Talent, operations, and allied/private depth
A large cyber force, world-class technology sector, threat-sharing institutions, and close intelligence allies give the United States many defensive and offensive pathways.
The cyber and electromagnetic contest is genuinely unresolved. The United States fields a large, mission-ready Cyber Mission Force and benefits from an unmatched private-sector and allied defense ecosystem, but the PRC has demonstrated persistent access to U.S. telecommunications and critical infrastructure, can exploit a vast and uneven defense supply chain, and integrates cyber and electronic warfare within a theater-focused information architecture.
The judgment separates force size from protected mission output. U.S. Cyber Command reports its presented forces mission ready, while GAO documents nearly 440 DOD cyber organizations and 61,000 personnel. Those are real strengths, but not proof that mobilization, weapons, logistics, or spectrum-dependent missions survive attack. Observed PRC pre-positioning, CMMC's incomplete three-year rollout across a 200,000-company industrial base, organizational overlap, and immature comparative EW measures prevent a U.S. edge.
A large cyber force, world-class technology sector, threat-sharing institutions, and close intelligence allies give the United States many defensive and offensive pathways.
Volt Typhoon, Salt Typhoon, and compromised edge devices show a strategy of living inside civilian and military-adjacent networks that enable mobilization.
DOD depends on roughly 200,000 companies while certification, zero trust, asset visibility, and small-business assistance remain incomplete.
Grade cyber and EW by whether priority operational threads continue and recover under representative compromise—not by compliance, headcount, or software installed.
Drivers are adjudicated separately so parallel strengths, dependencies, bottlenecks, and contrary evidence remain visible. The overall call is not a mechanical average.
Publicly attributed PRC campaigns demonstrate long-lived access to telecommunications, critical infrastructure, and edge devices intended to support espionage and potential disruption before conflict.
Public reporting exposes discovered campaigns, not the full balance of access; U.S. offensive operations and adversary losses are mostly classified.
U.S. Cyber Command reports mission-ready forces with current operational integration, and DOD maintains a large professional cyber structure.
The commander also states the force is insufficiently scaled for the threat, while public readiness measures do not establish effect quality or persistence.
A 200,000-company defense industrial base and essential civilian infrastructure create a broad, uneven attack surface that current certification and assistance programs have not yet covered.
CMMC, Project Spectrum, NSA services, sector regulation, and strong private defenders provide a scalable response; PRC access does not guarantee destructive effect.
DOD has made substantial zero-trust and cyber-planning progress, but gaps remain in business systems and cross-organizational command-and-control integration.
Twenty of 24 assessed major IT business programs reported a zero-trust implementation plan, and operational networks may outperform the sampled business portfolio.
The PLA deliberately integrates cyber, electronic warfare, and technical reconnaissance. The United States possesses advanced systems but public evidence does not show comparative threat-to-field update time or joint spectrum outcome under attack.
The Air Force is funding integrated reprogramming and DOD has created joint spectrum governance and training mechanisms; classified performance may be stronger.
U.S. public-private defenders regularly expose PRC campaigns, but discovery after prolonged access and the lack of mission-recovery metrics make comparative resilience uncertain.
Joint advisories, threat intelligence, endpoint defense, and exercise networks create learning advantages that static breach counts understate.
Cyber and EW do not form one serial pipeline. Persistent access, force employment, industrial defense, spectrum adaptation, and recovery act in parallel and intersect at specific mission dependencies. Each is therefore adjudicated independently.
Consequence-selected mission or capability chains drive the call.
Each fact is connected to a rule, bucket, and comparative effect.
Missing or incomparable evidence stays visible instead of becoming zero.
Mission effectKeep telecommunications, energy, transportation, water, and logistics available to mobilize and deploy forces.
Analytical scopeConfirmed access, affected sectors, persistence, detection, segmentation, and recovery—not speculative worst cases.
Action priorityRemove PRC latent leverage
Observed Volt and Salt Typhoon activity demonstrates that PRC actors have achieved strategic access in networks the U.S. would need during crisis; the public record does not show complete eviction or assured mission continuity.
Joint intelligence, mandatory logging, phishing-resistant identity, segmentation, clean recovery environments, and sector exercises can turn discovery into durable denial.
The number of still-compromised networks, operational technology reach, access persistence, and U.S. access inside PRC systems are classified or unknown.
