The consequences of encrypting wrongly quite possibly are worse than if you never encrypted at all.
- "Don't use unproven cryptography" is a reasonable policy.
- Policymaking can be subverted by bad actors.
FIPS validation address the compliance problem of needing validation. Beyond that, the benefits are ambiguous at best.
The consequences of encrypting wrongly quite possibly are worse than if you never encrypted at all.