808bits

ASA 5512-X, ASA 5515-X, ASA 5525-X, ASA 5545-X, ASA 5555-X, ASA 5580-20, ASA 5580-40, ASA 5585-X SSP-10, 5585-X SSP-20, 5585-X SSP-40 and 5585-X SSP-60 Security Appliances

FIPS 140-2 certificate #2176 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. 186-2 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper evident seals and security devices installed as indicated in the Security Policy

Certificate

Certificate number2176
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Hardware versions5580-20 [2], 5580-40 [2], 5512-X [1], 5515-X [1], 5525-X [1], 5545-X [1], 5555-X[1], 5585-X SSP-10 [3], 5585-X SSP-20 [3], 5585-X SSP-40 [3], 5585-X SSP-60 [3] with [FIPS Kit (DS-FIPS-KIT= Rev -BO)] [1], [ASA 5580 FIPS Kit (ASA5580-FIPS-KIT)] [2], or [ASA 5585 FIPS Kit (ASA5585-X-FIPS-KIT)] [3]
Firmware versions9.1.7.9

Module description

The market-leading Cisco ASA Security Appliance Series deliver robust user and application policy enforcement, multi-vector attack protection, and secure connectivity services in cost-effective, easy-to-deploy solutions. The ASA 5500 Series Adaptive Security Appliances provide comprehensive security, performance, and reliability for network environments of all sizes.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES105, 1407, 2049, 2050, 2444, 2472, 2480, 2482, 2483
DRBG332, 336, 339, 341
ECDSA411, 412
HMAC125, 301, 1246, 1247, 1514, 1524, 1525
RSA106, 261, 1066, 1260, 1269, 1271, 1272
SHS196, 630, 1793, 1794, 2091, 2100, 2101
Triple-DES217, 559, 960, 1321, 1513, 1520, 1521

Other algorithms

DES; Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); HMAC-MD5; MD5; NDRNG; RC4; RNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2014-06-18InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2014-08-29UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-01-12UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-03-02UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-06-29UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-08-15UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-08-31UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-06-18, 2014-08-29, 2016-01-12, 2016-03-02, 2016-06-29, 2016-08-15, 2016-08-31

Source documents