U.S. and allied agencies confirmed Volt Typhoon compromises in communications, energy, transportation, and water systems, including U.S. territories, and assessed with high confidence that the access supported potential disruptive effects during crisis.
4 named critical-infrastructure sectorsConfirmed persistent access across multiple required civilian sectors is a current strategic exposure even before destructive action occurs.
Creates the strongest PRC leverage in the cyber assessment.
The 2025 multi-agency advisory attributes a global PRC campaign targeting backbone and edge routers across telecommunications, government, transportation, lodging, and military infrastructure networks and maintaining long-term access.
Access to communications infrastructure used by many downstream missions receives greater weight than a single enterprise breach.
Strengthens the PRC access edge and creates cross-domain consequences.
Targeting and access do not establish successful wartime disruption or complete provider compromise.
The Defense Department reported a 2024 PRC operation that infected approximately 200,000 internet devices to create infrastructure useful for hiding and routing cyber operations.
200000 compromised internet devicesA six-figure compromised-device network materially improves evasion and scale, while device count is not treated as mission effect.
Raises detection and attribution burden on U.S. defenders.
The report does not disclose how many devices remained controlled or operationally useful.
Mission effectDefend assigned terrain, support combatant commands, disrupt adversary systems, and integrate cyber effects with joint operations.
Analytical scopePresented mission teams, staffing, training, command, tools, and observed operational integration—not total personnel alone.
Action priorityExploit the U.S. edge
The United States has the more transparent, mature, and globally integrated operational cyber force, but scale and organizational complexity keep it below a lead.
Service-like authorities, direct readiness reporting, role-based training, and AI-enabled tooling can increase team output without simply adding headquarters.
Cyber effects, access, mission success, tool reliability, and PLA force readiness are mostly classified and not symmetrically measurable.
The Cyber Command commander reported in 2026 that all service cyber components and presented forces remained mission ready and that readiness data feed the Defense Readiness and Reporting System.
Command-certified mission readiness with formal reporting is direct force evidence, but is bounded by the lack of public outcome and scale metrics.
Supports a U.S. edge in operational cyber forces.
Commander testimony is official self-reporting and omits classified standards and shortfalls.
GAO identified nearly 440 DOD organizations with about 61,000 military and civilian personnel plus more than 9,500 contractors conducting cyberspace operations.
~61000 + >9500 personnel and contractorsA large, specialized force is a comparative enabler, not a performance score; readiness and effect must be demonstrated separately.
Provides depth behind the U.S. operational edge.
The count includes diverse organizations and DODIN functions and is not comparable to opaque PLA staffing.
Cyber Command stated that the current force meets readiness standards but is insufficiently scaled for the threat environment.
A ready force explicitly assessed below threat-driven scale receives an edge, not a lead.
Caps the U.S. force advantage.
Mission effectProtect designs, production, maintenance, logistics, and software dependencies from theft or disruption.
Analytical scopeRelevant suppliers, verified controls, assessors, secure services, incident sharing, and continuity—not compliance paperwork alone.
Action priorityClose the coverage gap
The breadth of the DIB exceeds current verified defense. CMMC is now rolling out, but the three-year phase and external assessor constraints leave a large, heterogeneous exposure.
Shared secure cloud services, free NSA defense, Project Spectrum, priority-tier sequencing, and contract-enforced reporting can concentrate protection where compromise matters most.
Public data do not show how many critical suppliers meet each control level, actual incident rates, or PRC access inside the DIB.
DOD relies on roughly 200,000 private companies for goods and services, many of which store sensitive information in their own systems.
200000 DIB companiesA six-figure supplier base with decentralized systems creates a structural defense challenge unless criticality and verified controls are known.
Supports a PRC edge in exploitable industrial exposure.
Not every company holds the same data or supports the same mission criticality.
CMMC implementation began as a three-year phased rollout, while GAO found DOD had not fully assessed external factors such as whether enough private assessors would be available.
3 years in planned rolloutA multi-year verification rollout with unresolved assessor capacity is a current coverage gap, not evidence that unassessed firms are insecure or secure.
Preserves the DIB resilience weakness while recognizing active remediation.
Contract phasing and required CMMC level vary by company.
Project Spectrum had 21,535 registered participants as of July 2025, and NSA's Cybersecurity Collaboration Center served approximately 1,600 participants across its services as of August 2025.
