8/13/26

Can We Automate Trust? The Future of FIPS 140 and Common Criteria

Can we automate trust? And if we can, what happens to cybersecurity certification as we know it? In this episode of Trust & Turbulence, I’m joined by longtime colleagues Ashit Vora and Shawn Geddis, who are both building technologies designed to rethink how security certification gets done — but they’re approaching the problem in very different ways.

Ashit is using AI to automate Common Criteria certification, with an eye toward expanding into areas such as the EU Cyber Resilience Act.

Shawn is taking an intelligent automation (IA) approach to FIPS 140 and other assurance processes, emphasizing deterministic testing, standardized data, and machine-to-machine evidence exchange.

Next

From CRA Deadlines to Q-Day: The New Era of Cybersecurity Compliance