Protecting Data at Rest at the Tactical Edge: An Army Mission View

Kelvin Quezada
•
August 19, 2026
•
9 minute read
•

The Army is pushing more computing, sensors, artificial intelligence, and decision-making to the tactical edge. That creates enormous operational advantages, but it also puts more sensitive and classified data on devices operating far outside the physical protection of traditional data centers and command facilities.

For the Army, protecting that information is becoming a mission requirement, not simply an IT requirement. Every tactical system should prompt a basic question:

If this device is lost, abandoned, damaged but recoverable, or captured by an adversary, what happens to the information stored inside it? That is the problem Data-at-Rest (DAR) protection is designed to address.

What Is Data at Rest?

Data at Rest is information stored on a device rather than actively moving across a network.

A mission plan transmitted over a tactical network is data in transit. Once saved to a laptop, server, SSD, or other storage device, it becomes data at rest.

Across the Army, DAR can reside on:

If a device retains information after power is removed, it potentially contains DAR.

At the tactical edge, that information can be extraordinarily valuable.

What Does a Tactical Device Know?

A captured device doesn’t need thousands of classified documents to create a serious intelligence loss.

Depending on its mission, it may retain:

Collectively, this information can tell an adversary where Army forces have been, what they have observed, how they communicate, what they intend to do, and potentially how they fight.

Why the Risk Is Growing

The Army has always operated computers outside secure facilities. What’s changing is the quantity and value of information being pushed to the edge.

Edge computing moves processing and storage closer to the mission, reducing dependence on centralized infrastructure and connectivity. But it also puts valuable information on more tactical endpoints. Artificial intelligence further increases the value of those endpoints. Systems can now retain trained models, algorithms, sensor information, and operational datasets needed to make decisions locally. Unmanned and autonomous systems create another rapidly expanding category of physically vulnerable endpoints. Whether remotely controlled, semi-autonomous, or autonomous, these systems can store mission data that may become accessible if the platform is recovered. Distributed and contested operations further increase the possibility that computing equipment will be lost, abandoned, damaged, or captured.

The operational assumption therefore needs to change: We cannot assume we will always retain physical control of the endpoint.

When the Adversary Has the Device, Cybersecurity Changes

Most cybersecurity focuses on preventing an attacker from remotely gaining access to a computer or network. At the tactical edge, we also need to consider what happens when the adversary already has the computer. Imagine a tactical endpoint captured and transported to a nation-state exploitation laboratory. The attacker now possesses its motherboard, storage, firmware, processor, operating system, and other components. They can remove the SSD, disassemble the equipment, connect components to forensic tools, study identical systems, and potentially spend months looking for weaknesses. The question is no longer: “Can they penetrate our network?” It becomes: “With our device sitting on their laboratory bench, can they recover what’s stored inside it?” That is a DAR problem.

Why Commercial Encryption Isn’t Necessarily Enough

Commercial encryption technologies can provide excellent protection for enterprise information. But classified National Security Systems face a different threat model. A common misconception is that a device is adequately protected because it uses AES-256, commercial full-disk encryption, or a “FIPS-certified” drive. Those can all be valuable security attributes. They don’t, by themselves, constitute a classified DAR architecture.

A sophisticated adversary doesn’t necessarily need to mathematically break AES. Easier paths may exist:

The better question isn’t: “How strong is the encryption?” It is: “What must an adversary defeat before the classified data becomes accessible?”

Why “FIPS Certified” Doesn’t Mean “Approved for Classified”

This distinction is especially important in acquisition discussions.

FIPS validation provides important assurance that specified cryptographic functionality has been tested against defined requirements. But that does not mean every device containing FIPS-validated cryptography is automatically suitable for protecting classified DAR. Think about constructing a secure facility.  Having an approved vault door is important. But installing an approved vault door doesn’t automatically make the entire building secure. You still need walls, locks, access controls, authentication, procedures, and an overall security architecture. The same principle applies to DAR. Cryptography is a critical component of security. It isn’t the entire security architecture.

NSPM-12 Reinforces NSA’s Role in Protecting NSS

This distinction has become even more relevant with the issuance of National Security Presidential Memorandum 12 (NSPM-12), National Policy for the Cybersecurity of National Security Systems, in June 2026. NSPM-12 establishes cybersecurity governance for National Security Systems and reinforces accountability for protecting systems supporting military, intelligence, and other national-security missions. Importantly, it reestablishes the Director of the National Security Agency as the National Manager for NSS, with responsibilities that include establishing authoritative minimum requirements for cryptology and cryptographic systems. For Army organizations developing, acquiring, or operating NSS, the message is important: Protecting classified information isn’t simply a matter of selecting commercial cybersecurity products. NSA has a defined national role in establishing how cryptographic protection for NSS is implemented. One important way NSA fulfills that mission is through the Commercial Solutions for Classified program.

