at all and will fail any tender that names FIPS 140. Within the Kanguru range, the Defender Elite30, Defender SSD 35 and Defender HDD 35 are FIPS 197 only, and the Defender SED30 is stated as AES 256-bit hardware encryption with no FIPS 140 certification.
How do I verify a FIPS 140-3 certificate number?
Ask the vendor for the certificate number in writing, then look it up on the NIST Cryptographic Module Validation Program validated modules search at csrc.nist.gov, which lets you search by certificate number, vendor or module name across FIPS 140-2 and FIPS 140-3, including the historical and revoked lists. Check three things on the entry: that the module name matches the product you are actually buying, that the standard and level are what was claimed, and whether it sits on the active or historical list. If a datasheet gives no number, treat the claim as unverified until the vendor supplies one.
Is a password protected USB drive HIPAA compliant?
No. A password on a folder, a zip file or a partition is access control, not encryption. The underlying data remains readable on the flash chip to anyone willing to read the chip directly, so the password adds no protection once the drive is out of your hands. HIPAA does not ban USB drives; it makes a lost unencrypted one a reportable breach, while properly encrypted data generally falls under safe harbour. Only a drive that encrypts in hardware, with the key held inside the controller, moves lost data out of breach-notification scope.
Does the UAE Information Assurance Standard require encrypted USB drives?
It does not name encryption technology or a brand, but control T1.4.1, management of removable media, requires a defined procedure for authorising, handling, storing, transporting and disposing of removable media. Combined with Dubai Data Law No. 26 of 2015, which puts Secret data on a need-to-know basis, and the UAE PDPL requirement for appropriate technical measures, the practical effect is that classified and personal data on portable media must be encrypted, inventoried and controlled. Consumer flash drives cannot satisfy that, because they offer no inventory, no enforcement and no way to prove a lost drive was inaccessible.
What does TAA compliant mean on a USB flash drive?
TAA compliance refers to the US Trade Agreements Act, and it is a country-of-origin and trusted supply chain requirement rather than a security test. It says nothing about encryption strength. It has become one of the sharpest filters in GCC government and defence procurement because buyers increasingly want to know where a drive was assembled and who controlled the firmware. Explicit TAA statements appear on the Kanguru Defender 3000, Elite300, SSD350, SSD 35, HDD 35, SED300, SED30 and the UltraLock range, and on the iStorage datAshur PRO+C, PRO+A, diskAshur3, diskAshur PRO3 and diskAshur DT3. No TAA statement appears on the Defender Elite30 or Defender HDD350 product pages.
Which Kanguru drives carry FIPS 140-3 certification?
Kanguru states that in June 2026 the Kanguru Defender 3000 achieved FIPS 140-3 Level 3 Certification under Cert #5364, having previously carried FIPS 140-2 Level 3. Among the iStorage models Kanguru supplies alongside the Defender range, the datAshur PRO+C and datAshur PRO+A carry FIPS 140-3 Level 3, dated to December 2024. The iStorage diskAshur PRO3 and diskAshur DT3 are pending FIPS 140-3 Level 3 validation and must not be described as certified. Other Defender models carry FIPS 140-2, and several carry FIPS 197 only.
Why does a certified encrypted drive cost ten times a consumer drive?
Because you are buying a tested cryptographic module, a physically protected controller, signed firmware, a supply chain statement and an auditable management layer, none of which exist in a retail flash drive. The comparison that matters is unit price against the cost of one reportable incident. UAE PDPL penalties run from AED 50,000 to AED 5 million with suspension of processing on top, and the average healthcare data breach reached 7.42 million dollars in 2025. Across a fleet of a few hundred drives, a single avoided incident covers the difference several times over. If the data genuinely carries no regulatory tier, though, a certified drive is over-specified and we will tell you so.
التخزين المشفّر عتادياً في الإمارات: ما الذي تشترطه الأنظمة فعلياً
وحدة التخزين المشفّرة عتادياً هي فلاش ميموري مشفرة أو هارد ديسك خارجي مشفر يجري التشفير داخله في متحكم مخصص مدمج بالجهاز، بخوارزمية AES 256 بت في نمط XTS، بحيث لا يغادر مفتاح التشفير حدود ذلك المتحكم. ولا يحتاج إلى تثبيت برامج أو صلاحيات مدير، وتتم المصادقة بكلمة مرور أو بلوحة مفاتيح رقمية مدمجة.
