Uniqcli

DoDIN APL for Cisco Buyers: What the DoD Approved Products List Means

A practical guide to the DoDIN Approved Products List for buyers specifying Cisco on DoD networks, covering what APL placement actually certifies, how it differs from FedRAMP and TAA, and how to keep a program on schedule.

UT
Uniqcli Team
May 26, 2026 · 12 min read
Share
DoDIN APL for Cisco Buyers: What the DoD Approved Products List Means

Key takeaways

  • The DoDIN APL was DISA's single, consolidated list of products certified for connection to Department of Defense networks. DISA sunset the program on September 30, 2025, and is keeping the repository of approved products available only through FY2026, so a platform that completed DoDIN APL certification still helps a connection package today, but new solicitations are shifting to STIG, FIPS, and UCR evidence instead.
  • APL listing is a network-connection approval tied to a tested release and configuration, not a blanket security stamp. It is distinct from FedRAMP (cloud authorization) and TAA (country-of-origin sourcing), and you frequently need all three for different parts of one buy.
  • Know the difference between the product-level APL certification, the Authority to Operate (ATO) your Authorizing Official grants the assembled system, and the Approval to Connect (ATC) DISA issues for that system's connection to the DISN after the ATO is in hand.
  • APL entries are version-specific. Buying the wrong software train, or letting a listing lapse, can void the approval even when the hardware is identical.
  • Confirming a platform's APL certification history, TAA country-of-origin, FIPS posture, and STIG-ability before the BOM is locked is what keeps a DoD buy from bouncing back in review.

What the DoDIN APL actually is

The Department of Defense Information Network Approved Products List, almost always shortened to DoDIN APL, was the master register of hardware and software products that completed DISA cybersecurity and interoperability certification for connection to DoD networks. DISA sunset the program on September 30, 2025, closed out scheduled testing by December 31, 2025, and is maintaining the repository of approved products through FY2026, with cybersecurity requirements moving to the DISA vendor STIG program and interoperability requirements to the UCR-CORE document enforced through contract terms. It is administered through the Defense Information Systems Agency, and it grew out of the older Unified Capabilities (UC) APL that historically covered voice, video, and collaboration gear. Today the scope is much broader, spanning switches, routers, wireless, firewalls, and access control platforms that sit on the network backbone agencies run every day.

For a buyer in FY2026, the practical meaning is this. A product that completed DoDIN APL certification still gives a program office defensible evidence for its connection package while the repository is maintained. A product that never did can no longer be submitted, so the program has to make its case on STIG compliance, FIPS 140 validation, Common Criteria, and UCR conformance instead, and a reviewer who still expects an APL line may ask for a risk acceptance, which costs time, signatures, and political capital. Many solicitations written before the sunset still name APL status as a gating requirement, so read each one for the evidence it actually asks for, and settle that with the contracting officer before the hardware is on a dock.

Cisco carried a large share of its switching, wireless, and security platforms through the APL process while it ran, which is one reason those lines show up so often in DoD architectures. Cisco publishes its own public-sector positioning, but the APL was a DISA-controlled list, not a vendor marketing claim, and that distinction matters when you are defending a bill of materials in review.

Why APL placement is not the same as 'secure'

A common and expensive misreading is to treat APL listing as a general security certification. It is not. The APL confirms that a specific product, at a specific software release and in a defined configuration, was tested against the cybersecurity and interoperability requirements DISA applies and was found acceptable to connect. It is a connection approval, anchored to a tested baseline, not a promise that any way you deploy the box is secure.

That tested baseline is built on a stack of underlying standards. Most APL-relevant Cisco platforms carry FIPS 140 validated cryptography, many hold Common Criteria evaluations, and almost all of them have to be hardened against the Security Technical Implementation Guides that DISA publishes. The published STIGs at the DoD Cyber Exchange are where the day-two configuration work actually lives, and a platform being 'STIG-able' is part of what makes APL listing meaningful in the field rather than just on paper.

The standards underneath the APL trace back to recognized authorities. FIPS 140 validation comes from the NIST Cryptographic Module Validation Program, the controls a program authorizes against live in NIST SP 800-53 under the Risk Management Framework, and interoperability leans on industry bodies like the IEEE and the Wi-Fi Alliance for the radios and protocols. When you specify Cisco security platforms through our security practice or scope identity and access control, the APL line item is the visible tip of that much deeper compliance stack.

