DoDIN APL Explained: The Approved Products List and Its Sunset
DISA is retiring the DoDIN APL mid-transition. Here's how the list worked, what replaces it, and what to cite on your RFQ while the successor framework is still being drafted.
By Uniqcli Team · · 5 min read

Key takeaways
- The DoDIN APL formally sunset Sept 30, 2025; DISA stopped initiating new APL certifications after that date.
- Cybersecurity certification moves to the DISA Vendor STIG program; interoperability moves to the UCR-CORE document.
- Products bought while APL-listed can still be used if applicable STIGs are applied and CYBERCOM IAVAs stay current.
- DISA will keep the APLITS repository of already-approved products viewable only through the end of FY2026.
- Confirm a listing hasn't moved to DISA's separate Removal List before citing it in a solicitation or contract.
On this page
Procurement Guidance
The DoDIN APL is sunsetting mid-transition. Here's what to cite on your RFQ now.
For 15 years, "is it on the APL?" was the first question every DoD network buyer asked before a purchase. DISA's July 2025 sunset memo has put that question in flux — with the successor framework still being drafted. This briefing lays out how the list worked, what has and hasn't replaced it, and what buyers and contracting officers should demand from vendors during the gap.
What the DoDIN APL was — and the two certifications it bundled
The DoD Information Network Approved Products List (DoDIN APL) is the single consolidated list of IT products that have cleared both Cybersecurity (CS) and Interoperability (IO) certification testing for use on the DoDIN/DISN. It bundled two distinct evaluations into one status: interoperability testing performed by the Joint Interoperability Test Command (JITC), a DISA component at Fort Meade, and cybersecurity testing — formerly called Information Assurance testing — documented in a Cybersecurity Assessment Report (CAR). Scope and requirements were defined by the Unified Capabilities Requirements (UCR) document.
The list was formerly the UC APL (Unified Capabilities Approved Products List), with oversight later moving from the Unified Capabilities Certification Office to the Approved Products Certification Office. Its authority rests on DoD Instruction 8100.04, which directs DoD Components to procure or operate Unified Capabilities products listed on the DoDIN APL unless granted an exception to policy.
Products spanned network infrastructure — routers, switches, firewalls, IDS/IPS — communications systems such as VoIP and video collaboration, and cybersecurity software intended for DoD network environments. Any product using cryptographic modules first needed FIPS 140 (140-2 or 140-3) validation as a precondition for the cybersecurity certification, with Common Criteria evaluation typically required on a separate cost and time track as well.
How APL status showed up in the buy
Under DoDI 8100.04, the list wasn't optional guidance — it shaped how contracting officers ran the acquisition.
- DoD Components were required to procure or operate listed Unified Capabilities products unless granted a documented exception to policy.
- Army CHESS guidance directed Contracting Officers to consult the APL before purchasing systems.
- RFQ responses had to clearly identify whether an offered solution was APL-listed.
- DoDIN APL acquisitions commonly proceeded through the ITES-3H (IT Enterprise Solutions-3 Hardware) contract vehicle.
- When no listed product met the mission, offices could request an Exception to Policy under DoDI 8100.04 — documented in the RFQ.
- Alternatively, a program office could sponsor a vendor's product for APL testing rather than accept a listed substitute.
How products got listed, and how to search what's there
Two things buyers still need to understand: the certification pipeline that produced a listing, and the portal where existing listings — and expirations — live.
The certification pipeline
Vendors moved through Initial Assessment, Self-Assessment, an Initial Contact Meeting, and Formal Testing at JITC or DISA-assigned labs. Vendors could not shop for a cheaper lab — fees were set by the assigned lab and could be substantial. Timelines historically ran roughly 13 to 15 months, with certification valid up to three years and an option to extend another three before recertification.
Searching the APLITS portal
The list was searchable at the DISA APLITS portal (aplits.disa.mil), where users filtered by vendor, product category, product name, or product number. DISA has committed to keep the repository viewable through the end of FY2026.
Watch the Removal List
When a previously approved product's listing expired without renewal or retest, it moved to DISA's separate DoDIN APL Removal List rather than remaining active. Before you cite a listing, confirm it hasn't rolled off — the active list and the removal list are not the same view.
