808bits

Cisco Firepower Threat Defense on 4K/9K Cryptographic Module

FIPS 140-2 certificate #3821 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. When installed, initialized and configured as specified in Section 3 of the Security Policy

Certificate

Certificate number3821
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorCisco Systems, Inc. · website
Hardware versionsFPR4110, FPR4115, FPR4120, FPR4125, FPR4140, FPR4145, FPR4150, FPR9K-SM-24, FPR9K-SM-36, FPR9K-SM-40, FPR9K-SM-44, FPR9K-SM-48 and FPR9K-SM-56
Firmware versions6.4

Module description

Cisco Firepower Threat Defense (FTD) is a unified software image, which includes the Cisco ASA features and FirePOWER Services. This unified software is capable of offering the function of ASA and FirePOWER in one platform. This consolidates next-generation firewall, including stateful firewalling, routing, Next-Generation Intrusion Prevention System (NGIPS), Application Visibility and Control (AVC), URL filtering, and Advanced Malware Protection (AMP).

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2034, 2035, 4905, C784, C1026
CVL1521, C784
DRBG197, 1735, C784, C1026
ECDSA1254, C784
HMAC1233, 3272, C784, C1026
RSA2678, C784
SHS1780, 4012, C784, C1026
Triple-DES1311, 2559, C784, C1026

Allowed algorithms

Diffie-Hellman (CVL Certs. #1521 and #C784, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1521 and #C784, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-02-23InitialGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-02-23

Source documents