FIPS 201 Approved Product List
This page is for program managers and acquisition professionals looking for approved products for physical access control systems and PIV cards. This page also contains the removed products list.
If you think this page is missing something, contact us to ask a question.
How To Purchase
Visit the Buy Page to view FICAM products, services and purchasing guidance.
Approved Products - 13.01 and 13.02 Topology
The Physical Access Control System (PACS) products listed under the “Approved” section below have met the security and functional requirements set by GSA’s FIPS 201 Evaluation Program, and have been approved for use by the Federal Government. The agency deploying the solution is responsible for verifying that the deployment architecture (e.g., on-site, private cloud, public cloud, etc.) meets the agency’s security requirements, such as FedRAMP. Note that the Approved PACS Products below are grouped by either 13.01 or 13.02 topologies and indicated as Cloud infrastructure where appropriate:
- 13.01 Topology – end-to-end systems that integrate components from three categories: PACS Infrastructure, Validation System, and PIV PACS Reader.
- 13.02 Topology – end-to-end systems that integrate the first two components (PACS Infrastructure and Validation System) into a PACS Validation Infrastructure, which is then integrated with the third component category (PIV PACS Reader).
Approved 13.01 Topology PACS Products
Approved 13.01 Cloud Topology PACS Products
| PACS Infrastructure | PACS APL # | Validation System | Validation APL # | 
|---|---|---|---|
| Datawatch Systems Site Controller | 10117 | Validation System for Datawatch | 10118 | 
Note: The agency deploying the solution is responsible for verifying that the deployment architecture (e.g., on-site, private cloud, public cloud, etc.) meets the agency’s security requirements, such as FedRAMP.
Approved 13.02 Topology PACS Products
| PACS Infrastructure and Validation System | APL # | 
|---|---|
| Identiv Velocity Security Management System | 10103 | 
| Gallagher Command Centre PACS | 10114 | 
| Software House C●CURE-9000 V3.0 PACS | 10159 | 
Approved 13.02 Cloud Topology PACS Products
| PACS Infrastructure and Validation System | APL # | 
|---|---|
| XTec AuthentX ePACS PACS and Validation Infrastructure | 10077 | 
| Kastle Systems CPS (EP) PACS and Validation Infrastructure | 10116 | 
Note: The agency deploying the solution is responsible for verifying that the deployment architecture (e.g., on-site, private cloud, public cloud, etc.) meets the agency’s security requirements, such as FedRAMP.
PACS Readers
NOTE: PACS readers are approved as part of a complete solution. The list below represents the readers that have been tested and verified as part of a solution (e.g., Infrastructure + Validation Engine + Reader). Each of the linked approval letters lists the approved reader types, associated APL#, and tested PACS solution.
- Allegion Schlage Smart Card Readers
- ASSA ABLOY integrated Signo Readers
- ASSA ABLOY integrated pivCLASS Readers
- Gallagher T Series PIV Readers
- HID pivCLASS Series Readers
- HID Signo Series Readers
- Identiv uTrust Series Readers
- IDFACTORS Readers
- Innometriks Cheetah Series Readers
- Veridt Series Readers
- XTec X Series Readers
- WaveLynx Technologies Readers
PACS Solutions Awaiting Approval
| Position | Solution | APL Numbers | New/Update | Testing Status | 
|---|---|---|---|---|
| 1 | AMAG Symmetry Professional + HID Global Validation System | 10047 & 10048 | Update | In queue | 
| 2 | Gallagher PIV Command Centre + HID Global Validation System for Gallagher Command Center | 10019 & 10020 | Update | In queue | 
| 3 | LenelS2 OnGuard 8.3 + HID pivCLASS 5.32.0 | 10112 & 10113 | Update | In queue | 
Cycle 2 and 3 updates are moved to the front of the test queue once they are installed. While between cycles, solutions may not appear here.
Approved Products - PIV Smart Cards
The Personal Identity Verification (PIV) cards listed below are approved for FICAM implementation under the FIPS 201 Evaluation Program. They are blank PIV cards that are available for purchase. A PIV service provider will personalize these blank cards for federal agencies and contractors. PIV service providers are required to use PIV cardstock from the Approved Products List (APL).
If you do not see a card below, it’s possible it’s on the Removed Product List.
