UAS Data-at-Rest Protection for Classified Data

Conner Crisafulli
•
September 23, 2026
•
16 minute read
•

UAS data-at-rest protection is becoming increasingly important as unmanned and autonomous aircraft carry more sensing, computing, storage, and mission capabilities into contested environments.

Unmanned aircraft systems are evolving beyond remotely piloted intelligence, surveillance, and reconnaissance platforms. Modern UAS can support sensing, targeting, electronic warfare, communications, logistics, and other mission functions while relying on increasingly capable onboard computing and autonomy software.

This article explains what information UAS can retain, how physical capture changes the security problem, why the supporting UAS ecosystem also requires protection, and how authentication and CSfC Data-at-Rest architecture apply to systems carrying classified information.

Key Takeaways

What Is UAS Data-at-Rest Protection?

UAS data-at-rest protection addresses information stored on an unmanned aircraft system or its supporting devices. The objective is to prevent unauthorized access to that information when the aircraft, storage device, or supporting equipment leaves authorized physical control.

Data at rest can include information stored on SSDs, embedded storage, mission computers, ground-control stations, tactical servers, maintenance equipment, and other devices within the UAS ecosystem.

For systems carrying classified information, DAR protection requires more than determining whether the storage uses encryption. Programs also need to evaluate authentication, cryptographic key protection, startup behavior, independent protection layers, and the conditions under which protected storage becomes accessible.

Not Every UAS Presents the Same Data Risk

UAS vary significantly in mission, capability, onboard computing, storage, and the information they retain. Those differences create different data-at-rest requirements.

A small system carrying limited processing and mission information presents a different security problem from a sophisticated ISR aircraft, electronic-warfare platform, or Collaborative Combat Aircraft with advanced sensors, onboard compute, and mission-autonomy software.

Programs should begin by determining what information the aircraft actually retains and what security requirements apply to it.

Relevant questions include:

The answers determine the appropriate DAR architecture rather than the UAS category alone.

Why Are UAS Becoming Computing and Storage Platforms?

Modern UAS can combine flight systems and sensors with processors, storage devices, operating systems, communications capabilities, mission applications, and autonomy software. As onboard processing increases, more operationally valuable information can reside on the aircraft itself.

Depending on the platform and mission, stored information could include:

The security concern can therefore extend beyond information associated with a single mission. Technical information stored on the aircraft may also provide insight into how the system is configured, how its sensors operate, or how its autonomy and mission software function.

How Does the Collaborative Combat Aircraft Program Illustrate This Change?

The U.S. Air Force’s Collaborative Combat Aircraft program demonstrates how unmanned systems are becoming increasingly software-driven and autonomous.

In 2026, the Air Force reported that it was integrating its government-owned Autonomy Government Reference Architecture across multiple vendor platforms and conducting semi-autonomous flight testing. The architecture is designed to allow mission software to be separated from specific aircraft hardware.

In June 2026, the Department of the Air Force also awarded contracts covering CCA air vehicles and mission-autonomy software. The Air Force established a multi-vendor mission-autonomy software pool to support continued development and competition.

This type of architecture creates important DAR considerations. Programs need to determine what mission-autonomy software, configurations, sensor information, operational data, and other information reside on the aircraft and how those assets remain protected if the platform leaves authorized control.

Why Should UAS Be Designed With Loss of Physical Control in Mind?

UAS can operate in environments where continued physical control of the aircraft cannot be assumed. DAR architecture therefore needs to address what happens to stored information when a system is lost, damaged, abandoned, recovered by an unauthorized party, or captured.

This is particularly relevant for aircraft deliberately operating in contested or adversary-controlled environments. Communications may be disrupted, recovery may not be possible, and the platform may become physically accessible to another party.

Programs should therefore consider two separate security objectives: reducing the likelihood that a platform is lost and protecting the information if physical control is lost.

For DAR, the second question is central.

If an unauthorized party obtains the complete aircraft, what information can they recover from it?

What Information Could a Captured UAS Expose?

A captured UAS can potentially expose operational and technical information retained on the aircraft. The specific exposure depends on the platform, mission, system architecture, information classification, and storage configuration.

