I'm helping a small manufacturing client—fewer than 25 employees—select and deploy the equipment for a CMMC- and FIPS-compliant network. A third-party consultant is guiding the compliance and documentation process, while I'm responsible for choosing and implementing the technology stack.
The client produces parts for contractors that ultimately support military work. This business line generates useful revenue but is not their main service, so they need to keep infrastructure costs under control. Their CUI workflow is expected to use PreVeil, with CUI potentially present in temporary storage and on the local workstation network while code files are distributed to systems in the shop.
We commonly deploy FortiGate, but the models I've found that appear to meet the required FIPS 140-2 Level 2 criteria and support roughly 25 users are the FortiGate 200F and Rugged 60F. In practice, a standard 60F would likely be sufficient from a performance standpoint, but the Rugged model costs several times more and is not as capable as a normal 60F. The 200F would likely be even more expensive.
My experience includes SonicWall, UniFi, Netgate, and FortiGate. I'm ruling out SonicWall for this project, UniFi does not appear to offer the required FIPS validation, and Netgate's current Level 2 support is still unclear. Are there other firewall vendors with a lower-cost desktop or small-office model that has an applicable FIPS 140-2 Level 2 validated cryptographic module? I'm also interested in how the firewall's role changes depending on whether it is handling VPN traffic or directly protecting CUI flows.
3 Answers
There may be lower-cost options from vendors such as WatchGuard, and some desktop models have appeared in federal or compliance-oriented product lists. Treat those lists as a starting point, not proof of compliance. Verify the current FIPS certificate, whether it is Level 2 rather than Level 1, whether the exact appliance is covered, and whether the validated firmware is still supported. A sales representative or partner should be able to provide the certificate number and security policy instead of just saying that the product is “FIPS compliant.”
The right answer depends heavily on where CUI actually exists and how it moves. If the firewall is only providing ordinary internet access and the CUI is handled through a separate protected service, its cryptographic validation may not be the main control protecting that data. On the other hand, if the firewall terminates a VPN carrying CUI or provides a security boundary around systems that store or process it, the validated cryptographic module and approved operating mode become much more important. Document the data flow first, then have the consultant confirm which components are actually in scope.
Start with the validated cryptographic module certificate rather than the appliance marketing page. The NIST Cryptographic Module Validation Program database has the authoritative certificate details, including the module version, validation level, and product families that use it. Be careful about assuming that one validated module automatically makes every appliance model Level 2 compliant; the exact model, firmware, operating mode, and configuration still need to match the validation and your assessor’s interpretation. Some non-rugged models may use the same validated module, so it is worth checking the certificate and vendor security documentation before limiting yourself to the 200F or Rugged 60F.
That matches what our compliance advisor has told us: many models may inherit Level 1 coverage, but only specific models or configurations qualify for Level 2. I’m going back through the NIST certificate and the vendor’s current product matrix rather than relying on a generic product list.

In this setup, the client receives CUI from its customer through PreVeil. The data may exist briefly in temporary storage and on the local workstation network, so I’m not sure an SMB-only encryption recommendation covers the whole workflow. I’ll map the transfer and storage paths with the consultant before finalizing the firewall requirements.