IOS Common Cryptographic Module (IC2M)
IOS Common Cryptographic Module (IC2M), from Cisco Systems, Inc., holds FIPS 140-3 certificate #4752 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: Interim Validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
Certificate
| Certificate number | 4752 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 1 |
| Module type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Cisco Systems, Inc. · website |
| Firmware versions | Rel5b |
Module description
Quoted from the NIST CMVP entry for this certificate.
The IC2M module provides the FIPS validated cryptographic algorithms for services requiring those algorithms. The module does not implement any protocols directly; Instead, it provides the cryptographic primitives and functions to allow IOS to implement those various protocols.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (32)
| Algorithm | CAVP certificates |
|---|---|
| AES-CBC | A4354 |
| AES-CFB128 | A4354 |
| AES-CMAC | A4354 |
| AES-ECB | A4354 |
| AES-GCM | A4354 |
| AES-GMAC | A4354 |
| AES-KW | A4354 |
| Counter DRBG | A4354 |
| ECDSA KeyGen (FIPS186-4) | A4354 |
| ECDSA KeyVer (FIPS186-4) | A4354 |
| ECDSA SigGen (FIPS186-4) | A4354 |
| ECDSA SigVer (FIPS186-4) | A4354 |
| HMAC-SHA-1 | A4354 |
| HMAC-SHA2-256 | A4354 |
| HMAC-SHA2-384 | A4354 |
| HMAC-SHA2-512 | A4354 |
| KAS-ECC-SSC Sp800-56Ar3 | A4354 |
| KAS-FFC-SSC Sp800-56Ar3 | A4354 |
| KDF IKEv2 | A4354 |
| KDF SNMP | A4354 |
| KDF SRTP | A4354 |
| KDF SSH | A4354 |
| RSA KeyGen (FIPS186-4) | A4354 |
| RSA SigGen (FIPS186-4) | A4354 |
| RSA SigVer (FIPS186-4) | A4354 |
| Safe Primes Key Generation | A4354 |
| SHA-1 | A4354 |
| SHA2-256 | A4354 |
| SHA2-384 | A4354 |
| SHA2-512 | A4354 |
| TLS v1.2 KDF RFC7627 | A4354 |
| TLS v1.3 KDF | A4354 |
Tested configurations
- IOS-XE 17.12 running on Cisco Aggregated Services Router (ASR) 1001-HX with Intel Xeon E3-1125C v2 processor
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-08-07 | Initial | Gossamer Security Solutions |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-08-07