https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm Skip to main content U.S. flag An official website of the United States government Here's how you know Here's how you know [icon-dot-g] Official websites use .gov A .gov website belongs to an official government organization in the United States. [icon-https] Secure .gov websites use HTTPS A lock ( A locked padlock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. https://www.nist.gov/news-events/news/2022/12/ nist-retires-sha-1-cryptographic-algorithm National Institute of Standards and Technology National Institute of Standards and Technology Search NIST [ ] Search Menu Close * Topics + All Topics + Advanced communications + Artificial intelligence + Bioscience + Buildings and construction + Chemistry + Climate + Cybersecurity + Electronics + Energy + Environment + Fire + Forensic science + Health + Information technology + Infrastructure + Manufacturing + Materials + Mathematics and statistics + Metrology + Nanotechnology + Neutron research + Performance excellence + Physics + Public safety + Resilience + Standards + Transportation * Publications * Labs & Major Programs + Laboratories o Communications Technology Laboratory o Engineering Laboratory o Information Technology Laboratory o Material Measurement Laboratory o Physical Measurement Laboratory + User Facilities o NIST Center for Neutron Research o CNST NanoFab + Research Test Beds + Research Projects + Tools & Instruments + Major Programs o Baldrige Performance Excellence Program o Manufacturing Extension Partnership (MEP) o Office of Advanced Manufacturing o Special Programs Office o Technology Partnerships Office * Services & Resources + Standards and Measurements o Calibration Services o Laboratory Accreditation (NVLAP) o Quality System o Standard Reference Materials (SRMs) o Standards.gov o Time Services o Office of Weights and Measures + Software + Data o Chemistry WebBook o National Vulnerability Database o Physical Reference Data o Standard Reference Data (SRD) + Storefront + License & Patents + Computer Security Resource Center (CSRC) + NIST Research Library * News & Events + News + Events + Blogs + Feature Stories + Awards + Video Gallery + Image Gallery + Media Contacts * About NIST + About Us + Contact Us + Visit + Careers + Our Organization o Office of the Director o Budget & Planning + Work with NIST + History o NIST Digital Archives o NIST Museum o NIST and the Nobel + Educational Resources NEWS NIST Retires SHA-1 Cryptographic Algorithm The venerable cryptographic hash function has vulnerabilities that make its further use inadvisable. December 15, 2022 Share Facebook Linkedin Twitter Email In illustration featuring a laptop, text with the letters SHA-1 is crossed out, with check marks next to the letters SHA-2 and SHA-3. NIST recommends that anyone relying on SHA-1 for security switch to using the more secure SHA-2 and SHA-3 groups of algorithms. Credit: B. Hayes/NIST The SHA-1 algorithm, one of the first widely used methods of protecting electronic information, has reached the end of its useful life, according to security experts at the National Institute of Standards and Technology (NIST). The agency is now recommending that IT professionals replace SHA-1, in the limited situations where it is still used, with newer algorithms that are more secure. SHA-1, whose initials stand for "secure hash algorithm," has been in use since 1995 as part of the Federal Information Processing Standard (FIPS) 180-1. It is a slightly modified version of SHA, the first hash function the federal government standardized for widespread use in 1993. As today's increasingly powerful computers are able to attack the algorithm, NIST is announcing that SHA-1 should be phased out by Dec. 31, 2030, in favor of the more secure SHA-2 and SHA-3 groups of algorithms. "We recommend that anyone relying on SHA-1 for security migrate to SHA-2 or SHA-3 as soon as possible," said NIST computer scientist Chris Celi. SHA-1 has served as a building block for many security applications, such as validating websites -- so that when you load a webpage, you can trust that its purported source is genuine. It secures information by performing a complex math operation on the characters of a message, producing a short string of characters called a hash. It is impossible to reconstruct the original message from the hash alone, but knowing the hash provides an easy way for a recipient to check whether the original message has been compromised, as even a slight change to the message alters the resulting hash dramatically. "We recommend that anyone relying on SHA-1 for security migrate to SHA-2 or SHA-3 as soon as possible." --Chris Celi, NIST computer scientist Today's more powerful computers can create fraudulent messages that result in the same hash as the original, potentially compromising the authentic message. These "collision" attacks have been used to undermine SHA-1 in recent years. NIST has announced previously that federal agencies should stop using SHA-1 in situations where collision attacks are a critical threat, such as for the creation of digital signatures. As attacks on SHA-1 in other applications have become increasingly severe, NIST will stop using SHA-1 in its last remaining specified protocols by Dec. 31, 2030. By that date, NIST plans to: * Publish FIPS 180-5 (a revision of FIPS 180) to remove the SHA-1 specification. * Revise SP 800-131A and other affected NIST publications to reflect the planned withdrawal of SHA-1. * Create and publish a transition strategy for validating cryptographic modules and algorithms. The last item refers to NIST's Cryptographic Module Validation Program (CMVP), which assesses whether modules -- the building blocks that form a functional encryption system -- work effectively. All cryptographic modules used in federal encryption must be validated every five years, so SHA-1's status change will affect companies that develop modules. "Modules that still use SHA-1 after 2030 will not be permitted for purchase by the federal government," Celi said. "Companies have eight years to submit updated modules that no longer use SHA-1. Because there is often a backlog of submissions before a deadline, we recommend that developers submit their updated modules well in advance, so that CMVP has time to respond." Questions about the transition can be sent to sha-1-transition [at] nist.gov. More information is available at the NIST Computer Security Resource Center transition page. Information technology, Cybersecurity and Cryptography Media Contact * Chad Boutin charles.boutin@nist.gov (301) 975-4261 Organizations * NIST Headquarters * + Laboratory Programs + o Information Technology Laboratory o # Computer Security Division # @ Security Test, Validation and Measurement Group Sign up for updates from NIST Enter Email Address [ ] [Sign up] Released December 15, 2022 National Institute of Standards and Technology logo HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 301-975-2000 Webmaster | Contact Us | Our Other Offices Twitter Facebook LinkedIn Instagram YouTube Giphy RSS Feed Mailing List How are we doing? Feedback * Site Privacy * Accessibility * Privacy Program * Copyrights * Vulnerability Disclosure * No Fear Act Policy * FOIA * Environmental Policy * Scientific Integrity * Information Quality Standards * Commerce.gov * Science.gov * USA.gov * Vote.gov