Cisco Catalyst 9300 Series Switches
Caveat: When operated in FIPS mode, installed, initialized and configured as specified in Section 3 of the Security Policy. This module contains the embedded module 'ACT2Lite Cryptographic Module' validated to FIPS 140-2 under Cert. #3637 operating in FIPS mode
Certificate
| Certificate number | 4494 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Cisco Systems, Inc. · website |
| Hardware versions | Cisco Catalyst 9300-24S, Cisco Catalyst 9300-48S,Cisco Catalyst 9300L-24T-4G, Cisco Catalyst 9300L-24P-4G, Cisco Catalyst 9300L-48T-4G, Cisco Catalyst 9300L-48P-4G, Cisco Catalyst 9300L-24T-4X, Cisco Catalyst 9300L-24P-4X, Cisco Catalyst 9300L-48T-4X, Cisco Catalyst 9300L-48P-4X, Cisco Catalyst 9300L-24UX-4X, Cisco Catalyst 9300L-48UX-4X, Cisco Catalyst 9300L-24UX-2Q and Cisco Catalyst 9300L-48UX-2Q |
| Firmware versions | Cisco IOS-XE 16.12 and Cisco IOS-XE 17.3 |
Module description
The Cisco Catalyst 9300 Series Switches are stackable enterprise switching platform built for security, IoT, mobility, and cloud. The switches meet FIPS 140-2 overall Level 1 requirements as multi-chip standalone modules. The modules include cryptographic algorithms implemented in IOS-XE software as well as hardware ASIC. Advanced security feature supports MACsec encryption, hardware anchored secure boot and Secure Unique Device Identification (SUDI) support.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 2
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A1462, C431, 4769 |
| CKG | vendor affirmed |
| CVL | A1462, C431 |
| DRBG | A1462, C431 |
| DSA | C431 |
| ECDSA | A1462, C431 |
| HMAC | A1462, C431 |
| KAS | |
| KAS-SSC | A1462 |
| KBKDF | A1462, C431 |
| KTS | |
| KTS | |
| RSA | A1462, C220, C431 |
| SHS | A1462, C220, C431 |
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-04-28 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2023-04-28