Please note:
- Tri-Interface cards are not approved for federal government PIV or CAC card use, so agencies should not procure them. They are listed on the APL for industry-only acquisition.
- Manufacturers may call Tri-Interface cards by different names (for example, Dual Hybrid). The prohibited feature of Tri-Interface cards is a prox interface (a 125 kHz antenna).
- Agencies should procure only cards validated by the NIST Personal Identity Verification Program (NPIVP).
Approved PIV Cards
| APL Number | Product Name | Valid Date | 
|---|---|---|
| 1429 | Giesecke+Devrient Mobile Security SmartCafe Expert 7.0 with HID Global ActivID Applet v2.7.5 | 11/09/2017 | 
| 1511 | IDEMIA Cosmo V8.0 | 11/13/2019 | 
| 1512 | ID-One PIV v 2.4.2 on Cosmo V8.2 | 11/16/2021 | 
| 1513 | IDEMIA ID-One PIV 243 | 6/17/2025 | 
Legacy PIV Cards
The FIPS 201 Evaluation Program no longer approves the purchase of legacy PIV cards. Any cardstock designated as "legacy" is placed on this legacy list for three (3) years and then placed on the Removed Product List for three (3) years. However, some federal agencies still need to procure the legacy cardstock while upgrading existing systems. Agencies must stop using cardstock on the legacy list by June 30, 2027.
Legacy PIV cards include the following:
| APL Number | Product Name | Valid Date | 
|---|---|---|
| 1510 | Safenet IDPrime PIV v3.0 | 08/01/2019 | 
| 1502 | Giesecke+Devrient Mobile Security SmartCafe Expert 7.0 with StarSign Applet v1.0 | 12/13/2018 | 
| 1500 | Gemalto TOP DL v2.1 with HID Global ActivID Applet Suite v2.7.4 | 08/03/2018 | 
| 1431 | HID Global Crescendo PIV | 01/24/2018 | 
| 1430 | Gemalto IDPrime PIV v2.1 | 01/10/2018 | 
| 1428 | ID-One PIV v 2.4.1 on Cosmo V8.1 (EEPROM) | 11/13/2017 | 
| 1428 | ID-One PIV v 2.4.1 on Cosmo V8.1 (ROM) | 11/13/2017 | 
| 1428 | ID-One PIV v 2.4.0 on Cosmo V8.1 (EEPROM) | 08/15/2017 | 
| 1354 | ID-One PIV v 2.3.5 on Cosmo V8 | 06/17/2015 | 
| 1355 | ID-One PIV v 2.3.5 on Cosmo V8 (High Speed) | 06/17/2015 | 
Agencies procuring cardstock from the legacy list assume all risks associated with its use.
If your agency needs to purchase cardstock from this legacy list, you must submit an Assumption of Risk Memorandum (memo) from the agency Chief Information Officer(s) to the General Services Administration (GSA). The memo must contain the following information:
- Acknowledgment of the assumption of all associated security risks;
- Acknowledgment of non-compliance with NIST standards;
- A transition plan specifying major milestones to achieve full compliance by the 2027 deadline and
- Implications resulting from non-compliance with federal policy related to this purchase.
Submit the memo to GSA’s Associate Administrator for Government-wide Policy (OGP) (regardless of the vehicle used in the acquisition). If using the GSA Multiple Award Schedule as the acquisition vehicle, submit a copy of the memo to the Commissioner of GSA’s Federal Acquisition Service.
Note: GSA will provide the Office of the Federal Chief Information Officer (OFCIO) at the Office of Management and Budget (OMB) with copies of all memos submitted.
