Five registries decide what you are allowed to build.

Almost every argument in a CSfC program eventually resolves to one of five sources. Knowing which registry answers which question — and in what order they constrain each other — turns a sprawling compliance problem into a sequence of lookups.

The Dependency Chain

They are not five parallel checkboxes.

Each one feeds the next. Understanding the order saves you from the most expensive mistake in this space: verifying the wrong thing, in the wrong sequence, too late.

FIPS 140 the crypto is correct CC / NIAP the product is evaluated CSfC LIST you may use it REGISTERED solution approved STIG how to configure it the configuration baseline applies across everything you fielded DoDIN APL sat alongside this chain governing network connection — see the note below

Read left to right. FIPS validates that a cryptographic module implements its algorithms correctly. Common Criteria, run in the US by NIAP, evaluates the whole product against a Protection Profile — and assumes the crypto underneath is sound. CSfC listing requires NIAP validation first, then an agreement with NSA. Only components on that list may go into a registered solution. And the STIG governs how whatever you fielded must actually be configured.

The practical consequence: a vendor telling you their device is "FIPS validated" has told you about the leftmost box only. That is necessary and nowhere near sufficient.

The Resource Library

Where to look, and what each source actually tells you.

CSfC

NSA Commercial Solutions for Classified

The program itself. Home of the Capability Packages that define solution architectures, and the Components List that defines what you may build them from.

Answers: Which architecture applies to my mission? Which products am I allowed to use? What does registration require?

Go here first. Every other source on this page exists to feed a decision that this one governs.

NIAP

National Information Assurance Partnership

The US Common Criteria scheme, operated by NSA. Publishes Protection Profiles and maintains the Product Compliant List of everything evaluated against them.

Answers: Has this exact product, at this exact version, been evaluated — and against which Protection Profile?

Watch for: validations age off the Product Compliant List. NIAP retains entries for a limited window, after which products move to the Archived list. A validation from three years ago may no longer be current.

FIPS

FIPS Publications & NIST CMVP

The federal standards themselves, plus the Cryptographic Module Validation Program that issues certificates against FIPS 140-2 and 140-3.

Answers: Is this cryptographic module validated, at what security level, and is the certificate still active?

Two traps. Certificates carry sunset dates, and certificates marked Historical should not be included in new federal procurements. Also: CAVP validates algorithms, CMVP validates modules. A vendor citing CAVP numbers has not shown you a validated module.

APL

DoDIN Approved Products List

DISA's list of products cleared to connect to the Department of Defense Information Network, covering interoperability and cybersecurity testing by JITC.

Answers: Historically — may this product connect to a DoD network?

Program sunset

Reporting indicates DISA sunset the DoDIN APL program effective 30 September 2025, with the repository maintained through FY2026 and requirements migrating to the DISA Vendor STIG program and an updated UCR-CORE. Treat existing listings as historical record rather than a forward-looking credential, and confirm current policy with your own chain.

STIG

STIG Viewer & the DISA STIG Library

Security Technical Implementation Guides are DISA's mandatory configuration baselines. STIG Viewer is the tool that opens them and produces the checklist you will be assessed against.

Answers: Exactly how must this device be configured, and how do I evidence that it is?

STIGs ship as XCCDF XML inside a ZIP. STIG Viewer 3.x opens them, builds checklists, and exports .cklb for eMASS. With the APL winding down, the STIG program becomes the primary DoD cybersecurity gate — this source is getting more important, not less.

CC

Common Criteria Portal

The international scheme (ISO/IEC 15408) that NIAP operates within. Useful when a product was certified under another nation's scheme, or when you need the underlying evaluation documents.

Answers: What was actually evaluated, and to what depth?

Practical tip: NIAP's own site is a JavaScript application that can be awkward to search. The Validation Reports and Security Targets behind NIAP validations are mirrored here as plain PDFs — often the fastest route to the real evaluation detail.

Current as of August 2026. Registries change continuously — every card links to the authoritative source rather than restating its contents, because a copied listing goes stale invisibly.

Next

Device Specific Deployments

Once you know which registry answers which question, the next question is what it says about the platform in your hand. Guidance by device family.

Not sure which source governs your question?

Describe what you are trying to decide and we will tell you which registry actually answers it — and which ones are noise for your case.