DoDIN APL and Dell: What Goes on the Approved Products List and Why It Matters

securityUniqcli TeamMay 20, 20266 min read
DoDIN APL and Dell: What Goes on the Approved Products List and Why It Matters

If you are buying IT for a Department of Defense network, "Dell makes it" is not the same as "you can connect it." The gatekeeper is the DoD Information Network Approved Products List (DoDIN APL) — and understanding how it works saves contracting officers and system owners from buying hardware that stalls at the Authorizing Official's desk. This post explains what the DoDIN APL is, which categories of Dell Technologies products it touches, and how to combine listed and non-listed gear into a connection package that actually gets approved.

What the DoDIN APL Actually Is

The DoDIN APL is the single consolidated list of products that have completed interoperability (IO) and cybersecurity (CS) certification and are approved to connect to DoD networks. It is managed by the Defense Information Systems Agency (DISA) through the Unified Capabilities Certification Office (UCCO), and it has the force of policy: under DoD instruction, products that connect to the DISN must be selected from the DoDIN APL.

Two points trip people up:

  • The APL certifies a system or capability, not a part number. Listings are tied to a specific vendor, product, version/firmware, and a defined configuration tested as a unit. Change the firmware train or the topology and the listing may no longer cover you.
  • Not every device on a DoD network has to be APL-listed. The APL governs specific capability categories — things like Session Border Controllers, routers and switches in the network infrastructure path, VVoIP/UC components, VPN concentrators, and similar boundary and transport elements. General-purpose compute and storage are usually authorized through the Risk Management Framework (RMF) and the system ATO, not through a standalone APL entry.

That distinction is the whole game. The APL handles the categories where DISA wants centralized interoperability and security testing; RMF handles the rest at the system level.

Where Dell Fits in the APL Picture

Dell Technologies is overwhelmingly a compute, storage, client, and data-protection vendor. Most of its flagship platforms are not in APL categories — they are the workload-bearing equipment that an accreditation boundary is built around. That is not a gap; it is the correct lane.

Typical Dell platforms and how they reach a DoD network:

  • Servers — PowerEdge R660 and R760. These ride the system ATO under RMF. What matters for accreditation is the security posture you can prove: iDRAC9 for out-of-band management with signed firmware and a hardware root of trust, Secured Component Verification, OpenManage for lifecycle and patch evidence, and the ability to map controls to NIST SP 800-171/800-53.
  • Storage — PowerStore, PowerMax, PowerScale. Authorized within the boundary. The relevant features are data-at-rest encryption with FIPS 140-validated cryptographic modules, secure snapshots, and audit logging that feeds your continuous monitoring.
  • Data protection — PowerProtect. Backup and cyber-recovery sit inside the boundary; immutability and air-gapped vaulting support the resilience controls assessors look for.
  • Clients — Latitude, Precision, OptiPlex. Endpoints are governed by STIGs and endpoint security tooling, not the APL. Dell's commercial-grade firmware security, TPM 2.0, and BIOS verification matter here.

Where Dell-adjacent gear can touch the APL is in the network infrastructure category — switching and routing in the connection path. If a switch sits in a category DISA certifies, then the specific model and firmware must carry a valid listing. Always verify the exact product-and-version entry rather than assuming a product family is covered.

How a Product Gets — and Stays — on the List

The path is structured and version-specific:

  • The vendor sponsors the product and submits it through the UCCO process.
  • The product undergoes Interoperability (IO) testing (does it play correctly with the DoD environment) and Cybersecurity (CS) assessment (is its security posture acceptable, including STIG/SRG compliance).
  • Once approved, it is published with a defined certified configuration and an expiration. Listings carry a finite lifecycle, and re-certification is required as versions evolve.

The practical takeaway for buyers: an APL entry is a snapshot of a tested version. Before you cite an entry in a connection request, confirm the listing covers the firmware you intend to deploy and that it has not aged out.

What This Means for Your Connection Approval

For a real procurement, you are almost never buying "an APL product." You are assembling a package where:

  • Boundary/transport components in APL-governed categories carry current listings, and
  • Compute, storage, data protection, and clients — the Dell layer — are accredited through RMF inside the system boundary.

To keep that package moving, line up the evidence early:

  • Configuration management. Document the exact PowerEdge, PowerStore, or PowerProtect firmware/code levels and lock them to a baseline OpenManage can report against.
  • STIG compliance. Apply the applicable DISA STIGs to iDRAC, host OS, and storage management interfaces, and keep the scan results.
  • Crypto validation. Where encryption is in scope, confirm FIPS 140-validated modules are enabled, not merely available.
  • Supply chain. For federal buys, confirm TAA-compliant country-of-origin so the acquisition matches the compliance story.

Get those four aligned and the Dell layer rarely becomes the obstacle. The friction usually comes from version drift, missing STIG evidence, or assuming a switch is covered when its specific build is not.

The Bottom Line

The DoDIN APL is a category-specific gate for interoperability- and security-tested network capabilities — not a master catalog every device must appear in. Dell's core lineup (PowerEdge R660/R760, PowerStore, PowerMax, PowerScale, PowerProtect, Latitude, Precision, OptiPlex) generally earns its place on a DoD network through RMF and the system ATO, with APL listings reserved for the network-path categories DISA certifies. Buy to the certified configuration, hold the line on firmware and STIG evidence, and route the purchase through a compliant contract.

If you are scoping a DoD-connected refresh and want help mapping which components need APL listings versus RMF authorization — and getting TAA-compliant Dell hardware quoted by RFQ — request a quote or talk to a Uniqcli specialist. We will help you build a package that survives the AO review.

Build your Dell bill of materials.

Send us the requirement, the project, or an existing quote to beat. We come back with a validated, TAA-compliant Dell configuration and a real price, often below list.

[email protected] · Chicago, IL