FIPS Compliance

Veeam Backup & Replication can be configured to run in a FIPS-compliant operation mode. When this mode is enabled, Veeam Backup & Replication uses platform-provided cryptographic APIs and the Veeam Cryptographic Module to meet FIPS-compliance requirements. Additionally, connections cannot be established with components that are not FIPS-compliant.

Note

To make your backup infrastructure FIPS-compliant, follow vendor recommendations. For more information on Microsoft Windows Server, see this article.

To enable the FIPS-compliant operation mode:

  1. From the main menu on the backup server, select Options.
  2. Open the Security tab.
  3. In the FIPS compliance section, select the Use FIPS-certified encryption modules check box.
  4. Click OK.

Note

If you use Amazon S3 or Amazon S3 Glacier object repositories in your backup infrastructure and enable the FIPS-compliant operation mode, Veeam Backup & Replication checks if these components are FIPS-compliant. If any of them are not, a warning will be displayed.

Important

If you have backup infrastructure components based on Linux servers with persistent Veeam Data Movers and select or clear the Use FIPS-certified encryption modules check box, you must open the Edit Linux Server wizard for each Linux server with the persistent Veeam Data Mover and proceed to the end of the wizard. This will update server settings. If you do not update the settings, the servers will be unavailable.

FIPS Compliance 

Page updated 3/24/2025

Page content applies to build 12.3.1.1139