Compliance

Standards Reference

Tessera is built against a defined set of NATO and IETF standards. This page lists each standard, what it specifies, and how it is implemented across our products.

Standards implemented

ACP-240 STANAG 4774 STANAG 4778 ADatP-5636 ADatP-4774 ADatP-4778 ADatP-5663 XMLSPIF v2.1 XMLSPIF v3.0 RFC 5652 RFC 8785 RFC 9449 RFC 5280 RFC 3464

NATO & CCEB Standards

Core standards that define the data-centric security model and security label framework.

Standard Title Scope Tessera Implementation Product Status
ACP-240 Zero Trust Data Format (ZTDF) Encrypted archive format — payload encryption, ABAC policy, key-access protocol, and manifest structure for the .ztdf container. Full .ztdf archive production and consumption. AES-256-GCM payload, RSA-OAEP-SHA256 key wrap, HMAC-bound ABAC policy, JSON manifest with RFC 8785 canonical form. KAS /rewrap endpoint. Windows Implemented
STANAG 4774 Confidentiality Metadata Labels for Information Objects XML schema for a Confidentiality Label: classification value, policy identifier, categories, handling instructions, and authority information. STANAG 4774 Confidentiality Label generation and parsing in all write paths (Office add-ins, Explorer, service). Label embedded in OOXML custom XML, XMP metadata, and sidecar .bdo files per ADatP-4778.2 profiles. Windows CDS Implemented
STANAG 4778 Binding Data Object (BDO) Cryptographic binding of a Confidentiality Label to a specific content object; defines the Binding Data Object structure and the cryptographic artefacts that carry it. XML-DSIG BDO production with SHA-384 digests (label-signing CA issues a per-document certificate); CMS SignedData for the SMTP/MIME profile. BDO verification on every read path and in the CDS proxy pipelines. ADatP-4778.2 binding profiles: OOXML/OPC custom XML (§5.6, §3.4), XMP (§10.5), SMTP/MIME (§3.5), and detached .bdo sidecars. Windows CDS Implemented
ADatP-5636 Object Classification Label (OCL) JSON structured label carrying classification level, categories, and policy reference; embedded as a handling assertion in the ACP-240 archive manifest. OCL generation and parsing for document-level and portion-level marks. Portioning strings computed from SPIF marking instructions and embedded in OOXML core properties and email headers. Windows CDS Implemented
ADatP-4774 Confidentiality Metadata Label (CML) Specification Normative XSD for the Confidentiality Label XML instance; defines the XML structure and allowed values. Labels validated against the ADatP-4774 normative XSD on all read paths. XML declarations use UTF-8 without BOM per the ADatP-4774 normative example. Windows CDS Implemented
ADatP-4778 Binding Information — Profiles ADatP-4778.2 defines application-specific profiles for embedding the BDO in OOXML, PDF/image XMP, email, and standalone sidecar files. OOXML/OPC (custom XML part), XMP (PDF, JPEG, PNG, TIFF, WebP), SMTP/MIME, ID3 for audio and video, and a detached .bdo sidecar for everything else. The write path picks the profile from the format; readers follow the same cascade, so a binding is found wherever the format allowed it to be put. Windows CDS Implemented
XMLSPIF v2.1 Security Policy Information Format (XML, version 2.1) Machine-readable XML format for a domain security policy: classification hierarchy, category definitions, marking instructions, and equivalence mappings. Full XMLSPIF v2.1 parsing. SPIF drives classification ordering, category attribute URI mapping, ABAC policy construction, and portioning mark rendering. NATO, Belgian national and CWIX25/26 policies are included, plus a fictional TESSERA policy published for demonstration and testing. Windows CDS Implemented
XMLSPIF v3.0 Security Policy Information Format (XML, version 3.0) Updated SPIF schema with extended category types and marking instruction changes. XMLSPIF v3.0 parsing supported alongside v2.1. CWIX26 v3.0 SPIF included as a test reference. Windows CDS Implemented

IETF & Cryptographic Standards

Underlying protocol and cryptographic specifications used by Tessera.

