Cisco Meraki for Government: FedRAMP, TAA, and the Gov Region
Meraki for Government is a separate, FedRAMP Moderate dashboard region with a FIPS firmware requirement. TAA is a different check, done per part number. Here is how the pieces fit on a real order.

Cisco Meraki for Government is a separate US Government region of the Meraki cloud dashboard. It holds a FedRAMP Moderate authorization dated February 18, 2025 (FedRAMP Marketplace package FR2315535023) and a StateRAMP Moderate status. TAA compliance is a different question: Cisco tracks it per model and per part number, so the platform's authorization tells you nothing about whether a given MX, MS, or MR unit qualifies.
Below: what the Government region is, which hardware runs in it, the FIPS firmware rule, how TAA gets confirmed on a Meraki order, and when Catalyst is the better fit for a federal site. If TAA itself is new to you, start with what TAA compliant means and come back.
What is the Meraki US Government region?
Meraki's own documentation calls it the "Cisco Meraki US Government Region." It is a distinct instance of the Meraki dashboard, separate from the commercial dashboard, built for US federal agencies, US government contractors, and critical infrastructure customers. The documentation states it operates under an Authorization to Operate at the FedRAMP Moderate impact level, and Cisco says telemetry stays on U.S. soil. The Meraki US Government Region documentation is the page to bookmark; it carries the supported-hardware list and the TAA caveats quoted below.
The practical consequence: decide up front that an order is for the Government region. That drives three checks a commercial Meraki order skips. The model has to be on the supported-hardware list. The firmware has to meet the FIPS minimum. And if your contract carries the Trade Agreements clause, each part number has to clear TAA on its own.
Is Cisco Meraki FedRAMP authorized?
Yes, for the Government region. The FedRAMP Marketplace listing shows Cisco Meraki for Government at the Moderate impact level, Rev 5 baseline, authorized February 18, 2025 through the Agency authorization path. Six ATO/ATU letters are on file. The sponsoring agency was the DHS Cybersecurity and Infrastructure Security Agency (CISA), per Cisco's own announcement of February 25, 2025. The same offering also carries StateRAMP Moderate, which matters if you are a state agency, a county, or a school district that works from StateRAMP rather than FedRAMP.
Naming the sponsor identifies the authorization path only. It says nothing about any agency's view of any reseller, including us.
Does a FedRAMP authorization mean the hardware is approved?
No. FedRAMP is an authorization of the cloud service, in this case the dashboard that manages your devices. Whether a specific access point or switch belongs in your network is decided by three other things: the Government region supported-hardware list, the FIPS firmware minimum, and, for procurement, TAA. A model can be on the supported list and still need a TAA confirmation. The MS120 caveat below is the proof.
The FIPS 140-2 firmware requirement
The Government region uses FIPS 140-2 validated cryptography for data at rest and in transit. Devices in it must run a minimum FIPS firmware version. Meraki publishes a Supported FIPS Firmware List, plus FIPS Compliance Letters you can drop straight into an ATO package. Cisco's federal Meraki page sums the pitch up as "Safeguard networks with FIPS 140-2 encryption, continuous monitoring, and advanced security." The Cisco US federal Meraki page is the public overview; the documentation page above holds the firmware list itself.
- Check every model on your bill of materials against the Supported FIPS Firmware List before you send the RFQ, not after delivery.
- Plan the FIPS firmware version as a deployment step. A unit that arrives on commercial firmware is not out of spec, it just needs the upgrade before you call it compliant.
- Ask for the FIPS Compliance Letter for each product family and file it with your system security plan.
Which Meraki hardware works in the Government region?
Meraki documentation lists these models as supported in the US Government region at the time of writing. The list changes, so confirm it on the documentation page the day you order.
| Family | Supported models (per Meraki documentation) | Our product page |
|---|---|---|
| SD-WAN and security (MX) | MX67, MX67W, MX68, MX75, MX85, MX95, MX105, MX250, MX450, C8455-G2-MX, C8111-G2-MX | Meraki MX |
| Wireless (MR and CW) | MR36, MR44, MR46, MR46E, MR56, MR57, MR76, MR86, CW9xxx | Meraki MR |
| Switching (MS and Catalyst 9300) | MS120, MS125, MS130, MS150, MS355, MS390, MS450, C9300 series | Meraki MS |
| Cellular gateways (MG) | MG21/E, MG41/E, MG51/E, MG52/E | Ask us |
Two exclusions are explicit: the documentation states that MX67C-HW-WW and MX68CW-HW-WW devices are not supported. Those look like ordinary MX67 and MX68 part numbers at a glance, so check the suffix before one slips onto a Government region order.
Note the C9300 series in the switching row: Catalyst 9300 hardware is supported in the Government region too, not just the MS line. See our Catalyst 9300 page.
Is Meraki TAA compliant?
