The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Prerequisites to use Drive Encryption in FIPS mode

Prev Next

For Drive Encryption 8.x or later to be in compliance with FIPS 140-2, the software must meet these conditions.

  • The Drive Encryption client package must be installed on the client in FIPS mode.

  • Depending on compliance requirements mandated by your auditor (with particular regard to key generation), you might also need to install ePO - On-prem in FIPs mode. For more information, refer to the Knowledge Base article KB83483.

If you don't install both ePO - On-prem and Drive Encryption in FIPS mode, the configuration does not operate in a FIPS-certified manner.

Important

Drive Encryption must be operating in FIPS mode at the time of activation of a client to ensure that keys are generated in a FIPS-approved manner. Upgrading an active Drive Encryption client to a FIPS mode version of Drive Encryption 8.x or later does not imply that the client is now running with FIPS quality keys. A Drive Encryption active client should be decrypted, deactivated, and then reactivated using a FIPS mode client installation in order to be FIPS-compliant.