Removed Product List
The FIPS 201 Evaluation Program’s Removed Products List (RPL) displays products and services that were once on the Approved Products List but are no longer approved for government procurement. Due to security concerns, products on the RPL are not recommended for government acquisition. Products will be removed from the RPL 3 years after the removal date.
| 13.01 PACS and Validation Infrastructure Category | |||||
|---|---|---|---|---|---|
| PACS Infrastructure | PACS APL # | Validation System | Validation APL # | Removal Date | Reason | 
| ACRE Security Feenics Keep V3 SW 1.0.42 | 10120 | HID pivCLASS 5.8.1 Registration Engine for Feenics Keep V3 | 10121 | 03/18/2025 | Not approved for FRTC 1.3.3 | 
| ACRE Security Open Options DNA Fusion | 10075 | HID pivCLASS 5.19.0 Registration Engine for Open Options DNA Fusion 7.1 | 10076 | 05/08/2025 | Didn't meet the APL resubmission timeline. | 
| ACRE Security RS2 AccessIT! | 10036 | HID pivCLASS 5.19.3 Registration Engine for RS2 AccessIt! | 10037 | 05/08/2025 | Didn't meet the APL resubmission timeline. | 
| Amag Symmetry Professional V8.1 | 10087 | Technology Industries Validation System for AMAG Professional | 10086 | 06/09/2022 | Not approved for FRTC 1.3.3 | 
| American Direct Procurement, Inc. Quintron AccessNsite | 10043 | pivCLASS Registration Engine for AccesNsite | 10044 | 11/01/2022 | Not approved for FRTC 1.4.2 | 
| Identiv Velocity 3.8.4 w/pivCLASS validation 5.20 | 10013 | pivCLASS validation system 5.20 for Hirsch-Identiv Velocity 3.8.4 | 10014 | 10/16/2023 | 13.01 removed per vendor request. The approved 13.02 Identiv Velocity System is APL #10103 | 
| System Galaxy Software 11.3.0.1 | 10083 | Validation System for Galaxy Control Systems - Entrypoint 5.8.3 | 10084 | 05/01/2025 | 13.01 removed per vendor request. The approved 13.02 Software House CCURE-9000 V3.0 PACS is APL #10159 | 
| Tyco Security Products Ccure 9000 2.70.SP5 | 10001 | Validation System for Tyco Security Products C●CURE 9000 – HID 5.11.0 | 10002 | 05/01/2025 | 13.01 removed per vendor request. The approved 13.02 Software House CCURE-9000 V3.0 PACS is APL #10159 | 
| Tyco Security Products Ccure 9000 2.8 SP6 | 10115 | Validation System for Tyco/Software House C*CURE 9000 - IDS v2.3.2 B3 | 10108 | 05/01/2025 | 13.01 removed per vendor request. The approved 13.02 Software House CCURE-9000 V3.0 PACS is APL #10159 | 
| 13.02 PACS and Validation Infrastructure Category | |||||
|---|---|---|---|---|---|
| PACS Infrastructure | PACS APL # | Validation System | Validation APL # | Removal Date | Reason | 
| PIV Card Category | |||||
|---|---|---|---|---|---|
| APL # | Supplier | Product Name(s) | Product Number | Removal Date | Reason For Removal | 
| 1430 | Gemalto | IDPrime PIV v.2.1 | O1110994 | 07/01/2024 | CMVP certificate is now historical. | 
| 1510 | Gemalto | Safenet IDPrime PIV v3.0 | O1138439 | 07/01/2024 | CMVP certificate is now historical. | 
| 1500 | Gemalto | Gemalto TOP DL v2.1 with HID Global ActivID Applet Suite v2.7.4 | O1115095 | 07/01/2024 | CMVP certificate is now historical. | 
| 1431 | HID | HID Global Crescendo PIV | 40030M-D14 | 07/01/2024 | CMVP certificate is now historical. | 
| 1354 | Oberthur | ID-One PIV v 2.3.5 on Cosmo V8 | 1276885 | 07/01/2024 | CMVP certificate is now historical. | 
| 1355 | Oberthur | ID-One PIV v 2.3.5 on Cosmo V8 (High Speed) | 1276885-XS | 07/01/2024 | CMVP certificate is now historical. | 
| 1428 | Idemia | ID-One PIV v 2.4.1 on Cosmo V8.1 (ROM) | 1585242 | 07/01/2024 | CMVP certificate is now historical. | 
| 1428 | Idemia | ID-One PIV v2.4 on Cosmos V8.1 (EEPROM) | 1501381 | 07/01/2024 | CMVP certificate is now historical. | 
| 1502 | Giesecke + Devrient Mobile Security | SmartCafe Expert 7.0 with StarSign Applet v1.0 | 50254711 | 07/01/2024 | CMVP certificate is now historical. | 
 
           
        