Topic

Federal Data Security

Reference hub on the federal mandates that govern agency and contractor data protection, from FISMA and FedRAMP through DoD zero trust requirements.

13 posts

Federal data security requirements are the statutory, regulatory, and contractual rules governing how United States government agencies and their contractors protect data. FISMA sets the statutory duty for agencies, FedRAMP authorizes cloud services for federal use, and CMMC 2.0 pushes defense requirements into the supply base. Together they define what a control must achieve before data crosses a federal boundary.

Deadlines bind on paper and then get measured at the wrong layer. Agencies report zero trust progress in terms of identity federation, device inventory, and network segmentation, because those are countable. Data-layer enforcement, where policy travels with the object across an authorization boundary, is harder to instrument and correspondingly easy to defer.

Posts under this hub cover the FedRAMP High baseline, DoD Zero Trust Overlays, authority to operate timelines, FIPS 140-3 module validation, federal post-quantum deadlines and post-quantum key encapsulation, and the zero trust data fabric (ZTDF) format that procurement officers keep meeting in requirements language.

Frequently asked questions

What is the difference between FISMA and FedRAMP?

FISMA is the statute requiring federal agencies to run an information security program and to authorize each system, using NIST SP 800-53 Rev 5 controls. FedRAMP applies that model to cloud services: a provider is assessed once against a Low, Moderate, or High baseline, and agencies reuse the authorization package instead of repeating the assessment themselves.

What does CMMC Level 2 require?

CMMC 2.0 Level 2 requires a contractor handling controlled unclassified information to implement the security requirements in NIST SP 800-171, covering access control, media protection, audit and accountability, and cryptographic protection. Assessment runs through a certified third party for prioritized acquisitions and through self-assessment otherwise, with a company official affirming the result.

What are the DoD Zero Trust Overlays?

The DoD Zero Trust Overlays map the department zero trust capabilities and activities onto NIST SP 800-53 Rev 5 controls. They tell a system owner which controls satisfy each target activity across the seven DoD zero trust pillars, and at which level, Target or Advanced. Their function is translating strategy language into concrete control selection.

Does FedRAMP authorization cover data after it leaves the cloud service?

No. A FedRAMP authorization applies to a defined system boundary. Once data is exported, synced to an endpoint, or passed to another service outside that boundary, the authorization says nothing about it. Controls that persist require policy bound to the data object and evaluated at each access request, not at the service perimeter.

Reading on federal data security

Lattix branded cover for 30+ Days to FIPS 140-2 Sunset: The CMVP Validation Backlog Compounds the Calendar. Dark grid background, surgical yellow accent, IBM Plex Mono typography. Reference box reads CMVP MODULES IN PROCESS with the date 21 SEP 2026 and the figure 31 DAYS.

30+ Days to FIPS 140-2 Sunset: The CMVP Validation Backlog Compounds the Calendar

August 21, 2026

Thirty-one days remain before FIPS 140-2 certificates move to historical status. The CMVP queue has already decided which modules make it. This post covers the queue math and what a program does with the modules that will not clear.

Read More →
Lattix branded cover for ACP 240 and Zero Trust Data Format: What the CCEB Standard Specifies. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a labelled data object crossing a coalition boundary intact.

ACP 240 and Zero Trust Data Format: What the CCEB Standard Specifies

August 11, 2026

ACP 240 is a CCEB allied publication covering data-centric security interoperability, and it is where Zero Trust Data Format is specified. A ZTDF object carries NATO STANAG 4774 labels and STANAG 4778 bindings. NATO has not adopted ZTDF for its own framework.

Read More →
Lattix branded cover for the sovereign data architecture mid-year analysis, /45 section number on a dark grid in IBM Plex Mono with surgical yellow accent lines, headline stating sovereignty is a property of the object, and a stat panel citing the DOJ Data Security Program enforcement dates.

Sovereign Data Architecture at Mid-2026: Policy Bound to the Object

July 6, 2026

A mid-2026 stocktake of data sovereignty: DOJ 28 CFR Part 202 enforcement, the EU's sovereign cloud framework, and coalition data sharing all point to the same conclusion. Region-pinning fails at the data layer. Only policy bound to the object travels with the data.

Read More →
Lattix branded cover for the Executive Order 14409 post-quantum analysis. /42 section number, IBM Plex Mono on a dark grid background, the order named and dated June 22 2026, the December 31 2030 key-establishment deadline, and a crypto-inventory strip with the object-level enforcement point highlighted in surgical yellow.

EO 14409 Sets Federal Post-Quantum Deadlines. The Cryptographic Bill of Materials Is the Test.

July 3, 2026

Executive Order 14409 sets December 2030 and 2031 deadlines for federal post-quantum migration and orders a cryptographic bill of materials. The binding requirement is naming which algorithm protects which data object, not swapping a transport cipher.

