Topic

Defense Data Security

How zero trust applies to mission data across classification levels, coalition partners, and disconnected networks.

21 posts

Defense data security applies zero trust to mission data across classification levels, coalition boundaries, and disconnected networks. The DoD Zero Trust Overlays specify controls pillar by pillar, and the data pillar assumes protection travels with the object rather than with the enclave. NATO practice binds confidentiality labels using STANAG 4774 and STANAG 4778, keeping a label cryptographically attached to the data it describes.

The hard part is release, not storage. Cross-domain solutions built as guard appliances inspect content at one fixed boundary, forcing every sharing decision through a chokepoint that slows coalition operations. Denied and disconnected conditions add a second constraint, because policy evaluation has to behave predictably, and fail-closed, when the decision service cannot be reached.

Posts under this hub cover CMMC Level 2 and protection of controlled unclassified information, CNSA 2.0 and the January 2027 national security systems deadline, JADC2 data sharing, cross-domain modernization toward object-level release, and the audit failure patterns recurring across the defense industrial base.

Frequently asked questions

What do the DoD Zero Trust Overlays say about data?

The DoD Zero Trust Overlays organize controls by pillar and treat data as a pillar with its own activities, including labeling, encryption, rights management, and monitoring. Read together, those activities describe protection bound to the object rather than to the enclave that stores it. The overlays map each activity to existing control catalogs, which lets programs show coverage against requirements they already track.

What does CMMC Level 2 require for CUI?

CMMC Level 2 assesses a contractor against the NIST SP 800-171 control set for controlled unclassified information, covering access control, media protection, encryption, audit, and incident response. Assessment evidence has to show controls operating, not policies written. Contractors most often fail where CUI moves outside systems they operate, since the requirements follow the information rather than the network.

What is CNSA 2.0 and when is the deadline?

CNSA 2.0 is the NSA Commercial National Security Algorithm Suite specifying quantum-resistant algorithms for national security systems, with January 2027 as a key milestone for new acquisitions. It selects ML-KEM for post-quantum key encapsulation, standardized in FIPS 203, at a parameter strength above ML-KEM-768, so commercial deployments built on ML-KEM-768 will not satisfy national security systems requirements.

How can coalition partners share classified data without shared infrastructure?

Bind releasability rules to each object and let partners hold encrypted copies on their own systems. A partner requesting access presents attributes such as nationality, clearance, and mission role, and the originator's policy decides whether a key is released. No common network, shared directory, or negotiated joint enclave is required before sharing can begin.

Reading on defense data security

Lattix branded cover for OpenTDF, TDF, and ZTDF: How the Three Terms Relate. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box separating a format, a profile of that format, and an implementation of it.

OpenTDF, TDF, and ZTDF: How the Three Terms Relate

August 21, 2026

TDF is a data object format. ZTDF is a coalition profile of that format. OpenTDF is the open-source specification and implementation. The three names are used interchangeably in the market and refer to different things.

Read More →
Lattix branded cover for Data-Centric Security for Defense: A Reference Architecture. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing seven stacked pillars and a labelled data object bound to a policy decision.

Data-Centric Security for Defense: A Reference Architecture

August 13, 2026

Data-centric security for defense protects the data object itself rather than the network around it. This reference architecture maps the DoD Zero Trust Strategy data pillar to NIST SP 800-53 controls and to the NSA implementation phases.

Read More →
Lattix branded cover for Protecting CUI After It Leaves Your Network. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a CUI-marked object leaving a prime contractor boundary and still requiring a policy decision to open.

Protecting CUI After It Leaves Your Network

August 13, 2026

Controlled Unclassified Information stays protected outside the boundary only when the access control is bound to the object rather than to the network. DFARS obligations, NIST SP 800-171 and SPRS submission remain in force through the CMMC reform review.

Read More →
Lattix branded cover for How Coalition Partners Share Classified Data Without Shared Infrastructure. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a labelled object crossing between two national enclaves that share no common network.

How Coalition Partners Share Classified Data Without Shared Infrastructure

August 12, 2026

Coalition partners share classified data by binding a machine-readable confidentiality label to each object and enforcing release at the object, not by building a common network. STANAG 4774, STANAG 4778 and Federated Mission Networking define how.

Read More →
Lattix branded cover for Cross-Domain Solutions: A Practitioner Reference. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a guard appliance between a high-side and low-side domain and a labelled object queued for release.

Cross-Domain Solutions: A Practitioner Reference

August 12, 2026

A cross-domain solution is an accredited controlled interface for accessing or transferring information between security domains of different classification. This reference covers the guard model, Raise the Bar, NCDSMO accreditation and the limits of both.