CSfC Data at Rest: An Architecture for Classified Information

NSA’s Commercial Solutions for Classified (CSfC) program enables organizations to use appropriately evaluated commercial technologies within NSA-defined architectures to protect classified information. For stored information, NSA’s Data-at-Rest Capability Package defines architectures for DAR protection. CSfC changes the question from: “Is this product encrypted?” to: “Does the complete solution provide the layers of protection required for classified information?” The current NSA DAR Capability Package is Version 5.1.0, approved in March 2026. It provides DAR solution designs and implementation guidance for protecting classified information using commercial components.

Several concepts are especially important.

Layered Protection

CSfC DAR employs defense in depth rather than placing all trust in one security mechanism. If an adversary compromises one independent layer, another protection layer is intended to remain between the attacker and the classified information.

Evaluated Components

CSfC solutions use commercial products evaluated for specific security functions and selected in accordance with NSA requirements. It’s not enough for a vendor to claim that a product “uses military-grade encryption.” The product and its role within the architecture matter.

Encryption Plus Authentication

Strong encryption is useful only if unauthorized users cannot cause the system to unlock. Think of hardware-encrypted storage as a high-security safe. The encryption engine provides the steel walls. Authentication provides the lock. An extremely strong safe that automatically opens when someone turns on the computer doesn’t provide the protection its strong walls imply.

Protection of Keys

Encryption keys are critical assets. An adversary may have little reason to break AES if they can instead obtain or exploit the mechanism protecting the keys. DAR architecture therefore has to consider key generation, storage, protection, and authorization, not simply the encryption algorithm.

Protection That Travels With the Endpoint

This may be the most important characteristic at the tactical edge. A captured endpoint may have no friendly network connection. Remote wipe may be impossible. Enterprise security services may be unreachable. The security protecting its stored information therefore has to remain effective on the device itself. Physical possession of the endpoint should not equal possession of its classified data.

DAR Is Information Survivability

The Army has long engineered systems for survivability. Armor protects vehicles. Countermeasures protect aircraft. Electronic warfare protects communications and sensors. Redundancy allows systems to continue operating after failures. As computing moves deeper into tactical operations, information survivability needs similar consideration.

Programs developing and acquiring NSS endpoints should ask:

And most importantly: Does the system implement the appropriate NSA-approved DAR architecture for the information it carries?

The Bottom Line

Edge computing, AI, autonomous systems, advanced sensors, distributed operations, and increasingly sophisticated weapons are placing more valuable information on tactical endpoints. That creates a straightforward operational reality: If we cannot guarantee possession of the device, we must ensure that possession of the device does not provide possession of its data. Commercial encryption and FIPS-validated cryptography can be important components. For classified information, however, checking an encryption box isn’t enough. NSPM-12 reinforces NSA’s central role in establishing cybersecurity and cryptographic requirements for National Security Systems, while NSA’s CSfC DAR program provides architectures for applying evaluated commercial technologies to protect classified data. For the tactical Army, DAR protection shouldn’t be viewed simply as an IT or cybersecurity requirement. It is information survivability. The Army may not always be able to prevent a tactical device from being lost, abandoned, damaged, or captured. It can, and should, design systems so the classified information stored on that device doesn’t become an adversary’s intelligence gain.

Kelvin Quezada

Kelvin Quezada is a Product Marketing Manager at Cigent, where he leads strategy, positioning, and go-to-market efforts for the company’s Data-at-Rest protection solutions. With more than a decade of experience across cybersecurity deployments, product marketing, and technical enablement, he translates complex technical concepts into clear, mission-focused value for defense programs.

More from Cigent

JADC2 Data-at-Rest Protection at the Tactical Edge
Blog
•
17 minute read
•
September 29, 2026

JADC2 Data-at-Rest Protection at the Tactical Edge

UAS Data-at-Rest Protection for Classified Data
Blog
•
16 minute read
•
September 23, 2026

UAS Data-at-Rest Protection for Classified Data

Army UxV Data-at-Rest Protection for Uncrewed Systems
Blog
•
16 minute read
•
September 22, 2026

Army UxV Data-at-Rest Protection for Uncrewed Systems