generated: '2026-08-19' method: searched probe: true url: https://www.cisco.com/c/en/us/about/trust-center.html trust_portal: https://trustportal.cisco.com/c/r/ctp/trust-portal.html note: Cisco runs a corporate Trust Center and a Trust Portal, both reachable anonymously (HTTP 200), where documents are requested per-customer rather than listed openly — the automated probe recorded no certification keywords because the portal renders client-side. What IS openly published and product-specific for Cisco ISE is the cryptographic-module validation, named with its NIST certificate number in Cisco's own ISE compatibility documentation. Only claims verified on a page fetched during this pass are recorded below. certifications: - name: FIPS 140-2 scope: Cisco ISE embedded cryptographic module — Cisco FIPS Object Module version 7.2a certificate: '#4036' issuer: NIST CMVP evidence: https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/compatibility_doc/b_ise_sdt_35.html verified: '2026-08-19' http_status: 200 note: Also present verbatim in the ISE 3.3 compatibility document. FIPS mode is opt-in on the appliance; when enabled, any function using a non-FIPS algorithm fails, and certificate keys must be 2048 bits or greater. - name: FIPS 140-3 scope: Cisco ISE 3.4 — Virtual Tunnel Interfaces with Native IPsec aligned to FIPS 140-3 certificate: null issuer: NIST CMVP evidence: https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/release_notes/cisco-identity-services-engine-release-notes-34.html verified: '2026-08-19' http_status: 200 corporate_programs: - name: FedRAMP scope: Cisco corporate compliance program (not ISE-specific) evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html verified: '2026-08-19' http_status: 200 - name: HIPAA scope: Cisco corporate compliance program evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html verified: '2026-08-19' http_status: 200 - name: C5 (Germany) scope: Cisco corporate compliance program evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html verified: '2026-08-19' http_status: 200 - name: IRAP (Australia) scope: Cisco corporate compliance program evidence: https://www.cisco.com/c/en/us/about/trust-center/compliance.html verified: '2026-08-19' http_status: 200 not_verified: - SOC 2 - ISO/IEC 27001 - PCI DSS - CSA STAR - Common Criteria for ISE specifically not_verified_note: These are commonly assumed for a vendor of this size but were NOT confirmed on any page fetched during this pass — the Trust Portal gates its document library. Recorded as unverified rather than asserted. government_certifications: https://www.cisco.com/c/en/us/solutions/industries/government/global-government-certifications/fips-140.html psirt: security_txt: https://www.cisco.com/.well-known/security.txt policy: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html contact: psirt@cisco.com csaf: https://www.cisco.com/.well-known/csaf/provider-metadata.json evidence: - source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-5/compatibility_doc/b_ise_sdt_35.html http_status: 200 keywords: - 'Certificate #4036' - source: https://www.cisco.com/c/en/us/about/trust-center/compliance.html http_status: 200 keywords: - FedRAMP - HIPAA - C5 - IRAP - source: https://trustportal.cisco.com/c/r/ctp/trust-portal.html http_status: 200 keywords: [] note: reachable but client-side rendered; no certification names in the served HTML