Uniqcli

InsightsProcurement Guidance

DoDIN APL Explained: The Approved Products List and Its Sunset

DISA is retiring the DoDIN APL mid-transition. Here's how the list worked, what replaces it, and what to cite on your RFQ while the successor framework is still being drafted.

By Uniqcli Team · · 8 min read · Updated

Key takeaways

  • The DoDIN APL formally sunset Sept 30, 2025; DISA stopped initiating new APL certifications after that date.
  • Cybersecurity certification moves to the DISA Vendor STIG program; interoperability moves to the UCR-CORE document.
  • Products bought while APL-listed can still be used if applicable STIGs are applied and CYBERCOM IAVAs stay current.
  • DISA will keep the APLITS repository of already-approved products viewable only through the end of FY2026.
  • Confirm a listing hasn't moved to DISA's separate Removal List before citing it in a solicitation or contract.
On this page

Procurement Guidance

The DoDIN APL is sunsetting mid-transition. Here's what to cite on your RFQ now.

The DoD Information Network Approved Products List (DoDIN APL) is DISA's single consolidated list of IT products that have cleared both cybersecurity and interoperability certification testing for use on the DoDIN/DISN. For 15 years, "is it on the APL?" was the first question every DoD network buyer asked before a purchase — and DISA's July 2025 sunset memo has now put that question in flux, with the successor framework still being drafted. This briefing lays out how the list worked, what has and hasn't replaced it, and what buyers and contracting officers should demand from vendors during the gap.

What the DoDIN APL was — and the two certifications it bundled

The DoD Information Network Approved Products List (DoDIN APL) is the single consolidated list of IT products that have cleared both Cybersecurity (CS) and Interoperability (IO) certification testing for use on the DoDIN/DISN. It bundled two distinct evaluations into one status: interoperability testing performed by the Joint Interoperability Test Command (JITC), a DISA component at Fort Meade, and cybersecurity testing — formerly called Information Assurance testing — documented in a Cybersecurity Assessment Report (CAR). Scope and requirements were defined by the Unified Capabilities Requirements (UCR) document.

The list was formerly the UC APL (Unified Capabilities Approved Products List), with oversight later moving from the Unified Capabilities Certification Office to the Approved Products Certification Office. Its authority rests on DoD Instruction 8100.04, which directs DoD Components to procure or operate Unified Capabilities products listed on the DoDIN APL unless granted an exception to policy.

Products spanned network infrastructure — routers, switches, firewalls, IDS/IPS — communications systems such as VoIP and video collaboration, and cybersecurity software intended for DoD network environments. Any product using cryptographic modules first needed FIPS 140 (140-2 or 140-3) validation as a precondition for the cybersecurity certification, with Common Criteria evaluation typically required on a separate cost and time track as well.

How APL status showed up in the buy

Under DoDI 8100.04, the list wasn't optional guidance — it shaped how contracting officers ran the acquisition.

  • DoD Components were required to procure or operate listed Unified Capabilities products unless granted a documented exception to policy.
  • Army CHESS guidance directed Contracting Officers to consult the APL before purchasing systems.
  • RFQ responses had to clearly identify whether an offered solution was APL-listed.
  • DoDIN APL acquisitions commonly proceeded through the ITES-3H (IT Enterprise Solutions-3 Hardware) contract vehicle.
  • When no listed product met the mission, offices could request an Exception to Policy under DoDI 8100.04 — documented in the RFQ.
  • Alternatively, a program office could sponsor a vendor's product for APL testing rather than accept a listed substitute.

How products got listed, and how to search what's there

Two things buyers still need to understand: the certification pipeline that produced a listing, and the portal where existing listings — and expirations — live.

The certification pipeline

Vendors moved through Initial Assessment, Self-Assessment, an Initial Contact Meeting, and Formal Testing at JITC or DISA-assigned labs. Vendors could not shop for a cheaper lab — fees were set by the assigned lab and could be substantial. Timelines historically ran roughly 13 to 15 months, with certification valid up to three years and an option to extend another three before recertification.

Searching the APLITS portal

The list was searchable at the DISA APLITS portal (aplits.disa.mil), where users filtered by vendor, product category, product name, or product number. DISA has committed to keep the repository viewable through the end of FY2026.

Watch the Removal List

When a previously approved product's listing expired without renewal or retest, it moved to DISA's separate DoDIN APL Removal List rather than remaining active. Before you cite a listing, confirm it hasn't rolled off — the active list and the removal list are not the same view.

Match the tested configuration to the quoted line

An entry covers what was submitted and tested, not a product family. Compare the model variant, the version and any bundled components named in the entry against the line on the quote, and treat a difference as a question for the vendor rather than a rounding error.

