Sovereign Communications Procurement: Questions to Ask Before You Buy
Before buying a sovereign communications solution, ask whether it can support secure coordination before, during, and after an isolation event, including manual operations, personnel accountability, partner reporting, and recovery.
Sep 25, 2026
·Blog
·Secure Communications
What separates marketing claims from proven performance? Peter Weiler and Chris Greco from BlackBerry discuss how certifications help procurement leaders make informed, confident decisions.
Price is the easiest number to compare on a procurement scorecard, but it can also be the most misleading. A solution that looks affordable at signing may carry costs that surface only after deployment, including exposure to foreign jurisdiction laws, outdated certifications, or service failures when primary infrastructure goes down.
For government agencies and critical infrastructure operators, those costs are measured in operational risk, not just budget overruns. The wrong choice can increase the risk of exposing classified conversations, personnel locations, and strategic decisions to unauthorized access.
This guide outlines the procurement questions that matter most when assessing a sovereign communications vendor. It also helps buyers compare common delivery models, including government-owned platforms, commercial off-the-shelf solutions, and deployment approaches that place infrastructure, keys, and operations under approved national control while preserving the ability to coordinate when normal networks are isolated or unavailable.
Sovereign Control and the Long-Term Operating Model
Governments are right to demand sovereign control over communications. The procurement question is which approach delivers it without creating a long-term operating burden your agency is not equipped to maintain.
Does the solution require your organization to build and maintain the platform?
A government-built or adapted platform can offer control, but it also makes the government responsible for patching, upstream code tracking, recertification, roadmap decisions, liability, 24/7 operations, and specialized talent retention.
Can the model meet sovereignty requirements without shifting control away from government?
Whether the approach is government-built, commercial, hybrid, or managed, it should make clear who controls infrastructure, encryption keys, approvals, support, and long-term maintenance.
Does the platform protect more than messaging?
Secure mission-critical communications include the message, the endpoint it runs on, and the ability to coordinate action across agencies that may not share a chain of command. A procurement review should test whether the solution covers the full mission, not just encrypted chat.
What Security Certifications Should a Sovereign Solution Hold?
Certifications give you a way to verify security claims through independent validation. A vendor can claim government-grade security; an accredited body confirming it carries more weight.
“The real question is who verified it, what standard was it verified against, how is the product evaluated?” —Peter Weiler, Senior Director, Product Security at BlackBerry
Which independent certifications does the solution hold?
Look for validation from recognized authorities such as NATO, NIAP, FIPS, Common Criteria, and FedRAMP, where those standards apply to the product and deployment model. These certifications signal that an independent body tested the solution against a defined standard rather than accepting the vendor's assurances. Consumer messaging apps and general enterprise collaboration tools may not provide the same validation profile required for highly regulated environments, especially when they remain cloud-dependent at their core.
Are the certifications current and regularly audited?
A certification earned five years ago against a retired standard tells you little about today's threats. Ask when each certification was last renewed and how often the vendor undergoes third-party audits. Certification is a process, not a plaque.
“Certifications are an investment. They take time. They take money to maintain.” —Peter Weiler
Does the vendor disclose audit results?
A vendor willing to share independent audit findings gives you another concrete signal about how the vendor actually operates.
Where Is Your Data Stored and Who Controls the Keys?
Sovereignty is where many communications solutions fall short. Encryption alone does not prevent legal or operational exposure if the keys, infrastructure, or administrative controls sit outside your organization's authority.
“It really comes down to, does the customer control their data?” —Chris Greco, Vice President, Product Management & User Experience at BlackBerry
Where is your data stored, and who has access?
Data hosted in a foreign jurisdiction may be subject to that jurisdiction's laws. Frameworks such as the U.S. CLOUD Act and GDPR can create legal or regulatory obligations that affect how data is handled, even when the customer operates elsewhere. Ask exactly where data resides and which entities, including the vendor, can access it.
Can the vendor prevent unauthorized external access to communications?
This is the practical test of sovereignty. Vendors that rely on external infrastructure may not be able to give customers complete control over data location, encryption keys, and operational dependencies.
“Residency does not equal sovereignty.” —Chris Greco
Who owns the encryption keys and infrastructure?
Genuine sovereign control means the customer controls the security model: encryption keys, identity verification, infrastructure, policies, and audit records. Vendor support should not equal vendor custody.
Are sovereign deployment options available in your region?
Confirm the vendor can support your required jurisdiction, data residency needs, and hosting location. Ask whether on-premises, dark site, hybrid cloud, or private cloud options are available in your region, with local support and service commitments that meet your security and compliance requirements.
How Does the Solution Perform During a Crisis?
A communications platform proves its value when things go wrong. Ask how it behaves when networks fail, infrastructure is strained, or primary systems are under attack, not just on a normal day.
How does the solution perform during network outages, isolation events, or infrastructure failures?
Adversaries target communication channels precisely because disruption creates opportunity. Ask for specifics on failover behavior and multi-channel delivery across SMS, voice, desktop alerts, mobile, and channels independent of the compromised network.
What redundancy measures ensure continuous operation?
Confirm the platform has redundant infrastructure, alternate delivery paths, geographic failover, backup notification channels, offline-ready rosters and escalation paths, and tested recovery procedures. Ask how often these measures are tested under simulated outage conditions and what service commitments apply during extended isolation or degraded network conditions.
Can the platform function independently if primary IT systems are compromised?
Out-of-band communication matters most during a cyberattack, when your primary network may be the thing under attack. A solution that relies on the same infrastructure being attacked may provide little value during a crisis.
Can teams coordinate manual operations after isolation?
