808bits

Cisco Firepower Threat Defense Cryptographic Module

FIPS 140-2 certificate #3695 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper evident seals and opacity shield installed as indicated in the Security Policy

Certificate

Certificate number3695
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsFPR1010[1], FPR1120[2], FPR1140[2], FPR2110[3], FPR2120[3], FPR2130[3] and FPR2140[3] with FIPS Kit (AIR-AP-FIPSKIT=) and Opacity Shield 800-44098-01[1], 800-45098-01[2] and 69-100250-01[3]
Firmware versions6.4

Module description

The 1K is a family of three platforms, 1010 for desktop and 1120 and 1140 for rack mount. While the 2K is a family of four threat-focused NGFW security rack mount platforms. These are all next generation security services platforms capable of running multiple (firewall (NGFW), traffic management) security services simultaneously.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3301, 4905, C784
CVL1521, C784
DRBG819, 1735, C784
ECDSA1254, C784
HMAC2095, 3272, C784
RSA2678, C784
SHS2737, 4012, C784
Triple-DES1881, 2559, C784

Allowed algorithms

Diffie-Hellman (CVL Certs. #C784 and #1521, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #C784 and #1521, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2020-08-06InitialGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-08-06

Source documents