Built on FIPS 140-Validated Modules

FIPSMQ — Secure, Compliant Message Brokering

FIPSMQ delivers message brokering on FIPS 140-2 and FIPS 140-3 validated cryptographic modules built on RabbitMQ. Designed for defense, federal, and regulated enterprise environments that cannot compromise on cryptographic assurance.

View Compliance Docs
FIPS 140-2/3Validated Cryptography
99.99%HA Cluster Uptime
AMQP · MQTT · STOMPProtocol Support

Trusted by regulated enterprises and federal teams globally

Named by the RabbitMQ Core Team

The Featured Authorized Partner for RabbitMQ — named by the engineers who build it

AceMQ is the Featured Authorized Partner for RabbitMQ, named by the RabbitMQ Core Engineering Team — the people who write and maintain the broker. That recognition covers RabbitMQ support, licensing and professional services, and it makes AceMQ the only RabbitMQ partner with a direct line to the core team. When an escalation needs an answer that is not in the documentation, it does not stop at a support tier.

You do not have to take our word for it — RabbitMQ lists AceMQ on its own site.

See AceMQ listed on rabbitmq.com
Only
RabbitMQ partner with a direct line to the Core Engineering Team
Support · Licensing · Services
the full scope the partner status covers
Below 72 cores
the only provider globally licensing commercial RabbitMQ under Broadcom's minimum
Why Teams Arrive Here

The moment this becomes urgent

Nobody researches validated cryptography for pleasure. These are the situations that send people looking.

A control assessor has flagged the messaging layer's cryptography and the ATO package is blocked
A contract requires FIPS 140-2 or 140-3 validated cryptography and your broker cannot evidence it
You are running RabbitMQ in a federal or defense environment on a build nobody has validated
An agency customer is asking which modules are validated and you have no answer to give them
The broker terminates TLS with a library outside the validated boundary and it was never noticed
A migration to a compliant footprint has been scoped and shelved twice on risk grounds
You need FIPS mode without giving up clustering, high availability or throughput
Your current vendor supports the platform but will not speak to the compliance question
Empowering Secure and Scalable Messaging

What Is FIPSMQ?

FIPSMQ is a hardened distribution, built on FIPS 140-2 and FIPS 140-3 validated cryptographic modules, of RabbitMQ. Every cryptographic operation — TLS handshakes, certificate verification, and data-in-transit encryption — runs exclusively through NIST-approved modules. Organizations subject to DoD, FISMA, FFIEC, or FedRAMP requirements can deploy FIPSMQ with confidence that the message layer satisfies their compliance mandate.

Built on FIPS 140-Validated Modules

All cryptographic operations use NIST-validated modules. TLS 1.2 and TLS 1.3 are enforced with approved cipher suites only — no fallback to non-FIPS algorithms.

Built on RabbitMQ

FIPSMQ inherits RabbitMQ's battle-tested AMQP, MQTT, and STOMP protocol support. Teams already familiar with RabbitMQ operations require minimal retraining.

Regulation-Ready

Satisfies the messaging-layer requirements for DoD IL2–IL5, FISMA Moderate/High, FedRAMP, FFIEC, and HIPAA regulated environments out of the box.

Cryptographic Security

FIPS Compliance & Security Assurance

FIPSMQ enforces cryptographic boundaries at every layer of the message broker stack. From cluster inter-node communication to client connections, no unvalidated algorithm can enter the data path.

FIPS-Mode OS Enforcement

FIPSMQ runs on an operating system with FIPS mode enabled at the kernel level, preventing any process from loading non-approved cryptographic libraries. This is a prerequisite for FIPS 140-3 compliance.

Audit Logging & Observability

All authentication events, connection attempts, permission changes, and administrative actions are logged to a tamper-evident audit trail, satisfying DoD audit requirements and FISMA audit controls.

mTLS Client Authentication

FIPSMQ enforces mutual TLS authentication for all client connections. Certificate authorities, certificate lifetimes, and cipher suite restrictions are configurable per environment requirements.

Change Management & Documentation

Every configuration change is documented in version-controlled policy files. Change management procedures, rollback plans, and deployment runbooks are maintained as auditable artifacts.

Competencies covered

Change ManagementDeploymentDisaster RecoveryQATeam CultureGame DayDocumentationCapacity PlanningRoot Cause AnalysisHigh Availability
Clearance Coverage

Regulation-Ready Out of the Box

FIPSMQ satisfies the messaging-layer cryptographic requirements across these frameworks without custom configuration — because the defaults are already hardened.

DoD IL2

Controlled Unclassified

DoD IL4

Controlled Defense

DoD IL5

National Security

FedRAMP Mod

Moderate Impact

FedRAMP High

High Impact

FISMA Mod

Moderate Baseline

FISMA High

High Baseline

FFIEC

Financial Institutions

HIPAA

Healthcare Data

CMMC 2.0

Defense Supply Chain

Cryptographic compliance is a necessary but insufficient condition for regulatory approval. to discuss your full compliance program.

Mission Resilience

High Availability & Fault Tolerance

Mission-critical environments cannot afford message loss. FIPSMQ uses RabbitMQ's quorum queue architecture with FIPS-compliant inter-node replication to deliver 99.99% availability even when individual nodes fail.

