PDS or Encryption? Choosing the Right Secure-Link Control

When protecting classified or sensitive data in transit, understanding the difference between a Protected Distribution System and encryption—and knowing when each applies—is essential for federal facility designers and security engineers.

By Todd Taskerud, AWS CCP, RCDD/NTS/OSP/WD, LEED GA
5 min read

PDS or Encryption? Choosing the Right Secure-Link Control

Two Paths to Secure Transmission—and Why the Choice Matters

Network designers tasked with securing classified government communications routinely face a fork in the road: install a Protected Distribution System (PDS) to safeguard the physical link, rely on encryption to protect the data itself, or deploy a layered combination of both. Getting that decision wrong can mean failed inspections, costly rework, or—far worse—an undetected compromise of classified information. This article walks through the governing frameworks, the real-world trade-offs, and the product options that Heather Technologies can bring to bear on each approach.

What Is a Protected Distribution System?

A PDS is a US government–defined architecture that allows classified information to traverse a physical medium without encryption, provided the pathway itself delivers sufficient physical and electromagnetic safeguards to prevent interception or tampering. The governing authority is the Committee on National Security Systems; the current standard is CNSSI No. 7003 (2015), which superseded the earlier NSTISSI No. 7003 (1996). Any facility or program office referencing the older document should update its documentation and inspection criteria accordingly.

CNSSI No. 7003 defines several PDS categories, most notably:

  • Hardened Distribution System (HDS) — rigid metallic conduit or equivalent that resists penetration and provides a high degree of emanations control.
  • Simple Distribution System — a baseline pathway with defined inspection and construction requirements but without continuous monitoring.
  • Alarmed Carrier — conduit equipped with continuous monitoring (typically acoustic or pressure sensing) that can detect an intrusion attempt in near-real time and trigger an alert or automated protective response.

It is equally important to know what PDS does not cover. TEMPEST—the discipline concerned with unintentional electromagnetic emanations from equipment—is a separate, parallel requirement. A properly constructed PDS protects the transmission line from physical attack; it does not, by itself, address the radiated emissions from the endpoints. Programs with stringent TEMPEST requirements must address both independently.

PDS and the Physical-Layer Standards

Because PDS is built around conduit and pathways, it intersects directly with ANSI/TIA-569 (pathways and spaces) for routing and bend-radius compliance, and with ANSI/TIA-607 (bonding and grounding) when metallic conduit systems must be bonded to the Telecommunications Main Grounding Busbar (TMGB) or Telecommunications Grounding Busbar (TGB). Labeling and documentation of PDS segments should conform to ANSI/TIA-606 so that inspection personnel can rapidly identify and audit every link. Cable jacket ratings—plenum (CMP) or riser (CMR) as required by NEC/NFPA 70—still apply inside the conduit system.

On the media side, fiber is frequently preferred for classified runs because optical fiber carries no electrical signal and therefore offers an inherently lower emanations profile than copper. ANSI/TIA-568.3-D governs optical-fiber cabling and components, including multimode grades OM3, OM4, and OM5 (laser-optimized 50/125 µm) and singlemode OS1/OS2. For copper-based PDS segments, ANSI/TIA-568.2-D governs balanced twisted-pair categories from Cat 5e through Cat 8; shielded constructions such as F/UTP or S/FTP are typically specified to reduce radiated emissions within the conduit.

Alarmed Carrier PDS: Continuous Monitoring in Practice

The Alarmed Carrier category is where modern sensor technology meaningfully advances the PDS model. Rather than relying solely on periodic physical visual inspections (PVIs), an Alarmed Carrier system monitors the conduit continuously—detecting acoustic, vibrational, or other anomalies that indicate an intrusion attempt—and can automate the documentation required under CNSSI No. 7003.

Heather Technologies partners with CyberSecure IPS, whose Alarmed Carrier PDS solution embeds acoustic-sensing fiber inside the conduit alongside the signal cable. Any penetration attempt generates a detectable disturbance; the system triggers an alarm and automatically logs the event to streamline PVI reporting and compliance documentation against CNSSI No. 7003 requirements. For program managers who need to demonstrate continuous compliance rather than point-in-time inspection records, this automation significantly reduces administrative burden and audit risk.

Encryption: Protecting Data Regardless of Physical Path

Encryption secures the data itself, meaning a compromised physical link still yields only ciphertext to an adversary. For many programs, National Security Agency–approved Type 1 encryption is the mandated control for classified traffic, and it can traverse virtually any physical medium—fiber, copper, or wireless—without requiring the conduit infrastructure of a PDS. Encryption is also the only practical option for wide-area and off-premises segments where a PDS cannot be constructed or inspected.

The trade-off is operational complexity and latency. Cryptographic devices require key management, periodic re-keying, and certified maintenance. For high-throughput data-center interconnects operating under ANSI/TIA-942 redundancy requirements, the overhead of inline encryption must be factored into bandwidth and availability budgets.

PDS vs. Encryption: A Decision Framework

Criterion PDS (Alarmed Carrier) Encryption (Type 1 / Approved)
Governing authority CNSS / CNSSI No. 7003 (2015) NSA / program-specific ICD
Protects against Physical line tap / intrusion Data exposure at any point
Infrastructure required Conduit, sensors, inspection regime Crypto device, key management
Media flexibility Limited to routed pathway Any medium, including WAN/wireless
TEMPEST coverage No (separate requirement) No (separate requirement)
Continuous monitoring Yes (Alarmed Carrier) Via key/session management
Best fit Intra-facility classified links Off-premises, WAN, all segments

Layered Deployments: When Both Are Required

Many accrediting authorities require encryption and a PDS for the most sensitive compartmented programs. In these architectures, the PDS provides physical assurance at the link layer while encryption ensures that any residual risk from an undetected physical compromise does not result in data exposure. Designing both in concert from project inception—coordinating conduit routing per ANSI/TIA-569, grounding per ANSI/TIA-607, and media selection per ANSI/TIA-568.3-D or ANSI/TIA-568.2-D as appropriate—avoids the costly retrofits that arise when security requirements are bolted on after construction.

Engage Early, Design Right

The most common and expensive mistake I see in secure-facility projects is treating PDS as a conduit procurement decision rather than a system design decision. CNSSI No. 7003 imposes specific construction, inspection, and documentation requirements that touch every trade on the project—low-voltage cabling, electrical (NEC/NFPA 70), structural, and security systems. Bringing an RCDD and a cleared security engineer to the table at schematic design—not at closeout—is the single highest-value action a program office can take.

Heather Technologies and our partners, including CyberSecure IPS, are available to support pre-design consultations, conduit system specification, and compliance documentation strategy. Contact your Heather Technologies account team to start the conversation.


About the author — Todd Taskerud, AWS CCP, RCDD/NTS/OSP/WD, LEED GA, is a BICSI-credentialed communications distribution designer at Heather Technologies, specializing in fiber, copper, and data-center network infrastructure.