JADC2 data-at-rest protection addresses a critical challenge created as classified information and computing move closer to the tactical edge. Joint All-Domain Command and Control connects sensors, decision-makers, and effects across the joint force, but the information supporting those connections can also remain stored on distributed mission systems.
That information cannot reside exclusively inside centralized data centers and highly protected facilities. It can be processed and stored on aircraft, ships, vehicles, uncrewed systems, tactical servers, command posts, sensors, weapons platforms, and other edge systems.
This creates an important security question: What protects classified information stored on a JADC2-connected endpoint if the physical system leaves authorized control? This article explains the DAR challenge at the tactical edge, the role of NSA’s CSfC architecture, and the questions programs should address when designing National Security Systems.
Data at rest is information stored on a physical device or storage media rather than actively moving between systems or across a network. Within JADC2, that can include classified information retained on tactical computers, mission systems, servers, sensors, vehicles, aircraft, ships, uncrewed systems, and other edge devices.
Consider targeting information moving from a sensor through a joint network to another mission system. While that information is moving between systems, it is data in transit. When the same information is stored on a sensor, tactical server, mission computer, aircraft, ship, or weapons platform, it becomes data at rest.
DAR can therefore exist throughout a JADC2 architecture, including on:
If a system retains information after power is removed, it can contain data at rest. As more information is processed and stored at the tactical edge, protecting that information becomes an increasingly important part of the security architecture.
The value of a captured endpoint is not necessarily determined by the number of documents stored on it. A single system may retain information that provides insight into a broader mission, network, platform, or joint-force capability.
Depending on the endpoint’s role, stored information could include:
A compromised endpoint can therefore potentially expose more than information about the device itself. Depending on the information retained, it may provide insight into how systems sense, communicate, process information, or support mission decisions.
JADC2 does not create the DAR challenge, but several characteristics associated with distributed joint operations can increase the number of locations where mission information is processed and stored.
Moving every piece of information back to centralized infrastructure for processing can introduce latency, consume bandwidth, and increase dependence on communications that may be degraded or denied.
Edge computing allows more processing to occur closer to the sensor, mission system, or weapon. That can create operational advantages, but local processing can also create locally stored information.
Information that might otherwise remain within centralized infrastructure can therefore reside on tactical endpoints operating outside traditional physical-security boundaries.
AI can support processing of sensor information, pattern identification, data fusion, decision support, targeting, autonomy, and other mission functions.
AI-enabled edge systems may also store trained models, algorithms, mission datasets, sensor information, configurations, and associated software.
DAR planning should therefore account for both operational data and technical information retained by AI-enabled mission systems.
Uncrewed systems are used across air, land, surface, and undersea environments. Some operate autonomously, while others are remotely controlled or semi-autonomous.
From a DAR perspective, the defining issue is the information retained by the platform and the applicable security requirements.
If an uncrewed platform stores classified information and can leave authorized physical control, programs need to determine what protects that information under those conditions.
Distributed operations place more systems outside centralized facilities and traditional physical-security boundaries.
That creates more locations where classified information may need to remain protected even when friendly forces no longer control the underlying hardware.
JADC2 connects capabilities across the joint force. Information generated by one Service or system can contribute to missions involving other platforms, organizations, and operational domains.
An Air Force sensor may provide information supporting an Army weapon. A Navy platform may contribute targeting information to a joint operational picture. Marine Corps expeditionary forces may operate sensors and weapons from distributed locations. Space Force capabilities can support communications, sensing, positioning, and other mission functions.
This interconnected environment means DAR protection cannot be considered solely as a platform-specific issue.
A compromised endpoint can potentially expose information with relevance beyond the organization operating the physical device. Programs should therefore consider the sensitivity and mission significance of all information stored on a JADC2-connected endpoint.
Many cybersecurity controls focus on preventing unauthorized remote access to networks, applications, and systems. Tactical systems also need to account for a different scenario: an unauthorized party physically possesses the endpoint.
A captured tactical server, aircraft component, UAS, ground system, sensor, mission computer, or other device can potentially provide physical access to its storage, processors, firmware, operating environment, and security hardware.
Storage could potentially be removed and examined separately. Hardware and firmware interfaces could be analyzed. The boot environment could be examined or manipulated. Comparable hardware could be used for testing.
The security question therefore changes.
Instead of asking only whether an unauthorized party can gain access through the network, programs also need to ask what information could become accessible if the complete endpoint and its storage are physically available for examination.
That is the threat scenario DAR protection is designed to address.
Commercial encryption can provide an important security function, but the presence of encryption alone does not define a complete architecture for protecting classified data at rest.
A system may use AES-256 or a cryptographic module validated under the NIST Cryptographic Module Validation Program while still requiring evaluation of other security mechanisms.
