What is a cross-domain solution?

Moving data between a secret network and a less secret one, without joining them together.

By Ihor Havrysh ยท Last reviewed July 2026

Eaglepedia mascot

A cross-domain solution is an accredited system for moving data between networks held at different security classifications, allowing information to be shared without connecting the networks to each other. It combines hardware separation, content filtering and policy enforcement, and is used mainly in defence, government and critical infrastructure.

The requirement it exists to serve

Organisations that classify information end up running more than one network. A higher-classification network holds sensitive material and is kept apart from everything else; a lower one carries ordinary business traffic and may reach the internet.

The difficulty is that the work does not respect the boundary. Intelligence from the open network is needed on the secure side. Reports produced on the secure side need releasing, in redacted form, to partners who cannot be given access. Sensor readings, imagery, logistics data and maintenance schedules all need to cross.

Connecting the networks would collapse the distinction the classification exists to maintain. Refusing to connect them makes people work around the problem, usually with removable media, which is exactly the route that has historically carried malware into isolated environments. A cross-domain solution exists to provide the third option: a narrow, heavily controlled, accredited path for the specific data that is permitted to travel.

What one is made of

A cross-domain solution is a system rather than a box, and current guidance is emphatic on that point. The NCSC's framework describes cross domain not as a single boundary appliance but as an end-to-end pipeline of layered control points spread across multiple zones of trust.

The layers typically include:

  • Hardware separation. A data diode enforcing that traffic can physically travel in one direction only
  • Protocol break. The incoming transmission is terminated, the payload extracted and a fresh transmission started on the other side, so nothing about the original protocol carries through
  • Content filtering and validation. Checking that data really is the format it claims, that its structure is well formed and that it satisfies policy
  • Sanitisation. Transforming and rebuilding files to remove metadata and active content, so what arrives is reconstructed in a safe form
  • Policy enforcement and audit. Rules about which classifications, formats and data types may move, and a complete record of everything that did

Flows are directional by design. An import flow, moving data from a lower classification to a higher one, is principally worried about integrity: what might be arriving. An export flow, going the other way, is principally worried about confidentiality: what might be leaking. Where both are needed, they are built as two discrete flows rather than as one two-way channel, because the controls on each are genuinely different.

Cross-domain solution as five layered stages between two classifications, with separate import and export flows
Import and export are built as two discrete flows because the question each one answers is not the other one reversed.

Accreditation is the defining feature

What separates a cross-domain solution from an assembly of security products is that it is assessed against a formal standard and approved for a specific use.

In the United States, the National Security Agency's National Cross Domain Strategy and Management Office oversees this. Its Raise the Bar strategy sets expectations for the design, development, assessment, implementation and use of cross-domain solutions, and applies both to those protecting US Government classified information and to those sold for export. The office also maintains security requirements and runs a testing programme.

In the UK, products can be assessed under the NCSC's Commercial Product Assurance scheme, with approvals changing over time as products are evaluated and certifications renewed.

The practical consequence is that these are procured, deployed and operated as accredited capabilities with a lifecycle attached. That is appropriate for the environments they serve, and it is also why they are a poor fit for anything outside them.

Do you need one?

For the overwhelming majority of organisations, no, and it is worth being direct about that because the language around cross-domain security can make it sound like a general answer to accepting files safely.

You need a cross-domain solution when you are moving data between networks at formally different classifications and are obliged to demonstrate that against an accreditation standard. That is defence, national security, parts of government and some critical national infrastructure.

If your actual requirement is that customers, suppliers or the public send you documents and you would like those documents not to hurt you, then the layer you want is the sanitisation one, without the accreditation apparatus around it. That capability is the same idea, applied at a different scale: rebuild the file from components that carry legitimate content, and discard the rest.

Our guide to how the file sanitisation market splits covers the four ways it is sold, including the high-assurance route, and where each one could be the right choice.

The same principle, without the accreditation programme. Sanitisation is the layer inside a cross-domain solution that deals with the file itself. The Red Eagle Tech CDR API offers it as a straightforward HTTPS call with published per-document pricing, so you can rebuild documents from their safe components and be running in minutes.

Frequently asked questions

Two requirements that pull against each other. An organisation holds information at different classifications on separate networks, and people on both sides need to share some of it. Connecting the networks would defeat the classification; keeping them apart stops the work. A cross-domain solution provides a controlled, inspected, accredited path for the specific data that is allowed to move.

A data diode is usually a component within one rather than a solution in itself. The diode enforces the direction of travel in hardware. A cross-domain solution adds the filtering, content inspection, format validation and policy enforcement that decide whether a particular piece of data is allowed to make the trip at all.

It is the US National Security Agency's strategy for improving the security of cross-domain solutions, run through its National Cross Domain Strategy and Management Office. It sets design, development, assessment and implementation expectations, and applies to solutions protecting US Government classified information as well as those sold for export. If you encounter the phrase in a product datasheet, that is what it refers to.

An import flow moves data from a lower classification to a higher one, and its main concern is integrity: what might be arriving. An export flow moves data the other way, and its main concern is confidentiality: what might be leaking. The two need different controls, which is why a bidirectional capability is built as two separate flows rather than as a two-way channel.

Almost certainly not. Cross-domain solutions are built for formally classified environments, they carry accreditation requirements, and they are procured and operated accordingly. If your requirement is to accept files from customers or suppliers safely, the control you are looking for is content inspection and sanitisation, which is available as an ordinary service without any of that overhead.
Ihor Havrysh - Software Engineer at Red Eagle Tech

About the author

Ihor Havrysh

Software Engineer

Software Engineer at Red Eagle Tech with expertise in cybersecurity, Power BI, and modern software architecture. I specialise in building secure, scalable solutions and helping businesses navigate complex technical challenges with practical, actionable insights.

Read more about Ihor

Discovery call

A friendly 15-minute video call with Kat to understand your needs. No preparation needed.

  • Discuss your project
  • Get honest advice
  • No obligation
Kat Korson, Founder of Red Eagle Tech

Kat Korson

Founder & Technical Director

Our team has 10+ years delivering software solutions for growing businesses across the UK.

Send us a message

Your information is secure. See our privacy policy.

Find us