Protecting Mission Data with CSfC-Listed U.2 and E3.S Secure Storage

Kelvin Quezada
•
August 10, 2026
•
10 minute read
•

Mission data is not limited to endpoints such as laptops or embedded devices. Sensitive and classified information increasingly resides across enterprise servers, edge compute platforms, mission systems, and other high-performance infrastructure where storage capacity, performance, and data protection all matter.

Cigent’s CSfC-listed U.2 and E3.S Secure SSDs bring enterprise-class storage to CSfC Data at Rest (DAR) architectures for these environments. Validated under NIAP VID 11669, the drives are listed on the NSA CSfC Components List as Hardware Full Drive Encryption (HWFDE) Encryption Engine components.

But protecting mission data requires more than an encrypted drive. Paired with Cigent Pre-Boot Authentication (PBA), the drives provide hardware-based encryption with authenticated access before protected storage is unlocked and made available to the operating system.

Key Takeaways

What Is a U.2 SSD?

A U.2 SSD is a 2.5-inch enterprise storage form factor commonly used to provide high-performance NVMe storage in servers, storage arrays, edge compute platforms, and other systems that require scalable, serviceable storage.

What Is E3.S?

E3.S is an Enterprise and Datacenter Standard Form Factor (EDSFF) designed for modern servers and storage systems, providing a compact, front-accessible form factor optimized for flash density, thermal management, scalability, and current and future generations of PCIe.

Enterprise Storage for Mission-Critical Data

Servers and high-performance computing platforms can hold large volumes of operational data, intelligence, application data, system information, and other sensitive information that must remain protected if the underlying system is lost, removed, captured, or accessed without authorization. That makes data-at-rest protection a critical architectural consideration, not simply a storage feature.

U.2 and E3.S form factors allow secure storage to extend into enterprise and mission environments where traditional client SSD form factors may not meet the storage requirements of the platform. For defense organizations, OEMs, and system integrators building these systems, the question is not simply whether the drive encrypts its data. The protection architecture must also determine when that encrypted storage can be unlocked and who or what is authorized to access it.

Hardware Encryption Is the Foundation

Self-encrypting drives provide an important foundation for data-at-rest protection by performing encryption within the storage device itself. But encryption and authorization serve different purposes. Hardware full drive encryption protects the data written to the media. It does not, by itself, establish that the user or system attempting to unlock the drive should be trusted.

Without a compatible and validated pre-boot authorization mechanism, encrypted storage may be unlocked during the normal system boot process before an authorized user or system has been verified. Once the storage is unlocked, the security of the data increasingly depends on the protections provided by the system and operating environment. For sensitive and classified data, that creates an important distinction between having an encrypted drive and implementing a complete encrypted storage solution.

Authenticate Before the Drive Unlocks

Cigent pairs its secure drives with Cigent Pre-Boot Authentication to control access before the operating system loads. Rather than allowing protected storage to become available automatically during normal boot, PBA establishes an authorization boundary before the drive is unlocked. PBA supports multiple authentication methods, including passwords, CAC/PIV smart cards, security keys, and USB tokens, with support for enforcing multiple authentication factors when required.

The secure drive provides hardware-based encryption. Cigent PBA controls access to that encrypted drive. Together, they provide an encrypted storage solution designed to keep protected data inaccessible until the required authentication occurs. This approach also aligns with the way NSA defines component roles within CSfC architectures. Cigent’s U.2 and E3.S Secure SSDs are listed as Encryption Engine components, while Cigent PBA is separately listed as an Authentication Agent.

Building CSfC Data at Rest Architectures for Enterprise Systems

NSA’s Commercial Solutions for Classified program enables organizations to use validated commercial products as components of layered solutions for protecting classified information. Products on the CSfC Components List are selected and implemented according to the applicable Capability Package and reference architecture.

The addition of enterprise U.2 and E3.S storage to Cigent’s CSfC-listed secure storage portfolio expands the types of systems that can incorporate these validated HWFDE components. That is particularly important as mission data moves across a broader range of infrastructure, including enterprise servers, edge compute platforms, vehicle systems, autonomous platforms, and forward-deployed mission systems.

U.2 vs. E3.S Secure SSDs

Feature U.2 E3.S
Interface PCIe / NVMe enterprise storage PCIe / NVMe enterprise storage through the EDSFF E3 interface
Dimensions Traditional 2.5-inch enterprise drive form factor 76 mm x 112.75 mm x 7.5 mm for standard E3.S
Thermal / Density Design Established enterprise form factor used across existing server and storage infrastructure Designed for improved flash density, airflow, thermal management, and higher-density modern server architectures
Typical Deployment Enterprise servers, storage arrays, edge compute, deployable infrastructure, and existing U.2-based systems Modern servers, dense storage systems, edge compute platforms, and next-generation enterprise infrastructure
Security Capability Cigent U.2 Secure SSD is CSfC-listed as a Hardware Full Drive Encryption Encryption Engine component Cigent E3.S Secure SSD is CSfC-listed as a Hardware Full Drive Encryption Encryption Engine component
Role in Cigent DAR Architecture Provides the hardware encryption foundation and pairs with Cigent PBA for authenticated access before the operating system loads Provides the hardware encryption foundation and pairs with Cigent PBA for authenticated access before the operating system loads

Regardless of where the system operates, physical possession of the hardware should not automatically provide access to the information stored within it. Protecting that information requires an architecture that combines strong encryption with authenticated access to the encrypted storage. Beyond authentication, Cigent PBA also provides security controls for managing the protected storage environment throughout its lifecycle. Administrators can manage users and protected drives, support multi-drive systems, review PBA activity, and initiate secure drive erasure when required.

