CSfC
NSA Commercial Solutions for Classified
The program itself. Home of the Capability Packages that define solution architectures, and the
Components List that defines what you may build them from.
Answers: Which architecture applies to my mission? Which products am I allowed to use?
What does registration require?
Go here first. Every other source on this page exists to feed a decision that this one
governs.
NIAP
National Information Assurance Partnership
The US Common Criteria scheme, operated by NSA. Publishes Protection Profiles and maintains the
Product Compliant List of everything evaluated against them.
Answers: Has this exact product, at this exact version, been evaluated — and against
which Protection Profile?
Watch for: validations age off the Product Compliant List. NIAP retains entries for a
limited window, after which products move to the Archived list. A validation from three years
ago may no longer be current.
FIPS
FIPS Publications & NIST CMVP
The federal standards themselves, plus the Cryptographic Module Validation Program that issues
certificates against FIPS 140-2 and 140-3.
Answers: Is this cryptographic module validated, at what security level, and is the
certificate still active?
Two traps. Certificates carry sunset dates, and certificates marked
Historical should not be included in new federal procurements. Also: CAVP validates
algorithms, CMVP validates modules. A vendor citing CAVP numbers has not
shown you a validated module.
APL
DoDIN Approved Products List
DISA's list of products cleared to connect to the Department of Defense Information Network,
covering interoperability and cybersecurity testing by JITC.
Answers: Historically — may this product connect to a DoD network?
Program sunset
Reporting indicates DISA sunset the DoDIN APL program effective 30 September 2025, with
the repository maintained through FY2026 and requirements migrating to the DISA Vendor STIG
program and an updated UCR-CORE. Treat existing listings as historical record rather than a
forward-looking credential, and confirm current policy with your own chain.
STIG
STIG Viewer & the DISA STIG Library
Security Technical Implementation Guides are DISA's mandatory configuration baselines. STIG
Viewer is the tool that opens them and produces the checklist you will be assessed against.
Answers: Exactly how must this device be configured, and how do I evidence that it is?
STIGs ship as XCCDF XML inside a ZIP. STIG Viewer 3.x opens them, builds checklists, and exports
.cklb for eMASS. With the APL winding down, the STIG program becomes the primary DoD
cybersecurity gate — this source is getting more important, not less.
CC
Common Criteria Portal
The international scheme (ISO/IEC 15408) that NIAP operates within. Useful when a product was
certified under another nation's scheme, or when you need the underlying evaluation documents.
Answers: What was actually evaluated, and to what depth?
Practical tip: NIAP's own site is a JavaScript application that can be awkward to search.
The Validation Reports and Security Targets behind NIAP validations are mirrored here as plain
PDFs — often the fastest route to the real evaluation detail.
Current as of August 2026. Registries change continuously — every card links to the authoritative
source rather than restating its contents, because a copied listing goes stale invisibly.