AWS Storage Gateway adds FIPS 140-3 PrivateLink endpoints
For years, the FIPS-PrivateLink gap forced regulated workloads to choose between validated encryption and private networking.
TL;DR
AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Tape and Volume Gateway. Previously, FIPS endpoints were only reachable over the public internet, forcing regulated-workload operators to choose between FIPS-compliant encryption and private network architecture. The feature is available in eight regions including both GovCloud endpoints, with gateway software version 3.2.7 or later required. The fix closes a long-standing gap that competing cloud storage services addressed earlier, but for GovCloud tenants already running Storage Gateway, it removes a genuine operational constraint.
AWS Storage Gateway's Tape and Volume Gateway flavors previously had a binary choice baked into their architecture: FIPS 140-3 validated endpoints, or AWS PrivateLink connectivity. You couldn't have both. For contractors handling CUI under CMMC or agencies operating under FedRAMP authorization boundaries, that meant either routing FIPS-encrypted backup traffic over the public internet (which many security plans explicitly prohibit) or using PrivateLink without FIPS validation (which fails the compliance checkbox on cryptographic modules).
The new capability resolves that tension directly. Operators can now create a FIPS interface endpoint for Storage Gateway inside their VPC, select the FIPS VPC endpoint option at gateway activation, and get both validated encryption and private AWS network transport. The gateway must run software version 3.2.7 or later.
The feature ships to eight North American regions covering US commercial, Canada, and both GovCloud endpoints. Notably absent are any non-North American FIPS endpoints; Storage Gateway's FIPS footprint remains hemispheric.
For defense contractors and federal agencies already operating Storage Gateway in GovCloud, the announcement is genuinely useful. It removes a compliance-versus-security tradeoff that never should have existed. The version-gating is light (3.2.7 ships alongside the announcement), and the PrivateLink configuration workflow is standard enough that most VPC administrators can implement it without a support case.
The broader note is that FIPS-over-PrivateLink is table-stakes infrastructure for competing services at this point. AWS is catching up here, not leading. But catching up on a gap that directly constrained regulated workloads is still worth knowing about Monday morning.
Published ·Updated ·Deep Fathom