Cisco Identity Services Engine · Trust Center
Cisco Ise Trust Center
Trust center
Cisco Identity Services Engine maintains a public trust center documenting FIPS 140-2 and FIPS 140-3 compliance.
IdentityNetwork AccessZero TrustSecurityPolicyEnterprise802.1XRADIUSTACACS+TrustSecGuest AccessBYODEndpoint ProfilingPostureNetwork SegmentationNAC
Trust center: https://www.cisco.com/c/en/us/about/trust-center.html
Certifications & Compliance
FIPS 140-2FIPS 140-3
Source
Trust Center
generated: '2026-08-19'
method: searched
probe: true
url: https://www.cisco.com/c/en/us/about/trust-center.html
trust_portal: https://trustportal.cisco.com/c/r/ctp/trust-portal.html
note: Cisco runs a corporate Trust Center and a Trust Portal, both reachable anonymously (HTTP 200), where documents are requested
per-customer rather than listed openly — the automated probe recorded no certification keywords because the portal renders
client-side. What IS openly published and product-specific for Cisco ISE is the cryptographic-module validation, named with
its NIST certificate number in Cisco's own ISE compatibility documentation. Only claims verified on a page fetched during
this pass are recorded below.
certifications:
- name: FIPS 140-2
scope: Cisco ISE embedded cryptographic module — Cisco FIPS Object Module version 7.2a
certificate: '#4036'
issuer: NIST CMVP
evidence: https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/compatibility_doc/b_ise_sdt_35.html
verified: '2026-08-19'
http_status: 200
note: Also present verbatim in the ISE 3.3 compatibility document. FIPS mode is opt-in on the appliance; when enabled, any
function using a non-FIPS algorithm fails, and certificate keys must be 2048 bits or greater.
- name: FIPS 140-3
scope: Cisco ISE 3.4 — Virtual Tunnel Interfaces with Native IPsec aligned to FIPS 140-3
certificate: null
issuer: NIST CMVP
evidence: https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/release_notes/cisco-identity-services-engine-release-notes-34.html
verified: '2026-08-19'
http_status: 200
corporate_programs:
- name: FedRAMP
scope: Cisco corporate compliance program (not ISE-specific)
evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html
verified: '2026-08-19'
http_status: 200
- name: HIPAA
scope: Cisco corporate compliance program
evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html
verified: '2026-08-19'
http_status: 200
- name: C5 (Germany)
scope: Cisco corporate compliance program
evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html
verified: '2026-08-19'
http_status: 200
- name: IRAP (Australia)
scope: Cisco corporate compliance program
evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html
verified: '2026-08-19'
http_status: 200
not_verified:
- SOC 2
- ISO/IEC 27001
- PCI DSS
- CSA STAR
- Common Criteria for ISE specifically
not_verified_note: These are commonly assumed for a vendor of this size but were NOT confirmed on any page fetched during
this pass — the Trust Portal gates its document library. Recorded as unverified rather than asserted.
government_certifications: https://www.cisco.com/c/en/us/solutions/industries/government/global-government-certifications/fips-140.html
psirt:
security_txt: https://www.cisco.com/.well-known/security.txt
policy: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html
contact: psirt@cisco.com
csaf: https://www.cisco.com/.well-known/csaf/provider-metadata.json
evidence:
- source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/compatibility_doc/b_ise_sdt_35.html
http_status: 200
keywords:
- 'Certificate #4036'
- source: https://www.cisco.com/c/en/us/about/trust-center/compliance.html
http_status: 200
keywords:
- FedRAMP
- HIPAA
- C5
- IRAP
- source: https://trustportal.cisco.com/c/r/ctp/trust-portal.html
http_status: 200
keywords: []
note: reachable but client-side rendered; no certification names in the served HTML