ACP 240 and Zero Trust Data Format: What the CCEB Standard Specifies
Allied Communications Publication 240 (ACP 240) covers data-centric security interoperability for allied information sharing, and it is the publication in which Zero Trust Data Format (ZTDF) is specified. ACP 240 is sponsored by the Combined Communications-Electronics Board (CCEB), whose members are Australia, Canada, New Zealand, the United Kingdom and the United States. A ZTDF object carries structured security metadata and key access information bound to the payload, so protection travels with the data rather than with the network that carried it. ZTDF is a CCEB format that carries NATO labelling standards inside it. NATO has not adopted ZTDF for NATO's own data-centric security framework, and the gap between those two statements is where most public confusion about this publication starts.
What ACP 240 is
ACP 240 is an Allied Communications Publication. Allied Communications Publications are standardization documents defining procedures and formats for military communications among allied forces, developed through the Combined Communications-Electronics Board and NATO and identified by number, with revisions marked by a bracketed letter.
ACP 240 addresses data-centric interoperability: the ability of allied partners to exchange protected information objects that each partner's systems can evaluate and, where authorized, open. NATO's own C3 Staff architecture reporting publicly describes ACP 240 Edition A as a guide to achieving secure data-centric interoperability, introducing ZTDF for secure object encoding and covering attribute-based access control alongside a dedicated access control framework.
The publication is not distributed openly in full. What circulates publicly comes from CCEB and national announcements, NATO architecture reporting that references it, vendor material from participants in allied trials, and secondary technical commentary. ACP 240 carries an edition letter and an amendment number, and its supplements are numbered separately, so a citation naming only "ACP 240" does not identify a specific text.
Who publishes ACP 240 and who it applies to
The Combined Communications-Electronics Board is the sponsoring authority for Allied Communications Publications. The CCEB is a five-nation joint military communications-electronics organization comprising Australia, Canada, New Zealand, the United Kingdom and the United States. It coordinates with NATO, including through the NATO Standardization Office, and CCEB procedures serve as a basis for NATO members developing national communications documents.
That structure matters for accuracy. ACP 240 is commonly referred to as a NATO standard in vendor and press material. The precise position is that ACP 240 is a CCEB-sponsored allied publication used by the five CCEB nations and allied partners, in coordination with, but not identical to, NATO's own standardization output. Public sources state that ACP 240 is being adopted by the United States Joint Chiefs of Staff, and describe adoption across Five Eyes and other allied nations.
Buyers writing coalition requirements should name the publication and the sponsoring body explicitly rather than relying on the phrase "NATO standard", which does not identify a single testable document.
What ACP 240 specifies about Zero Trust Data Format
ZTDF is specified in ACP 240 rather than referenced from somewhere else. Public technical commentary places the specification in Supplements 3 and 4, which cover the data framework and the data format schema respectively.
A ZTDF object binds three things to a payload. The first is structured security metadata, including confidentiality labelling and release markings. The second is key access information sufficient to reach the decryption material. The third is an access control policy stating the attributes a subject must satisfy before that material is released. The binding is cryptographic, so a recipient can verify that the labelling accompanying an object is the labelling its originator applied. Because the metadata and the key access information travel inside the object, an object that crosses a coalition boundary carries the conditions of its own release.
ZTDF descends from the Trusted Data Format lineage rather than being invented alongside it. That heritage is why an implementation built against TDF or OpenTDF is close to, but not automatically conformant with, what the allied publication requires. Conformance is a separate question from format family, and procurement language should treat it that way. The distinction between the format, the allied specification and the open-source implementation is set out in OpenTDF, TDF, and ZTDF: How the Three Terms Relate, and the underlying object structure in What Is Trusted Data Format: A Technical Reference.
How ACP 240 relates to the NATO STANAG family
ZTDF and the NATO labelling standards are layered, not competing. A ZTDF object carries STANAG 4774 confidentiality labels and STANAG 4778 metadata bindings inside it, alongside key access information and an access control policy. The NATO standards define what a label says and how it stays attached to what it describes. ACP 240 defines the container that moves labelled, bound, encrypted objects between partners.