21535 / ~1600 registered participantsParticipation demonstrates scalable mitigation but cannot be treated as secured coverage, because programs provide partial assistance and populations overlap.
Shows U.S. defensive depth without erasing the coverage gap.
Registration is not control implementation; participant populations are not directly comparable or additive.
Mission effectKeep command links, sensors, seekers, platforms, and spectrum access effective as adversaries exploit or change signatures.
Analytical scopeZero trust, network segmentation, mission data, EW reprogramming, spectrum planning, distribution, and field loading.
Action priorityShorten threat-to-field time
The United States has advanced cyber and EW technology and is modernizing reprogramming, but public evidence does not establish joint threat-to-field speed or mission performance against the PLA's integrated cyber/EW force.
Open interfaces, common reprogramming equipment, software delivery, and the Joint Electromagnetic Spectrum Operations Center create practical pathways.
Actual update latency, signature coverage, platform loading, spectrum denial, and operational effectiveness are classified.
Of 24 major DOD IT business programs assessed by GAO, 20 reported plans to implement zero trust, while four had not developed plans and two lacked an approved cybersecurity strategy.
20 of 24 programs with zero-trust implementation plansBroad but incomplete planning is a positive current condition; plans without implementation or outcome do not establish resilient service.
Keeps network architecture contested.
The sample covers major business systems, not all combat networks or weapon systems.
The Air Force's fiscal 2026 Electromagnetic Warfare Integrated Reprogramming effort is a $5.24 million new start intended to repair and modernize existing reprogramming programs and the wider EW enterprise.
$5.24M FY2026 RDT&E requestA new-start modernization effort identifies an existing operational need but remains an enabler until update latency and fielded effect improve.
Shows a U.S. response without changing the current EW rating.
Budget request is not delivered software, equipment, or measured reprogramming speed.
The 2025 PRC report assigns cyber, electronic warfare, and technical reconnaissance to the Cyberspace Force; no public source provides comparable U.S./PLA time-to-reprogram or mission success in a representative contested spectrum.
Organizational integration establishes adversary intent and capacity, but mission superiority requires measured operational outcomes.
Prevents either side from receiving an EW lead from organizational claims alone.
Mission effectContinue or rapidly restore priority military and infrastructure functions after compromise and disruption.
Analytical scopeAsset knowledge, telemetry, containment, clean recovery, manual alternatives, data integrity, exercises, and mission restoration time.
Action priorityMake resilience observable
U.S. defenders demonstrate strong campaign discovery and sharing, but long adversary dwell and limited public mission-recovery evidence prevent a defensive advantage.
Allied advisories, commercial telemetry, central logging, clean-room recovery, and operational continuity exercises create learning and substitution advantages.
Time-to-detect, time-to-evict, reinfection, restored mission service, and PRC defensive performance are not publicly comparable.
U.S. and allied agencies published detailed joint technical advisories on Volt and Salt Typhoon activity, including observed tactics and concrete mitigations.
Multi-agency, multinational technical attribution demonstrates a defensive learning network, but discovery does not prove full eviction or recovery.
Provides a U.S./allied offset in resilience.
GAO found nearly 440 DOD cyber organizations and potential overlap in service training and administration of 23 cybersecurity service providers.
23 DOD cybersecurity service providersIntentional redundancy can improve resilience, but unmeasured overlap and duplicate services reduce speed and accountability until roles and outcomes are clear.
Offsets part of the U.S. institutional-depth advantage.
Public sources do not report how quickly priority DOD, DIB, and mobilization services return to a trusted minimum level after representative persistent compromise and infrastructure disruption.
Device remediation, compliance, and exercise participation cannot substitute for end-to-end restored mission service.
Keeps detection and recovery contested.
Lead time is an implementation attribute—not a forecasted future rating. Every action has an owner, prerequisite, and observable completion test.
A uniform compliance rollout across 200,000 companies cannot protect the most consequential production and mobilization nodes quickly enough.
Map priority mission threads to named suppliers and infrastructure dependencies; sequence verified controls, hunt support, shared secure services, logging, segmentation, and clean recovery around consequence and substitutability.
PrerequisitesAuthoritative supplier graph, mission criticality tiers, contract data rights, and protected incident sharing.