Per model and per part number, never as a blanket. Meraki's documentation says it plainly: "MS120 has limited TAA Compliance." That one line tells you two things. Cisco tracks TAA status at the model level for Meraki. And a model can be supported in the Government region without being TAA compliant.
The second wrinkle is part numbering. For Catalyst switches, IP phones, and optics, Cisco publishes TAA-certified versions under a ++ suffix, such as C9200-24P-A++ or SFP-10G-LR++=. We explain that convention in what ++ means on a Cisco part number. We have not found a Cisco page listing Meraki ++ or TAA part numbers. So for Meraki, TAA status is confirmed per PID through the country-of-origin process: the blue TAA indicator in Cisco Commerce, Cisco's country-of-origin list, and a country-of-origin statement for each line on the order. Our guide to verifying TAA compliance walks through what that paperwork looks like.
When does TAA actually apply to a Meraki order?
The TAA purchase restriction in FAR 25.403 applies at or above the WTO GPA supply threshold, which is $174,000 under FAR 25.402 for 2026 to 2027. Below that, an open-market purchase is not subject to it, though your agency can require TAA on its own terms. Two exceptions catch people. Any order under a GSA Schedule contract is TAA-covered at any dollar value. And any contract that already carries FAR 52.225-5 is covered regardless of order size. So a $9,000 wireless refresh on a purchase card and a $9,000 wireless refresh off a Schedule are different animals. Our TAA compliant Cisco hub covers the thresholds and the purchase paths in more depth. On a Meraki order that needs TAA, the process with us runs like this:
- You send us the base part numbers and tell us TAA is required.
- We check each PID for the TAA indicator and request the country-of-origin statement.
- If a PID has no TAA-eligible version, we request a TAA Certificate through Cisco for you to review with your contracting officer.
- We flag accessories and spares ordered on their own. Cisco warns that many spares ordered separately carry a different country of origin, so we quote them as configured options into the top-level PID where we can.
Meraki vs Catalyst for a government network
Meraki and Catalyst are both Cisco, and both can land in a federal network. The difference is where the management plane lives. Meraki is managed from the cloud dashboard, which in the government case means the US Government region. Catalyst is managed on premises through Catalyst Center, or directly from the CLI, and its authorization question is your own ATO boundary rather than a cloud provider's.
| Meraki for Government | Catalyst | |
|---|---|---|
| Management plane | Cloud dashboard in the US Government region | On-premises Catalyst Center or CLI |
| FedRAMP status | FedRAMP Moderate, authorized February 18, 2025 (package FR2315535023); StateRAMP Moderate | Not a cloud service; on-prem management sits inside your own ATO boundary |
| FIPS | FIPS 140-2 validated cryptography; devices must run the minimum FIPS firmware from Meraki's published list | Depends on platform and software release; confirm per model before you buy |
| TAA handling | Per model and per PID; no public ++ list, so confirmed through the country-of-origin process | Per PID; ++ versions exist for many models (for example C9200-24P-A++), confirmed the same way |
| Offline or air-gapped | Needs a path to the dashboard; not a fit for isolated or classified enclaves | Runs with no outside connection; the usual choice for air-gapped and classified sites |
| Licensing model | Subscription per device, co-terminated to one renewal date across the organization | Per-device subscription tiers (Essentials or Advantage) bought with the hardware |
When does Meraki fit a federal or SLED site?
Distributed sites with a small IT staff, where one dashboard across every site beats a controller at each one. Field offices, clinics, campuses, anywhere the network team is remote. The Meraki MS vs Catalyst and Meraki MR vs Catalyst access point comparisons go into the feature trade-offs. The government-specific additions are the Government region itself and the FIPS firmware step.
When does Catalyst win?
Any enclave with no outbound path. Classified networks, tactical kits, labs that are deliberately isolated, and sites whose accreditation forbids a cloud management plane. Catalyst also wins where you already run Catalyst Center and do not want a second management system. On the wireless side, our Catalyst 9800 vs Meraki Wi-Fi 7 comparison covers the controller-versus-cloud choice in detail.
Budgeting a Meraki government order
Three cost lines: hardware, the per-device license term, and TAA lead time. Quote the license term you actually intend to run, not the shortest one. Co-termination means devices added later share the organization's renewal date, so model that before you commit. For rough commercial numbers, see how much Cisco Meraki costs. On the government side, TAA confirmation and FIPS firmware planning add time. Cisco says its ++ PIDs can take up to 8 to 10 weeks to fulfil; build comparable lead time into your need-by date for any TAA-routed order.
Frequently asked questions
Is Cisco Meraki FedRAMP authorized?
