PAN-OS 11.1/11.2 running on PA-400 Series, PA-800 Series, PA-1400 Series, PA-3200 Series, PA-3400 Series, PA-5200 Series, PA-5400 Series, PA-5450, PA-7000 Series, and PA-7500 NGFWs
Caveat: When installed, initialized and configured as specified in Section 11.1 of the Security Policy. The tamper evident seals and physical kit installed as indicated in the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy
Certificate
| Certificate number | 5326 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-06-09 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | MultiChipStand |
| Vendor | Palo Alto Networks, Inc. · website |
Module description
Palo Alto Networks offers a full line of next-generation security appliances. Our platform architecture is based on our single-pass engine, PAN-OS, for networking, security, threat prevention, and management functionality that is consistent across all platforms. The devices differ only in capacities, performance, and physical configuration.
Security level exceptions
- Roles, services, and authentication: Level 3
- Operational environment: N/A
- Non-invasive security: N/A
- Life-cycle assurance: Level 3
- Mitigation of other attacks: N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-06-10 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-06-10