Operational information could include:

Technical information could include software, algorithms, AI models, configurations, operating-system information, sensor-processing capabilities, autonomy functions, and other information associated with how the aircraft operates.

A recovered system could therefore provide information about both previous missions and the underlying platform. Protecting that stored information is a separate requirement from protecting or replacing the physical aircraft.

Why Does the Entire UAS Ecosystem Need DAR Protection?

DAR protection needs to follow classified information throughout the UAS ecosystem rather than focusing exclusively on the aircraft.

Modern UAS can depend on supporting systems including:

The Air Force’s Collaborative Combat Aircraft program provides a current example. In August 2026, the Department of the Air Force completed prototype evaluations of a Portable Command and Control Enclave designed to support tactical control of semi-autonomous systems in austere environments.

Each additional system can represent another location where mission or classified information resides.

Protecting an aircraft while leaving the same classified information exposed on a ground-control station, maintenance system, or tactical server does not resolve the overall DAR requirement.

Why Isn’t Encryption Alone Enough for Classified UAS Data?

Encryption is an important component of DAR protection, but classified information requires evaluation of the complete security architecture.

A system can use strong encryption while still requiring controls governing authentication, cryptographic key protection, startup behavior, implementation, configuration, and independent protection layers.

For applicable Cigent CSfC DAR architectures, the two protection layers are:

  1. An encrypted drive with pre-boot authentication as the hardware layer.
  2. Independent software full drive encryption as the second layer.

The encrypted drive and pre-boot authentication constitute one layer. PBA controls access to the encrypted drive and is not counted as a separate third layer.

This distinction becomes particularly important when an unauthorized party physically possesses the complete aircraft. Programs should determine not only whether information is encrypted, but also what must occur before the protected storage becomes accessible.

Why Does Authentication Matter for Autonomous Aircraft?

Authentication determines when a protected system is permitted to make encrypted storage accessible. Autonomous aircraft create a distinct architecture challenge because a person may not be physically present to provide credentials during startup or operation.

A conventional laptop can require an authorized user to authenticate before protected storage becomes available. A UAS may need to initialize, authenticate, and begin operating without a person physically interacting with the aircraft.

The architecture therefore needs an authentication mechanism appropriate to autonomous operation.

Programs need to determine how authorization is established, which conditions allow protected storage to become accessible, how cryptographic keys are protected, and what occurs if the platform is no longer operating under authorized conditions.

These requirements need to be designed alongside the system’s storage, boot, compute, and autonomy architecture.

What Is Headless Authentication for a UAS?

Headless authentication allows a system to establish authorization without requiring a person to physically enter credentials at the device. This can support UAS and other autonomous systems that need to initialize or operate without personnel physically present.

The implementation depends on the system architecture, operating environment, mission, and applicable security requirements. It may involve trusted hardware, cryptographic credentials, platform state, or other appropriately implemented security mechanisms.

The fundamental requirement is to support autonomous operation while maintaining appropriate control over access to protected storage.

An autonomous aircraft should not automatically make protected data accessible under every circumstance simply because it has powered on. Programs need to define the conditions under which storage can be accessed and what happens when authorized operating conditions are no longer met.

How Does CSfC DAR Apply to UAS?

NSA’s Commercial Solutions for Classified program provides Capability Packages for implementing commercial technologies within defined architectures to protect classified information.

The current CSfC Data-at-Rest Capability Package is v5.1.0, dated March 2026.

NSA describes the DAR Capability Package as providing solution designs using independent layers of encryption to protect classified information at rest. The applicable architecture depends on the system design and use case.

For applicable Cigent CSfC DAR architectures, the encrypted drive with pre-boot authentication forms the hardware layer, while independent software full drive encryption provides the second layer.

The encrypted drive and PBA constitute one layer rather than two separate layers.

This defense-in-depth approach is particularly relevant to UAS that may operate outside continuously controlled facilities or in environments where loss of physical control is a realistic operating condition.

What Does Positive Control Mean for UAS DAR?

Positive control is an important consideration when determining how DAR protections apply to systems that can physically leave authorized custody.