What to Verify Before Procuring Enterprise Secure Storage

Before selecting U.2, E3.S, or another enterprise SSD for a classified data-at-rest architecture, verify the complete security role of the component rather than relying on an encryption claim alone.

Cigent U.2 and E3.S Secure SSDs provide the hardware encryption foundation. Cigent Pre-Boot Authentication controls when that protected storage can be unlocked. Together, they bring enterprise-class encrypted storage to CSfC Data at Rest architectures designed to protect mission data before the operating system ever takes control.

Frequently Asked Questions

What is a U.2 SSD?

A U.2 SSD is a 2.5-inch enterprise storage form factor commonly used for high-performance NVMe storage in servers, storage arrays, and edge compute systems. U.2 provides a familiar, serviceable enterprise drive format for platforms that require high capacity, performance, hot-plug capability, and scalable storage outside traditional client SSD form factors.

What is an E3.S SSD?

An E3.S SSD uses the Enterprise and Datacenter Standard Form Factor developed for modern server and storage architectures. Standard E3.S measures 76 mm x 112.75 mm x 7.5 mm and is designed to improve storage density, airflow, thermal management, and scalability while supporting current and future generations of PCIe-based enterprise storage.

What is the difference between U.2 and E3.S?

U.2 is an established 2.5-inch enterprise SSD form factor widely deployed in existing servers and storage systems. E3.S is a newer EDSFF design intended for modern, higher-density server architectures, with a narrower physical profile and greater flexibility for future PCIe generations, thermal requirements, and increasing storage density.

Can enterprise SSDs be CSfC components?

Yes. Enterprise SSDs can serve specific roles within a CSfC Data at Rest architecture when the exact product has met the applicable evaluation requirements and is listed on the NSA CSfC Components List. Cigent U.2 and E3.S Secure SSDs are listed as Hardware Full Drive Encryption Encryption Engine components.

What does CSfC-listed mean?

CSfC-listed means a commercial product appears on the NSA CSfC Components List for a defined security role and can be selected for an applicable CSfC architecture. Listing does not make the product a complete CSfC solution by itself. Components must be selected, configured, and combined according to the applicable Capability Package.

Do servers need two-layer data-at-rest protection?

When a server is protecting classified data under a two-layer CSfC DAR solution design, moving the workload from a laptop to enterprise infrastructure does not eliminate the layered protection requirement. In a hardware/software FDE design, hardware full drive encryption with PBA provides one layer and independent software full drive encryption provides the second.

Where are U.2 and E3.S secure SSDs deployed?

U.2 and E3.S storage can support enterprise servers, storage arrays, high-performance computing systems, edge compute platforms, vehicle systems, autonomous platforms, and forward-deployed mission infrastructure. These environments increasingly process and retain operational, intelligence, application, and system data locally, making storage-level data-at-rest protection important beyond the traditional data center.

Do U.2 and E3.S SSDs support Pre-Boot Authentication architectures?

Yes, when the specific secure drive and authentication components are designed and evaluated for those roles. Cigent U.2 and E3.S Secure SSDs provide the Hardware Full Drive Encryption Encryption Engine function and pair with Cigent Pre-Boot Authentication to control authorization before the encrypted storage is unlocked and made available to the operating system.

How do I verify that a U.2 or E3.S SSD is CSfC-listed?

Use the NSA CSfC Components List rather than relying solely on a vendor datasheet. Confirm the exact manufacturer and product, its current listing status, the security category under which it appears, and the role it performs. For hardware-encrypted storage, also verify that the complete architecture provides the required authentication and authorization functions.

What should programs consider when migrating from SATA or SAS to U.2 or E3.S?

Start with the target system architecture rather than the drive alone. Evaluate interface compatibility, physical dimensions, capacity, performance, power, cooling, serviceability, and platform support. For classified systems, also verify the new drive’s CSfC listing and security role and ensure the migration preserves the authentication and independent encryption layers required by the DAR architecture.

Kelvin Quezada

Kelvin Quezada is a Product Marketing Manager at Cigent, where he leads strategy, positioning, and go-to-market efforts for the company’s Data-at-Rest protection solutions. With more than a decade of experience across cybersecurity deployments, product marketing, and technical enablement, he translates complex technical concepts into clear, mission-focused value for defense programs.

More from Cigent

UAS Data-at-Rest Protection for Classified Data
Blog
•
16 minute read
•
September 23, 2026

UAS Data-at-Rest Protection for Classified Data

Army UxV Data-at-Rest Protection for Uncrewed Systems
Blog
•
16 minute read
•
September 22, 2026

Army UxV Data-at-Rest Protection for Uncrewed Systems

DLP vs. Data-at-Rest Protection for National Security Systems
Blog
•
14 minute read
•
September 21, 2026

DLP vs. Data-at-Rest Protection for National Security Systems