Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #5417

Details

Module Name
CiscoSSL FIPS Provider
Standard
FIPS 140-3
Status
Active
Sunset Date
7/14/2031
Overall Level
1
Caveat
When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
Security Level Exceptions
  • Non-invasive security: N/A
Module Type
Firmware
Embodiment
MultiChipStand
Description
The CiscoSSL FIPS Provider is a firmware library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module is comprised of a single object module file called fips.so.
Approved Algorithms
AES-CBC
AES-CBC
AES-CBC-CS1
AES-CBC-CS1
AES-CBC-CS2
AES-CBC-CS2
AES-CBC-CS3
AES-CBC-CS3
AES-CCM
AES-CCM
AES-CFB1
AES-CFB1
AES-CFB128
AES-CFB128
AES-CFB8
AES-CFB8
AES-CMAC
AES-CMAC
AES-CTR
AES-CTR
AES-ECB
AES-ECB
AES-GCM
AES-GCM
AES-GMAC
AES-GMAC
AES-KW
AES-KW
AES-KWP
AES-KWP
AES-OFB
AES-OFB
AES-XTS Testing Revision 2.0
AES-XTS Testing Revision 2.0
Counter DRBG
Counter DRBG
Deterministic ECDSA SigGen (FIPS186-5)
Deterministic ECDSA SigGen (FIPS186-5)
DSA PQGVer (FIPS186-4)
DSA PQGVer (FIPS186-4)
DSA SigVer (FIPS186-4)
DSA SigVer (FIPS186-4)
ECDSA KeyGen (FIPS186-5)
ECDSA KeyGen (FIPS186-5)
ECDSA KeyVer (FIPS186-5)
ECDSA KeyVer (FIPS186-5)
ECDSA SigGen (FIPS186-5)
ECDSA SigGen (FIPS186-5)
ECDSA SigVer (FIPS186-5)
ECDSA SigVer (FIPS186-5)
Hash DRBG
Hash DRBG
HMAC DRBG
HMAC DRBG
HMAC-SHA-1
HMAC-SHA-1
HMAC-SHA2-224
HMAC-SHA2-224
HMAC-SHA2-256
HMAC-SHA2-256
HMAC-SHA2-384
HMAC-SHA2-384
HMAC-SHA2-512
HMAC-SHA2-512
HMAC-SHA2-512/224
HMAC-SHA2-512/224
HMAC-SHA2-512/256
HMAC-SHA2-512/256
HMAC-SHA3-224
HMAC-SHA3-224
HMAC-SHA3-256
HMAC-SHA3-256
HMAC-SHA3-384
HMAC-SHA3-384
HMAC-SHA3-512
HMAC-SHA3-512
KAS-ECC CDH-Component SP800-56Ar3
KAS-ECC CDH-Component SP800-56Ar3
KAS-ECC-SSC Sp800-56Ar3
KAS-ECC-SSC Sp800-56Ar3
KAS-FFC-SSC Sp800-56Ar3
KAS-FFC-SSC Sp800-56Ar3
KAS-IFC-SSC
KAS-IFC-SSC
KDA HKDF SP800-56Cr2
KDA HKDF SP800-56Cr2
KDA OneStep SP800-56Cr2
KDA OneStep SP800-56Cr2
KDA TwoStep SP800-56Cr2
KDA TwoStep SP800-56Cr2
KDF ANS 9.42
KDF ANS 9.42
KDF ANS 9.63
KDF ANS 9.63
KDF IKEv2
KDF IKEv2
KDF SNMP
KDF SNMP
KDF SP800-108
KDF SP800-108
KDF SRTP
KDF SRTP
KDF SSH
KDF SSH
KMAC-128
KMAC-128
KMAC-256
KMAC-256
KTS-IFC
KTS-IFC
PBKDF
PBKDF
RSA Decryption Primitive Sp800-56Br2
RSA Decryption Primitive Sp800-56Br2
RSA KeyGen (FIPS186-5)
RSA KeyGen (FIPS186-5)
RSA SigGen (FIPS186-5)
RSA SigGen (FIPS186-5)
RSA Signature Primitive
RSA Signature Primitive
RSA SigVer (FIPS186-5)
RSA SigVer (FIPS186-5)
Safe Primes Key Generation
Safe Primes Key Generation
Safe Primes Key Verification
Safe Primes Key Verification
SHA-1
SHA-1
SHA2-224
SHA2-224
SHA2-256
SHA2-256
SHA2-384
SHA2-384
SHA2-512
SHA2-512
SHA2-512/224
SHA2-512/224
SHA2-512/256
SHA2-512/256
SHA3-224
SHA3-224
SHA3-256
SHA3-256
SHA3-384
SHA3-384
SHA3-512
SHA3-512
SHAKE-128
SHAKE-128
SHAKE-256
SHAKE-256
TDES-CBC
TDES-CBC
TDES-CMAC
TDES-CMAC
TDES-ECB
TDES-ECB
TLS v1.2 KDF RFC7627
TLS v1.2 KDF RFC7627
TLS v1.3 KDF
TLS v1.3 KDF

Vendor

Cisco Systems Inc
170 West Tasman Dr.
San Jose, California 95314
USA

Global Certification Team
[email protected]
Phone: 800-553-6387

Validation History

Date Type Lab
7/15/2026 Initial DEKRA Cybersecurity Certification Laboratory