808bits

Cisco Optical Networking Solution (ONS) 15454 Multiservice Transport Platforms (MSTPs)

FIPS 140-2 certificate #2270 · Cisco Systems, Inc. · data as of 2026-09-03

Cisco Optical Networking Solution (ONS) 15454 Multiservice Transport Platforms (MSTPs), from Cisco Systems, Inc., holds FIPS 140-2 certificate #2270 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and when tamper evident labels are installed on the initially built configuration as indicated in the Security Policy

Certificate

Certificate number2270
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Hardware versions[15454-M2-SA, 15454-M6-SA, 15454-M-TNC-K9, 15454-M-TSC-K9, 15454-M-TNCE-K9, 15454-M-TSCE-K9, 15454-M-WSE-K9 and 10X10G-LC] with FIPS Kit: CISCO-FIPS-KIT=
Firmware versions9.8.1.2 or 9.8.1.3

Module description

Quoted from the NIST CMVP entry for this certificate.

The Cisco ONS 15454 Multiservice Transport Platform (MSTP) is the most deployed metropolitan-area (metro) and regional dense wavelength division multiplexing (DWDM) solution in the world featuring two- through eight-degree reconfigurable optical add/drop multiplexer (ROADM) technology that enables wavelength provisioning across entire networks and eliminates the need for optical-to-electrical-to-optical (OEO) transponder conversions.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (8)

AlgorithmCAVP certificates
AES2352, 2369, 2886, 2887
CVL316, 317
DRBG521, 522
HMAC1820, 1821
KBKDF29
RSA1526, 1527
SHS2427, 2428
Triple-DES1721

Other algorithms

DES; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); HMAC-MD5; MD5; NDRNG; RC4; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Validation history

DateTypeLab
2014-10-22InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2015-06-09UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-10-22, 2015-06-09

Source documents