Read More →
Lattix branded cover for ACP 240 and Zero Trust Data Format: What the CCEB Standard Specifies. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a labelled data object crossing a coalition boundary intact.

ACP 240 and Zero Trust Data Format: What the CCEB Standard Specifies

August 11, 2026

ACP 240 is a CCEB allied publication covering data-centric security interoperability, and it is where Zero Trust Data Format is specified. A ZTDF object carries NATO STANAG 4774 labels and STANAG 4778 bindings. NATO has not adopted ZTDF for its own framework.

Read More →
Lattix branded cover for Defense Industrial Base Audit Failure Patterns. /31 section number, 110 NIST 800-171 practices statistic, three recurring NOT MET findings highlighted, IBM Plex Mono on dark grid background, surgical yellow accent on the architectural pattern in a practice family strip.

Defense Industrial Base Audit Failure Patterns Point to the Same Data Controls

June 25, 2026

CMMC Phase 1 assessment data, DCMA audit findings, and GAO supply chain reports converge on the same NOT MET controls. SC.L2-3.13.11 on cryptographic protection. MP.L2-3.8.9 on backup encryption. AC.L2-3.1.20 on external information system flows. The pattern is architectural.

Read More →
Lattix branded cover for JADC2 Cross-Domain Data Sharing Requires a Data-Centric Substrate. /29 section number, JADC2 milestone date, four cross-domain release patterns statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the policy enforcement point in a multi-domain release strip.

JADC2 Cross-Domain Data Sharing Requires a Data-Centric Substrate

June 18, 2026

DoD JADC2 and CJADC2 milestones depend on cross-domain release of mission data at operational tempo. Guard-appliance cross-domain solutions do not scale to that tempo. ABAC at the policy enforcement point over ZTDF-formatted objects is the substrate that does.

Read More →
Lattix branded cover for TDF and ZTDF for Procurement Officers. /29 section number, TDF-to-ZTDF specification diff at the policy and key access layers, IBM Plex Mono on dark grid background, yellow accent on the procurement language that resolves to a configurable capability rather than a custom integration.

TDF and ZTDF for Procurement Officers: What the Specification Actually Specifies

June 17, 2026

NSA Phase Two cites ZTDF and IC-TDF as data rights management schema examples. The two specifications differ in scope, lifecycle, and required cryptographic agility. The differences matter when writing FY27 acquisition language. Walk through what each binds and how that maps to procurable capability.

Read More →
Lattix branded cover for Cross-Domain Solutions Modernize From Guard Appliances to Object-Level Release. /27 section number, twenty-year guard lineage to ZTDF/IC-TDF object-level release, IBM Plex Mono on dark grid background, yellow accent on the object-level release decision point.

Cross-Domain Solutions Modernize From Guard Appliances to Object-Level Release

June 8, 2026

Guard appliances have served twenty years of joint and coalition cross-domain release. They evaluate data at the boundary. NSA Phase Two cites ZTDF and IC-TDF as schemas that move release evaluation to the object itself, at cryptographic speed.

Read More →
Lattix branded cover for CMMC Level 2 Compliance Through Data-Centric Security. /11 section number, 110 practices and 14 domains metadata, IBM Plex Mono on dark grid background, surgical yellow accent.

CMMC Level 2 Compliance Through Data-Centric Security

June 4, 2026

CMMC Level 2 requires 110 practices across 14 domains. Data-centric security maps to 76 of them through a single architectural primitive bound to the CUI object.

Read More →
Lattix branded cover for CMMC Phase 2 Starts November 10. /16 section number, 110 practice count and November 10 2026 deadline metadata, IBM Plex Mono on dark grid background, surgical yellow accent on the Level 2 step in a four-phase rollout strip.

CMMC Phase 2 Is Suspended. The Level 2 Data Requirements Still Bind.

May 15, 2026

CMMC Phase 2 was suspended in July 2026 and there is no November 10 enforcement date. The third-party C3PAO gate is paused, but DFARS 252.204-7012 and 7020 still bind, Phase 1 self-assessment with SPRS submission still applies, and the 110 NIST SP 800-171 Rev 2 practices still govern what Level 2 requires.

Read More →
Lattix branded cover for CNSA 2.0 and the January 2027 Deadline for National Security Systems. /18 section number, twenty months remaining statistic, ML-KEM-1024 / ML-DSA-87 algorithm metadata, IBM Plex Mono on dark grid background, surgical yellow accent on the January 2027 milestone in a transition timeline strip.

