808bits

Cisco Catalyst 9200L Series Switches

FIPS 140-2 certificate #4487 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 3 of the Security Policy. This module contains the embedded module 'ACT2Lite Cryptographic Module' validated to FIPS 140-2 under Cert. #3637 operating in FIPS mode

Certificate

Certificate number4487
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Hardware versionsCisco Catalyst C9200L-24P-4G, Cisco Catalyst C9200L-24P-4X, Cisco Catalyst C9200L-24T-4G, Cisco Catalyst C9200L-24T-4X, Cisco Catalyst C9200L-48P-4G, Cisco Catalyst C9200L-48P-4X, Cisco Catalyst C9200L-48T-4G, Cisco Catalyst C9200L-48T-4X, Cisco Catalyst C9200L-24P8X-2Y, Cisco Catalyst C9200L-24P8X-4X, Cisco Catalyst C9200L-48P12X-4X and Cisco Catalyst C9200L-48P8X-2Y
Firmware versionsCisco IOS-XE 16.12 and Cisco IOS-XE 17.3

Module description

With full PoE+ capability, power and fan redundancy, stacking bandwidth up to 160 Gbps, modular uplinks, Layer 3 feature support, and cold patching, Catalyst 9200L Series switches are the industry’s unparalleled solution with differentiated resiliency and progressive architecture for cost-effective branch-office access. The switches meet FIPS 140-2 overall Level 1 requirements as multi-chip standalone modules. Advanced security feature supports IOS-XE software, MACsec encryption, hardware anchored secure boot, Secure Unique Device Identification (SUDI) support.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA1462, 4769
CKGvendor affirmed
CVLA1462
DRBGA1462
ECDSAA1462
HMACA1462
KAS
KAS-SSCA1462
KBKDFA1462
KTS
RSAA1462, C1301
SHSA1462, C1301

Allowed algorithms

NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2023-04-26InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2023-04-26

Source documents