808bits

FortiOS 6.4/7.0

FIPS 140-2 certificate #4443 · Fortinet, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode. Authentication at level 3 is only applicable when identity-based authentication is enforced for the User role.

Certificate

Certificate number4443
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
VendorFortinet, Inc. · website
Firmware versionsFortiOS 6.4 (FIPS-CC-64-5) and FortiOS 7.0 (FIPS-CC-70-6)

Module description

The FortiOS 6.4/7.0 is a firmware based operating system that runs exclusively on Fortinet's FortiGate/FortiWiFi product family. The FortiOS provides integrated firewall, VPN, antivirus, antispam, intrusion prevention, content filtering and traffic shaping and HA capabilities.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AESA2225, A2229, A2242, A2269, A2270
CVLA2269, A2270
DRBGA2225, A2229
ECDSAA2242, A2269, A2270
ENT
HMACA2225, A2229, A2242, A2269, A2270
KAS
KAS-SSCA2269, A2270
KTS
KTS
RSAA2242, A2269, A2270
SHSA2225, A2229, A2242, A2269, A2270

Tested configurations

  • FortiGate-61F with SoC4 (ARMv8) Processor

Validation history

DateTypeLab
2023-02-23InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-02-23

Source documents