Certification of NetApp products to the DoDIN APL means that U.S. defense agencies can use them with confidence and provides valuable assurances to customers supporting the defense industrial base.
Certification of NetApp products to the DoDIN APL means that U.S. defense agencies can use them with confidence and provides valuable assurances to customers supporting the defense industrial base.
The U.S. Department of Defense Information Network Approved Products List (DoDIN APL) is the master list of products that have completed cybersecurity and interoperability certification and are approved for deployment in the DoD’s technology infrastructure. Departments and agencies in the DoD may need to purchase products on this list to meet procurement requirements for products that will be connected to the DoDIN.
The U.S. Defense Information Systems Agency (DISA) manages the rigorous selection process, which is used to test, validate, and certify products to meet the required security and interoperability specifications. A sponsoring DoD agency works with the vendor who submits documentation that includes a system description and a component list; a response to a DoD Security Technical Implementation Guide (STIG) questionnaire, which defines the required cybersecurity configuration standards; and a letter of compliance. After document review, DISA determines which STIGs to apply and audits the product at one of its testing facilities. When the DISA evaluator determines that the DoD STIG requirements have been met, the product receives its certification for placement on the DoDIN APL. The certification is good for 3 years before recertification is required.
Continuing a tradition dating back to 2005 when NetApp ONTAP was first certified, NetApp systems were most recently certified in December 2019 by DISA and placed on the DoDIN APL. NetApp has long been involved in this DoD certification process—our contributions led to the development of requirements for data storage controllers in the predecessor of the DoDIN APL, the Unified Capabilities Approved Products List (UC APL).
For the current certification, NetApp submitted the required documentation to DISA, including a letter of compliance, our attestation that we meet requirements (such as IPv6) that DoD does not test, and a Self-Assessment Report. In its Joint Interoperability Test Center (JITC), DISA tested the products’ cybersecurity against the STIGS it determined to be applicable. Based on that audit, DISA determined that in-scope NetApp products satisfy the requirements and placed them on the APL. This means that U.S. defense agencies can choose these compliant NetApp products and services with confidence, assured of their stringent security processes.
The following hardware platforms, software versions, and virtual platforms are covered under the DoDIN APL.
Not all software versions run on all hardware platforms. If you have a NetApp Support account, refer to Hardware Universe for compatibility listings.
Each certification is good for 3 years, at which point NetApp will recertify and reaccredit the products. Each of the links below points to the DISA DoDIN APL Approval Memo, where you’ll find a link to the detailed components and configuration.
* NetApp is no longer supporting this product or continuing its certification for DoDIN APL. Customers who require this certification should contact their account representative to ensure this product meets their compliance requirements.To request a copy, send email to the Approved Products Certification Office. The CAP can be sent only to U.S. government civilians or U.S. uniformed military personnel. The request must be received from a .mil or .gov email address and be sent with a digital PKI signature attached.