Cisco Catalyst 9000X: Models, Features and Migration

Cisco Catalyst 9000X: Models, Features and Migration

Cisco's Catalyst 9000X generation brings Silicon One-based core switching, 100G/400G uplinks, and line-rate encryption to the campus. Here's what changed across the 9300X, 9400X, 9500X, and 9600X.

Key Points

  • The Catalyst 9000X generation spans four series: 9300X and 9400X (access) and 9500X and 9600X (core) - there is no 9200X.
  • The Catalyst 9500X is Cisco's first campus-core switch built on the Silicon One Q200 ASIC, with up to 12.8 Tbps switching capacity and 400G QSFP-DD ports.
  • The Catalyst 9300X and 9400X use newer UADP 2.0sec/3.0sec ASICs that add 100G line-rate IPsec without a throughput penalty.
  • Every 9000X model adds line-rate 256-bit MACsec plus hardware-anchored Trustworthy Systems features (Secure Boot, SUDI).
  • X-generation switches are targeted upgrades, not a full replacement - the original 9200/9300/9500 remain active for lower-throughput deployments.
At a Glance
New in this generation Catalyst 9300X, 9400X, 9500X, 9600X
Core ASIC Cisco Silicon One Q200 (9500X)
Access ASIC UADP 2.0sec / 3.0sec (9300X / 9400X)
Top uplink speed Up to 400G (QSFP-DD, 9500X)
Where to check current MSRP GlobalPriceList.com (updated daily)

Cisco's Catalyst 9000 family has been the default campus switching platform for most enterprises since it replaced the 3850/3650 and 6800 series back in 2017, but the newest wave of hardware - collectively referred to as the Catalyst 9000X generation - is the biggest architectural jump the line has seen since that original launch. The "X" models aren't just a clock-speed bump: they bring Cisco's Silicon One ASIC, previously reserved for service-provider and data-center gear, into the campus core, push uplinks into 100G and 400G territory, and add crypto-capable silicon that lets switches encrypt traffic at line rate instead of taking a throughput hit for it. Here's what actually changed, model by model, and what it means if you're planning a refresh.

What Is the Catalyst 9000X Generation?

"Catalyst 9000X" isn't a single switch - it's Cisco's label for the newer, higher-performance models layered on top of the existing Catalyst 9000 lineup. As of this generation, the X treatment covers four series: the Catalyst 9300X (fixed-configuration access), Catalyst 9400X (modular access, via new SUP-2/2XL supervisors), Catalyst 9500X (fixed campus core), and Catalyst 9600X (modular campus core). Notably, there is no Catalyst 9200X - the entry-level 9200 series has not received an X-generation refresh, so it remains Cisco's baseline access switch for smaller branch and lower-density deployments.

It's also worth being clear that the 9000X models are additions to the catalog, not a wholesale replacement. The original Catalyst 9200, 9300, and 9500 switches are still active, still orderable, and still the right fit for a large share of deployments that don't need 100G-class uplinks or line-rate encryption. The X models exist for the specific cases where bandwidth, crypto performance, or campus-core throughput has become the bottleneck - dense Wi-Fi 6E/7 rollouts, IoT and smart-building convergence, encrypted WAN links, or a core that's aggregating more 25G/40G access switches than it was originally sized for.

That distinction matters when you're scoping a project budget, because it's easy to assume a refresh means ripping out an entire campus and replacing every switch with an X model. In practice, most networks end up with a mix: 9200 or 9300 switches still covering lower-density closets, 9300X or 9400X where PoE budget or encryption requirements have grown past what the older hardware can deliver, and a 9500X or 9600X at the core where multiple higher-speed access switches now converge. Treating the 9000X line as a targeted upgrade path - rather than an all-or-nothing platform swap - is usually the more cost-effective way to plan a multi-year refresh.

