RackTop Systems
CSfC Component

RackTop SPEAR — Software Full Drive Encryption

A software-based Full Drive Encryption solution implementing both the Authorization Acquisition and Encryption Engine functions, designed as the inner encryption layer of a CSfC Data at Rest solution.

What SPEAR is

SPEAR is a software-based Full Drive Encryption (FDE) solution. The TOE implements both the Authorization Acquisition (AA) function and the Encryption Engine (EE) function, as defined in the Full Disk Encryption collaborative Protection Profiles.

It was designed to be the inner encryption layer of a CSfC Data at Rest solution. SPEAR leverages CNSA 2.0 compliant algorithms and was designed to meet the NSA CSfC DAR 5.1 Capability Package.

Where things stand

Evaluation underway, listing expected Q4 2026

RackTop is in Common Criteria evaluation. NSA CSfC Component listing is expected in Q4 2026. The two are not interchangeable, and this page will keep saying “expected” until the listing is real.

If your milestones are tied to that date, talk to us rather than planning against a marketing page. We would rather give you the current position directly.

Request

Ask about SPEAR, or ask for a copy of the software

Tell us what you are building and how the encryption layer is meant to work in it. A RackTop federal mission engineer will come back to you on availability, and on the questions your reviewers are likely to raise.

For the outer layer, see RackTop SHIELD. For the full platform these components ship in, see BrickStor CSfC DAR.

Loading request form…

Questions

What programs tend to ask first

The Full Disk Encryption collaborative Protection Profiles define two functions: Authorization Acquisition, which handles the authorization factors and produces the Border Encryption Value, and Encryption Engine, which uses that value to encrypt and decrypt the drive. SPEAR implements both, so a single component provides the complete encryption layer rather than two products that have to be integrated.
A CSfC Data at Rest solution uses two independent layers. SPEAR is designed to be the inner layer, encrypting in software. SHIELD is designed to be the outer layer, handling the Authorization Acquisition function for CSfC listed drives. They solve for different positions in the architecture, so the question is usually not which one, but which layer you are filling.
No. It is designed as one layer of a two-layer architecture, and the CSfC DAR Capability Package requires both. SPEAR covers the inner layer; the outer layer comes from elsewhere in your solution design.
RackTop is in Common Criteria evaluation, with NSA CSfC Component listing expected in Q4 2026. Evaluation against the applicable Protection Profile comes first, and listing on the Components List follows. Until that listing exists we will not describe it as though it does.
Use the form on this page and tell us how you intend to deploy it. A RackTop federal mission engineer will follow up about availability and the architecture questions that usually come with it.

Talk it through before you commit the design

Tell us which components you have selected and what your reviewers will want to see. We will be straight about where SPEAR fits and where it does not.

RackTop SPEAR: Software Full Drive Encryption for CSfC DAR | RackTop Systems