Capability Package
A Capability Package is a document published by the National Security Agency (NSA) that describes, in vendor-neutral terms, how to build an approved solution for protecting classified information using commercial products. Rather than naming specific products, it lays out the overall design of a solution along with the security and configuration requirements an organization must meet. Capability Packages are associated with NSA's Commercial Solutions for Classified (CSfC) program, and readers should consult the current NSA-published versions and annexes for authoritative requirements.
Within NSA's Commercial Solutions for Classified (CSfC) program, a Capability Package (CP) is a set of vendor-agnostic, solution-level specifications published by the National Security Agency that defines a system-level solution framework and documents the security and configuration requirements customers and integrators must satisfy to protect classified information. CPs are product-neutral and describe general solution architectures, such as protecting classified data as it traverses an untrusted network or protecting data at rest, rather than prescribing particular commercial products; product-specific configuration detail is generally addressed through associated annexes. NSA maintains and releases CPs and annexes under a defined implementation and release schedule, and CPs are versioned (for example, the CSfC Data-at-Rest Capability Package has been issued in successive revisions), so practitioners should verify the currently published CP version and its annexes against NSA's authoritative CSfC materials. This entry describes the concept of the CP and does not cover the full certification, registration, or solution-approval process, product selection, or the classification-handling and accreditation requirements that apply to the resulting solution, all of which must be confirmed against current NSA guidance and applicable national security system authorities.
Why it matters
Capability Packages sit at the center of NSA's Commercial Solutions for Classified (CSfC) program, which allows organizations to protect classified information using layered commercial products rather than waiting for purpose-built government cryptographic equipment. For programs operating on tight timelines or seeking greater flexibility in commercial technology refresh cycles, the CP is the authoritative starting point that defines what an approved solution must look like at the architectural level. Without adhering to a current Capability Package, an integrator has no sanctioned framework for assembling commercial components into a solution NSA will recognize as suitable for classified data.
Because CPs are vendor-neutral and describe general solution architectures, such as protecting classified information as it travels across an untrusted network, or protecting classified data at rest, they establish a common baseline of security and configuration requirements that customers and integrators must satisfy. This separation of solution design from specific product selection is deliberate: it lets NSA maintain the security framework independently of the commercial products that come and go beneath it, with product-specific detail generally handled through associated annexes.
A common and consequential mistake is treating a Capability Package as static reference material. NSA maintains and releases CPs and annexes under a defined implementation and release schedule, and CPs are versioned through successive revisions. Building to a superseded version, or overlooking the annexes that accompany a CP, can leave a solution out of alignment with current requirements. Practitioners should also recognize that meeting a CP's design and configuration requirements is only one part of fielding a classified solution, it does not by itself resolve the certification, registration, solution-approval, or accreditation obligations that apply under national security system authorities.
Who it's relevant to
Inside CP
Common questions
Answers to the questions practitioners most commonly ask about CP.