Guide
Who does end-use monitoring of Controlled Cryptographic Items sold through Foreign Military Sales?
always carry enhanced end-use monitoring, and who performs it depends on who holds them. , its member nations, Australia and New Zealand assess and report under their own policies; for other international organizations and nations that have signed a Communications Interoperability and Security or like agreement, U.S. custodians funded through the case do it; for nations that have not, the Office does, reporting to its .
Who does end-use monitoring of Controlled Cryptographic Items sold through Foreign Military Sales?
International partners who receive through the must establish accounts and have an appointed custodian in their country. The custodian assumes accountability for the equipment or materiel upon receipt, then controls its dissemination to authorized individuals on job requirements and a need-to-know basis.
Every purchaser agrees in the LOA that the U.S. Government may verify how the articles it buys are used, transferred and secured; end-use monitoring under Golden Sentry, the DoW program DSCA administers, is how that verification is done. Routine end-use monitoring applies to every government-to-government transfer unless an article is designated for Enhanced EUM, which adds serial-number inventories, certified storage sites and security and accountability notes in the LOA. A designation starts with a MILDEP or Implementing Agency request, or an interagency or Congressional recommendation, and DSCA and State PM review and approve it; which articles are designated is not listed in the public SAMM, and none are named here.
References
SAMM
- SAMM GLOSSARY/controlled-cryptographic-items-cci — Controlled Cryptographic Items (CCI)
- SAMM C8.4.5.1.1
- SAMM C8.4.5.1.2
- SAMM C8.4.5.1.3
- SAMM C8.4.5.1.4
- SAMM C3.7.3.3.2.3 — Non-North Atlantic Treaty Organization Member Nations, Except Australia and New Zealand, with Access to Communications Security, Joining the North Atlantic Treaty Organization.
- SAMM C7.3.5.1.1 — North Atlantic Treaty Organization.
DSCA policy memoranda
- DSCA 24-07 — DSCA Policy Memo 24-07 — Communications Security Letter of Offer and Acceptance Note Change for Communications and Information Security Memorandum of Agreement Nations Joining North Atlantic Treaty Organization
Related
Controlled Cryptographic Items (CCI)
CCIs are devices that embody cryptographic logic or other cryptographic design, but do not perform the entire Communications Security (COMSEC) function. CCIs are dependent upon host equipment or assemblies to complete and operate COMSEC functions. Un-keyed CCI is unclassified. An item may be designated CCI because its entire component is controlled (e.g. Inline Network Encryptor (INE)), or because the item contains an embedded cryptographic National Security Agency (NSA) Type-1 certified module to encrypt/de-encrypt information (e.g. secure radio).
SAMM Glossary, as of 12 September 2026
Glossary entry →Open the manual’s entry → (opens in new tab)
Memorandum of Agreement (MOA)
An agreement between sovereign states or international organizations that is legally binding under international law.
SAMM Glossary, as of 12 September 2026
Glossary entry →Open the manual’s entry → (opens in new tab)
Security Cooperation
Activities undertaken by the DoD to encourage and enable international partners to work with the United States to achieve strategic objectives. It includes all DoD interactions with foreign defense and security establishments, including all DoD-administered security assistance programs, that: build defense and security relationships that promote specific U.S. security interests, including all international armaments cooperation activities and security assistance activities; develop allied and friendly military capabilities for self-defense and multinational operations; and provide U.S. forces with peacetime and contingency access to host nations.
SAMM Glossary, as of 12 September 2026
Glossary entry →Open the manual’s entry → (opens in new tab)
Combatant Command (CCMD)
A unified or specified command with a broad continuing mission under a single commander established and so designated by the President, through the Secretary of Defense and with the advice and assistance of the Chairman of the Joint Chiefs of Staff. Also called CCMD.
SAMM Glossary, as of 12 September 2026
Glossary entry →Open the manual’s entry → (opens in new tab)
CCI — Controlled Cryptographic Item
SAMM Acronyms, as of 12 September 2026
Communications Security (COMSEC)
The measures and controls taken to deny unauthorized persons’ information derived from telecommunications and other information systems, and technologies necessary to ensure the authenticity of such communications. COMSEC includes cryptographic security, transmission security, emissions security, and physical security of COMSEC material. Secure telecommunication or information system cryptographic components are the primary COMSEC products for transmission security and commonly called COMSEC devices or products. COMSEC devices are designated Controlled Cryptographic Items (CCI).
SAMM Glossary, as of 12 September 2026
Glossary entry →Open the manual’s entry → (opens in new tab)
COMSEC — Communications Security
SAMM Acronyms, as of 12 September 2026
CISMOA — Communications Interoperability and Security Memorandum of Agreement
SAMM Acronyms, as of 12 September 2026
FMS — Foreign Military Sale
SAMM Acronyms, as of 12 September 2026
SCO — Security Cooperation Organization
SAMM Acronyms, as of 12 September 2026
LOA — Letter of Offer and Acceptance
SAMM Acronyms, as of 12 September 2026
DSCA — Defense Security Cooperation Agency
SAMM Acronyms, as of 12 September 2026
Glossary entry →Defense Security Cooperation Agency (DSCA) →