Catalyst 9500X and 9600X: Silicon One Comes to the Campus Core

The headline change in this generation is architectural: Cisco's Silicon One ASIC family, built for hyperscale and service-provider networks, now powers a campus-core switch for the first time. That matters because Silicon One was designed from the ground up for high-radix, high-bandwidth forwarding - exactly the profile a campus core needs as access-layer uplinks move from 10G/25G to 40G/100G.

Catalyst 9500X: Two Fixed Models Built on Silicon One Q200

The Catalyst 9500X is built around the Cisco Silicon One Q200 ASIC, which Cisco describes as purpose-built for next-generation network core-plus-edge switching. It ships in two fixed configurations aimed at slightly different port-density needs:

  • C9500X-28C8D - 28 ports of 40/100 Gigabit Ethernet (QSFP28) plus 8 ports of 40/100/200/400 Gigabit Ethernet (QSFP-DD)
  • C9500X-60L4D - 60 ports of 10/25/50 Gigabit Ethernet (SFP-56) plus 4 ports of 40/100/200/400 Gigabit Ethernet (QSFP-DD)

Cisco lists switching capacity at up to 12.8 Tbps with an 8 Bpps forwarding rate for the platform - a substantial jump over the fixed-core throughput available in the original 9500 series, and enough headroom to aggregate a much larger number of 25G/40G-capable access switches without the core itself becoming the constraint. The 400G QSFP-DD ports are the detail worth flagging for anyone doing longer-term capacity planning: even if nothing in a campus needs 400G today, having that ceiling on the core uplinks buys years of runway before the next refresh.

Catalyst 9600X: The Modular Core Alternative

For campuses that need chassis-based redundancy - dual supervisors, hot-swappable line cards, and the ability to scale port density over time without a forklift upgrade - the Catalyst 9600X is Cisco's modular counterpart to the fixed 9500X. It sits in the same "enterprise-class midsize and large campus-core" category Cisco uses for the 9500X, but in a chassis form factor for organizations that specifically need modularity: mixed line-card generations in the same chassis, in-service software upgrades without a full outage, or a core that's expected to grow port-by-port rather than being replaced as a fixed unit. If you're deciding between the two, the practical question is less about raw performance and more about whether your operations team needs modular, field-serviceable redundancy at the core - if yes, the 9600X's chassis architecture is the reason to pick it over the fixed 9500X.

Catalyst 9300X and 9400X: The Next-Gen Access Layer

Silicon One is a core-layer story for now; at the access layer, the 9000X generation's gains come from a newer generation of Cisco's own UADP ASIC, faster stacking fabric, and dedicated crypto hardware.

Catalyst 9300X: Fixed Access With Line-Rate Crypto

The Catalyst 9300X is built on the UADP 2.0sec ASIC, and the "sec" in that name is the point - it adds hardware support for crypto operations, including 100G line-rate IPsec, that the standard 9300 ASIC doesn't handle at full speed. Other notable specs:

  • StackWise-1T stacking - up to 1 Tbps of stacking bandwidth across an 8-member stack, roughly double what StackWise-480 offered on earlier 9300 models
  • Up to 48 Multigigabit ports per switch in standalone mode, or 448 Multigigabit ports across a full 8-member stack
  • Cisco UPOE+ at 90W - up to 48 ports per switch standalone, or 384 ports across an 8-member stack, enough power budget for Wi-Fi 6E/7 access points, PTZ cameras, and other higher-draw PoE endpoints that a standard UPOE (60W) port can't fully support
  • MACsec 256-bit (AES-256) encryption available on all models
  • 2x the onboard hosting resources compared to the original Catalyst 9300, plus Intel QuickAssist Technology (QAT) for offloading crypto and application workloads

In practice, the 9300X is the switch to reach for when an access-layer refresh needs to support encrypted traffic (site-to-site segmentation, compliance-driven encryption requirements) or higher-wattage PoE at scale, not just more ports.