The mission and threat environment influence when a system should be considered outside the positive control of authorized users. That determination can be especially significant for an aircraft deliberately operating remotely or over contested territory.

Programs should therefore define loss-of-positive-control scenarios during system design and determine how the DAR architecture behaves under those conditions.

Relevant questions include whether protected storage remains accessible, what authentication conditions remain valid, how cryptographic keys are protected, and whether independent protection layers continue to provide the required security.

What Should Authorizing Officials Ask About UAS Data at Rest?

Authorizing Officials and program teams should evaluate DAR against the actual operating conditions of the aircraft rather than treating encryption as a standalone product feature.

Relevant questions include:

These questions should be addressed during architecture, acquisition, integration, testing, authorization, fielding, and sustainment.

Why Should DAR Be Addressed Before a UAS Is Fielded?

DAR should be addressed during system design because decisions about storage, compute, boot behavior, authentication, autonomy, and command and control can be established well before an aircraft reaches final authorization testing.

The Air Force is already flight-testing Collaborative Combat Aircraft, integrating a government-owned autonomy architecture, developing mission-autonomy software, and evaluating portable command-and-control systems.

Introducing DAR requirements after the underlying architecture has been established can require changes to hardware, software, authentication, storage, boot processes, or system integration.

Early planning allows programs to identify the classified information a system will retain, determine applicable DAR requirements, select appropriate components, and incorporate authentication into the operational architecture.

This is particularly important for autonomous aircraft because authentication must support mission requirements without assuming that a person will always be physically present.

UAS Data-at-Rest Protection Checklist

Design Question What the Program Should Determine
Stored information What sensitive or classified information will reside on the aircraft?
Physical storage Which drives, modules, or other media retain the information?
Loss of control What conditions constitute loss of positive control for the mission?
Capture scenario What happens to stored information if an unauthorized party obtains the aircraft?
Authentication What must occur before encrypted storage becomes accessible?
Headless operation How does authentication work without personnel physically present?
Encryption layers Are the required independent DAR protection layers correctly implemented?
Key protection How are cryptographic keys generated, stored, protected, and authorized?
Supporting systems Where else in the UAS ecosystem does the same classified information reside?
Component status Are applicable components listed for their intended CSfC role?

Public Validation and Policy Basis

In February 2026, the U.S. Air Force reported that it was implementing its government-owned Autonomy Government Reference Architecture across multiple Collaborative Combat Aircraft vendor platforms. The Air Force also reported semi-autonomous flight testing involving the YFQ-42 and YFQ-44 platforms.

In June 2026, the Department of the Air Force announced additional CCA contracts covering air vehicles and mission-autonomy software. The Air Force established a multi-vendor mission-autonomy software pool as part of the program.

In August 2026, the Department of the Air Force completed prototype evaluations for the CCA Portable Command and Control Enclave. The evaluations examined portable command-and-control systems intended to support tactical control of semi-autonomous systems in austere environments.

NSA publishes the CSfC Data-at-Rest Capability Package v5.1.0, dated March 2026. Programs implementing CSfC DAR should verify current Capability Package requirements and applicable component status against NSA’s live public resources during architecture and procurement decisions.

The Bottom Line

Unmanned and autonomous aircraft are carrying more sensing, computing, software, and mission information into environments where physical possession of the platform cannot always be maintained. Programs therefore need to evaluate not only how the aircraft performs its mission, but what information remains stored on it if physical control is lost.

DAR protection should extend across the entire UAS ecosystem, including the aircraft, ground-control equipment, command-and-control systems, mission-planning computers, maintenance devices, tactical servers, and other systems that retain classified information. Autonomous aircraft also require authentication architectures capable of supporting headless operation while maintaining appropriate control over protected storage.

For Air Force Authorizing Officials, program offices, and defense manufacturers evaluating classified data-at-rest requirements for UAS, take the CSfC DAR Readiness Assessment to identify architecture considerations and areas that may require further review.

Take the CSfC DAR Readiness Assessment

Frequently Asked Questions

What is UAS data-at-rest protection?

UAS data-at-rest protection protects information stored on an unmanned aircraft system or supporting device against unauthorized access. It can involve encryption, authentication, cryptographic key protection, and related architecture controls. For classified information, programs need to evaluate the complete DAR architecture against applicable requirements rather than relying on encryption alone.

