I am currently utilizing a Let's Encrypt certificate in an environment that is undergoing a federal audit. Concerns were raised that Let's Encrypt does not state that they utilize FIPS VALIDATED modules, only FIPS compliant.
In the Let's Encrypt documentation you state: "ISRG uses HSMs meeting FIPS 140-2 Level 3 (or higher) requirements." which implies FIPS compliance but not FIPS validation.
There's a brief mention of them getting new donated HSMs from Thales in this blog post a couple years ago:
I don't know as that's really what you're looking for, or would be meaningful enough for an "audit".
I wouldn't expect that you'd need to have more detail than what's already listed in Let's Encrypt's own audits in order to just be using LE Certificates, but I have luckily managed to stay away from the term "FIPS" in my career.
That blog post may help since it specifically ties you guys to the Luna HSM. I will try to further the conversation with that information. If we are still struggling to get through, would it be appropriate to email the security address provided in contacts to get an attestation? I avoided that as I didn't want to flood that email with unneeded questions.
I'm now kind of amused that in the CP/CPS, Destroying Private Keys says that destruction is done via a "FIPS 140-2 (or higher) validated zeroize method", but that creating private keys refers to standards and controls that it "uses HSMs meeting FIPS 140-2 Level 3 (or higher) requirements." I didn't know that there was a difference between "validated" and "meeting requirements", but I'm curious if that wording difference is intentional.
To be clear, I'm just a random person on the Internet who sometimes posts on this forum. You may yet get an answer here from someone who actually works for Let's Encrypt when they get a chance, though they can pretty busy.
I think they prefer to correspond via the forums if possible. That security address I think is more intended for reporting security vulnerabilities, not for asking for help with your audits.
To wrap this up in a bow for anyone else chasing this rabbit hole the summary of the response is as follows.
Let's Encrypt utilizes Luna HSM which is a FIPS 140-2 VALIDATED module. This relationship has been published in multiple locations (see comments above).
Aside from the known association with Luna, Let's Encrypt is audited against the WebTrust Principles and Criteria for Certification Authorities Version 2.2.2 (version subject to change). Specifically, Illustrative Principal 4.1.1 from this baseline addresses the need for the certification authority to utilize cryptographic modules that meet the requirements of 'ISO 19790 and ISO 13491-1/FIPS 140-2 (or equivalent)/ANSI X9.66 and the business requirements in accordance with the CPS'". These audit reports are publicly available and demonstrate compliance with this control.
While this does not explicitly address the extremely detailed auditors need to explicitly see the term a FIPS "validated" module, it should provide enough context to ensure a healthy conversation and argue for acceptance of these certificates.