Save the evidence with the contract file

The repository is committed to stay viewable only through the end of FY2026, and no new certifications are being initiated. Export or capture the entry along with the date you accessed it and file it with the justification — the citation has to outlive the portal.

When nothing fit the mission

The historical safety valves were the Exception to Policy route under DoDI 8100.04 and vendor sponsorship for testing. With new certifications no longer being initiated, the practical move now is to document the gap and the vendor's successor-program status directly in contract language.

The pivot: the 2025 sunset and what replaces it

On 18 July 2025, the DoD CIO issued a memo announcing a phased sunset of the entire DoDIN APL program and its certification processes. Per the plan, the program officially sunset on 30 September 2025; all already-scheduled APL testing was to conclude by 31 December 2025; and DISA committed to maintain the repository of already-approved products through the end of Fiscal Year 2026. No new APL certifications are being initiated.

The successor framework splits the two certifications the APL used to bundle. Cybersecurity requirements are transitioning to the DISA Risk Management Executive (RME) Vendor STIG program — a defined sequence in which a vendor submits an Intent Form, receives DISA approval, completes a questionnaire, applies a Security Requirements Guide template, then moves through authoring, DISA review, and publication of the STIG. Interoperability requirements move to an updated UCR-CORE document, enforced contractually rather than through a centralized approved list.

The gap is real and worth naming plainly: a draft UCR-CORE was expected around 30 January 2026 per vendors tracking the transition, which means the interoperability side of the successor framework was still being finalized as buyers headed toward FY27. That is precisely why contract language, not a consolidated list, is where compliance now has to be pinned down.

The DISA approved products list, and what replaced it

Most people arriving at this question are still looking for the DISA approved products list by name, and the vocabulary is now the hardest part of the answer. There is no longer a single DISA-maintained list of approved products to point a new requirement at. DISA stopped initiating certifications when the program sunset on 30 September 2025, and the repository of already-approved products is committed to stay viewable only through the end of Fiscal Year 2026. Anyone instructed to "check the DISA approved products list" before a FY27 buy is being sent to a document that cannot answer the question being asked of it.

What replaced it is two things rather than one, which is why there is no successor list to redirect to. The cybersecurity half of what the APL used to certify now runs through the DISA Vendor STIG program under the Risk Management Executive; the interoperability half moved to the UCR-CORE document, enforced through contract language rather than through a centralized listing. A product is consequently no longer simply on the list or off it — it holds a position in a STIG publication sequence, and a set of interoperability requirements that somebody has to write into the buy.

That changes what a search is actually for. APLITS, while it remains up, is the place to establish what was approved and when, because prior listing is what makes continued use of already-purchased equipment defensible. For anything being bought now, the artifact that answers the question is the vendor's own documented Vendor STIG position and its UCR-CORE approach, captured in the solicitation itself — which is what the checklist below is written to collect.

APL vs STIG vs CMMC: three different questions

These three arrive in the same conversation and get used interchangeably in requirements documents, which is how a program ends up demanding the wrong artifact from the wrong party. Each one has a different subject: the product, the configuration, or the company.

DoDIN APL — the product

Asked of a product being connected to the DoDIN: has it cleared interoperability and cybersecurity testing under the UCR, and is it listed for the purposes of DoDI 8100.04? For new buys that question is now historical. The program sunset on 30 September 2025 and no new certifications are being initiated.

STIG — the configuration

A Security Technical Implementation Guide is DISA's published hardening standard for a platform or product category. It applies after the equipment arrives, to how the device is configured and scanned, which is why a product is not "STIG certified" — it is configured to the applicable STIG and verified against it. The cybersecurity half of the old APL now runs through the DISA Vendor STIG program.

CMMC — the company

The Cybersecurity Maturity Model Certification assesses a contractor's own environment for handling federal contract information and CUI at the level the contract requires. It is asked of the organization holding the award, says nothing about the equipment on the quote, and no product listing substitutes for it.

Where the three overlap on one buy

A single network refresh can touch all three without any of them answering for another. The product question is asked at selection, and now has to be answered with vendor documentation rather than a list lookup. The configuration question is asked at installation and again at every scan cycle, and it lands on whoever operates the network rather than on the manufacturer. The company question is asked of whoever holds the contract, and it is assessed on its own schedule against the contract's own requirement.

The failure mode is a requirements document that asks a switch vendor to be "STIG compliant and CMMC certified." A manufacturer can tell you which STIG or SRG applies to its platform and where it sits in the Vendor STIG sequence — Intent Form, questionnaire, SRG template, authoring, DISA review, publication. It cannot certify that the device will be configured correctly on your network, and its own CMMC status is a fact about the vendor's business rather than about the hardware being shipped. Put each question to the party that can answer it, and record the three answers separately in the file.