CNSA 2.0 and the January 2027 Deadline for National Security Systems

May 15, 2026

CNSA 2.0 binds new National Security System acquisitions to ML-KEM-1024 and ML-DSA-87 effective January 1, 2027. Twenty months remain on the clock. The target is not the hard part. The transition pattern is.

Read More →
Lattix branded cover for DOJ 28 CFR Part 202 Enforcement Starts October 6. /19 section number, October 6 2026 enforcement deadline metadata, six countries of concern statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the enforcement milestone in a rule timeline strip.

DOJ 28 CFR Part 202 Enforcement Starts October 6. Data-Centric Controls Carry the Evidence.

May 15, 2026

The DOJ Bulk Sensitive Data rule under 28 CFR Part 202 took effect April 8, 2025. Active enforcement actions begin October 6, 2026. Most compliance frameworks treat the rule as a contract control. The evidence the rule actually requires is technical.

Read More →
Lattix branded cover for The DoD Zero Trust Overlays Already Describe a Data-Centric Architecture. /15 section number, 152 capability outcomes statistic, seven pillar map highlighting data pillar, IBM Plex Mono on dark grid background, surgical yellow accent.

The DoD Zero Trust Overlays Already Describe a Data-Centric Architecture

May 12, 2026

The September 2024 DoD Zero Trust Overlays define 152 capability outcomes across seven pillars. The Data Pillar outcomes do not name a vendor and do not name a product category. They describe the architecture data-centric security has been building toward since the original strategy.

Read More →
Lattix branded cover for NSA's Zero Trust Implementation Guidelines Turn Target-Level Maturity Into Sequence. /06 section number, Phase One and Phase Two metadata, IBM Plex Mono on dark grid background.

NSA's Zero Trust Implementation Guidelines Turn Target-Level Maturity Into Sequence

May 12, 2026

NSA published Phase One of its Zero Trust Implementation Guidelines in January 2026 and Phase Two later that month. The market did not need another zero trust definition. It needed the sequence, and the guidelines provide it.

Read More →
Lattix branded cover for NSA Phase Two Cites ZTDF and IC-TDF as DRM Examples. Procurement Catches Up Next. /13 section number, ZIG Phase Two metadata, Data Rights Management schema callout, IBM Plex Mono on dark grid background, surgical yellow accent.

NSA Phase Two Cites ZTDF and IC-TDF as DRM Examples. Procurement Catches Up Next.

May 12, 2026

NSA's Zero Trust Implementation Guideline Phase Two, released January 30, 2026, tells participating components to standardize a data rights management schema and cites ZTDF and IC-TDF as the examples. A recommendation, not a mandate, and enough to write a requirement against.

Read More →
Lattix branded cover for Coalition Data Sharing. /06 section number, IBM Plex Mono on dark grid background, surgical yellow accent.

Coalition Data Sharing Without Infrastructure Agreement

May 8, 2026

When allied partners operate separate networks and classification systems, data-centric security moves enforcement from infrastructure to the data itself.

Read More →
Lattix branded cover for DoD Zero Trust Strategy 2.0 Extends to OT and Weapon Systems. /05 section number, FY27 91 capability outcomes metadata, IBM Plex Mono on dark grid background.

DoD Zero Trust Strategy 2.0 Extends to OT and Weapon Systems

May 7, 2026

DoD Zero Trust Strategy 2.0, published March 2026, brings operational technology, IoT, defense critical infrastructure, and weapon systems under the same target-level maturity expectations as enterprise IT. The data pillar is where the new scope hits hardest.

Read More →
Lattix branded cover for CISA's April 2026 OT Zero Trust Guidance Leaves the Data Plane Unaddressed. /04 section number, OT zero trust maturity reference, IBM Plex Mono on dark grid background, surgical yellow accent.

CISA's April 2026 OT Zero Trust Guidance Leaves the Data Plane Unaddressed

May 5, 2026

On April 30, 2026, CISA and four federal partners released a joint guide adapting zero trust principles to operational technology. The guide advances identity, network, and visibility maturity for OT. The data plane remains an open enforcement gap.

Read More →
Lattix branded cover for CNSA 2.0 Just Narrowed the PQC Field. /04 section number, ML-KEM-1024 and ML-DSA-87 metadata strip, IBM Plex Mono on dark grid background.

CNSA 2.0 Just Narrowed the PQC Field. ML-KEM-768 Will Not Clear NSS.

May 5, 2026

NSA's April 2026 clarification narrowed the post-quantum field for National Security Systems to ML-KEM-1024 and ML-DSA-87. ML-KEM-768 will not clear NSS. Vendors that staked PQC-ready claims on the smaller parameter set need new statements.

Read More →