wonna know something?
so there's a company called cellcrypt which (was) actually NSA certified. they're trying to get certified again, it's expected to come out of testing soon.
but they wrote this artical which is now archived https://web.archive.org/web/20250126023940/https://www.cellcrypt.com/post/consumer-secure-messaging-apps-are-not-the-solution for those that can't parse hyperlinks. they basically argue against public infrastructure (reasonible) yet they now have an offering which uses public infrastructure.
are you for it, or are you against it? com e on, make up your mind!
@kkarhan #infosec #cybersecurity #security #encryption #cellcrypt #niap #nsa
Quantum-Safe Encrypted Calls & Messaging | Cellcrypt

Military-grade encrypted calls, messaging and file transfer with dual-layer post-quantum protection (Kyber + Classic McEliece). Built for government, defence and regulated enterprises.

Cellcrypt
NIAP: Compliant Product

NIAP-CCEVS manages a national program for the evaluation of information technology products for conformance to the International Common Criteria for Information Technology Security Evaluation.

It would be a great accelerator for #sbom adoption if there was a way to leverage them to accelerate #NIAP / #FIPS / #FedRAMP

If one was able to digitally attest to known approved versions of software libraries in their SBOM, you would think it could reduce their certification burden.

The current NIAP/CC/FedRAMP process is endlessly broken and this could be a great way to start to modernize it.