NIAP: Archived U.S. Government Approved Protection Profile - collaborative Protection Profile for Network Devices Version 2.0

Short Name: cpp_nd_v2.0

Technology Type: Network Device

CC Version: 3.1

Date: 05 May 2017

Transition End Date: 05 November 2017

Preceded By: cpp_nd_v1.0

Succeeded By: cpp_nd_v2.0e

Sunset Date: 14 March 2018 [Sunset Icon]

Conformance Claim: None



This is a Collaborative Protection Profile (cPP) whose Target of Evaluation (TOE) is a network device. It provides a minimal set of security requirements expected by all network devices that
target the mitigation of a set of defined threats. This baseline set of requirements will be built upon by future cPPs to provide an overall set of security solutions for networks up to carrier
and enterprise scale. A network device in the context of this cPP is a device composed of both hardware and software that is connected to the network and has an infrastructure role within
the network. The TOE may be standalone or distributed, where a distributed TOE is one that requires multiple distinct components to operate as a logical whole in order to fulfil the
requirements of this cPP.       

Assigned to the following Validated Products

Related Technical Decisions

  • 0292 – NIT technical decision for validation and valid termination of certificate chains x509 verification
  • 0291 – NIT technical decision for DH14 and FCS_CKM.1
  • 0290 – NIT technical decision for physical interruption of trusted path/channel.
  • 0289 – NIT technical decision for FCS_TLSC_EXT.x.1 Test 5e
  • 0281 – NIT Technical Decision for Testing both thresholds for SSH rekey
  • 0262 – NIT Technical Decision for TLS server testing - Empty Certificate Authorities list
  • 0260 – NIT Technical Decision for Typo in FCS_SSHS_EXT.1.4
  • 0259 – NIT Technical Decision for Support for X509 ssh rsa authentication IAW RFC 6187
  • 0258 – NIT Technical Decision for TLS and DTLS Server Tests - Applying RfI#201643 to NDcPPv2
  • 0257 – NIT Technical Decision for Updating FCS_DTLSC_EXT.x.2/FCS_TLSC_EXT.x.2 Tests 1-4
  • 0256 – NIT Technical Decision for Handling of TLS connections with and without mutual authentication
  • 0228 – NIT Technical Decision for CA certificates - basicConstraints validation

Please forward any questions or comments to

Site Map              Contact Us              Home