Quorum Queues

Raft-based consensus ensures messages are replicated across a configurable majority of nodes before being acknowledged. No data loss on node failure.

Multi-AZ Clustering

FIPSMQ clusters span multiple availability zones. Automatic leader election ensures continuous operation when an AZ becomes unavailable.

Automatic Failover

Cluster health is monitored continuously. Failed nodes are detected within seconds and leadership is transferred automatically with no manual intervention.

Dead-Letter Handling

Messages that cannot be delivered are routed to dead-letter exchanges for inspection and replay, eliminating silent message loss in failure scenarios.

By the numbers

99.99%

Cluster Uptime SLA

< 10s

Failover Time

0

Message Loss on Node Failure

Game Day and Disaster Recovery Testing

AceMQ conducts planned failure exercises — killing nodes, partitioning networks, and exhausting disk — to validate that your FIPSMQ cluster recovers within your defined RTO and RPO. Each exercise produces a signed report suitable for auditors.

FIPS compliance without sacrificing performance. AceMQ deploys and supports FIPSMQ in your environment.

Protocol Stack

Advanced Messaging Patterns & Optimization

FIPSMQ supports the full range of RabbitMQ messaging patterns — all encrypted end-to-end with FIPS-approved algorithms. Route, transform, prioritize, and monitor your message flows without sacrificing compliance.

Topic & Direct Routing

Route messages to specific consumers using topic patterns, direct bindings, or headers-based matching. Each routing decision traverses FIPS-validated TLS connections.

Message Transformation

Transform message payloads at the exchange layer using Shovel and Federation plugins. Cross-datacenter message replication maintains FIPS compliance at every hop.

Channel Multiplexing

A single FIPS-validated TLS connection supports hundreds of AMQP channels, reducing connection overhead while maintaining per-channel flow control and isolation.

Monitoring & Alerting

Prometheus metrics and Grafana dashboards expose queue depth, consumer lag, memory usage, and connection state. Alerts fire before capacity limits are reached.

Priority Queuing

Assign 1–255 priority levels to messages. Critical security events can be guaranteed delivery ahead of lower-priority operational messages within the same queue.

Consistent Hashing Exchange

Distribute messages evenly across consumer pools using consistent hashing. Horizontal scaling of consumers requires no application-layer changes.

Messaging capabilities

TransformationChannelsMonitoringRoutingConstructionDead-LetterPriority QueuingShovelFederationFlow Control
How It Works

How a FIPS deployment actually runs

An accreditation package has a submission date, so the deciding question is sequence and duration rather than capability.

11–2 weeks

Boundary review

We establish where cryptography is actually performed in your deployment — broker, client libraries, TLS termination, management plane — and which of those sit inside a validated boundary today. This is usually where the surprise is.

2Within a week

Gap findings and target design

What has to change to bring the messaging layer inside the boundary, written against the controls your assessor is citing rather than a generic hardening list, with the clustering and throughput implications stated.

3Scoped per environment

Deployment and evidence

Build and rollout in FIPS mode with high availability intact, plus the configuration evidence and documentation your accreditation package needs.

Frequently Asked Questions

Common questions about FIPSMQ deployment, compliance coverage, and compatibility with existing RabbitMQ infrastructure.

FIPSMQ is a hardened RabbitMQ distribution built on FIPS 140-2 and FIPS 140-3 validated cryptographic modules. It delivers cryptographically assured messaging for defense, federal government, and regulated enterprise environments that require NIST-approved cryptographic modules.

FIPSMQ performs all cryptographic operations through FIPS 140-2 and FIPS 140-3 validated modules, including TLS 1.2 and TLS 1.3 with FIPS-approved cipher suites. All cryptographic operations use NIST-validated modules, satisfying DoD, federal agency, and commercial compliance requirements.

Standard RabbitMQ uses OpenSSL which may not operate in FIPS mode by default. FIPSMQ is configured to run exclusively with FIPS 140-2/140-3 approved cryptographic modules, with FIPS-mode enforcement at the OS and application layer, audit logging, and hardened TLS configuration using only approved cipher suites.

Yes. FIPSMQ supports high availability clustering with quorum queues for durability and fault tolerance. Clusters can be deployed across multiple availability zones with automatic failover, maintaining FIPS compliance throughout the cluster communication using mTLS with FIPS-approved certificates.

FIPSMQ supports AMQP 0-9-1, AMQP 1.0, MQTT, and STOMP protocols, all secured with FIPS-compliant TLS. It provides topic, direct, fanout, and headers exchange types, plus dead-letter queues, priority queues, and quorum queues for fault-tolerant message delivery.

FIPSMQ is designed for U.S. federal agencies (including DoD, IC, and civilian agencies), defense contractors, financial institutions subject to FFIEC guidance, and any enterprise operating in a regulated environment that mandates FIPS 140-2 or FIPS 140-3 cryptographic validation for all data in transit.

FIPS 140-2 & 140-3Validated Cryptography
99.99%HA Cluster SLA
< 10sAutomatic Failover
200+Enterprise Deployments

Empower Your Messaging with FIPSMQ

Whether you're modernizing a legacy federal messaging system or building a new compliant infrastructure from scratch, AceMQ deploys and supports FIPSMQ with the same rigor we apply to every enterprise RabbitMQ engagement.

View Compliance Docs

Have a technical question? with an AceMQ engineer.