Yes, for the US Government region. The FedRAMP Marketplace lists Cisco Meraki for Government at the Moderate impact level, Rev 5, authorized February 18, 2025 through the Agency path under package FR2315535023, with CISA as sponsor. It also carries StateRAMP Moderate. The commercial Meraki dashboard is a separate instance; the authorization applies to the Government region, so make sure your organization is created there.
Is Meraki TAA compliant?
Only per model and per part number. Meraki's documentation notes that the MS120 has limited TAA compliance, which shows Cisco tracks it at the model level. There is no public list of Meraki ++ or TAA part numbers, so status is confirmed per PID through Cisco's TAA indicator and a country-of-origin statement. TAA applies at or above the $174,000 WTO GPA threshold, on any GSA Schedule order, and wherever your contract carries FAR 52.225-5.
What is the Meraki US Government region?
A separate region of the Meraki cloud dashboard for US federal agencies, US government contractors, and critical infrastructure customers. Meraki documentation states it holds an Authorization to Operate at the FedRAMP Moderate level, uses FIPS 140-2 validated cryptography for data at rest and in transit, and Cisco says telemetry stays on U.S. soil. Devices in it must run a minimum FIPS firmware version from Meraki's published list.
Which Meraki hardware works in the Government region?
Per Meraki documentation: MX67, MX67W, MX68, MX75, MX85, MX95, MX105, MX250, MX450, C8455-G2-MX, and C8111-G2-MX for SD-WAN; MR36, MR44, MR46, MR46E, MR56, MR57, MR76, MR86, and CW9xxx for wireless; MS120, MS125, MS130, MS150, MS355, MS390, MS450, and the C9300 series for switching; MG21/E, MG41/E, MG51/E, and MG52/E for cellular. MX67C-HW-WW and MX68CW-HW-WW are not supported. Check the documentation page before ordering, since the list changes.
Can Meraki run in an air-gapped network?
Not in a practical sense. Meraki's management plane is the cloud dashboard, and the Government region is a cloud region. A network with no path to that dashboard has no management plane, which rules Meraki out for classified enclaves and deliberately isolated sites. For those, Catalyst switches and access points managed on premises through Catalyst Center or the CLI are the standard answer. Ask us and we will quote the Catalyst equivalents.
Meraki or Catalyst for a federal site?
Meraki for distributed sites with small teams, where one FedRAMP Moderate dashboard across locations is the point, and the site has an outbound path. Catalyst for air-gapped or classified enclaves, sites that forbid a cloud management plane, or shops already standardized on Catalyst Center. Both need per-PID TAA confirmation above the threshold or on a Schedule order. Catalyst has published ++ part numbers for many models; Meraki does not, so allow time for the country-of-origin check.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteRelated reading
View all →
ComplianceCisco wireless for federal and DoD facilities: a compliance primer
Federal and DoD wireless is two designs sharing one budget: the RF plan and the compliance stack. Here is how FIPS, WPA3-Enterprise, DISA STIGs, the DoDIN APL, and TAA sourcing fit together on Cisco wireless, and why building them in from the first design call beats retrofitting before an assessment.
June 6, 2026 · 13 min read
NewsCisco Live 2026: Cloud Control, AgenticOps, and Quantum-Safe Security, What It Means for Buyers
Cisco used its June 2026 conference to put a stake in the ground on three fronts that change how networks get built and defended. Here is what landed, who it affects, and how to turn the announcements into a funded, deployable plan.
June 4, 2026 · 7 min read
ComplianceCisco SEWP Quote Guide for Federal Buyers
NASA SEWP is one of the busiest IT contracts in the federal government, and with SEWP VI awarded and going live on November 1, 2026, it remains a fast lane for Cisco hardware when you set the buy up correctly. Here is how the vehicle works, what makes a quote clear on the first pass, and the mistakes that push an award past fiscal year end.
May 22, 2026 · 10 min read
GuidesCisco Meraki MX60 (MX60-HW) Replacement & MX67 Migration
The Meraki MX60 hit Last Day of Support on 2022-10-24, no firmware, no PSIRT fixes, no RMA. Here is exactly what that means and how to migrate a small branch to the MX67 cleanly.
April 8, 2026 · 7 min read
GuidesCisco Meraki MR26 EoL: Migrate to Catalyst CW9164I
The Meraki MR26 passed Last Day of Support on May 9, 2023, it gets no PSIRT fixes, no firmware, and no RMA. Here is what that means for an 802.11n fleet still in your ceilings and how to refresh cleanly to the Wi-Fi 6E Catalyst CW9164I on the Meraki dashboard.
March 30, 2026 · 9 min read
GuidesCisco Meraki MR72 EoL: Migrating Outdoor Wi-Fi to the MR76
The Meraki MR72 passed Last Day of Support on April 30, 2024. Here's exactly what that means for your outdoor network and how to migrate cleanly to the Wi-Fi 6 Meraki MR76 without leaving the dashboard.
March 19, 2026 · 7 min read