Standard Title Scope Tessera Implementation Product Status
RFC 5652 Cryptographic Message Syntax (CMS) Defines the SignedData, EnvelopedData, and other CMS content types used for cryptographic operations on digital content. CMS SignedData carries the STANAG 4778 binding in the SMTP/MIME profile; the document, image and sidecar profiles use XML-DSIG instead. The label-binding CA is an RSA-4096 key signing SHA-256, and issues the per-document RSA-2048 certificates that sign each binding. Windows CDS Implemented
RFC 8785 JSON Canonicalization Scheme (JCS) Defines a canonical serialisation for JSON values to enable deterministic HMAC and hash computation over JSON-structured data. JCS applied to the ACP-240 manifest before computing the HMAC binding the ABAC policy to the wrapped DEK. Ensures consistent HMAC computation across implementations. Windows Implemented
RFC 3464 Extensible Message Format for Delivery Status Notifications Defines the format of email Non-Delivery Reports (NDR) generated when a message cannot be delivered. RFC 3464 NDRs generated by CDS proxy services when an email flow is rejected at any stage (label validation failure, DLP, malware, Guard DENY). NDR is returned to the originating sender; the destination never sees the rejected message. CDS Implemented
PKCS#1 / RFC 8017 RSA Cryptography Specifications RSA-OAEP key encapsulation and RSA signature algorithms. RSA-OAEP-SHA256 for ACP-240 DEK wrapping, RSA-PSS-SHA256 for the signature the KAS returns over its rewrap result. The client generates a fresh RSA-2048 keypair for every rewrap request, so a released key is encrypted to that request alone. Elliptic-curve KAS keys are supported as an alternative to RSA, and the KAS private key may be held in an HSM over PKCS#11. Windows CDS Implemented
FIPS 197 Advanced Encryption Standard (AES) AES block cipher; AES-GCM authenticated encryption mode. AES-256-GCM for ACP-240 payload encryption. Unique 96-bit IV per file. GCM authentication tag provides integrity verification of the ciphertext. Windows Implemented
RFC 9449 OAuth 2.0 Demonstrating Proof of Possession (DPoP) Binds an access token to a key held by the client, so a token intercepted in transit cannot be replayed by anyone else. Every /rewrap request carries an ES256 DPoP proof covering the method, the URI and a hash of the access token. The KAS refuses any request without one, checks the proof against the token, and keeps a replay cache of proof identifiers shared across the fleet. Windows Implemented
ADatP-5663 Federated Identity and Access Management How a subject's clearance, Community-of-Interest membership and citizenship are expressed as identity claims across a federation. Tokens carry the ADatP-5663.4 claim names, with clearance as a structured ADatP-4774 clearance object rather than a flat string. Citizenship is enforced, not merely recorded. Partner identity providers are brokered through the local OIDC provider. Windows Implemented
RFC 5280 X.509 Public Key Infrastructure and CRL Profile Certificate and certificate-revocation-list formats, and the rules for validating a certification path. The label-binding CA issues per-document signing certificates and publishes a real X.509 CRL. Consumers reject stale and replayed CRLs, and an unobtainable revocation status is a configurable decision rather than a silent pass. Windows CDS Implemented

Interoperability

Standards-body testing and interoperability verification.

Programme Description Tessera Status
CWIX Coalition Warrior Interoperability eXploration, eXperimentation, eXamination and eXercise — annual NATO interoperability exercise for testing coalition communications and information sharing standards. CWIX SPIFs included. ACP-240 interoperability test vectors verified against published examples. Test harness provided for standalone testing and validation.
Bold Quest US-led multinational coalition interoperability exercise assessing data-centric security and information-sharing capabilities across participating nations. ACP-240 interoperability test vectors produced.

Standards Compliance Is an Ongoing Process

NATO standards continue to evolve. Tessera tracks compliance against each standard and maintains a gap-remediation log documenting known deviations and the planned remediation for each. Where a standard has multiple implementation profiles, the profile in use is documented.

Learn how security labels work