I'm selecting equipment and implementing a network for a small manufacturing client that needs to meet CMMC requirements and use FIPS-validated cryptography. A third-party consultant is guiding the compliance work, while I'm responsible for choosing and deploying the technology stack.
The company has fewer than 25 employees and only handles defense-related work indirectly, so keeping costs reasonable is important. We normally deploy FortiGate, but the models I've identified as meeting the needed FIPS 140-2 Level 2 requirements are the FortiGate 200F and Rugged 60F. A standard 60F would probably be sufficient from a performance standpoint, but the Rugged model costs several times more and is not as capable in other ways. The 200F may be even more expensive.
I've also considered SonicWall, UniFi, and Netgate. I'm not interested in using SonicWall, UniFi does not appear to offer the required FIPS validation, and Netgate currently advertises Level 1 support; I'm waiting for confirmation about Level 2.
Are there any lower-cost firewall vendors or desktop-class models with a current FIPS 140-2 or 140-3 Level 2 validated cryptographic module that could work for an organization this size? I'm also interested in how others are determining whether a specific appliance and firmware combination actually satisfies the requirement.
3 Answers
Make sure the model list you’re using is current. The relevant question is not simply whether a firewall advertises FIPS support, but which specific firmware uses a validated module and what validation level applies. The NIST Cryptographic Module Validation Program certificate database is a useful place to check this. Some non-rugged models may run a validated firmware version even if the hardware list you were given only mentions the 200F and Rugged 60F.
If the appliance is not terminating a VPN or otherwise handling protected traffic, it may not be the component directly protecting CUI with cryptography. That does not eliminate the need for a properly configured boundary device, but it does mean the compliance decision should be based on the actual data flows rather than assuming the firewall itself must provide every control. Document where CUI is received, stored, transmitted, and accessed before selecting hardware.
WatchGuard may be worth checking. Some of its smaller desktop appliances have appeared in federal encryption and compliance references, although you’ll need to verify the exact appliance, firmware release, and validated cryptographic module rather than relying only on the product family name. A consultant or authorized reseller may also be able to identify models that are less expensive than the FortiGate options.

That helps. My compliance advisor said the models they reviewed were Level 1, while only certain models qualified for Level 2, so I’ll compare the exact firmware and certificate details against the NIST database.