APL, FedRAMP, and TAA are three different things

Buyers routinely collapse three separate requirements into one mental bucket, and that is where proposals get rejected. The DoDIN APL governs whether a product can connect to a DoD network. FedRAMP governs whether a cloud service is authorized for federal use. The Trade Agreements Act governs where a product is manufactured or substantially transformed. They overlap in a single program, but each is judged on its own evidence and by different reviewers.

A realistic DoD deployment touches all three at once. The on-premises Catalyst switches and Secure Firewall appliances need APL coverage and TAA-compliant country-of-origin documentation. A SaaS management plane or a cloud-delivered security service needs a FedRAMP authorization at the right impact level. The cryptography under all of it needs FIPS validation. Treating these as one checkbox is how a BOM clears the hardware review and then dies on the cloud review three weeks later.

Cisco itself publishes how it lines up against federal acquisition through resources tied to government contract vehicles, but the contract vehicle is not the compliance. We keep a country-of-origin position per SKU and a TAA posture for the whole bill of materials, which is the core of our procurement and compliance work. Pairing that with verified APL status is what lets a government program clear acquisition the first time instead of looping through corrections.

ATC versus ATO: who approves what

Three approvals get confused on DoD networking buys. Placement on the DoDIN APL was a product certification: DISA had tested the platform, in a defined configuration, for cybersecurity and interoperability. It was never an Approval to Connect. The ATC, or its interim form the IATC, is a connection decision DISA's Connection Approval Office issues to a specific enclave or system before it attaches to the DISN, and it comes after the system has its own authorization.

The Authority to Operate, or ATO, is different again and it does not come from the APL or the connection office. The ATO is granted by the local Authorizing Official for a specific system at a specific site under the Risk Management Framework. Even with every device on the APL, your program still assembles the system, hardens it to the STIGs, documents the controls, and earns its own ATO. The APL shortens that path; it does not replace it.

The way to think about it: the APL certified the part, the ATO clears the system, and the ATC clears the system's connection to the DISN. A great deal of avoidable schedule slip comes from teams assuming an APL-listed switch arrives with an operating authority baked in. It does not. Mapping which approvals belong to the product and which belong to the program is exactly the kind of sequencing we work through with defense and DoD customers before anyone signs a purchase order.

APL entries are version-specific, and that bites people

The single most overlooked detail on the DoDIN APL is that listings are tied to tested releases and configurations, not to a product name in the abstract. A Catalyst platform might be listed at a particular software train, and the approval is for that train. Order the same chassis but spec a newer or older code version that was never submitted, and you can find yourself technically out of compliance with hardware that is otherwise identical.

Listings also age. Products carry a tracking identifier and a status, entries can move toward removal as a platform approaches end of sale, and since the program sunset no new listings or re-certifications are being issued, so a listing that lapses cannot be renewed. That ties directly into Cisco's published end-of-life and end-of-sale policy, because a model drifting toward EoS is also a model whose APL coverage you should verify rather than assume. The two lifecycles do not move in lockstep, and the gap is where surprises live.

This is also a coverage question, not just a status question. APL alignment is one input; keeping the supported software train under an active Smart Net Total Care contract is another. We track the version on the listing against the version on the BOM, and we fold that into licensing and lifecycle management so the release you field is the release that was actually approved, not a close cousin.

Which Cisco platforms show up on DoD networks

Across DoD architectures, a recognizable set of Cisco platforms recurs. On the access and aggregation layer, the Catalyst 9300 Series is a workhorse, and its capabilities are spelled out in the published Catalyst 9300 data sheet that programs lean on for port, PoE, and uplink planning. Wireless tends to ride on Catalyst 9800 controllers paired with Wi-Fi 6E and Wi-Fi 7 access points, and security frequently centers on the Secure Firewall family.

On the security edge, the Secure Firewall 3100 Series is a common reference for throughput and interface sizing, and for newer wireless builds the Cisco Wireless 9176 access point covers the Wi-Fi 7 radios agencies are starting to field. We reproduce these data sheets natively so your team can size from real numbers without chasing PDFs across the open web.

Identity and segmentation usually round out the picture, with the Identity Services Engine enforcing posture and access policy behind the firewall. When you scope these through our switching and access points catalogs, every model is something we can check against its APL certification record, its TAA-compliant options, and its FIPS status before it lands in a proposal, rather than after.

