808bits

Cisco ASR 1000 Series Routers without MACSEC

FIPS 140-2 certificate #3988 · Cisco Systems, Inc. · data as of 2026-09-03

Cisco ASR 1000 Series Routers without MACSEC, from Cisco Systems, Inc., holds FIPS 140-2 certificate #3988 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition - replaced by certificate #4643. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 9 of the Security Policy

Certificate

Certificate number3988
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsASR1002-X, [ASR1004 and ASR1006 with components ASR-1000-RP2, ASR1000-ESP20 and ASR1000-ESP40]
Firmware versionsCisco IOS-XE 16.12

Module description

Quoted from the NIST CMVP entry for this certificate.

The Cisco ASR 1000 Series Routers accelerate services by offering performance and resiliency with optimized, intelligent services; establishing a benchmark for price-to-performance offerings in the enterprise routing, service provider edge, and broadband aggregation segments; facilitating significant network innovations in areas such as secure WAN aggregation, managed customer-premises-equipment services, and service provider edge services; reducing operating expenses and capital expenditures by facilitating managed or hosted services over identical architectures and operating environments.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (8)

AlgorithmCAVP certificates
AES333, 4583, C462
CVL1257, 1258, C462
DRBG1529, C462
HMAC137, 3034, C462
KTS
RSA2500, C462
SHS408, 3760, C462
Triple-DES397, 2436, C462

Allowed algorithms

Diffie-Hellman (CVL Cert. #1257 with CVL Cert. #1258, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1257 with CVL Cert. #1258, key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-07-19InitialAcumen Security
2021-08-25UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-07-19, 2021-08-25

Source documents