Any keys generated on an 7200, 7210,6200, 6210, and 8200v appliance running in FIPS mode will be FIPS compliant. If you import certificates (and their associated public and private keys) to the appliance, it is your responsibility to make sure that they are also FIPS compliant. Certificates must be exported and then reimported when you switch FIPS mode on or off. For the export and import procedure, see Exporting and Importing FIPS-Compliant Certificates.
The best way to ensure that the certificates you’re using are FIPS compliant is to generate all CSRs (certificate signing requests) on a FIPS-enabled appliance.