When nothing fit the mission
The historical safety valves were the Exception to Policy route under DoDI 8100.04 and vendor sponsorship for testing. With new certifications no longer being initiated, the practical move now is to document the gap and the vendor's successor-program status directly in contract language.
The pivot: the 2025 sunset and what replaces it
On 18 July 2025, the DoD CIO issued a memo announcing a phased sunset of the entire DoDIN APL program and its certification processes. Per the plan, the program officially sunset on 30 September 2025; all already-scheduled APL testing was to conclude by 31 December 2025; and DISA committed to maintain the repository of already-approved products through the end of Fiscal Year 2026. No new APL certifications are being initiated.
The successor framework splits the two certifications the APL used to bundle. Cybersecurity requirements are transitioning to the DISA Risk Management Executive (RME) Vendor STIG program — a defined sequence in which a vendor submits an Intent Form, receives DISA approval, completes a questionnaire, applies a Security Requirements Guide template, then moves through authoring, DISA review, and publication of the STIG. Interoperability requirements move to an updated UCR-CORE document, enforced contractually rather than through a centralized approved list.
The gap is real and worth naming plainly: a draft UCR-CORE was expected around 30 January 2026 per vendors tracking the transition, which means the interoperability side of the successor framework was still being finalized as buyers headed toward FY27. That is precisely why contract language, not a consolidated list, is where compliance now has to be pinned down.
What buyers and contracting officers should demand during the gap
Existing APL-listed gear stays usable, but new buys need a different paper trail. Here's what to build into the buy while the successor framework catches up.
- Confirm continued use is defensible: DISA guidance permits ongoing use of products purchased while APL-listed, provided applicable STIGs/SRGs are applied, CYBERCOM IAVAs/IAVMs are kept current, and the vendor still provides support.
- Verify the listing hasn't moved to the Removal List before you rely on it in a solicitation or justification.
- Ask vendors directly about their DISA Vendor STIG status — where they sit in the Intent Form → SRG template → authoring → publication sequence, not just whether they "plan to comply."
- Ask how the vendor is addressing UCR-CORE interoperability requirements, recognizing the draft was expected around January 2026 and language may still be firming up.
- Build that documentation into RFQ and contract language rather than waiting on a new consolidated list to appear.
- Watch UCR-CORE as it finalizes, and revisit interim contract language once the interoperability requirements are formally published.
Common questions on the APL sunset
Is the DoDIN APL still active, or has it been replaced?
It's in a managed sunset, not an instant shutdown. The DoD CIO memo issued 18 July 2025 set the program's formal sunset for 30 September 2025, with already-scheduled testing wrapping up by 31 December 2025. DISA has committed to keep the list of already-approved products viewable through the end of FY2026, but no new APL certifications are being initiated. Cybersecurity validation moves to the DISA Vendor STIG program, and interoperability requirements move to the UCR-CORE document enforced through contract language.
Can we still buy and use a product that was on the DoDIN APL?
Yes. DISA's guidance says continued use of products purchased while APL-listed remains acceptable, as long as the applicable STIGs/SRGs are applied, CYBERCOM IAVAs/IAVMs are kept current, and the vendor still provides support. Just confirm the listing hasn't rolled off to DISA's separate Removal List, which tracks products whose approval lapsed.
Our vendor's product isn't on the APL and won't be certified before the program winds down — what do we put in our RFQ or contract?
Historically, program offices could request a documented Exception to Policy under DoDI 8100.04 or sponsor the vendor for testing if no listed alternative met mission needs, and Army CHESS guidance required Contracting Officers to flag APL status or the exception in the RFQ. With new APL testing no longer being initiated, ask the vendor directly about their DISA Vendor STIG status for cybersecurity and how they're addressing UCR-CORE interoperability requirements, then build that documentation into contract language rather than waiting on a new consolidated list.
Cite the right evidence on the next RFQ
Mid-transition, the safest move is naming the certification you actually need — Common Criteria, FIPS validation, JITC interoperability — and screening the quote against it. Send the requirement and we'll match the lines to the evidence.