808bits

FortiOS 5.6

FIPS 140-2 certificate #3639 · Fortinet, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in the FIPS 140-2 Compliant Operation Section of the Security Policy

Certificate

Certificate number3639
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
VendorFortinet, Inc. · website
Firmware versionsFortiOS 5.6, build6022,190808

Module description

The FortiOS is a firmware based operating system that runs exclusively on Fortinet's FortiGate/FortiWiFi product family. The FortiOS provides integrated firewall, VPN, antivirus, antispam, intrusion prevention, content filtering and traffic shaping and HA capabilities.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AESC468, C530, C531
CVLC468, C530, C531
DRBGC529
ECDSAC468, C530, C531
HMACC468, C530, C531
KTS
KTS
RSAC530, C531
SHSC468, C530, C531

Allowed algorithms

Diffie-Hellman (CVL Certs. #C468 and #C530, key agreement; key establishment methodology provides between 112 and 196 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C530, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • FortiGate-301E

Validation history

DateTypeLab
2020-04-02InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-04-02

Source documents