Programs should consider questions including:
The relevant question is therefore broader than the strength of the encryption algorithm. Programs need to determine what security mechanisms must be satisfied before classified information becomes accessible.
FIPS validation provides assurance that specified cryptographic functionality has been tested against defined requirements. A cryptographic module can be validated under the NIST Cryptographic Module Validation Program.
That validation is important, but it does not by itself establish that a complete endpoint architecture meets requirements for protecting classified data at rest.
A useful comparison is an integrated defensive system. One capable component does not constitute the entire architecture. Protection depends on multiple security functions working together according to defined requirements.
For classified National Security Systems, programs therefore need to evaluate the complete DAR architecture rather than treating FIPS validation as the security outcome.
National Security Presidential Memorandum 12, National Policy for the Cybersecurity of National Security Systems, was issued on June 12, 2026. The memorandum establishes cybersecurity governance for National Security Systems and reestablishes the Director of the National Security Agency as the National Manager for NSS.
NSPM-12 also establishes the NSA Director as the cryptologic authority for NSS. The National Manager’s responsibilities include providing authoritative minimum requirements for cryptology and cryptographic systems and carrying out other responsibilities related to the cybersecurity of National Security Systems.
This is relevant to JADC2 because its systems can cross organizational, Service, platform, network, and mission boundaries while processing or storing classified information.
For NSS, cryptographic protection therefore exists within a broader national-security framework rather than being determined solely by individual product capabilities.
NSA’s Commercial Solutions for Classified program enables commercial technologies to be used within defined architectures for protecting classified information.
The current CSfC Data-at-Rest Capability Package is v5.1.0, dated March 2026. It provides solution designs and implementation requirements for protecting classified data at rest.
For applicable Cigent CSfC DAR architectures, the two protection layers are:
The encrypted drive and pre-boot authentication constitute one layer. PBA controls access to the encrypted drive and should not be counted as a separate third layer.
This defense-in-depth architecture prevents the protection of classified information from depending entirely on one encryption mechanism.
Encryption protects stored information by transforming it into ciphertext. Authentication controls whether the conditions required to access protected storage have been satisfied.
For a tactical endpoint, both functions need to be considered together.
A useful analogy is a safe. Encryption provides the safe that protects the information inside. Pre-boot authentication provides the lock controlling access to the encrypted drive.
Programs should therefore evaluate not only whether storage is encrypted, but what authentication is required before the protected information becomes accessible and how that authentication behaves if physical control of the endpoint is lost.
Cryptographic keys are a critical part of an encrypted storage architecture. Protecting the encryption algorithm while inadequately protecting the associated keys can undermine the intended security outcome.
DAR architecture therefore needs to consider how keys are generated, stored, protected, released, and authorized.
This becomes particularly important in a physical-capture scenario because an unauthorized party may possess the complete endpoint and have time to examine its storage, hardware, firmware, and startup environment.
The security architecture should account for that threat rather than assuming that the endpoint remains within friendly physical control.
A JADC2 endpoint operating at the tactical edge may be disconnected from friendly networks when protection is needed most.
Communications may be degraded or denied. Remote management services may be unavailable. Enterprise identity services may not be reachable. A captured endpoint may be completely disconnected from U.S. infrastructure.
DAR protections therefore need to operate on the endpoint itself according to the applicable architecture and security requirements.
Physical possession of the device should not, by itself, provide access to the classified information stored on it.
Zero Trust and DAR address different security questions and can complement each other within a broader cybersecurity architecture.
Zero Trust architectures evaluate access to resources based on users, devices, services, context, and applicable policy. DAR focuses on protecting information stored on physical devices and media.
If an unauthorized party physically possesses a tactical endpoint and removes its storage, network access policies alone do not provide the cryptographic protection required for the information stored on that device.
DAR therefore addresses a distinct physical-storage threat that programs need to evaluate alongside identity, access, network, and other cybersecurity controls.
Programs developing JADC2-connected National Security Systems should evaluate DAR requirements against the information stored by the system, its operating environment, and the consequences of losing physical control of the endpoint.
Relevant questions include:
These questions should be addressed during architecture and acquisition rather than first being considered after systems have been fielded.
| Design Question | What the Program Should Determine |
|---|---|
| Stored information | What classified information will the endpoint retain? |
| Physical storage | Which drives, modules, or other media retain that information? |
| Capture scenario | What happens to stored information if physical control of the endpoint is lost? |
| Authentication | What must occur before encrypted storage becomes accessible? |
| Encryption layers | Are the required independent DAR protection layers implemented correctly? |
| Key protection | How are cryptographic keys generated, stored, protected, and authorized? |
| Disconnected operation | Does protection remain effective without network or enterprise services? |
| Supporting systems | Where else within the JADC2 architecture does the same information reside? |
| Component status | Are applicable components listed for their intended CSfC role? |
| Lifecycle | Are DAR requirements addressed through acquisition, integration, fielding, and sustainment? |
National Security Presidential Memorandum 12, issued June 12, 2026, establishes cybersecurity governance for National Security Systems. It reestablishes the Director of NSA as the National Manager for NSS and identifies the National Manager as the cryptologic authority for National Security Systems.
