808bits

Cisco ASR 1000 Series Routers with MACSEC

FIPS 140-2 certificate #3775 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition - replaced by certificate #4644. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 9 of the Security Policy

Certificate

Certificate number3775
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsASR1001-HX, ASR1002-HX, [[ASR1006-X with RP2, RP3, ESP40, ESP100, [ASR1000-MIP100 with EPA-10X10GE and EPA-1X40GE QSFP+]] and [[ASR-1009-X with RP2, RP3, ESP40, ESP100, ESP200, [ASR1000-MIP100 with EPA-10X10GE and EPA-1X40GE QSFP+]]
Firmware versionsCisco IOS-XE 16.12

Module description

The ASR 1000 Routers accelerate services by offering performance and resiliency with optimized, intelligent services; establishing a benchmark for price-to-performance offerings in the enterprise routing, service provider edge, and broadband aggregation segments; facilitating significant network innovations in areas such as secure WAN aggregation, managed customer-premises-equipment services, and service provider edge services, and reducing operating expenses and capital expenditures by facilitating managed or hosted services over identical architectures and operating environments.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES333, 2346, 3160, 3505, 4583, C462
CKGvendor affirmed
CVL1257, 1258, C462
DRBG1529, C462
ECDSA1241, C462
HMAC137, 1455, 3034, C462
KBKDF139, C462
KTS
RSA2500, C462
SHS408, 2023, 3760, C462
Triple-DES397, 1469, 2436, C462

Allowed algorithms

Diffie-Hellman (CVL Certs. #1257, #1258 and #C462, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1257, #1258 and #C462, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2020-12-18InitialAcumen Security
2021-06-11UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-12-18, 2021-06-11

Source documents