808bits

Cisco 7606-S and 7609-S Routers with Supervisor SUP720-3B

FIPS 140-2 certificate #1621 · Cisco Systems, Inc. · data as of 2026-09-08

Cisco 7606-S and 7609-S Routers with Supervisor SUP720-3B, from Cisco Systems, Inc., holds FIPS 140-2 certificate #1621 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with the tamper evident labels and opacity shields installed as indicated in the Security Policy

Certificate

Certificate number1621
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Hardware versions7606-S and 7609-S with SUP720-3B
Firmware versions15.1(3)S5

Module description

Quoted from the NIST CMVP entry for this certificate.

The Cisco 7606-S and 7609-S routers are designed for deployment at the network edge, where robust performance and IP/Multiprotocol Label Switching services are necessary to meet the requirements of both enterprises and service providers. It enables Carrier Ethernet service providers to deploy an advanced network infrastructure that supports a range of IP video and triple-play (voice, video, and data) system applications in both the residential and business services markets. They also deliver WAN and metropolitan-area network networking solutions at the enterprise edge.

Security level exceptions

  • Roles, Services, and Authentication: Level 3

Approved algorithms (6)

AlgorithmCAVP certificates
AES1634
DRBG88
HMAC961
RSA808
SHS1439
Triple-DES1070

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 156 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; DES MAC; HMAC MD5; MD4; MD5; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2011-10-28InitialSAIC-VA
2012-02-09UpdateSAIC-VA
2012-02-23Update
2012-07-09Update
2013-08-16UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2011-10-28, 2012-02-09, 2012-02-23, 2012-07-09, 2013-08-16

Source documents