What buyers and contracting officers should demand during the gap

Existing APL-listed gear stays usable, but new buys need a different paper trail. Here's what to build into the buy while the successor framework catches up.

  • Confirm continued use is defensible: DISA guidance permits ongoing use of products purchased while APL-listed, provided applicable STIGs/SRGs are applied, CYBERCOM IAVAs/IAVMs are kept current, and the vendor still provides support.
  • Verify the listing hasn't moved to the Removal List before you rely on it in a solicitation or justification.
  • Ask vendors directly about their DISA Vendor STIG status — where they sit in the Intent Form → SRG template → authoring → publication sequence, not just whether they "plan to comply."
  • Ask how the vendor is addressing UCR-CORE interoperability requirements, recognizing the draft was expected around January 2026 and language may still be firming up.
  • Build that documentation into RFQ and contract language rather than waiting on a new consolidated list to appear.
  • Watch UCR-CORE as it finalizes, and revisit interim contract language once the interoperability requirements are formally published.

Common questions on the APL sunset

Is the DoDIN APL still active, or has it been replaced?

It's in a managed sunset, not an instant shutdown. The DoD CIO memo issued 18 July 2025 set the program's formal sunset for 30 September 2025, with already-scheduled testing wrapping up by 31 December 2025. DISA has committed to keep the list of already-approved products viewable through the end of FY2026, but no new APL certifications are being initiated. Cybersecurity validation moves to the DISA Vendor STIG program, and interoperability requirements move to the UCR-CORE document enforced through contract language.

Can we still buy and use a product that was on the DoDIN APL?

Yes. DISA's guidance says continued use of products purchased while APL-listed remains acceptable, as long as the applicable STIGs/SRGs are applied, CYBERCOM IAVAs/IAVMs are kept current, and the vendor still provides support. Just confirm the listing hasn't rolled off to DISA's separate Removal List, which tracks products whose approval lapsed.

Our vendor's product isn't on the APL and won't be certified before the program winds down — what do we put in our RFQ or contract?

Historically, program offices could request a documented Exception to Policy under DoDI 8100.04 or sponsor the vendor for testing if no listed alternative met mission needs, and Army CHESS guidance required Contracting Officers to flag APL status or the exception in the RFQ. With new APL testing no longer being initiated, ask the vendor directly about their DISA Vendor STIG status for cybersecurity and how they're addressing UCR-CORE interoperability requirements, then build that documentation into contract language rather than waiting on a new consolidated list.

APLITS is only viewable through the end of FY2026. How do we preserve the evidence?

Capture it now rather than planning to look it up later. Export or screenshot the APLITS entry for every product you rely on — the product number, the certification and expiration dates, and the configuration that was tested — record the date you accessed it, and file that alongside the contract or the continued-use justification. Check the separate Removal List in the same pass and capture that result too, because a reviewer will want evidence the check was run, not just an assertion that the product was listed. Once the repository comes down there is no successor list to re-query, so a prior listing is worth exactly as much as the record you kept of it.

Is a STIG the same thing as APL certification?

No, and the difference matters when you write requirements. The DoDIN APL was a product-level status: a specific product had cleared interoperability and cybersecurity testing and was listed for use on the DoDIN. A Security Technical Implementation Guide is a configuration standard DISA publishes for a platform or product category, applied by whoever operates the equipment and verified by scanning. A product is therefore not "STIG certified" — it is configured to the applicable STIG. What connects them is the transition: the cybersecurity half of what the APL used to certify now runs through the DISA Vendor STIG program under the Risk Management Executive.

Our product's APL listing expires next year. Can we recertify it?

Not through the APL. New certifications stopped being initiated when the program sunset on 30 September 2025, and already-scheduled testing was to conclude by 31 December 2025, so a listing that lapses moves to the Removal List rather than being renewed. Continued use of equipment purchased while it was listed stays defensible on the conditions set out above. The paperwork for the next buy has to come from the vendor's Vendor STIG position and its UCR-CORE approach instead.

Cite the right evidence on the next RFQ

Mid-transition, the safest move is naming the certification you actually need — Common Criteria, FIPS validation, JITC interoperability — and screening the quote against it. Send the requirement and we'll match the lines to the evidence.

Ask AI about Uniqcli

One vendor, many brands

About the author

Uniqcli Team

Uniqcli's newsroom, buying guides and glossary are produced by our in-house team — seven procurement and technology professionals who source, screen and integrate IT and security hardware every day, working with two editors. Practitioners draft from live sourcing and integration work; editors review every piece for accuracy and plain language before it publishes.

More about the Uniqcli Team

Ready to scope your program?

Talk to a Uniqcli engineer, or send a bill of materials for a TAA-verified quote — no payment up front.