Release Gates for Sensitive Systems · 1 of 2

Releasing secure communications equipment

← All Insights

In short

  • For partners outside NATO other than Australia and New Zealand, wanting interoperability does not justify a COMSEC release.
  • A general release is not limited by quantity or tied to one weapon system.
  • When required, NSA answers an authorization request within 30 days.
Published1 October 2026
Last reviewed1 October 2026
Sources current as of1 October 2026

1. What the terms cover

Command, control, communications, computer, intelligence, surveillance and reconnaissance (C4ISR) systems collect and disseminate information, under the Security Assistance Management Manual (SAMM) (SAMM C3.7.3.1.1). They include intelligence and command networks, systems that build the common operational picture, and the information assurance products and standards that secure the exchange. The manual names two key aspects: access to secure networks controlled by information security products, and the classified data processed on those networks.

Information security (INFOSEC) protects information systems against unauthorized access, modification and denial of service, and is applied through cybersecurity and communications security (SAMM C3.7.3.1.2). Communications security (COMSEC) covers cryptographic, transmission, emission and physical security of the material (SAMM C3.7.3.1.3). COMSEC devices are designated Controlled Cryptographic Items (CCIs). A CCI is approved by the National Security Agency (NSA) and contains cryptographic logic, but depends on host equipment to complete the function (SAMM C3.7.3.1.4). An unkeyed CCI is unclassified. An item may be a CCI as a whole, such as an inline network encryptor, or because it embeds an NSA Type 1 module, such as a secure radio.

2. Who does what before a request

The manual sets out each organization’s role in a table (SAMM C3.7.3.2). The Security Cooperation Organization (SCO) tells the host country that requests for these systems need sponsorship from the North Atlantic Treaty Organization (NATO) or a Combatant Command (CCMD). It coordinates the requirement with the CCMD and the Defense Security Cooperation Agency (DSCA) before the Letter of Request (LOR), then forwards the request. The purchaser signs a bilateral Communications and Interoperability Security Memorandum of Agreement (CISMOA) or another binding agreement. It also asks for a dedicated facility staffed by two American-accredited COMSEC custodians.

The CCMD establishes the interoperability requirement and starts the release process, and on delegation negotiates and signs the CISMOA for nations outside NATO other than Australia and New Zealand (SAMM C3.7.3.2). DSCA reviews the requirement with NSA and the CCMD and, as appropriate, assigns the lead implementing agency (IA). IAs need DSCA approval before processing such a request. NSA identifies the security solution and writes the sales case for American INFOSEC products. In limited circumstances it lets a military department include them on its own case. The Chairman of the Joint Chiefs of Staff validates the requirement.

3. Which release route applies

Release of COMSEC products and information to foreign governments is a deliberately careful decision by the Committee on National Security Systems and NSA’s deputy national manager (SAMM C3.7.3.3.2). Transfers are approved only where there is a clearly defined benefit to American foreign policy, military, intelligence or economic objectives. For NATO, its members, Australia and New Zealand, release follows a committee policy and allied agreements govern what is released (SAMM C3.7.3.3.2.1).

For everyone else, release follows a Joint Chiefs instruction (SAMM C3.7.3.3.2.2). A nation’s wish to be interoperable, or to support a weapon sale, is not enough. Justification normally rests on a CCMD need to communicate securely with the partner, or on foreign policy objectives. The CCMD usually validates the requirement at a bilateral interoperability board, then starts a COMSEC release request. A CISMOA nation that later joins NATO gets a different note on its offers. DSCA adds the COMSEC enhanced end-use monitoring note for NATO members, Australia and New Zealand to future basic offers that add COMSEC equipment, and to new amendments and modifications of offers implemented before it joined (SAMM C3.7.3.3.2.3). How release approvals in principle and in specific gate offers is covered in anti-tamper and system release requirements.

4. The general release

A release in specific is needed for most communication devices sold with platforms, such as secure radios and tactical data links (SAMM C3.7.3.3.2.2.2). A general release is a variant that does not limit quantity or tie approval to one weapon system. The manual says it may be available for the Simple Key Loader in all variants, Mode 5 friend-or-foe identification, and two other key loaders (SAMM C3.7.3.3.2.2.2.1).

A country with an approved general release for a device can obtain it in any quantity when it is integrated in or used with American weapon systems (SAMM C3.7.3.3.2.2.2.1.1). It buys through NSA-authorized channels without further release approvals. It also needs no NSA authorization to sell for price and availability data or offer packages, where the products are used with American systems. The list of such countries is held by DSCA and is not for public or foreign release.

5. Systems that need more than COMSEC approval

Interoperable systems that exchange classified information need a disclosure review under the National Disclosure Policy (SAMM C3.7.3.3.1). All data flowing between foreign and secure American C4ISR systems is classified. Disclosure approval must come before the offer or price data is issued. Some equipment needs further interagency, service or multinational approvals as well (SAMM C3.7.3.3.4). The manual names the Multifunctional Information Distribution System low volume terminal, the Link-22 data link, precise positioning Global Positioning System (GPS) equipment and radio waveforms, and says early planning with the CCMD is crucial.

Positioning equipment has its own rule. Precise positioning GPS user equipment is not COMSEC or CCI, and release of that equipment and of anti-jam technology is decided by the Defense Department’s Chief Information Officer (SAMM C3.7.3.3.3). IAs must verify a recipient is authorized to receive it before transfer (SAMM C3.7.3.4.3). Encrypted precise positioning mode needs approval from the Air Force’s GPS production organization in the offer package. Network enabled weapons are guided munitions with datalinks for retargeting and handoff (SAMM C3.7.7). Those with NSA Type 1 encrypted links need COMSEC release and NSA authorization to transfer, on top of other approvals (SAMM C3.7.7.1).

6. Getting NSA’s answer

The Director of NSA is the national manager for INFOSEC products, including embedded cryptographic modules (SAMM C3.7.3.4). The IA for a device is set by its acquisition manager. NSA may let some of its products appear on another IA’s case case by case, but not where NSA has no existing case of its own. Special purpose “S” type COMSEC goes to nations outside NATO, other than Australia and New Zealand, only on NSA-managed cases (SAMM C3.7.3.4.1).

Except where a general release applies, every IA, even one that buys the device, must ask NSA whether a product is releasable and whether another IA’s offer may include it (SAMM C3.7.3.4.2). The request includes the LOR, the nomenclature, quantities and the platform. When a response is required, NSA gives it within 30 days as an authorization to sell for the offer package. Cross domain solutions follow the same route (SAMM C3.7.8.2). These devices pass information between security domains, and must be tested and certified by NSA, with its approval before they are offered (SAMM C3.7.8.1). Where a government classifies its request for these products, classifying the whole case is avoided where possible (SAMM C3.7.3.4.4).

Key terms

COMSECThe measures that deny unauthorized people information from telecommunications.
Controlled Cryptographic ItemAn NSA-approved device with cryptographic logic that relies on host equipment.
CISMOAThe bilateral security agreement a purchaser signs for secure communications products.
General releaseA COMSEC release not limited by quantity or tied to one weapon system.
Authorization to sellNSA’s written approval to include a product on a sales offer.

Every statement above links to the document behind it. The full source list for this piece is on the sources page.

This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.

How Sentfore supports this

Secure communications matter as much on the ground as in the systems sold. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.