That distinction locates the actual disagreement. NATO's reservations about ZTDF are not about labelling, because ZTDF carries the NATO labelling standards rather than replacing them. The reservations are about the encryption and key layer, which the next section covers.
| Standard | Sponsoring body | What it defines |
|---|---|---|
| ACP 240 | Combined Communications-Electronics Board | Data-centric security interoperability for allied information sharing, and the ZTDF object format |
| STANAG 4774 | NATO | Confidentiality label syntax: policy identifier, classification, security categories and label lifecycle metadata |
| STANAG 4778 | NATO | Metadata binding, associating metadata with data using encapsulating, embedded or detached bindings with cryptographic integrity |
| STANAG 5636 | NATO | The NATO Core Metadata Specification, covering the bibliographic and resource metadata carried alongside confidentiality labelling |
| STANAG 5663 | NATO | Identity, credential and access management, including attribute-based access control |
Programmes that must satisfy both should treat STANAG 4774 labelling, STANAG 4778 binding and ACP 240 object conformance as three separate obligations, because a system can satisfy any one of them without satisfying the others. Related design considerations appear in classified data sharing with coalition partners.
Whether NATO has adopted ZTDF
The two positions in circulation are not in conflict. They are accurate statements about different bodies.
Vendor material describes ZTDF as ratified through the CCEB and adopted across allied nations. Community technical commentary states that NATO has not adopted ZTDF for its data-centric security framework and is not working towards doing so. Both can hold at once, because CCEB ratification and NATO effectivity are separate events.
Allied Communications Publications are effective on receipt for the five CCEB nations, and effective for NATO nations and Strategic Commands only when the NATO Military Committee directs it. That promulgation formula appears in the letter of promulgation of publicly released ACPs across the series. The second event does not follow automatically from the first, and no public record of a NATO Military Committee direction covering ACP 240 has been identified.
The technical reservations are documented too. Community commentary cites two. ZTDF encrypts at file granularity, which does not serve structured command-and-control data where access has to be decided at field granularity. Its key model is centralized in a way that sits awkwardly against federated key sovereignty across sovereign nations. The same source describes NATO and the CCEB co-developing federated cryptographic key management standards intended for publication as both an ACP 240 supplement and a NATO allied publication, which reads as a convergence path rather than a stalemate.
The consequence for a requirements document is short. Name CCEB and ACP 240 when the requirement is ACP 240. Name STANAG 4774, 4778, 5636 and 5663 when the requirement is NATO. A specification asserting NATO-ratified ZTDF claims something the public record does not support, and a defense evaluator will check.
Where public detail on ACP 240 ends
Naming the boundary of public knowledge is part of describing this standard honestly.
Public sources do establish the following: that ACP 240 exists and covers data-centric security interoperability, that it is sponsored through the CCEB, that ZTDF is specified in it with the technical content in Supplements 3 and 4, that a ZTDF object carries STANAG 4774 labels and STANAG 4778 bindings together with key access information and an access control policy, that NATO C3 architecture reporting references the publication, that United States adoption is proceeding through the Joint Chiefs of Staff, and that allied exercises have been used as proving grounds, with the United Kingdom carrier strike group deployment Operation HIGHMAST described publicly in that role.
Public sources do not establish: the numbered requirements ACP 240 contains, the specific assertion identifiers and schema properties it mandates, the amendment status of individual supplements, ratification dates for individual nations, or the conformance testing regime. Statements in circulation about ACP 240 requiring particular cryptographic algorithms, key lengths or key management topologies are not verifiable from open material.
Organizations that need the text should request it through their national CCEB channel or programme sponsor. No public reference page, including this one, substitutes for the controlled document.
What ACP 240 changes for coalition information sharing
The operational problem ACP 240 addresses is release latency. Sharing a document across a coalition boundary conventionally requires a release decision, a cross-domain transfer, and a receiving enclave cleared to hold the result. Each step is a human and infrastructure dependency, and the aggregate delay is measured in hours or days.