How to keep a DoD buy on schedule

The pattern behind nearly every rejected DoD networking proposal is the same: compliance was treated as paperwork to attach at the end instead of constraints that shape the design from the start. The fix is to validate APL certification history, TAA country-of-origin, FIPS posture, and STIG-ability while the bill of materials is still being assembled, not after the Authorizing Official sees it. Catching a non-listed line item on day one costs a substitution; catching it in review costs a cycle.

That front-loading is the heart of how we work an acquisition. We translate the requirement into a validated Cisco BOM, confirm the listed software train matches what we are quoting, document country-of-origin per SKU, and structure the package with the CLIN and threshold language federal reviewers expect. The output is meant to clear review on the first pass, and we package it for the purchase paths we can actually transact on: a GPC purchase, Simplified Acquisition under FAR Part 13, or a FAR-based purchase order, with WAWF invoicing through PIEE for DoD.

Contract vehicles still matter. GSA Multiple Award Schedule and NASA SEWP are common routes for Cisco hardware in the federal space, and Uniqcli does not currently hold either (our MAS application is in progress), so if your program must buy through one, tell us at the start and we will say plainly what we can and cannot do rather than re-quoting later. When the design, the compliance evidence, and the purchase path are settled together up front, the buy moves; when they are settled one after another, it stalls. Our defense practice exists to keep those three threads moving in parallel.

Practical checklist before you lock the BOM

Before any DoD-bound bill of materials is finalized, a handful of checks separate a clean buy from a bounced one. None of them are exotic, but skipping any single one is usually what sends a proposal back. The goal is to make the compliance story self-evident to a reviewer who has never spoken to your team.

Treat the list below as the minimum diligence on every line item. Each point maps to a different reviewer and a different failure mode, which is exactly why they have to be checked together rather than one at a time.

When all of these line up, the BOM stops being a risk and starts being an asset in the proposal. That is the difference between a quote that survives review and one that triggers a corrections cycle, and it is the standard we hold every federal and DoD bill of materials to before it ships.

  • Confirm whether the exact product and the exact software release you intend to field completed DoDIN APL certification, not just the product family, and note that no new certifications have been issued since the program closed.
  • Verify the APL record is still in the DISA repository, which is maintained through FY2026, and not tied to a platform approaching end of sale.
  • Document TAA-compliant country-of-origin per SKU so the hardware review has nothing to chase.
  • Confirm FIPS 140 validated cryptography and that the platform can be hardened to the applicable STIGs.
  • Separate the product-level APL certification from the system-level ATO and the DISN-level ATC so the program knows what work remains after delivery.
  • Settle the purchase path, GPC, Simplified Acquisition, a FAR-based purchase order, or a contract vehicle the seller actually holds, before pricing is locked.

Cisco products involved

  • Cisco Catalyst 9300 Series
  • Cisco Catalyst 9800 Wireless Controller
  • Cisco Secure Firewall 3100 Series
  • Cisco Catalyst 9176 Access Point
  • Cisco Identity Services Engine
  • Cisco Nexus 9000 Series

Uniqcli can prepare a quote with each platform's APL certification record noted, packaged for your program's purchasing path, GPC, SAP, or a FAR-based purchase order.

Bottom line: A DoDIN APL certification covered the part, not the program, and with the program sunset it is one historical thread alongside the STIG, FIPS, TAA, ATO, and ATC evidence a DoD Cisco buy has to satisfy at once. Request a procurement-ready Cisco quote and we will confirm APL certification history, TAA-compliant options, and FIPS posture before the BOM is ever locked.

Frequently asked questions

Does a product on the DoDIN APL still need its own ATO?

Yes. APL placement meant DISA had certified the product for cybersecurity and interoperability in a defined configuration; it did not grant an Approval to Connect, which DISA issues to the enclave or system itself. Your program still has to assemble the system, harden it to the applicable STIGs, document its controls, earn an Authority to Operate from its Authorizing Official, and then obtain the ATC for the DISN connection. A completed APL certification shortens that path but never replaces it.

Is DoDIN APL the same as FedRAMP?

No. The DoDIN APL certified whether a product had passed DISA's cybersecurity and interoperability testing for DoD networks, while FedRAMP authorizes cloud services for federal use. A single deployment often needs both: APL coverage for the on-premises switches and firewalls, and a FedRAMP authorization for any cloud management plane or SaaS service. They are judged separately, by different reviewers, on different evidence.

