Hi NXP Team,
We are currently using the NXP Code Signing Tool (CST) for secure boot implementation and for generating/managing the keys and certificates used for image signing.
As part of our product security requirements, we need to understand the FIPS 140-3 Level 3 compliance of the CST-based code-signing process.
Could you please clarify the following:
1. Is the NXP Code Signing Tool (CST) itself FIPS 140-3 compliant or validated, specifically for FIPS 140-3 Level 3 requirements?
If yes, could you please share the relevant certification, validation details, or official NXP documentation confirming the compliance?
Thanks
CST is documented as an NXP code-signing tool, not as a FIPS 140-3 Level 3 validated cryptographic module.