CI Fortify readiness depends on more than disconnecting compromised systems. Ask whether operators can coordinate the shift from automated to manual control, manage handoffs, and continue shift changes using channels that do not rely on enterprise email, chat, directories, or collaboration tools.
Can incident commanders notify and account for personnel in real time?
During an isolation event, delivery confirmation is not enough. The platform should support two-way responses so leaders know who is safe, on site, unavailable, or unreachable, including field and non-desk staff.
Can the organization report status to external partners while isolated?
Critical infrastructure incidents often require updates to state authorities, federal agencies, sector risk-management agencies, mutual-aid partners, and neighboring operators. Ask whether the solution supports secure, auditable reporting channels that do not route through the network being isolated.
Has the organization tested beyond the moment of disconnection?
A tabletop exercise that ends when the network is isolated leaves the hardest questions unanswered. Ask vendors how their platform supports drills that continue through manual operations, personnel accountability, partner reporting, extended outages, and recovery.
“You need to be able to trust the solution. You need to be able to trust the partner you're getting the solution from.” —Peter Weiler
Has the Vendor Been Trusted by Governments and Critical Operators?
A vendor's history with high-stakes clients tells you more than any product demo. Mission-critical operations reveal whether a platform holds up under real pressure.
Has the vendor been trusted by governments and critical infrastructure operators?
Look for evidence of adoption across government, defense, emergency response, and critical infrastructure environments where secure communications are mission-critical. Long-term deployments, customer references, and published case studies can show whether the vendor has been trusted in comparable operating conditions. Current certifications, including NIAP and NATO, can further support that record, but they should reinforce demonstrated adoption rather than stand in for it.
What is the vendor's history supporting mission-critical operations?
Ask how long the vendor has operated in environments comparable to yours. Supporting classified, regulated, or crisis-response communications requires a different level of discipline than hosting a general enterprise chat tool.
Are published case studies or references available?
Request references from organizations facing challenges similar to your own. Peers who have deployed the solution under real conditions offer perspective no sales conversation can match.
How Well Does the Solution Integrate and Scale?
The strongest platform still fails if it cannot fit your environment or grow with your needs. Integration and scalability determine whether adoption succeeds or stalls.
How easily does the solution integrate with existing systems?
Cross-platform compatibility matters, especially where legacy phone and communication systems remain in place. A solution that ignores your current infrastructure creates friction that pushes users toward unsecured workarounds.
Can the platform scale across multiple agencies, regions, or departments?
Confirm the solution can extend across federated agencies, partners, and field teams so everyone works from the same operational picture. Fragmented communications undermine both security and response.
What is the total cost of ownership?
Look past the license fee to implementation, ongoing support, and training. When a solution is difficult to use, employees often turn to shadow IT, undermining the security controls you intended to strengthen.
“A vendor claim isn't evidence. It's marketing.” —Peter Weiler
For each answer, ask the vendor for supporting documentation, not just verbal confirmation. Certification records, audit summaries, architecture diagrams, deployment models, isolation-event playbooks, drill results, service-level commitments, key-management details, and customer references can help you compare vendors consistently and defend the final decision.
Making a Procurement Decision You Can Defend
“Meeting a mission critical standard is not defined by what a vendor claims. It's defined by what a trusted independent authority has validated.” —Peter Weiler
Choosing the right vendor takes more than comparing a price sheet. The questions above help you assess whether a platform can support the level of sovereign control, certification, resilience, accountability, and lifecycle responsibility your environment requires. Bring these questions to every vendor conversation. The strongest procurement decisions make the trade-offs visible before you commit to any delivery model and test whether communications can continue when isolation becomes necessary.
What is the difference between COTS and GOTS for sovereign communications?
Government off-the-shelf typically means the government owns or adapts a platform and takes on more responsibility for operations, patching, certification, and improvement. Commercial off-the-shelf typically means buying a product from a vendor, then assessing whether the deployment model gives the customer enough control over infrastructure, keys, support, and compliance obligations.
What does "sovereign" mean in sovereign communications?
Sovereign communications means your organization retains control over its data, encryption keys, and infrastructure within the jurisdiction and deployment model it chooses. The goal is to reduce reliance on foreign-controlled systems and limit external access to sensitive communications.
Why do security certifications matter for government procurement?
Certifications provide independent validation that a solution has been tested against defined security standards. Bodies such as NATO, NIAP, FIPS, Common Criteria, and FedRAMP assess solutions against rigorous benchmarks, giving your team evidence beyond vendor claims. For classified or mission-critical environments, this validation may be a procurement or compliance requirement.
Are encrypted messaging apps like Signal or WhatsApp suitable for government use?
These apps provide encrypted messaging but may lack the certification profile, centralized policy control, and compliance visibility required for highly regulated government environments. Encryption alone does not necessarily provide sovereign control over data residency or keys, which can create exposure under foreign jurisdiction laws depending on how the service is deployed and governed.
What is the risk of choosing a cloud-dependent communications provider?
Cloud-dependent providers may store encryption keys, data, or administrative controls on infrastructure outside the customer's direct authority, sometimes in foreign jurisdictions. As mentioned above, this can create legal and operational exposure under frameworks such as the U.S. CLOUD Act and GDPR, and may limit the customer's ability to control who can access sensitive communications.
How does CI Fortify change communications procurement?
CI Fortify pushes buyers to assess whether communications can survive isolation, not just whether a platform works during normal operations. That means evaluating manual operations coordination, personnel notification and accountability, independent reporting channels, tested failover, and recovery procedures.
%3Aquality(100)&w=3840&q=75)