What information can a UAS store?

A UAS can store ISR imagery, targeting information, mission routes, maps, sensor data, communications information, operational logs, software, and configuration information. More sophisticated aircraft may also retain autonomy software, AI models, algorithms, sensor-processing capabilities, mission applications, or other technical information associated with how the aircraft performs its mission.

Why is DAR important for unmanned aircraft?

Unmanned aircraft can operate where continued physical control cannot be assumed. A UAS may be damaged, lost, abandoned, or captured in an area where recovery is not possible. DAR protection addresses what happens to information stored on the aircraft if an unauthorized party gains physical access to the complete system.

Do all UAS require the same data-at-rest protection?

No. DAR requirements depend on the information stored by the aircraft, its classification, system architecture, operating environment, mission, and applicable security requirements. A small system retaining limited information can present a different security problem from an ISR, electronic-warfare, or autonomous aircraft carrying substantial mission and technical data.

Why isn’t an encrypted SSD enough for classified UAS data?

An encrypted SSD provides an important security function, but classified DAR requires evaluation of the complete architecture. Programs also need to address authentication, cryptographic key protection, startup behavior, configuration, and independent protection layers. Applicable NSA requirements determine how these functions are combined when implementing a CSfC DAR solution.

What is headless authentication for a UAS?

Headless authentication allows a system to establish authorization without requiring a person to physically enter credentials at the aircraft. This can support autonomous UAS that must initialize or operate without personnel present. The specific implementation depends on the architecture, mission environment, operational requirements, and applicable security requirements.

How many protection layers does CSfC DAR use?

CSfC DAR uses independent encryption layers. For applicable Cigent architectures, an encrypted drive with pre-boot authentication forms the hardware layer, while independent software full drive encryption provides the second layer. The encrypted drive and its pre-boot authentication together constitute one layer and should not be described as two separate layers.

Does DAR protection apply only to the aircraft?

No. Classified information can also reside on ground-control stations, command-and-control systems, mission-planning computers, tactical servers, maintenance systems, removable storage, and other supporting equipment. Programs should identify where information resides throughout the UAS ecosystem and apply appropriate DAR protections wherever applicable classified information is stored.

When should a UAS program address DAR requirements?

UAS programs should address DAR during system architecture and design. Storage, compute, boot, authentication, autonomy, and command-and-control decisions may be established well before authorization testing. Identifying requirements early allows programs to incorporate appropriate components and security functions before major architecture decisions become difficult or costly to change.

What should an Authorizing Official evaluate for UAS DAR?

An Authorizing Official should evaluate what classified information the UAS stores, where it resides, how encryption and authentication are implemented, how cryptographic keys are protected, how headless authentication functions, what constitutes loss of positive control, and whether the architecture and applicable components meet current DAR requirements for the system’s mission.

Conner Crisafulli

Conner Crisafulli is a solutions engineer and cybersecurity professional at Cigent with a unique background bridging elite military operations and advanced data security. Before joining Cigent, Conner served six years as a U.S. Air Force Combat Controller, where he specialized in high-stakes mission planning, communication systems, and joint operations coordination/execution. Drawing from his experience in complex, contested environments, Conner now helps federal agencies and enterprise clients strengthen their data-at-rest protection strategies. At Cigent, he focuses on practical applications of self-encrypting drives (SEDs), pre-boot authentication (PBA), and various CSfC (commercial solutions for classified) technologies to safeguard sensitive data against evolving cyber threats.

More from Cigent

Army UxV Data-at-Rest Protection for Uncrewed Systems
Blog
•
16 minute read
•
September 22, 2026

Army UxV Data-at-Rest Protection for Uncrewed Systems

DLP vs. Data-at-Rest Protection for National Security Systems
Blog
•
14 minute read
•
September 21, 2026

DLP vs. Data-at-Rest Protection for National Security Systems

Marine Corps Data at Rest Protection for Classified Data
Blog
•
15 minute read
•
September 17, 2026

Marine Corps Data at Rest Protection for Classified Data