Catalyst 9400X: Modular Access at Scale

The Catalyst 9400X isn't a new chassis - it's the existing 9400 chassis fitted with new SUP-2 and SUP-2XL supervisor engines built on the UADP 3.0sec ASIC, Cisco's newer-generation ASIC that also supports 100G line-rate IPsec. The new supervisors bring:

  • Up to 4 non-blocking 100/40 Gigabit Ethernet uplinks plus 4 non-blocking 25/10 Gigabit Ethernet uplinks per supervisor
  • UPOE+ (90W), UPOE (60W), and PoE+ (30W) power delivery across up to 384 ports simultaneously (with up to 260 ports able to run at full 90W under typical power budget constraints)
  • MACsec (AES-256) encryption, with the caveat that it isn't supported on supervisor uplink ports on the older SUP-1XL-Y model
  • Dual-supervisor redundancy with sub-second failover and In-Service Software Upgrade (ISSU) support, so a supervisor swap or software update doesn't require a scheduled outage

Because the 9400X is a supervisor upgrade rather than a full chassis replacement, it's the more capital-efficient path for organizations that already own 9400-series chassis and line cards and just need the crypto and uplink capacity the newer supervisors add. It's a meaningfully cheaper way to gain the same crypto and uplink benefits the 9300X delivers in a fixed form factor, provided your existing chassis and power supplies can support the new supervisor's requirements - worth confirming with a reseller or Cisco's compatibility matrix before assuming a straight drop-in swap.

Security and Zero-Trust Enhancements Across the Line

Every 9000X model shares a common security thread: Cisco has pushed encryption and platform-integrity features into hardware rather than treating them as software add-ons that cost throughput. Across the 9300X, 9400X, and 9500X you'll find line-rate 256-bit MACsec for encrypting traffic between switches and endpoints, and line-rate IPsec (100G-class on the 9300X/9400X) for encrypting traffic over Layer 3 paths - both running at full port speed instead of forcing a trade-off between "encrypted" and "fast."

On the platform-integrity side, Cisco's Trustworthy Systems features - hardware-anchored Secure Boot and Secure Unique Device Identification (SUDI) - are built into the 9000X hardware, giving you a way to verify that a switch is running genuine, unmodified Cisco software and hasn't been tampered with in the supply chain. The 9500X adds a dedicated Trust Anchor module and supports Cisco WAN MACsec (256-bit AES-GCM) for encrypting core-to-core links, along with object-group ACLs that make writing and maintaining large access-control policies more manageable than one rule per host or subnet.

None of this replaces a broader zero-trust architecture on its own - you still need policy enforcement through Cisco ISE, segmentation design, and continuous monitoring through Catalyst Center (formerly DNA Center) to get the full effect. What the 9000X hardware does is remove the old excuse that "encryption is too expensive for this switch to run," which previously pushed a lot of encryption decisions up to the WAN edge or left them undone at the campus layer entirely.

How the 9000X Generation Compares to Earlier Catalyst 9000 Switches

The table below lines up the X-generation models against their closest non-X counterparts on the specs that matter most for a refresh decision.

SeriesRoleASICTop uplink/port speedLine-rate crypto
Catalyst 9200Entry accessUADP mini1G/Multigigabit (model-dependent)No
Catalyst 9300Standard accessUADP 2.0Up to 10G uplinks (model-dependent)No
Catalyst 9300XStandard accessUADP 2.0secUp to 100G modular uplinksYes - 100G IPsec, MACsec 256-bit
Catalyst 9400XModular accessUADP 3.0sec (SUP-2/2XL)Up to 100G supervisor uplinksYes - 100G IPsec, MACsec 256-bit
Catalyst 9500Core/aggregationUADP 2.0/3.0 (model-dependent)Up to 100G (model-dependent)Limited/model-dependent
Catalyst 9500XCore/aggregationCisco Silicon One Q200Up to 400G (QSFP-DD)Yes - MACsec 256-bit, WAN MACsec
Catalyst 9600XModular coreNext-gen supervisor (chassis-based)High-density modular uplinksYes (platform-dependent)

The pattern across every row is the same: the X models trade a higher price point for either a new ASIC generation (Silicon One at the core, UADP 2.0sec/3.0sec at the access layer) or new supervisor hardware, and in exchange you get uplinks and forwarding capacity that didn't exist in the prior generation, plus crypto performance that used to require a dedicated appliance or a throughput compromise.