أما التشفير البرمجي فيعتمد على نظام التشغيل، ويمكن تعطيله أو نسخ الملفات قبل تفعيله، كما أن حماية الفلاشة بكلمة مرور على مستوى مجلد هي ضبط وصول لا تشفير. التشفير العتادي يعمل بمعزل عن نظام التشغيل، ويفرض حداً أقصى لمحاولات إدخال كلمة المرور ثم يمسح البيانات، ويحمي المتحكم التشفيري مادياً من العبث.
وشهادة FIPS هي لغة بنود المناقصات في المنطقة، والتمييز بين مصطلحاتها ضروري:
- معيار FIPS 140-3 المستوى 3: الأحدث لدى المعهد الأمريكي NIST، ويضيف مقاومة مادية للعبث ومصادقة قائمة على الهوية، ومثاله كانجرو (Kanguru) Defender 3000 بشهادة رقم 5364.
- معيار FIPS 140-2: شهاداته ما زالت سارية، لكن لم تعد تصدر شهادات جديدة بموجبه، أي أن عمره التنظيمي محدود.
- معيار FIPS 197: يعتمد خوارزمية AES وحدها لا الوحدة التي تنفذها، والجهاز الموصوف به فقط لا يحمل أي اعتماد FIPS 140 ولن يجتاز مناقصة تشترطه.
- عبارة «قيد الاعتماد» لا تعني معتمداً: اطلب رقم الشهادة في العرض الفني وتحقق منه في قائمة CMVP لدى NIST.
ولا تسمي الجهات التنظيمية في الدولة علامة بعينها، لكنها تشترط ضبط وسائط التخزين القابلة للإزالة وتشفيرها:
- معيار ضمان المعلومات الإماراتي وضابطه T1.4.1 لإدارة الوسائط القابلة للإزالة، وقانون بيانات دبي رقم 26 لسنة 2015 بتصنيفه الرباعي.
- قانون حماية البيانات الشخصية، المرسوم بقانون اتحادي رقم 45 لسنة 2021، بغرامات تصل إلى 5 ملايين درهم.
- معيار ADHICS الصادر عن دائرة الصحة في أبوظبي، ويلزم المستشفيات والعيادات بتشفير بيانات المرضى.
- إطار الأمن السيبراني لمصرف الإمارات المركزي ومعيار PCI DSS 4.0 للبنوك وشركات الصرافة ومزودي خدمات الدفع.
- معيار IEC 62443 في النفط والغاز والمرافق، حيث تبقى الوسائط المشفّرة ذات مفتاح الحماية من الكتابة وسيلة نقل البيانات الآمن بين الأنظمة المعزولة، وتقيّد الضوابط الأساسية السعودية ECC-1:2018 الوسائط الخارجية بالمثل.
بروتكنولوجي (PRO TECHnology)، ومقرها دبي منذ 1998، هي الموزع الحصري لكانجرو في الشرق الأوسط وشمال أفريقيا منذ سبتمبر 2021. نوفّر فلاش ميموري مشفرة وأقراص SSD وHDD خارجية مشفرة وأقراصاً داخلية ذاتية التشفير بسعات من 16 جيجابايت إلى 30 تيرابايت، مع مخزون في دبي، وضمان وإصلاح وقطع غيار من مركز خدمتنا، وتوريد إلى أبوظبي وبقية الإمارات ودول الخليج. كما نساعد على صياغة سياسة أمن وسائط التخزين وبنود الشهادات في كراسة الشروط. للاستشارة أو عرض سعر: +971 4 343 5501 أو sales@protech.ae
Get the certificate number before you raise the purchase order
Send us your removable media clause or your data classification and we will tell you which tier it needs, which models qualify, and the exact certificate number for each one. Stock held in Dubai, with in-house service and warranty across the UAE, the GCC and the wider Middle East. Call +971 4 343 5501 or email sales@protech.ae.