Skip to main content
DoD Encryption Solicitation Reveals Gaps You Can't AffordContracting & Acquisition
5 min readFor DIB Contractors

DoD Encryption Solicitation Reveals Gaps You Can't Afford

What Happened

On August 27, the Department of Defense issued a solicitation for commercial encryption software to secure data on weapon systems and acquisition programs. The request set a 30-day response window, closing on September 27. The requirements specify software-based solutions that operate without hardware modifications, support DoD-approved multifactor authentication, prevent unauthorized access, and ensure the department has complete control over decryption keys. These capabilities are framed as interim measures toward adopting post-quantum cryptography by the early 2030s.

In June, the DoD released a post-quantum cryptography strategy directing the military to retire legacy devices and platforms that can't support new protections. DoD Chief Information Officer Kirsten Davies noted that "nearly every deployed military asset will be affected in some way."

Timeline

June 2024: DoD releases a post-quantum cryptography strategy mandating the retirement of legacy systems unable to support advanced encryption.

August 27, 2024: DoD issues a solicitation for commercial encryption software with specific requirements for software-based implementation, approved authentication methods, and key management control.

September 27, 2024: Response deadline for commercial vendors.

Early 2030s: Target timeframe for full post-quantum cryptography deployment across DoD systems.

Which Controls Failed or Were Missing

The solicitation doesn't describe a breach but reveals systemic gaps in how defense contractors and DoD components have implemented cryptographic protection. The call for software-based solutions that don't require hardware replacement indicates widespread deployment of systems where encryption is either absent, hardware-dependent, or implemented in ways that block future upgrades.

Specific control failures align with several NIST SP 800-171 requirements that contractors should already meet:

3.13.11 (Cryptographic Protection): "Employ FIPS-validated cryptography when used to protect the confidentiality of CUI." Many existing systems lack validated encryption or rely on deprecated algorithms that won't withstand quantum computing threats.

3.13.16 (Protection of CUI at Rest): "Protect the confidentiality of CUI at rest." The solicitation's emphasis on data packet protection suggests gaps in how contractors encrypt stored data on weapon systems and acquisition platforms.

3.5.1 (Identification): "Identify information system users, processes acting on behalf of users, or devices." The requirement for DoD-approved multifactor authentication points to systems still relying on single-factor authentication or non-compliant methods.

3.5.3 (Multifactor Authentication): "Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts." This should already be standard for any system handling CUI.

The directive to retire legacy devices reveals a deeper issue: contractors deployed systems without considering cryptographic agility. You've built platforms where encryption is tightly coupled to specific hardware, making upgrades prohibitively expensive or technically impossible.

What the Relevant Standards Require

NIST SP 800-171 Rev 2 and the emerging Rev 3 establish baseline cryptographic requirements for any contractor handling CUI. These aren't suggestions:

FIPS 140-2 Validation: Any cryptographic module protecting CUI must hold current FIPS 140-2 validation. You can't use commercial encryption libraries or create your own crypto, no matter how confident your developers are.

Key Management (3.13.10): "Establish and manage cryptographic keys for cryptography employed in organizational systems." The solicitation's requirement for DoD control over decryption keys reflects this principle. If you're using encryption where a vendor holds the keys or where key recovery depends on external services, you're not compliant.

Cryptographic Agility: While not explicitly numbered in NIST SP 800-171, the concept appears throughout NIST SP 800-53 (SC-12, SC-13) and DoD guidance. Your encryption implementation must allow algorithm replacement without system redesign. The post-quantum transition exposes systems built without this flexibility.

Authentication Mechanisms (3.5.2, 3.5.3): Multifactor authentication is mandatory for privileged accounts and network access to non-privileged accounts. "DoD-approved" methods typically mean Personal Identity Verification credentials or solutions meeting Authenticator Assurance Level 3 under NIST SP 800-63B.

DFARS 252.204-7012 reinforces these requirements by mandating "adequate security" for covered defense information. When quantum computing renders your current encryption inadequate, you're in breach of your contract clauses.

Lessons and Action Items for Your Team

Audit your cryptographic implementations now. Don't wait for CMMC assessors or a contract modification to force the issue. Document every system handling CUI and identify:

  • Which FIPS 140-2 validated modules you're using (if any)
  • Whether encryption is software-based or hardware-dependent
  • Who controls the decryption keys
  • What your upgrade path looks like when NIST finalizes post-quantum algorithms

Test your cryptographic agility. Can you swap encryption algorithms without touching hardware? If the answer is no, you've got a design problem that will cost you contracts. Build systems where cryptographic functions are abstracted from the underlying platform.

Stop deploying single-factor authentication anywhere. The solicitation's emphasis on DoD-approved multifactor authentication reflects a basic NIST SP 800-171 requirement you should have implemented years ago. If you're still using passwords alone for system access, you're not meeting 3.5.3.

Review your System Security Plans. Your SSP should document cryptographic implementation with enough detail that an assessor can verify FIPS 140-2 compliance and key management practices. Generic statements like "we use industry-standard encryption" won't survive a CMMC Level 2 assessment.

Plan for post-quantum migration. The early 2030s sounds distant, but NIST is expected to finalize post-quantum cryptographic standards in 2024. You need a roadmap showing how you'll transition existing systems. Start with systems handling the most sensitive CUI and work backward.

Engage with your government customers. If you're a prime contractor, the post-quantum mandate affects your entire supply chain. Your subcontractors need the same cryptographic capabilities you're implementing. DFARS 252.204-7012 flow-down requirements mean their failures become your compliance gaps.

Document your key management procedures. The solicitation's requirement for DoD control over decryption keys reflects a fundamental principle: the data owner must control access. If you're using cloud encryption where the provider holds keys, or if your key recovery process involves third parties, document exactly how you maintain government control. Be prepared to demonstrate this during assessment.

The DoD's solicitation isn't just about buying new software. It's a signal that cryptographic protection has been inadequate across the defense industrial base, and the quantum computing timeline is forcing a reckoning. Your current encryption practices either position you for future contracts or disqualify you from them.

You Might Also Like