Data-at-Rest (DAR) Capability Package
The Data-at-Rest (DAR) Capability Package is one of the Capability Packages under the NSA's Commercial Solutions for Classified (CSfC) program, and it focuses on protecting classified data while it is stored (at rest) on a device or system. It provides guidance for using commercial products, layered together, to encrypt that stored data so it stays protected if the device is lost or stolen. It applies specifically to information stored on an End User Device (EUD) or protected system rather than data being transmitted across a network.
The DAR Capability Package is a CSfC design guidance document that specifies how to combine independent, commercially available cryptographic layers to protect classified data at rest on End User Devices (EUDs) or protected systems. In most implementations it generally requires two nested, independent layers of encryption so that stored data is encrypted more than once, meeting the assurance requirements for protecting classified DAR. The capability described here is version 5.0 as referenced in the evidence; because CSfC Capability Packages are revised over time, practitioners should verify the current applicable version and its specific component, authentication, and configuration requirements against the official CSfC/NSA source. This entry does not cover product-specific listings, implementation registration, or accreditation steps, which must be confirmed against current authoritative CSfC guidance.
Why it matters
Classified information stored on portable and fixed devices represents a persistent risk that traditional network defenses do not address: if an End User Device is lost, stolen, or physically captured, the data on it can be compromised regardless of how well the network perimeter was protected. The DAR Capability Package matters because it gives organizations a government-recognized design approach for protecting classified data at rest using commercially available products rather than requiring purpose-built government cryptographic equipment. This can shorten acquisition timelines and broaden the range of devices that can be used to handle classified information, while still meeting the NSA's assurance expectations.
The core reason the DAR CP holds a high bar is its reliance on layered encryption. As referenced in the evidence, the package is designed to ensure that data is encrypted not once but twice, using independent commercial cryptographic layers. This defense-in-depth model reflects a fundamental principle: a single encryption implementation may contain flaws, misconfigurations, or vulnerabilities, and relying on one layer alone is generally considered insufficient for classified information. Two nested, independent layers mean that the failure or compromise of one layer does not by itself expose the protected data.
Practitioners should be careful not to treat conformance with the DAR CP as a one-time or permanent achievement. CSfC Capability Packages are revised over time, the evidence references version 5.0, and component, authentication, and configuration requirements can change across revisions. Following the design guidance also does not, on its own, address product listing, solution registration, or accreditation obligations, which are separate steps that must be confirmed against current authoritative CSfC/NSA sources.
Who it's relevant to
Inside DAR CP
Common questions
Answers to the questions practitioners most commonly ask about DAR CP.