808bits

Cisco Catalyst 9300 Series Switches

FIPS 140-2 certificate #3853 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition - replaced by certificate #4494. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 3 of the Security Policy. This module contains the embedded module 'ACT2Lite Cryptographic Module' validated to FIPS 140-2 under Cert. #3637 operating in FIPS mode

Certificate

Certificate number3853
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsCisco Catalyst 9300-24S, Cisco Catalyst 9300-48S,Cisco Catalyst 9300L-24T-4G, Cisco Catalyst 9300L-24P-4G, Cisco Catalyst 9300L-48T-4G, Cisco Catalyst 9300L-48P-4G, Cisco Catalyst 9300L-24T-4X, Cisco Catalyst 9300L-24P-4X, Cisco Catalyst 9300L-48T-4X, Cisco Catalyst 9300L-48P-4X, Cisco Catalyst 9300L-24UX-4X, Cisco Catalyst 9300L-48UX-4X, Cisco Catalyst 9300L-24UX-2Q and Cisco Catalyst 9300L-48UX-2Q
Firmware versionsCisco IOS-XE 16.12 and Cisco IOS-XE 17.3

Module description

The Cisco Catalyst 9300 Series Switches are stackable enterprise switching platform built for security, IoT, mobility, and cloud. The switches meet FIPS 140-2 overall Level 1 requirements as multi-chip standalone modules. The modules include cryptographic algorithms implemented in IOS-XE software as well as hardware ASIC. Advanced security feature supports MACsec encryption, hardware anchored secure boot and Secure Unique Device Identification (SUDI) support.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC431, C462, 4769
CKGvendor affirmed
CVLC431, C462
DRBGC431, C462
DSAC431
ECDSAC431, C462
HMACC431, C462
KBKDFC431, C462
KTS
KTS
RSAC220, C431, C462
SHSC220, C431, C462
Triple-DESC431, C462

Allowed algorithms

Diffie-Hellman (CVL Cert. #C462 with CVL Cert. #C462, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C462 with CVL Cert. #C462, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-03-18InitialAcumen Security
2021-08-25UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-03-18, 2021-08-25

Source documents