← Back to Blog
DefenseZero TrustData SecurityZTDF

How Coalition Partners Share Classified Data Without Shared Infrastructure

Lattix branded cover for How Coalition Partners Share Classified Data Without Shared Infrastructure. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a labelled object crossing between two national enclaves that share no common network.

Coalition partners share classified data by binding a machine-readable confidentiality label to each data object and evaluating release against that label at the point of access, rather than by building shared infrastructure. NATO specifies the label syntax in STANAG 4774 and the binding mechanism in STANAG 4778, both promulgated as Allied Data Publications. Federated Mission Networking supplies the governance and standards profile under which national networks federate for a mission and then dissolve. The result is release decided per object, per partner, on infrastructure each nation continues to own and accredit.

Why coalition sharing cannot rely on a shared network

A coalition network requires every participating nation to accredit a common infrastructure, agree a common security policy, and accept a common risk owner. Coalitions form faster than accreditation processes complete.

The Afghanistan Mission Network demonstrated both the value and the cost. Troop-contributing nations operated inside a single information-sharing domain, which improved situational awareness and which NATO endorsed as a model. The cost was the time and negotiation required to stand that domain up.

Object-level release inverts the dependency. Each nation keeps its own accredited enclave. Objects carry their own labels and policies, and release is decided when a partner attempts access, using attributes both sides already assert about their users.

What Federated Mission Networking is

Federated Mission Networking (FMN) is, in NATO Allied Command Transformation's wording, "a governed conceptual framework consisting of people, processes and technology to plan, prepare, establish, use and terminate mission networks." It exists to support command and control through improved information sharing, and it is founded on trust, willingness and commitment rather than on a permanent shared network.

FMN operates through Affiliates. NATO and non-NATO nations join as Affiliates, maintain FMN-ready capabilities, and contribute forces on short notice. National implementations include the Canadian Deployable Mission Network, France's FRISE programme, the Polish Mission Network, and the United States Mission Partner Environment.

FMN develops in increments called Spirals. Each Spiral Specification documents requirements, architecture, standards, procedures and technical instructions, referencing several hundred standards with a vendor-neutral, commercial off-the-shelf bias. The FMN Management Group approved Spiral 6 on 6 November 2025.

What the NATO Interoperability Standards and Profiles document does

The NATO Interoperability Standards and Profiles document, published as NATO standard ADatP-34 and known as the NISP, is the catalogue of standards and profiles NATO uses to achieve interoperability. It is maintained across volumes covering introduction and governance, agreed standards profiles, and candidate or emerging standards.

The NISP is where FMN Spiral standards profiles are recorded. A Spiral profile names the standards a mission network must implement for a given service, so two Affiliates building independently arrive at systems that interoperate. That turns a framework agreement into a testable technical requirement.

The NISP is a profile catalogue, not an enforcement authority. Whether a nation implements a listed standard is a national decision governed by its own procurement and accreditation.

STANAG 4774 and STANAG 4778: the label and the binding

STANAG 4774, promulgated as ADatP-4774, specifies confidentiality metadata label syntax. A label under STANAG 4774 carries a policy identifier, a classification level, security categories that can be restrictive or permissive, and label lifecycle information such as creation and review dates. The structure derives from the SDN.801c security label model, which pairs a classification with an extensible category mechanism. Encodings include XML, JSON and CBOR.

STANAG 4778, promulgated as ADatP-4778, specifies the metadata binding mechanism: how a label is formally associated with the data it describes. STANAG 4778 defines generic binding plus profiles for specific formats and protocols, supports multiple labels on one object, and supports portion marking so different components of an object carry different labels. Cryptographic binding through digital signature is available, allowing a receiving system to validate both the label and the integrity of the content it covers.

The pair is the whole mechanism. STANAG 4774 makes the label machine-readable and comparable across nations; STANAG 4778 makes it inseparable from the data. Without 4778 a label is an assertion in a header that anything in the path can rewrite.

StandardAllied publicationWhat it specifiesWhat it does not specify
STANAG 4774ADatP-4774Confidentiality label syntax: policy identifier, classification, categories, lifecycleHow the label attaches to data
STANAG 4778ADatP-4778Binding of metadata to a data object, portion marking, optional cryptographic bindingWhat the label means in a given national policy
STANAG 5636ADatP-5636The NATO Core Metadata Specification: bibliographic and resource metadata carried alongside the confidentiality labelConfidentiality semantics or binding
STANAG 5663PromulgatedIdentity, credential and access management across NATO, including attribute-based access controlObject encryption or key distribution

What object-level release means in practice

Object-level release means the decision to disclose is taken per data object against that object's label and the requesting party's attributes, rather than per network connection or per user account. A single document can be released to one partner and withheld from another without producing two copies or two networks.

Portion marking under STANAG 4778 extends object-level release inside a document. A report can carry paragraphs at different classifications with different releasability categories, and a partner receives the portions their attributes satisfy.

Object-level release depends on attribute quality on both sides. If a partner nation cannot assert clearance, nationality and organizational attributes in a form the releasing party's policy can evaluate, the decision degrades to a coarse national-level allow or deny. Attribute-based access control (ABAC) at coalition scale is an identity federation problem before it is a cryptography problem, which is why STANAG 5663 sits alongside the labelling standards.

Where ZTDF sits relative to the NATO standards

Zero Trust Data Format (ZTDF) is frequently described as NATO-ratified. It is not, and the correction matters more for requirements documents than for commentary.

ZTDF is specified in ACP 240, an Allied Communications Publication sponsored by the Combined Communications Electronics Board, with the technical content in Supplements 3 and 4. The CCEB is a five-nation body comprising Australia, Canada, New Zealand, the United Kingdom and the United States. It coordinates with NATO and is not NATO. Vendor material describing ZTDF as ratified is accurate about the CCEB and is routinely read as though it said NATO.