Verify successEvery priority mission thread has verified controls, current telemetry, an exercised clean-recovery path, and a qualified substitute for its highest-consequence dependencies.
Control compliance and device cleanup do not show whether command, logistics, fuel, transportation, and weapons functions continue under attack.
Run persistent-adversary exercises from initial access through operational technology, corrupted data, denied communications, manual fallback, clean restoration, and reinfection; score minimum mission output and recovery time.
PrerequisitesRepresentative environments, safety controls, shared mission metrics, and authority to test cross-organization dependencies.
Verify successPriority mission threads sustain or restore trusted output inside specified thresholds with primary networks and external services compromised.
A large force and nearly 440 organizations can mask critical skill gaps, duplicate services, and slow mission ownership.
Map operational demand to standardized work roles, qualification, tool access, deployable teams, and outcome ownership; eliminate or deliberately justify overlapping training and service-provider functions.
Platform sophistication is wasted when signatures, techniques, software, distribution, and loading cannot update at operational speed.
Use common data contracts, government-accessible interfaces, automated verification, distributed labs, secure delivery, and platform telemetry to measure every step from observed emitter change to fielded mission data.
PrerequisitesReleasable signature data, interface rights, test capacity, configuration control, and allied distribution agreements.
Verify successRepresentative threat changes produce validated and loaded multi-platform updates inside the required operational latency under degraded communications.
Linked threadsCY-T4
The finding comes first. Open this section to inspect composition rules, evidence limitations, and every source record.
The assessment evaluates current cyber and electronic-warfare capacity using credible public evidence through August 5, 2026. Discovered access, verified force readiness, and fielded defenses receive more weight than strategy, planned controls, or requested software.
Threads are included when they represent distinct operational outcomes: pre-crisis access, force employment, industrial defense, cyber/EW adaptation, and mission recovery.
Offense, defense, resilience, and spectrum adaptation are parallel contributors with mission-specific dependencies. Personnel, breaches, controls, and organizations are not averaged into a black-box score.
Confirmed campaigns, independent oversight, official readiness reporting, and observed defensive mechanisms are distinguished from inferred access, compliance plans, and budget intent.
Classified offensive effects, accesses, readiness criteria, EW performance, and recovery exercises remain unknown. Publicly exposed PRC campaigns do not imply absent U.S. access, and that unknown is not scored.
Primary use: PRC cyber campaigns, force organization, EW integration, device infrastructure, and conflict objectives.
Known limitation: Unclassified threat assessment; accesses, methods, readiness, and U.S. comparisons are partly undisclosed.
Open public source ↗Primary use: Confirmed Volt Typhoon access, targeted sectors, assessed intent, and mitigations.
Known limitation: Victim and operational details are limited; publication date precedes later remediation.
Open public source ↗Primary use: Salt Typhoon-related backbone and edge-router activity, persistence, affected sectors, and mitigations.
Known limitation: Technical advisory does not quantify all victims, dwell time, or full remediation status.
Open public source ↗Primary use: DIB size, CMMC rollout, assessor risk, Project Spectrum, and NSA service participation.
Known limitation: Program participation and rollout plans do not directly measure company security or mission consequence.
Open public source ↗Primary use: Cyber organization, personnel, contractor, team, service-provider, and overlap evidence.
Known limitation: Organizational counts include varied missions and do not measure operational effectiveness.
Open public source ↗Primary use: Force readiness, scale, operational integration, authorities, and current priorities.
Known limitation: Commander self-assessment omits classified standards, effects, and detailed shortfalls.
Open public source ↗Primary use: Zero-trust planning, cybersecurity strategy, software, and performance-reporting evidence.
Known limitation: Sample covers 24 major business programs rather than all operational or weapon networks.
Open public source ↗Primary use: EW reprogramming modernization, program scope, new-start status, and requested funding.
Known limitation: Budget request and program intent do not establish delivered speed or operational effect.
Open public source ↗Primary use: Joint spectrum governance, JEC responsibilities, training, operational gap analysis, and external coordination.
Known limitation: Governance and planning structures do not provide comparative EW performance metrics.
Open public source ↗The public JSON contains the executive judgment, drivers, decisive threads, observations, actions, limitations, and source records.
This applied layer substantiates the current call without projecting future ratings or silently changing the core ten-area dataset. Compare the core capability record →