Top 7 Data Diodes for NCSC CAF Compliance and Protective Monitoring in 2026
UK operators of essential services face a hard requirement under the NCSC Cyber Assessment Framework (CAF). They must detect cyber security events without opening a return path into the systems they protect. Objective C of the CAF asks organizations to prove continuous security monitoring. This is often called protective monitoring, and it spans OT, ICS, and classified networks. Firewalls and access control lists rely on software rules. Those rules can be misconfigured or bypassed. A data diode removes that risk at the hardware level. It physically enforces one-way data flow. Telemetry, logs, and historian data can then leave a protected network with no return channel possible.
This guide compares seven vendors building hardware-enforced unidirectional transfer for CAF-aligned monitoring, NIS Regulations compliance, and wider critical infrastructure protection. Each entry below covers throughput, certification, and deployment model so you can match the right diode to your network.
Data Diode Vendors at a Glance
| Vendor | Key Feature / Strength | Max Throughput |
|---|---|---|
|
Diode capability integrated into existing TAP and packet broker chassis |
– |
|
|
Largest OT/ICS connector library, self-contained gateway software |
Up to 10 Gbps |
|
|
NCDSMO-listed cross domain solutions, DoD and Intelligence Community heritage |
Up to 2.5 Gbps |
|
|
Common Criteria EAL 7+ certified, defense-grade cross domain portfolio |
– |
|
|
Common Criteria EAL4+, approved for classified data up to Top Secret |
Up to 10 Gbps |
|
|
SPAN-based hardware diode, low-cost entry point for OT segmentation |
Up to 1 Gbps |
|
|
Sub-millisecond latency, Common Criteria EAL4+, MITRE ATT&CK for ICS mapping |
Up to 10 Gbps |
Network Critical
Network Critical brings data diode capability into the same hardware family that already handles network TAP and packet broker duties. Teams do not need a separate appliance for every unidirectional requirement. They can deploy a standalone hardware data diode module instead. Or they can configure diode behavior directly on the SmartNA-PortPlus or SmartNA-XL platforms they may already run for visibility. Network Critical states sub-millisecond latency and 99% reliability in high-throughput environments. Protocol-agnostic support across IP-based traffic removes the configuration overhead that protocol-specific diodes often introduce.
This approach matters most for sites where rack space, power, and cabling tolerance are tightly constrained. That covers OT sites, remote substations, and platform environments. A site already running SmartNA-XL for traffic visibility can configure unidirectional data flow on the same chassis. There is no need to rack and manage a separate diode appliance. The hybrid TAP-plus-broker design also reduces the change-management surface area. This matters for IEC 62443 segmentation projects and CAF Objective C evidence gathering alike.
Proven results:
- State of Maryland: Deployed SmartNA-XL to maintain quality of service across its unified communications network while meeting government monitoring requirements
- BP: Used passive fiber TAPs to enable centralized monitoring of IT and OT systems across refinery buildings with zero impact on production traffic
- Darktrace: Integrated SmartNA-PortPlus via API to feed full-fidelity traffic into automated threat detection for faster anomaly response
Waterfall Security Solutions
Waterfall Security Solutions pioneered the unidirectional gateway category. It remains one of the most widely deployed names in OT and ICS security. Its flagship WF-600 gateway offers 1 Gbps or 10 Gbps throughput options with standard high-availability configurations. The platform is self-contained and runs as gateway software. It needs no additional hosts on either network. Waterfall's connector library covers most industrial control systems, SCADA platforms, and OT data products. This simplifies integration compared with diodes that need custom proxy development for every protocol. The company positions its gateways as a direct replacement for one layer of firewalls at the IT and OT boundary. That pitch resonates strongly in energy, water, and manufacturing procurement conversations across UK critical national infrastructure.
