This is not to say that products not found on the validated products
list should be considered insecure. Why? Mainly because companies have
to pay for their product to be tested and validated in order to appear
on this list. As a result, those free security products out there may
not necessarily have been validated to FIPS 140-2. However, when you
have a choice between two or more comparable products and one of them
has been FIPS validated, that product would be the better choice. It
may help you and your customers sleep better at night knowing that an
independent entity validated the soundness of the encryption
capabilities.
Next time you issue an RFI, or are looking at a product that utilizes
encryption, make sure you include questions related to the soundness of
the implementation of the cryptographic components. Alternately, you
can search the FIPS Validated Product listing yourself.