Software Secure Firewall Threat Defense
Platform Secure Firewall Threat Defense Virtual
Activity Onboard

Interfaces and Device Settings Platform Settings UCAPL/CC Compliance

Last updated: Jul 29, 2025

UCAPL/CC Compliance

For more information about this setting and how to enable it for the Firewall Management Center, see Security Certifications Compliance.


 

After you enable this setting, you cannot disable it. If you need to take the appliance out of CC or UCAPL mode, you must reimage.

Before you begin

  • Secure Firewall Threat Defense devices cannot use an evaluation license; your Smart Software Manager account must be enabled for export-controlled features.

  • Secure Firewall Threat Defense devices must be deployed in routed mode.

  • You must be an Admin user to perform this task.

  • Security certifications compliance mode cannot be changed if the Firewall Threat Defense device is in high availability. Modify the security certifications compliance mode before forming the high availability pair.

Procedure

1

Choose Devices > Platform Settings and create or edit the Firewall Threat Defense policy.

2

Click UCAPL/CC Compliance.

3

To permanently enable security certifications compliance on the appliance, you have two choices:

  • To enable security certifications compliance in Common Criteria mode, choose CC from the drop-down list.
  • To enable security certifications compliance in Unified Capabilities Approved Products List mode, choose UCAPL from the drop-down list.
4

Click Save.

You can now go to Deploy > Deployment and deploy the policy to assigned devices. The changes are not active until you deploy them.