RackTop Systems
CSfC Component

RackTop SHIELD — Authorization Acquisition for CSfC Listed Drives

SHIELD is designed to be the outer layer of a CSfC Data at Rest solution, handling the Authorization Acquisition function for drives already listed on the NSA CSfC Components List.

What SHIELD is

SHIELD is designed to be the outer layer and handles the Authorization Acquisition (AA) function for CSfC listed drives.

The AA function is defined in the Full Disk Encryption collaborative Protection Profiles. It handles the authorization factors an operator presents and produces the Border Encryption Value the drive needs in order to unlock, with the drive itself providing the encryption. Where SPEAR is designed as the inner layer in software, SHIELD forms the outer encryption layer in combination with CSfC listed drives.

Where things stand

In evaluation now, listing expected Q4 2026

RackTop is in Common Criteria evaluation. NSA CSfC Component listing is expected in Q4 2026. Those are sequential milestones, not the same one, and we do not describe a product as listed until it appears on the Components List.

Program schedules get built on this kind of thing, so if yours depends on the date, ask us and we will put the current position in writing rather than leave you reading a web page.

Request

Ask about SHIELD, or ask for a copy of the software

The useful version of this conversation starts with what you are building. Tell us the shape of your solution and which drives you plan to use, and a RackTop federal mission engineer will follow up.

For the inner layer, see RackTop SPEAR. For the full platform these components ship in, see BrickStor CSfC DAR.

Loading request form…

Questions

The things people actually ask

It is the part of a Full Drive Encryption solution that deals with the operator. It handles the authorization factors presented, and on success produces the Border Encryption Value the drive needs in order to unlock. The Full Disk Encryption collaborative Protection Profiles define it separately from the Encryption Engine because authorization and cryptography are different security problems.
Drives that already appear on the NSA CSfC Components List, providing the encryption in hardware. SHIELD supplies the Authorization Acquisition function that sits in front of them, which is how the outer layer of the solution is formed.
A CSfC Data at Rest solution uses two independent layers. SHIELD is designed to be the outer layer, providing AA for CSfC listed drives. SPEAR is designed to be the inner layer, a software Full Drive Encryption solution implementing both the AA and EE functions. Most conversations start by working out which layer you are filling.
No. SHIELD does not impose a limit on the number of drives in a system.
Yes. SHIELD works for a boot drive, and the boot drive stays protected.
RackTop is in Common Criteria evaluation, with NSA CSfC Component listing expected in Q4 2026. Evaluation against the applicable Protection Profile comes first; listing on the Components List follows. We will say so here when it happens, and not before.
No, and be wary of anyone who says otherwise. Components are evaluated and listed; solutions are registered with NSA by the organization fielding them; systems are accredited by your own authorizing official. SHIELD is a component you build with. The registration and accreditation work still belongs to your program.
Ask through the form on this page. Tell us what you are building and which drives you intend to use, and a RackTop federal mission engineer will get back to you about availability and fit.

Bring us the architecture you are working on

Show us the capability package you are building to and the components you have already picked. We will tell you where SHIELD fits, and where it does not.

RackTop SHIELD: Authorization Acquisition for CSfC Listed Drives | RackTop Systems