Licensing, Compatibility, and Migration Considerations

Catalyst 9000X switches are licensed the same way as the rest of the 9000 family - hardware MSRP and the Cisco DNA/Catalyst Center software subscription (typically Essentials or Advantage tier) are separate line items, and the tier you choose determines whether you get basic switching or the full assurance, analytics, and SD-Access feature set. Nothing about the X generation changes that model; it just makes the higher subscription tiers more worth paying for, since features like continuous zero-trust monitoring and AI-driven troubleshooting are most useful on hardware that can actually push the traffic volumes those tools are analyzing.

A few practical migration notes worth planning around before ordering: StackWise-1T on the 9300X uses different physical stacking hardware than StackWise-480 on earlier 9300 models, so a mixed stack across generations isn't a drop-in operation - budget for new stacking cables and check compatibility model-by-model. Similarly, the 9500X's QSFP-DD ports for 400G connectivity require different optics and, in many cases, different cabling than the QSFP28-only ports on earlier 9500 models, so a core upgrade is a good time to also audit your fiber plant and optics inventory rather than assuming everything currently in the rack will carry over. And because the 9400X is a supervisor swap rather than a chassis replacement, confirm your existing 9400 chassis and line cards are on Cisco's supported compatibility list for SUP-2/2XL before ordering - not every legacy line card is guaranteed to pair with the newest supervisor.

Timing also matters. Because the 9000X models sit at the newer, higher-priced end of the Catalyst 9000 catalog, it's worth sequencing a refresh around where the bottleneck actually is rather than upgrading everything on the same cycle. A campus core aggregating a handful of 10G access switches usually doesn't need a 9500X yet; a wiring closet running 1G APs doesn't need 9300X-class crypto hardware. Save the X-generation budget for the specific tier - core throughput, PoE headroom, or encryption - that's actually constraining the network today, and let the rest of the refresh follow the normal multi-year replacement cycle.

Checking Current MSRP

Catalyst 9000X part numbers - switches, supervisors, and the higher-speed optics they require - carry their own MSRP separate from the rest of the 9000 family, and pricing on newer SKUs tends to move as adoption ramps up. Browse the current Cisco switches catalog on GlobalPriceList.com, updated daily, to check exact part-number MSRP before requesting a quote from a reseller.

Related Cisco guides: Compare the wider family in Catalyst 9200 vs 9300 vs 9500, then review Cisco DNA license tiers before building the full hardware and software budget.

Sources

FAQ

What does the "X" mean in Catalyst 9300X, 9500X, etc.?

It marks the newer, higher-performance generation of that series - built on a newer ASIC (UADP 2.0sec/3.0sec at the access layer, Cisco Silicon One at the core), with higher-speed uplinks and hardware-accelerated encryption compared to the original non-X model.

Is there a Catalyst 9200X switch?

No. As of this generation, the X refresh covers the 9300X, 9400X, 9500X, and 9600X. The Catalyst 9200 series has not received an X-generation update and remains Cisco's entry-level access switch.

What is Cisco Silicon One and why does it matter for campus switches?

Silicon One is Cisco's ASIC family originally built for service-provider and data-center networks. The Catalyst 9500X is the first campus-core switch to use it (the Silicon One Q200), bringing up to 12.8 Tbps of switching capacity and 400G uplink ports to campus-core deployments.

Do I need to replace my entire network with 9000X switches?

No. The 9000X models are additions to the Catalyst 9000 catalog, not a replacement. Most networks use a mix - keeping 9200/9300 switches in lower-density closets and adding 9300X, 9400X, 9500X, or 9600X only where bandwidth, PoE budget, or encryption needs have outgrown the older hardware.

Check Current Cisco Pricing

Browse the full, daily-updated Cisco GPL on GlobalPriceList.com.

View Cisco Price List