NIAP: U.S. Government Approved Protection Profile - collaborative Protection Profile for Network Devices Version 2.1

Short Name: cpp_nd_v2.1

Technology Type: Network Device

CC Version: 3.1

Date: 11 March 2019

Preceded By: cpp_nd_v2.0e

Conformance Claim: None



This is a Collaborative Protection Profile (cPP) whose Target of Evaluation (TOE) is a network device. It provides a minimal set of security requirements expected by all network devices that target the mitigation of a set of defined threats. This baseline set of requirements will be built upon by future cPPs to provide an overall set of security solutions for networks up to carrier and enterprise scale. A network device in the context of this cPP is a device composed of both hardware and software that is connected to the network and has an infrastructure role within the network. The TOE may be standalone or distributed, where a distributed TOE is one that requires multiple distinct components to operate as a logical whole in order to fulfil the requirements of this cPP.

This U.S. Government Approved Protection Profile is not assigned to any Validated Products

Related Technical Decisions

  • 0412 – NIT Technical Decision for FCS_SSHS_EXT.1.5 SFR and AA discrepancy
  • 0411 – NIT Technical Decision for FCS_SSHC_EXT.1.5, Test 1 - Server and client side seem to be confused
  • 0410 – NIT technical decision for Redundant assurance activities associated with FAU_GEN.1
  • 0409 – NIT decision for Applicability of FIA_AFL.1 to key-based SSH authentication
  • 0408 – NIT Technical Decision for local vs. remote administrator accounts
  • 0407 – NIT Technical Decision for handling Certification of Cloud Deployments
  • 0402 – NIT Technical Decision for RSA-based FCS_CKM.2 Selection
  • 0401 – NIT Technical Decision for Reliance on external servers to meet SFRs
  • 0400 – NIT Technical Decision for FCS_CKM.2 and elliptic curve-based key establishment
  • 0399 – NIT Technical Decision for Manual installation of CRL (FIA_X509_EXT.2)
  • 0398 – NIT Technical Decision for FCS_SSH*EXT.1.1 RFCs for AES-CTR
  • 0397 – NIT Technical Decision for Fixing AES-CTR Mode Tests
  • 0396 – NIT Technical Decision for FCS_TLSC_EXT.1.1, Test 2
  • 0395 – NIT Technical Decision for Different Handling of TLS1.1 and TLS1.2

Please forward any questions or comments to

Site Map              Contact Us              Home