As an Amazon Associate, RMF Insider earns from qualifying purchases.
If you handle CUI or classified data as a cleared professional, “just buy an external drive” is not good enough. Data-at-rest protection is a control, not a convenience feature, and NIST SP 800-53 SC-28 spells out what your organization actually has to show an assessor. This guide covers the hardware-encrypted drives for cleared work that hold up under that scrutiny, plus where a consumer-grade drive quietly falls short.
I have carried external drives through security checkpoints, justified them in system security plans, and watched an assessor ask “is that FIPS validated?” mid-review. The honest answer changes what you should buy.
Why SC-28 Matters More Than the Marketing Copy
SC-28 (Protection of Information at Rest) requires organizations to protect the confidentiality and integrity of information stored on system components. In practice, on a DoD system, that usually means encryption — but not just any encryption. The control enhancement SC-28(1) calls for cryptographic protection, and depending on your authorizing official’s interpretation and your system’s categorization, that can mean FIPS 140-2 or FIPS 140-3 validated cryptographic modules specifically, not just “AES-256” on a spec sheet.
This is where a lot of ISSOs get tripped up. A drive can advertise AES-256 encryption and still not satisfy a FIPS-validation requirement, because FIPS validation is about the specific cryptographic module being tested and certified by NIST’s CMVP program — not just the algorithm being used somewhere in the chain.
Two Different Categories, Two Different Use Cases
There are effectively two tiers of “encrypted” external storage relevant to cleared work:
- Consumer-grade encrypted SSDs — fast, affordable, cross-platform, but relying on software or firmware AES that is not independently FIPS validated.
- FIPS-validated hardware-encrypted drives — built around a dedicated crypto module with an actual CMVP certificate number you can hand to an assessor.
Which one you need depends on your system’s SSP language, your AO’s risk tolerance, and honestly, what the drive is actually being used for. A drive that never touches CUI and stays inside a SCIF for backups is a different risk conversation than one that leaves the building.
Samsung T7 Shield: Fast, Rugged, and Honest About Its Limits
The Samsung T7 Shield 2TB and the Samsung T7 Shield 4TB are the drives I actually reach for day to day. IP65 water and dust resistance, a 9.8-foot drop rating, and sequential speeds around 1,050 MB/s make it a genuinely good field drive for moving large evidence packages, imaging files, or backup sets.
Here is the part the marketing page will not tell you clearly: the T7 Shield’s encryption is AES 256-bit, but it is not a FIPS 140-2 or 140-3 validated module. That distinction matters if your SSP or your organization’s data-at-rest policy specifically requires validated cryptography rather than just “encryption is enabled.” For a lot of unclassified, non-CUI use cases — personal backup, moving public releasable files — this is a non-issue. For anything touching CUI where SC-28(1) is explicitly cited, it can be a finding.
If you want the same speed and ruggedness without the encryption question mark, the standard Samsung T7 1TB is worth considering too — it drops the IP65 rating but keeps the same performance profile at a lower price point, useful for a secondary or non-CUI drive.
Where a FIPS-Validated Drive Like the Apricorn Aegis Fits In
Apricorn’s Aegis line (Padlock and Secure Key series) is built specifically for this gap. These drives use a dedicated hardware encryption chip with a physical keypad, no software or drivers required, and — critically — FIPS 140-2 validated cryptographic modules on the models built for government and enterprise use. That is the line an assessor is looking for when your control narrative says “FIPS-validated” instead of just “encrypted.”
I am not linking a specific Aegis ASIN here because I could not verify current listing data with confidence, and I would rather point you toward the right search terms than risk sending you to the wrong SKU. Search “Apricorn Aegis Secure Key” or “Apricorn Aegis Padlock” directly on Amazon or through your organization’s approved vendor, and confirm the FIPS certificate number against NIST’s CMVP validated modules list before you buy — the cert number should be printed on the product page, and you can cross-check it yourself in about two minutes.
The tradeoff: Aegis drives cost more per gigabyte, top out at lower capacities than the T7 line, and the physical keypad, while convenient for cross-platform use with zero software install, is one more thing that can fail or be fumbled under time pressure.
Comparison Table: Consumer-Grade vs. FIPS-Validated
| Drive | Encryption | FIPS Validated | Best For |
|---|---|---|---|
| Samsung T7 (1TB) | AES 256-bit (software/firmware) | No | Non-CUI files, general backup, speed |
| Samsung T7 Shield (2TB/4TB) | AES 256-bit (software/firmware) | No | Field use, rugged non-CUI storage |
| Apricorn Aegis Padlock/Secure Key | AES 256-bit hardware module | Yes (check cert per model) | CUI, SC-28(1) control language, audit trail |
How to Actually Decide Which One You Need
Before you buy anything, pull up your system’s SSP and read the SC-28 and SC-28(1) control implementation statements as written. If the language says “the system employs FIPS-validated cryptography to protect information at rest on removable media,” a T7 Shield does not satisfy that statement no matter how good the marketing sounds. If the language is more general — “removable media is encrypted at rest” — a T7 Shield with BitLocker or the built-in software encryption may be defensible, but confirm with your ISSM before you rely on it.
A few practical questions worth asking yourself:
- Does this drive ever touch CUI, or is it strictly for non-sensitive personal or public data?
- Does my SSP or organizational policy specifically cite FIPS validation, or just “encryption”?
- Will this drive leave a controlled facility, and does that change the risk calculus?
- Am I buying this for myself, or is it going on an inventory list an assessor will eventually see?
If you cannot answer these confidently, it costs nothing to ask your ISSM directly before the purchase gets made — it is a much shorter conversation than explaining a finding six months later.
Documenting the Drive in Your SSP
Buying the right drive is only half the job. If a removable storage device is part of your system boundary or your data-at-rest story, it needs to show up somewhere in your documentation — not just live in a desk drawer as an assumption. A few things worth tracking:
- Make, model, and serial number, tied to an asset inventory entry.
- Encryption method and, if applicable, the FIPS certificate number.
- Who is authorized to use it and what data classes it is approved to hold.
- Sanitization procedure if the drive is ever repurposed or retired.
Assessors have seen the “we encrypt everything, trust us” answer before, and it does not hold up. A drive with a documented FIPS certificate and a paper trail is a five-minute conversation. A drive with neither turns into a POA&M line item, and now you are tracking remediation instead of just using the tool.
A Note on Physical Handling
Encryption protects the data if the drive is lost or stolen, but it does not replace physical accountability. Treat any drive that has touched CUI as if it were a controlled item: log when it leaves a facility, log when it comes back, and do not let “it’s encrypted anyway” become the reason nobody tracks it. Assessors care about the control being implemented and evidenced — not just technically true.
The Bottom Line
For speed, ruggedness, and day-to-day non-CUI use, the Samsung T7 Shield is genuinely excellent hardware and I use it regularly. But it is not a substitute for a FIPS-validated drive when your control language demands one. Know which document you are writing to before you swipe a card, and when in doubt, treat “encrypted” and “FIPS-validated” as two different claims — because on a DoD system, they are.
For more on how controls like SC-28 fit into the bigger authorization picture, see our RMF step-by-step guide.

Leave a Reply