NSPM-12 states that the National Manager is responsible for providing authoritative minimum requirements for cryptology and cryptographic systems. It also establishes a broader governance structure through the Committee on National Security Systems for cybersecurity requirements applicable to NSS.
NSA currently publishes Data-at-Rest Capability Package v5.1.0, dated March 2026. The Capability Package provides solution designs and requirements for implementing CSfC DAR using commercial technologies.
Programs should verify the current Capability Package, applicable requirements, and component status against NSA’s live public resources when designing or procuring a CSfC DAR solution.
JADC2 depends on making mission information available across a distributed joint force. As more processing, storage, AI, sensing, and decision support move to the tactical edge, classified information can reside on a growing number of physical endpoints operating outside traditional facilities.
Protecting the network is therefore only part of the security requirement. Programs also need to protect classified information stored on an endpoint if communications disappear, physical control is lost, or the system itself is captured. For applicable classified systems, CSfC DAR provides an architecture for implementing independent protection layers rather than relying on a single encryption mechanism.
For JADC2 programs evaluating classified data-at-rest requirements at the tactical edge, take the CSfC DAR Readiness Assessment to identify architecture considerations and areas that may require further review.
Take the CSfC DAR Readiness Assessment
Data at rest is information stored on a physical device or storage media rather than actively moving between systems. Within JADC2, this can include classified information retained on tactical computers, servers, aircraft, ships, vehicles, sensors, weapons platforms, uncrewed systems, mission computers, and other distributed edge devices.
JADC2 distributes information and computing across the joint force, including systems operating at the tactical edge. Some endpoints may leave authorized physical control through loss, damage, abandonment, or capture. DAR protection addresses what happens to classified information stored on those systems when an unauthorized party physically possesses the device.
A JADC2 endpoint can store mission plans, targeting information, ISR data, communications information, network configurations, electronic-warfare data, system logs, software, firmware, AI models, algorithms, and other operational or technical information. The specific data depends on the endpoint’s mission, architecture, classification, and role within the broader joint environment.
Encryption provides an important security function, but classified DAR requires evaluation of the complete architecture. Programs also need to address authentication, cryptographic key protection, startup behavior, configuration, and independent protection layers. Applicable NSA requirements determine how these functions work together within a CSfC DAR solution.
FIPS validation provides assurance that specified cryptographic functionality has been tested against defined requirements. It does not by itself establish that an endpoint provides a complete classified DAR architecture. Programs need to evaluate how cryptography, authentication, key protection, independent layers, and other security functions work together under applicable requirements.
NSPM-12, issued June 12, 2026, establishes cybersecurity governance for National Security Systems and reestablishes the Director of NSA as the National Manager for NSS. It also identifies the National Manager as the cryptologic authority for NSS and assigns responsibilities related to cryptographic requirements and NSS cybersecurity.
CSfC DAR uses independent encryption layers. For applicable Cigent architectures, an encrypted drive with pre-boot authentication forms the hardware layer, while independent software full drive encryption provides the second layer. The encrypted drive and its PBA together constitute one layer and should not be described as two separate layers.
Authentication controls the conditions under which protected storage becomes accessible. A tactical endpoint may be physically captured while disconnected from friendly networks and enterprise services. Programs therefore need to determine what authentication is required before encrypted storage can be accessed and how those controls behave when physical possession of the endpoint changes.
No. Zero Trust architectures govern access to resources based on identity, devices, services, context, and policy. DAR protects information stored on physical devices and media. A tactical architecture may need both because network and access controls do not replace cryptographic protection for storage that an unauthorized party physically possesses.
JADC2 programs should address DAR during system architecture and acquisition. Storage, compute, authentication, boot, and integration decisions can be established long before authorization testing. Identifying DAR requirements early allows programs to incorporate appropriate components and security functions before major architecture decisions become difficult or costly to change.
Conner Crisafulli is a solutions engineer and cybersecurity professional at Cigent with a unique background bridging elite military operations and advanced data security. Before joining Cigent, Conner served six years as a U.S. Air Force Combat Controller, where he specialized in high-stakes mission planning, communication systems, and joint operations coordination/execution. Drawing from his experience in complex, contested environments, Conner now helps federal agencies and enterprise clients strengthen their data-at-rest protection strategies. At Cigent, he focuses on practical applications of self-encrypting drives (SEDs), pre-boot authentication (PBA), and various CSfC (commercial solutions for classified) technologies to safeguard sensitive data against evolving cyber threats.