Skip to content
Capability/Classified & Special Access

Cross-Domain Solutions

CDS compliance, guard systems, and secure data transfer

01 / Overview

Cross-Domain Solutions enable controlled information transfer between networks at different security levels. Thalorin supports CDS implementations with compliance workflows addressing NSA Raise the Bar requirements, guard system authorization, and secure data transfer documentation.

National Security Memorandum 8, issued 19 January 2022, put a clock on cross-domain security. Within 60 days the National Manager had to issue a directive requiring every agency operating a cross-domain solution connected to a national security system to verify that logs are collected and archived, validate that authorised patches are installed, report the status of upgrading to a Raise the Bar compliant version, and develop plans to meet NCDSMO requirements. Within 90 days agency heads had to establish and maintain an inventory of every CDS deployment in their jurisdiction.

A cross-domain solution is also not authorized the way a system is. Under DoDI 8540.01, Cross Domain (CD) Policy — 8 May 2015, incorporating Change 1 of 28 August 2017 — the solution receives a Cross Domain Solution Authorization issued by DISA, and the DISN Connection Process Guide is explicit that a CDS does not go through the ordinary RMF assessment and authorization process. The CDSA reflects a risk decision by the DoD risk executive, because the risk lands on every network the connection touches rather than on one site.

The security policy of a guard is its ruleset. Data type identifiers, schemas, permitted markings, inspection depth and the direction each flow may run are the mechanism NIST SP 800-53 describes under AC-4, Information Flow Enforcement, whose control enhancements 3 through 32 the catalogue says primarily address cross-domain solution needs. That ruleset is also the part that moves. Because the annual review revalidates the approved configuration and not only the operational requirement, an undocumented ruleset change is a finding in waiting rather than routine maintenance.

Refusing to let the ruleset, the authorization and the requirement drift apart is where a platform earns its place here. Thalorin carries the Cross Domain Appendix, the Raise the Bar baseline release the deployment was assessed against, and the filter configuration currently running as one linked record, with classification handled per artifact. The annual review then becomes a comparison against a known state rather than an exercise in archaeology across three unconnected systems.

02 / Challenges

Classified environments require extraordinary controls

Procurement runs ahead of validation

Selection is constrained to what the NCDSMO baseline offers, and the connection requirement has to be validated and approved before the connection exists. Hardware chosen on engineering merit ahead of that approval is frequently not fieldable.

Raise the Bar is a versioned baseline

The NCDSMO revises its design and implementation requirements as threats, technology and assessment findings move. Compliance is therefore a claim about the release a product was assessed against, and it decays on a schedule the site does not control.

Only baselined technology can be fielded

Only technology on the NCDSMO baseline can be deployed. Anything modified or newly built must clear a lab-based security assessment first, so the choice between buying, modifying and building sets the schedule more than the engineering does.

The manual fallback is the exposure

Where no authorised solution handles the data type, transfer falls to a person with removable media working under written authorisation, transfer records and periodic inspection. That regime produces evidence somebody has to keep.

03 / Capabilities

How Thalorin helps

CNSSI 1253NSA CDSICD 503

CDS authorization documentation

Maintain the Cross Domain Appendix, the site-based security assessment and the security assessment report as versioned artifacts feeding the Cross Domain Solution Authorization, with the classification of each recorded.

Raise the Bar compliance

Record which Raise the Bar baseline release the deployment was assessed against and what has changed since, so a new release produces a delta rather than a fresh gap analysis.

Guard system security controls

Bind the AC-4 enhancements the product actually implements — security and privacy policy filters, data type identifiers, detection of unsanctioned information — to the Cross Domain Solution Overlay applied to CNSSI 1253.

Data transfer rule compliance

Version every filter ruleset, schema and permitted data type against the configuration the authorization approved, so a change surfaces as a re-test obligation at the moment it is made.

Bilateral security agreements

Hold the bilateral or multilateral security agreement permitting a partner connection alongside the foreign disclosure determination and the Delegation of Disclosure Authority Letter behind it, bound to the releasability rule the guard enforces.

CDS continuous monitoring

Keep the operational requirement, the approved configuration and the connection registration current between reviews, so the annual review memorandum confirms a state that is already documented.

Questions

Cross-Domain Solutions: common questions

Does a cross-domain solution get its own ATO?

No, it gets a Cross Domain Solution Authorization. The DISN Connection Process Guide states that cross-domain solutions do not undergo the RMF assessment and authorization process and that a CDS is issued a CDSA in accordance with DoDI 8540.01. The CDSA is issued by DISA and reflects a risk decision by the DoD risk executive — the Information Security Risk Management Committee, or the DSAWG acting on its behalf — while the enclaves on either side keep their own authorizations.

Can we buy a cross-domain solution and get it approved afterwards?

That sequence fails. The requirement is validated first, technology is selected from the NCDSMO baseline second, and the connection requirement is approved before the connection is built. Where nothing on the baseline fits the mission, the choice is between modifying an existing cross-domain solution and building a new one, and both routes require laboratory-based security assessment before fielding. Hardware bought on engineering merit ahead of that approval commonly sits unfielded, and the money spent on it is rarely recoverable.

Does a fielded cross-domain solution have to keep up with Raise the Bar?

Yes. National Security Memorandum 8 required a directive obliging every agency operating a cross-domain solution connected to a national security system to report the status of upgrading to a Raise the Bar compliant version and to develop plans to meet NCDSMO security requirements. Raise the Bar is published by the NCDSMO, the National Security Agency office that sets and oversees design and implementation requirements for cross-domain products, and it is revised as threats, technology and assessment findings move.

What has to be revalidated on a cross-domain connection each year?

Both the reason for the connection and its shape. Connections between networks of different security domains are revalidated annually under DoDI 8540.01 and the DISN Connection Process Guide, and the annual review memorandum revalidates the operational requirement and the approved configuration. The second half catches people out: a ruleset extended for a new message format, a data type added for a partner, or a schema updated during sustainment all change the authorized configuration.

How do coalition releasability rules get enforced by a guard?

They have to be expressed as filter rules. A disclosure decision under the National Disclosure Policy is taken by a foreign disclosure officer working from authority delegated in a Delegation of Disclosure Authority Letter, and it is a judgement about information rather than about a network. It becomes enforceable only when somebody translates it into the data types, markings and directions the guard permits. Export authorisation for the hardware itself is a separate question with a separate decision maker.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about Cross-Domain Solutions.

See how one evidence artifact satisfies Cross-Domain Solutions requirements alongside every other framework you carry.