July 10, 2025
To Whom It May Concern:
A compliance review of Cisco Catalyst SD-WAN [Manager, Validator, Controller] version 20.15 (“the Product”) deployed in the following platforms:
Various network elements
was completed and found that the Product incorporates the following FIPS 140-3 validated cryptographic module:
- Cisco FIPS Object Module version 7.3a (Certificate #4747)
Cisco confirms that the cryptographic module listed above provides cryptographic services for the following as applicable:
- TLSv1.2, TLSv1.3, SSHv2, DTLSv1.2 and SNMPv3 – FOM version 7.3a (Certificate #4747)
The review/testing confirmed that:
- The cryptographic module (mentioned above) does initialize in a manner that is compliant with its Security Policy.
- All applicable cryptographic algorithms used for the services listed above are handled within the cryptographic module.
- All applicable underlying cryptographic algorithms support each service's key derivation function.
This letter has been generated in accordance with guidance provided by the Cryptographic Module Validation Program (CMVP). The CMVP has not independently evaluated this compliance review.
Any questions regarding these statements may be directed via e-mail to the Cisco Global Certification Team (GCT) at certteam@cisco.com.
Sincerely,
Edward D Paradiso
Ed Paradise
Cisco Senior Vice President
Foundational & Government Security