Read More →
Lattix branded cover for Federal Cloud Migration ATO Acceleration Lives at the Data Layer. /31 section number, ATO control family pace comparison, IBM Plex Mono on dark grid background, yellow accent on the data-control families that consistently bottleneck ATO timelines.

Federal Cloud Migration ATO Acceleration Lives at the Data Layer

June 26, 2026

ATO timelines for federal cloud workloads consistently exceed the planned program schedule. Boundary, identity, and configuration controls converge quickly. Data controls do not. The architecture that produces ATO evidence by construction is the architecture that compresses the cycle.

Read More →
Lattix branded cover for TDF and ZTDF for Procurement Officers. /29 section number, TDF-to-ZTDF specification diff at the policy and key access layers, IBM Plex Mono on dark grid background, yellow accent on the procurement language that resolves to a configurable capability rather than a custom integration.

TDF and ZTDF for Procurement Officers: What the Specification Actually Specifies

June 17, 2026

NSA Phase Two cites ZTDF and IC-TDF as data rights management schema examples. The two specifications differ in scope, lifecycle, and required cryptographic agility. The differences matter when writing FY27 acquisition language. Walk through what each binds and how that maps to procurable capability.

Read More →
Lattix branded cover for DOJ 28 CFR Part 202 Enforcement Starts October 6. /19 section number, October 6 2026 enforcement deadline metadata, six countries of concern statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the enforcement milestone in a rule timeline strip.

DOJ 28 CFR Part 202 Enforcement Starts October 6. Data-Centric Controls Carry the Evidence.

May 15, 2026

The DOJ Bulk Sensitive Data rule under 28 CFR Part 202 took effect April 8, 2025. Active enforcement actions begin October 6, 2026. Most compliance frameworks treat the rule as a contract control. The evidence the rule actually requires is technical.

Read More →
Lattix branded cover for CISA's PQC product categories and federal acquisition. /11 section number, January 23 2026 publication date, two-tier procurement category map, IBM Plex Mono on dark grid background, surgical yellow accent.

CISA's PQC Product Categories Move Quantum-Safe From Roadmap to Procurement

May 12, 2026

CISA's January 23, 2026 product categories list, issued under Executive Order 14306, defines where federal buyers should acquire only PQC-capable products. The list is advisory. The procurement language built on it will not be.

Read More →
Lattix branded cover for Why Network Zero Trust Stops at the Data Boundary. /14 section number, five pillar maturity map showing data pillar gap, IBM Plex Mono on dark grid background, surgical yellow accent.

Why Network Zero Trust Stops at the Data Boundary

May 12, 2026

NIST SP 800-207 and the CISA Zero Trust Maturity Model define five pillars. Most enterprise programs stop at networks. The data pillar requires cryptographic enforcement bound to the object, not perimeter or session controls, and the gap is architectural rather than budgetary.

Read More →
Lattix branded cover for FedRAMP High cloud-native government workloads. /11 section number, IBM Plex Mono on dark grid background, surgical yellow accent.

FedRAMP High Baseline: 421 Controls and the Data-Centric Path

May 8, 2026

FedRAMP High imposes 421 controls on cloud service providers seeking federal authorization. Data-centric zero trust collapses several of the hardest controls into cryptographic enforcement at the policy enforcement point.

Read More →
Lattix branded cover for Federal Zero Trust Deadlines Are Binding. Data Layer Enforcement Is Not. Yellow accent bar, /02 section number, IBM Plex Mono typography on dark grid background.

Federal Zero Trust Deadlines Are Binding. Data Layer Enforcement Is Not.

May 6, 2026

CISA's April 2026 binding directive sets Q3/Q4 2026 deadlines for identity, network, and device zero trust controls. The data layer remains optional. Programs that hit every milestone without object-level enforcement still fail on a compromised service account.

Read More →
Lattix branded cover for CISA's April 2026 OT Zero Trust Guidance Leaves the Data Plane Unaddressed. /04 section number, OT zero trust maturity reference, IBM Plex Mono on dark grid background, surgical yellow accent.

CISA's April 2026 OT Zero Trust Guidance Leaves the Data Plane Unaddressed

May 5, 2026

On April 30, 2026, CISA and four federal partners released a joint guide adapting zero trust principles to operational technology. The guide advances identity, network, and visibility maturity for OT. The data plane remains an open enforcement gap.

Read More →
Lattix branded cover for Post-Quantum Cryptography: Why the Transition Has to Happen Now. /03 section number, FIPS 140-2 sunset date, IBM Plex Mono on dark grid background, surgical yellow accent.

Post-Quantum Cryptography: Why the Transition Has to Happen Now

May 4, 2026

Two PQC deadlines are already running. September 21, 2026 sunsets FIPS 140-2 for federal procurement. January 2027 binds CNSA 2.0 for National Security Systems. The migration that matters is not the algorithm. It is the cryptographic agility to swap one.

Read More →