Allied Communications Publications become effective on receipt for the five CCEB nations, and effective for NATO nations and Strategic Commands only when the NATO Military Committee directs it. That formula appears in the letter of promulgation carried by publicly released ACPs. CCEB ratification and NATO effectivity are separate events, and no public record of a Military Committee direction covering ACP 240 has been identified.

The two claims in circulation are therefore both true. Community technical commentary at datacentricsecurity.org states that NATO has not adopted ZTDF for its data-centric security framework and is not working towards doing so, citing file-level encryption granularity and centralized key management assumptions. That site is a community project rather than a NATO or vendor publication, so its statements carry the weight of informed commentary rather than official position, but nothing in the public record contradicts it.

The layering is the part most often missed. ZTDF does not compete with STANAG 4774 and STANAG 4778. A ZTDF object carries a STANAG 4774 label and a STANAG 4778 binding inside it, alongside key access information and an access control policy. NATO's reservations are about the encryption and key layer, not the labelling layer, which is why the same source describes NATO and the CCEB co-developing federated cryptographic key management standards intended for publication on both sides.

For a requirements document the rule is short. Name the CCEB and ACP 240 when the requirement is ACP 240. Name STANAG 4774, 4778, 5636 and 5663 when the requirement is NATO. Writing "NATO-ratified ZTDF" into a specification asserts something the public record does not support, and a defense evaluator will check. Background on the terminology sits in the origin and evolution of Trusted Data Format.

What coalition data-centric security does not solve

Label binding does not survive format transformation. Coalition interoperability frequently requires converting a message between formats, and a digital signature over the original bytes does not validate after conversion. Systems that transform data have to re-label and re-sign under an authority both sides trust, which is why gateways remain in coalition architectures.

Label binding does not decide policy. STANAG 4774 makes a classification comparable; it does not tell a receiving nation what its own rules permit with that classification. Policy equivalence between national schemes is a legal artifact encoded in a policy identifier, not derived from the label.

Label binding does not replace accredited transfer between classification levels. Moving an object from a higher domain to a lower one remains a cross-domain problem with its own accreditation regime, covered in Cross-Domain Solutions: A Practitioner Reference. Object labelling changes what the guard inspects; it does not remove the guard.

How Lattix supports coalition release

Lattix enforces release at the object. The policy decision point (PDP) evaluates ABAC across subject, device, environment and geography, purpose of use, network posture, risk, and data-object attributes, and returns a signed, short-lived decision carrying allow or deny, the reasons, the policy version hash, and the object identifier. The policy enforcement point (PEP) enforces at decrypt time, so a partner holding a copy still requires a live decision to open it. Defaults are fail-closed, revocation propagates to deny, and Merkle-tree lineage makes release history queryable per partner. Deployment spans cloud, regional hub, tactical edge and air-gapped environments with no posture change. See also classified data sharing with coalition partners and JADC2 cross-domain data sharing.

Frequently asked questions

How does classified data stay protected across coalition environments?

Classified data stays protected across coalition environments by carrying its own confidentiality label and access policy rather than relying on a shared accredited network. NATO specifies the label syntax in STANAG 4774 and the mechanism binding that label to the data object in STANAG 4778. Release is decided per object against the requesting party's attributes, so each nation keeps its own infrastructure.

How does NATO use data-centric security?

NATO uses data-centric security through promulgated standards: STANAG 4774 (ADatP-4774) for confidentiality metadata label syntax, STANAG 4778 (ADatP-4778) for binding metadata to data objects, STANAG 5636 (ADatP-5636) for the NATO Core Metadata Specification, and STANAG 5663 for identity, credential and access management including attribute-based access control. These are catalogued in the NATO Interoperability Standards and Profiles document, ADatP-34, and referenced by Federated Mission Networking Spiral specifications.

Has NATO adopted Zero Trust Data Format?

No. ZTDF is specified in ACP 240, sponsored by the Combined Communications Electronics Board, a five-nation body that coordinates with NATO but is not NATO. Allied Communications Publications are effective on receipt for CCEB nations and effective for NATO nations only when the NATO Military Committee directs it, and no such direction covering ACP 240 has been identified publicly. Community technical commentary states that NATO has not adopted ZTDF for its data-centric security framework and is not pursuing it. Requirements documents should name the CCEB, not NATO.

What is Federated Mission Networking?

Federated Mission Networking is NATO's governed framework of people, processes and technology for planning, preparing, establishing, using and terminating mission networks. Nations join as FMN Affiliates and maintain FMN-ready capabilities. FMN develops in Spirals, each documenting requirements, architecture and standards; the FMN Management Group approved Spiral 6 on 6 November 2025. FMN originated from Afghanistan Mission Network experience.

What is the difference between STANAG 4774 and STANAG 4778?

STANAG 4774 specifies what a confidentiality label contains: policy identifier, classification level, security categories and lifecycle metadata. STANAG 4778 specifies how that label is bound to the data object it describes, including portion marking for components at different classifications and optional cryptographic binding through digital signature. STANAG 4774 makes labels comparable; STANAG 4778 makes them inseparable from the data.

How does sharing across security domains differ from coalition sharing?

Sharing across security domains moves data between classification levels, such as SECRET to UNCLASSIFIED, and requires an accredited cross-domain solution with content inspection and filtering. Coalition sharing moves data between nations at a comparable classification, governed by releasability, and is decided by label and attribute evaluation. Object-level labelling supports both, but it does not substitute for cross-domain accreditation.