808bits

Cisco NCS 5500 Series Routers

FIPS 140-2 certificate #3570 · Cisco Systems, Inc. · data as of 2026-09-12

Cisco NCS 5500 Series Routers, from Cisco Systems, Inc., holds FIPS 140-2 certificate #3570 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 9 of the Security Policy

Certificate

Certificate number3570
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsNCS-5501, NCS-5502, NCS-55A1-36H-SE-S and [NCS-5508 with components NC55-RP, NC55-36X100G-S]
Firmware versionsCisco IOS XR 6.3

Module description

Quoted from the NIST CMVP entry for this certificate.

The Cisco Network Convergence System 5500 Series is a family of routing platforms including fixed and modular chassis. The platform offers high port density, high performance forwarding, low jitter and the lowest power consumption per Gigabits/sec at a very cost-effective price point. The routers meet FIPS 140-2 overall Level 1 requirements as multi-chip standalone modules. The modules include cryptographic algorithms implemented in IOS-XR software.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (8)

AlgorithmCAVP certificates
AES4369, C542
CVLC542
DRBGC542
HMACC542
KBKDFC542
RSAC542
SHSC542
Triple-DESC542

Allowed algorithms

Diffie-Hellman (Cert. #C542, key establishment methodology provides between 112 and 150-bits of encryption strength); EC Diffie-Hellman (Cert. #C542, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); RSA (Cert. #C542, key wrapping; key establishment methodology provides 112 and 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2019-11-22InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-11-22

Source documents