Owl Cyber Defense
Owl Cyber Defense is a US government-validated provider of data diode and cross domain solutions. Its products are built on patented DualDiode Technology. Products including the OCDS-FT01 and ECDS-FT01 appear on the National Cross Domain Strategy Management Office (NCDSMO) baseline inventory. Throughput options range from 155 Mbps up to 2.5 Gbps depending on the accredited configuration selected. Owl's diodes are used for intelligence, surveillance, and reconnaissance feeds. They also support command-and-control telemetry and continuous SOC and SIEM monitoring, with no inbound path exposed into the protected network. The company also publishes case studies covering historian replication, where OT data moves one-way into enterprise analytics platforms. Its strength lies in mission-grade assurance for defense and critical infrastructure environments. Evaluated, Common Criteria-aligned components are often a procurement requirement in this space.
BAE Systems
BAE Systems brings defense-grade credibility to the data diode space through its Cross Domain Solutions (CDS) portfolio. The Data Diode Solution supports unidirectional transfer of files, streaming data, and email. It converts information into sequenced packets that cross the diode and reconvert on the receiving side. It carries Common Criteria EAL 7+ certification and NCDSMO baseline approval. That is the highest assurance tier commonly cited in this market. BAE Systems also offers the XTS Diode, a Raise-The-Bar-compliant one-way transfer device. It is built to integrate with the company's XTS Guard cross domain architecture. UK buyers running programs under JSP 440 or equivalent assurance frameworks will find BAE Systems relevant. Sovereign supply chain and deep accreditation support are non-negotiable requirements for these programs, not nice-to-haves.
Advenica
Advenica is a Swedish high-assurance vendor. Its SecuriCDS range serves government and critical infrastructure customers up to Top Secret classification. The DD1000A model is a hardware-only diode using optical transmitter and receiver separation. It has no software installed, so there is nothing to misconfigure. The DD1G Gen 2 offers full Gigabit throughput with Power over Ethernet support for space-constrained sites. The DDSFX-10G ships in an SFP form factor for 10 Gbps environments. Advenica's products carry Common Criteria EAL4+ certification. They also hold approvals from national authorities including Sweden's Armed Forces and Austria's National Communication Security Authority. The company also offers VPN encryptors and cross domain security tools. This gives customers a single supplier for layered segmentation architecture.
Garland Technology
Garland Technology sells a SPAN-compatible hardware data diode line. It is built for critical infrastructure environments such as utility substations, manufacturing facilities, and metro locations. Models like the P1GCSSP1X3 support 10/100/1000M network speeds. They regenerate a SPAN port to multiple connected monitoring tools while enforcing one-way flow through physical hardware separation. This is a purpose-built, lower-cost approach compared with defense-grade cross domain solutions. It suits operators who need straightforward SPAN-to-monitoring protection rather than multi-classification data exchange. Garland's existing OT security partner ecosystem includes Nozomi Networks, TXOne, Dispel, EmberOT, and Radiflow. This gives buyers a path to pair the diode with broader ICS threat detection.
OPSWAT
OPSWAT brought data diode capability into its MetaDefender platform following its acquisition of Fend. This extended an established OT cybersecurity portfolio with hardware-enforced one-way transfer. The MetaDefender Optical Diode supports up to 10 Gbps transfer over fiber. Published testing shows latency around 0.6 milliseconds for TCP traffic. It carries Common Criteria EAL4+ certification and is positioned against MITRE ATT&CK for ICS techniques. Supported industrial protocols include Modbus, OPC, IEC 104, DNP3, and AVEVA PI historian feeds. The DIN rail model extends deployment into ruggedized industrial cabinets. The 1U rack model suits data center and control room environments. OPSWAT's breadth of protocol and framework alignment makes it a frequent shortlist candidate. This helps operators managing multiple jurisdictional requirements at once.
How to Choose the Right Data Diode for CAF and Protective Monitoring
Selecting a data diode for NCSC CAF alignment means matching assurance level, throughput, and integration model. Base that match on your actual data flows, not your network's headline speed. The criteria below reflect what UK CNI operators and government buyers weigh most heavily during procurement.
Certification and Assurance Level
Check which standards your sector or regulator actually requires before comparing vendors. Government and defense buyers typically need NCDSMO or Raise-The-Bar compliance. Critical infrastructure operators look for Common Criteria EAL4+ as a practical baseline. Some vendors publish IEC 62443 alignment directly. This can shorten CAF Objective B and C evidence gathering.
