In U.S. defense environments, protecting sensitive and classified data is a mission requirement. Whether data resides in an installation, a command center, a contractor environment, or in a forward operating environment, it must remain protected at all times and in all operational states. Software Full Drive Encryption (FDE) plays a critical role in this model by ensuring that mission data remains cryptographically protected whenever a device is powered off or unauthenticated, independent of network security controls, perimeter defenses, or endpoint monitoring tools.
This protection is achieved by enforcing authentication prior to data access and maintaining continuous encryption across the entire storage device. When properly implemented, software FDE ensures sensitive and classified data remains protected across all operational environments, regardless of device location, network connectivity, or physical access conditions.
Software Full Drive Encryption (FDE) cryptographically protects data across an entire storage device, requiring authentication before protected data becomes accessible. Encryption and decryption occur transparently in real time for authorized users while protection remains in place when the device is powered off or unauthenticated. Software FDE operates independently of network security controls and can be deployed as a standalone data-at-rest control or as an independent layer within a layered CSfC DAR architecture.
Software FDE must also integrate seamlessly into daily operations. Encryption and decryption occur transparently in real time, allowing authorized personnel to work without disruption while maintaining persistent, policy-aligned Data-at-Rest protection.
Beyond operating as a standalone control, software FDE can also complement hardware FDE to form a layered security architecture. Under the NSA’s CSfC Data-at-Rest capability package, mission systems are required to implement both certified hardware full drive encryption with pre-boot authentication and certified software full drive encryption, ensuring resilient, independently enforced protection for sensitive data.
Version 1.2.1 of Cigent Software Full Drive Encryption builds on these principles, with updates specifically designed for defense environments.
FDE 1.2.1 broadens support across commonly deployed OEM platforms used in defense and rugged environments. The release supports Windows 10 and Windows 11 systems sourced from vendors such as Dell, HP, Getac, and Panasonic, reducing deployment friction for programs standardizing on approved hardware configurations.
The release supports smart card authentication at boot, requiring both possession of a physical credential and PIN verification before granting access. This approach aligns with defense authentication standards and strengthens access control without changing user workflows.
FDE 1.2.1 supports automated, unattended deployment using MSI-based configuration options. User setup and credential configuration can be handled during installation, simplifying rollout across large endpoint populations and reducing operational overhead for IT teams.
The release is designed to interoperate with environments that rely on BitLocker for device governance, Group Policy enforcement, or audit workflows. This allows organizations to introduce Cigent FDE without disrupting existing Windows security controls, supporting incremental adoption rather than a rip-and-replace transition.
For programs operating in sensitive environments, assurance matters as much as capability. Cigent Software Full Drive Encryption v1.2.1 is currently undergoing evaluation under the Common Criteria Evaluation and Validation Scheme (CCEVS) as part of the NIAP certification process. This evaluation reflects Cigent’s continued focus on building encryption solutions aligned with federal assurance requirements.
As defense systems continue to evolve, protecting data at rest requires solutions that balance strong security with operational realities. Software Full Drive Encryption must integrate into existing environments, support standardized hardware platforms, and scale without introducing unnecessary complexity.
Cigent FDE v1.2.1 reflects this approach, strengthening data-at-rest protection while supporting how defense programs deploy, manage, and operate systems today.
Schedule a consultation with our security experts to learn how we can help you implement a robust security framework that starts before the OS boots.
Software Full Drive Encryption (FDE) uses software-based cryptography to protect data across an entire storage device. It maintains continuous encryption and requires authentication before protected data becomes accessible. Because protection does not depend on network connectivity, perimeter defenses, or endpoint monitoring, stored mission data remains protected when the system is powered off or unauthenticated.
Software FDE performs encryption through software running on the system, while hardware FDE performs cryptographic operations within the storage device itself. In a hardware/software FDE CSfC DAR architecture, hardware FDE with Pre-Boot Authentication (PBA) provides the hardware layer, while independent software FDE provides the second encryption layer.
Software FDE can provide strong standalone protection for sensitive data by continuously encrypting the storage device and requiring authentication before access. For classified data at rest using the hardware/software FDE CSfC architecture, however, it operates as one of two independent layers alongside hardware full drive encryption with Pre-Boot Authentication.
In a CSfC DAR architecture using hardware and software FDE, software full drive encryption provides the independent inner encryption layer after the outer hardware protection has been unlocked. Hardware full drive encryption with Pre-Boot Authentication provides the outer layer, creating separate cryptographic boundaries around classified data at rest.
Independence reduces the chance that one vulnerability or implementation weakness can compromise both encryption layers. The hardware and software layers use separate cryptographic implementations, key management, and protection boundaries. If one layer is defeated, the second independently implemented cryptographic barrier remains between an unauthorized user and the classified data.
When the device is powered off, data stored on the protected drive remains encrypted. The encryption does not depend on an active network connection, perimeter control, or endpoint monitoring service. When the system starts again, authentication is required before the protected data becomes accessible to an authorized user.
Cigent Software FDE performs encryption and decryption transparently in real time so authorized personnel can work without changing normal workflows. The software is designed to maintain persistent data-at-rest protection while integrating into daily operations, allowing protected information to be accessed normally after successful authentication.
Cigent Software FDE v1.2.1 broadens support across OEM platforms commonly deployed in defense and rugged environments. The release supports Windows 10 and Windows 11 systems from vendors including Dell, HP, Getac, and Panasonic, helping programs deploy software encryption across standardized defense hardware configurations without unnecessary deployment friction.
Cigent Software FDE v1.2.1 supports automated, unattended deployment using MSI-based configuration options. User setup and credential configuration can be handled during installation, helping IT teams deploy encryption across large endpoint populations while reducing manual configuration and operational overhead associated with protecting systems individually.
In the hardware/software FDE CSfC DAR architecture, Pre-Boot Authentication works with hardware full drive encryption to establish the outer protection layer before the operating system loads. Independent software FDE provides the second layer using a different cryptographic implementation, creating separate protection boundaries so compromise of one layer does not automatically expose classified data.
Understand how your current approach aligns with NSA CSfC Data at Rest requirements. Take the Cigent CSfC DAR Readiness Assessment to evaluate your platform, identify potential gaps in encryption and authentication, and determine the next steps for protecting classified data at rest.
Take the CSfC DAR Readiness Assessment
Conner Crisafulli is a solutions engineer and cybersecurity professional at Cigent with a unique background bridging elite military operations and advanced data security. Before joining Cigent, Conner served six years as a U.S. Air Force Combat Controller, where he specialized in high-stakes mission planning, communication systems, and joint operations coordination/execution. Drawing from his experience in complex, contested environments, Conner now helps federal agencies and enterprise clients strengthen their data-at-rest protection strategies. At Cigent, he focuses on practical applications of self-encrypting drives (SEDs), pre-boot authentication (PBA), and various CSfC (commercial solutions for classified) technologies to safeguard sensitive data against evolving cyber threats.