A format that binds labelling, release markings and key access information to the object moves the release decision to the moment of access. The object can traverse partner infrastructure as ciphertext. A partner system that can reach the appropriate key service and present satisfying attributes opens it; one that cannot holds an unreadable file. The decision is made per request rather than per transfer.
That property does not remove the need for cross-domain solutions and guard appliances where domains are separated at the network level. It changes what those devices carry. Further discussion appears in cross-domain solutions, guard appliances and object-level release.
How Lattix supports allied data-centric interoperability
Lattix produces and consumes TDF objects with a policy decision point evaluating ABAC across subject, device, environment and geography, purpose of use, network posture, risk, and data-object attributes. Decisions are signed, short-lived, and carry allow or deny, the reasons, the policy version hash, and the object identifier. Enforcement occurs at decrypt time through a policy enforcement point (PEP), defaults are fail-closed, and revocation propagates to deny. Merkle-tree lineage records make release history queryable for after-action review. The same enforcement posture deploys across cloud, regional hub, tactical edge and air-gapped environments with no configuration change, which is the condition coalition deployments impose.
Frequently asked questions
What is NATO ACP 240?
ACP 240 is an Allied Communications Publication covering data-centric security interoperability for allied information sharing, and it is where Zero Trust Data Format is specified. It is sponsored by the Combined Communications-Electronics Board, whose members are Australia, Canada, New Zealand, the United Kingdom and the United States. It is commonly called a NATO standard, which is imprecise: ACP 240 coordinates with NATO standardization, but NATO effectivity for an Allied Communications Publication requires direction from the NATO Military Committee.
What does ACP 240 specify about Zero Trust Data Format?
ACP 240 specifies ZTDF rather than referencing it from elsewhere, with the technical content located in Supplements 3 and 4. A ZTDF object binds structured security metadata, including STANAG 4774 confidentiality labelling and release markings, together with key access information and an access control policy, to the payload. Protection and labelling therefore travel with the object across partner infrastructure. The numbered requirements, schema properties and assertion identifiers are not documented in open sources.
What standards support secure information sharing between NATO partners?
Five carry most of the load. NATO STANAG 4774 defines confidentiality label syntax. STANAG 4778 defines metadata binding, using encapsulating, embedded or detached bindings with cryptographic integrity. STANAG 5636 defines the NATO Core Metadata Specification. STANAG 5663 covers identity, credential and access management including attribute-based access control. ACP 240, sponsored by the CCEB rather than NATO, defines the ZTDF object format that carries the first two inside it. Programmes exchanging with both CCEB and NATO partners typically have obligations under more than one.
Is ACP 240 a NATO standard or a Five Eyes standard?
ACP 240 is a Five Eyes publication. It is sponsored through the Combined Communications-Electronics Board, a five-nation body comprising Australia, Canada, New Zealand, the United Kingdom and the United States. Allied Communications Publications become effective on receipt for CCEB nations and effective for NATO nations and Strategic Commands only when the NATO Military Committee directs it, so CCEB sponsorship and NATO effectivity are separate events. NATO coordination is real. NATO authorship is not the accurate description.
Has NATO adopted Zero Trust Data Format?
Not on the public record. ZTDF is specified in ACP 240, a CCEB publication, and CCEB ratification is documented. Public technical commentary states that NATO has not adopted ZTDF for its data-centric security framework and is not pursuing it, citing file-level encryption granularity and a centralized key model as the reasons. NATO's own promulgated standards for this problem are STANAG 4774, 4778, 5636 and 5663. NATO and the CCEB are described as co-developing federated key management standards, which is the convergence path. Programmes should confirm status with their national authority.
Where can the full text of ACP 240 be obtained?
ACP 240 is not published openly in full. Access runs through national Combined Communications-Electronics Board channels or the sponsoring programme office, subject to the requesting organization's status and need. Publicly available material consists of national and vendor announcements, exercise reporting, and secondary technical commentary, none of which reproduces the numbered requirements of the publication.