Throughput Versus Actual Data Volume
Match the diode's rated throughput to your actual data volume, not your network's overall link speed. Most OT-to-IT diode traffic consists of logs, historian data, and telemetry rather than full-rate production traffic. Oversizing wastes budget. Undersizing forces you to queue or drop data at the boundary.
Deployment Model and Existing Infrastructure
Decide whether you need a standalone diode appliance or diode behavior configured onto visibility infrastructure you already operate. A hybrid TAP and packet broker approach can fold diode-enforced ports into a chassis already deployed for monitoring. This reduces rack space, cabling, and change-management overhead in space-constrained OT cabinets.
Protocol and Tool Integration
Some diodes pass raw data only. Others recognize and securely handle specific industrial protocols such as Modbus, OPC, or DNP3. That distinction affects how much configuration work your team faces at rollout. Confirm the vendor's connector library covers your historians, SCADA platforms, and SIEM or NDR tools before committing. Custom proxy development adds cost and delay to a project timeline.
Total Cost of Ownership
Factor in integration engineering, companion software for protocol mediation, accreditation support, and ongoing maintenance. Do not judge cost on the hardware list price alone. Vendors offering perpetual licensing avoid the recurring per-port fees that can inflate multi-site CNI deployments over a three-year budget cycle.
Sovereign Supply Chain and Support
UK and European buyers increasingly weight sovereign manufacture and support presence. This matters most for programs subject to data sovereignty requirements or JSP 440-style assurance frameworks. Confirm whether the vendor holds current NCSC recognition. Check whether it can be procured through Crown Commercial Service or an equivalent framework.
Frequently Asked Questions
What Is a Data Diode?
A data diode is a hardware device that physically enforces one-way data flow between networks of differing trust levels. A firewall or access control list relies on software rules that can be misconfigured or exploited. A data diode enforces unidirectional communication at the hardware level instead, with no return path.
How Does a Data Diode Support NCSC CAF Compliance?
A data diode primarily supports CAF Objective C, which asks organizations to demonstrate continuous security monitoring and anomaly detection. It lets logs, telemetry, and historian data leave an OT or classified network with no possibility of a return channel. This gives auditors evidence that protective monitoring cannot itself become an attack path.
Do I Need a Data Diode or a Cross Domain Solution?
A hardware-only data diode enforces unidirectional flow and nothing more. A cross domain solution adds content inspection, protocol validation, and policy enforcement on top of that hardware barrier. Most enterprise and government CAF deployments benefit from a full gateway approach rather than a diode alone.
How Much Does a Data Diode Cost?
Data diode pricing depends heavily on assurance level, throughput, and whether accreditation support is included. Defense-grade cross domain solutions with Common Criteria EAL 7+ certification cost significantly more. SPAN-based hardware diodes built for OT segmentation sit at the lower end of that range. Total cost of ownership should also include integration engineering and ongoing maintenance, not hardware price alone.
Can a Data Diode Be Bypassed or Hacked?
A properly implemented data diode is extremely difficult to bypass. It is physical hardware with no software interface to exploit. Poor implementation or side-channel attacks could still pose a risk. This is why independent assurance review matters as much as the underlying hardware.
Does a Data Diode Support Bidirectional Protocols Like TCP?
No, a true data diode does not support bidirectional protocols such as TCP handshakes. That would require a return path the hardware is designed to eliminate. Vendors work around this using protocol breaks or proxy systems on each side of the diode. This is why network TAPs and packet brokers are often deployed alongside a diode rather than instead of one.
Build Your Protective Monitoring Architecture With Network Critical
Choosing the right data diode shapes how confidently you can demonstrate CAF Objective C evidence. That confidence matters most during a GovAssure or regulator review. Network Critical's hybrid approach lets you configure hardware-enforced one-way transfer directly on the SmartNA-PortPlus platform. Many teams already run that platform for traffic visibility. There is no need to add a separate appliance and a separate support contract. That single-chassis model uses perpetual licensing instead of a subscription. It keeps deployment simple for teams who cannot risk production disruption during rollout.
Speak to the Network Critical team to walk through a hybrid TAP, packet broker, and data diode configuration. Find out how it fits your CAF Objective C evidence requirements.