Does APL listing mean a product is automatically TAA-compliant?

No. APL status and TAA compliance are unrelated tests. The APL was about DISA certification for DoD network connection; the Trade Agreements Act is about where the product is manufactured or substantially transformed, and TAA status is set per part number and lot, not per vendor. We keep a country-of-origin position per SKU so the bill of materials carries both pieces of evidence, because a reviewer can accept one and reject on the other.

Why does the software version matter for APL compliance?

APL entries are tied to the specific releases and configurations that were tested, not to a product name in general. If you field a software train that was never submitted, you can be out of compliance on hardware that is otherwise identical to a listed unit, and since DISA stopped accepting submissions at the end of 2025, a newer train cannot be added to the record. We match the version on the listing to the version on the quote so the release you deploy is the one that was actually approved.

Which Cisco platforms are commonly fielded on DoD networks?

Catalyst 9300 switches at the access layer, Catalyst 9800 wireless controllers with Wi-Fi 6E and Wi-Fi 7 access points, the Secure Firewall family at the edge, and the Identity Services Engine for posture and access control all recur across DoD architectures. We confirm each one against its APL certification record, its TAA-compliant options, and its FIPS status before it lands in a proposal.

How early should APL status be checked in a DoD buy?

Before the bill of materials is locked. Validating APL certification history, TAA country-of-origin, FIPS posture, and STIG-ability while the BOM is still being assembled is what prevents a proposal from bouncing back in review. Catching a non-listed line item on day one costs a substitution; catching it at the Authorizing Official's desk costs a full corrections cycle.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote

Related reading

Cisco wireless for federal and DoD facilities: a compliance primerCompliance

Cisco wireless for federal and DoD facilities: a compliance primer

Federal and DoD wireless is two designs sharing one budget: the RF plan and the compliance stack. Here is how FIPS, WPA3-Enterprise, DISA STIGs, the DoDIN APL, and TAA sourcing fit together on Cisco wireless, and why building them in from the first design call beats retrofitting before an assessment.

June 6, 2026 · 13 min read
The networking supercycle: what tripling AI traffic means for federal data center planningInsights

The networking supercycle: what tripling AI traffic means for federal data center planning

Cisco leadership is calling this a networking supercycle, with AI traffic on track to triple inside three years. For federal data centers, that is a capacity, power, and procurement problem you size now, before the accelerators land on the loading dock.

June 4, 2026 · 11 min read
Cisco SEWP Quote Guide for Federal BuyersCompliance

Cisco SEWP Quote Guide for Federal Buyers

NASA SEWP is one of the busiest IT contracts in the federal government, and with SEWP VI awarded and going live on November 1, 2026, it remains a fast lane for Cisco hardware when you set the buy up correctly. Here is how the vehicle works, what makes a quote clear on the first pass, and the mistakes that push an award past fiscal year end.

May 22, 2026 · 10 min read
Salt Typhoon, One Year On: Why Trusted, Monitored Network Infrastructure MattersNews

Salt Typhoon, One Year On: Why Trusted, Monitored Network Infrastructure Matters

A year after Salt Typhoon burrowed into at least nine US carriers and, per the FBI, 200-plus organizations across 80 countries, lawmakers are still demanding proof the intruders are gone. The story has shifted from breach to persistence, and persistence is a procurement and operations problem as much as a security one.

June 7, 2026 · 9 min read
Post-quantum cryptography for federal networks: securing Cisco from boot to transportCompliance

Post-quantum cryptography for federal networks: securing Cisco from boot to transport

A cryptographically relevant quantum computer does not exist yet, but the federal migration deadline is already set and adversaries are already collecting. Here is how post-quantum cryptography actually lands on a Cisco campus, branch, and data center, and how to sequence the refresh without a forklift.

June 5, 2026 · 12 min read
TAA-compliant AI infrastructure: the procurement path for Cisco GPU networkingCompliance

TAA-compliant AI infrastructure: the procurement path for Cisco GPU networking

An AI cluster is the most expensive and most supply-constrained buy most agencies will make this decade, which makes the procurement path as load-bearing as the architecture. Here is how to keep a Cisco GPU networking build TAA-compliant and award-ready from the first line item.

May 16, 2026 · 12 min read