An MSP takes on a county government: a few hundred endpoints across public safety, the assessor’s office, and public works. Two obligations land at once. The remote-management channel that reaches those machines has to protect data in transit with FIPS 140-3 validated cryptography, and the policy separately requires that known vulnerabilities be patched on a schedule, flaw remediation, which an assessor will want evidence for. A generic RMM can do the second while quietly failing the first.
This is not only a big-city problem. Village, town, county, and city police forces, along with the sheriff’s offices and MSPs that support them, all touch criminal justice information and all fall under the CJIS Security Policy. The smallest detachment carries the same obligation for information in transit as a metropolitan department.
Two controls, one platform
| The control | Lavawall® in FIPS mode |
|---|---|
| Validated remote sessions | The remote desktop session a technician uses to reach a regulated machine is protected in transit by a FIPS 140-3 validated cryptographic module, NIST CMVP Certificate #5247. That is the SC-13 case that runs through Lavawall. |
| Validated management channel | In FIPS mode the agent-to-console cryptography is performed by FIPS 140-3 validated modules. Lavawall uses more than one validated module across the platform, so ThreeShield documents the modules and certificates that apply to your deployment. |
| Validated administrator access | Technicians can be required to sign in with a FIPS 140-3 validated key, checked against the NIST CMVP list at registration and every login, before they touch a tenant. The YubiKey 5 FIPS Series (certificate 5291) is the model we enforce. |
| Flaw remediation | Cross-platform patch management for Windows, macOS, and Linux, with patch status recorded as timestamped evidence for the remediation control. |
| Multi-tenant separation | Each client is its own tenant, so an MSP can hold several regulated customers without co-mingling their data or their evidence. |
The YubiKey 5C NFC FIPS (140-3) is US$95 on Amazon, or US$88 direct from Yubico. Prices last checked: Amazon 2026-09-03, Yubico 2026-09-03. Check the retailer for the current figure.
Why the combination is the point
Buying an RMM for patching and bolting FIPS on afterwards is how gaps appear. Lavawall® runs patching, monitoring, remote support, and GRC from the same FIPS-mode console, so the cryptography is consistent and the patch evidence lands in the same place your framework mapping lives. Many remote-access tools rest their validation on FIPS 140-2, which NIST moves to its historical list on 21 September 2026; Lavawall cites a current FIPS 140-3 certificate for the remote-session path. See how to choose a FIPS 140-3 RMM for the questions to ask a vendor, and cross-platform patch management for the patching engine in detail.
Related
Frequently asked
- Is the RMM traffic protected by FIPS 140-3 validated cryptography?
- In FIPS mode the cryptography is performed by FIPS 140-3 validated modules. The remote desktop session a technician uses to reach a regulated machine runs through a validated module, NIST CMVP Certificate #5247. Lavawall uses more than one validated module across the platform, so ThreeShield documents the modules and certificates that apply to your deployment.
- Does patching itself count toward compliance?
- Yes. Timely patching is the flaw-remediation control in CJIS, NIST SP 800-171, and CMMC, and Lavawall records patch status as timestamped evidence for it, separate from the FIPS cryptography requirement.
- Who does CJIS apply to?
- Any agency that touches criminal justice information, which includes village, town, county, and city police forces, sheriff’s offices, and the MSPs that support them. If your technicians can reach a machine that displays that data, the remote-access path falls under the policy.