← Capability assessment Applied current-state analysis

Cyber & electronic warfare

The cyber and electromagnetic contest is genuinely unresolved. The United States fields a large, mission-ready Cyber Mission Force and benefits from an unmatched private-sector and allied defense ecosystem, but the PRC has demonstrated persistent access to U.S. telecommunications and critical infrastructure, can exploit a vast and uneven defense supply chain, and integrates cyber and electronic warfare within a theater-focused information architecture.

Evidence cutoff · August 5, 2026 5 decisive threads 15 applied observations 4 ranked actions
Current comparative call

Contested

Moderate confidence
PRC leadContestedU.S. / credible-allied lead
Why this call

The judgment separates force size from protected mission output. U.S. Cyber Command reports its presented forces mission ready, while GAO documents nearly 440 DOD cyber organizations and 61,000 personnel. Those are real strengths, but not proof that mobilization, weapons, logistics, or spectrum-dependent missions survive attack. Observed PRC pre-positioning, CMMC's incomplete three-year rollout across a 200,000-company industrial base, organizational overlap, and immature comparative EW measures prevent a U.S. edge.

Strongest U.S. advantage

Talent, operations, and allied/private depth

A large cyber force, world-class technology sector, threat-sharing institutions, and close intelligence allies give the United States many defensive and offensive pathways.

Most dangerous PRC leverage

Persistent access before crisis

Volt Typhoon, Salt Typhoon, and compromised edge devices show a strategy of living inside civilian and military-adjacent networks that enable mobilization.

Binding U.S. weakness

The attack surface is larger than verified defense

DOD depends on roughly 200,000 companies while certification, zero trust, asset visibility, and small-business assistance remain incomplete.

Decision

Measure recovered mission output

Grade cyber and EW by whether priority operational threads continue and recover under representative compromise—not by compliance, headcount, or software installed.

Current advantage profile

Where the edge actually sits.

Drivers are adjudicated separately so parallel strengths, dependencies, bottlenecks, and contrary evidence remain visible. The overall call is not a mechanical average.

CY-D1 · High confidence

Persistent access & offensive positioning

PRC edge
PRC advantageU.S. / credible-allied advantage

Publicly attributed PRC campaigns demonstrate long-lived access to telecommunications, critical infrastructure, and edge devices intended to support espionage and potential disruption before conflict.

Contrary evidence and caveat

Public reporting exposes discovered campaigns, not the full balance of access; U.S. offensive operations and adversary losses are mostly classified.

CY-D2 · Moderate confidence

Cyber force readiness & operational mastery

U.S. edge
PRC advantageU.S. / credible-allied advantage

U.S. Cyber Command reports mission-ready forces with current operational integration, and DOD maintains a large professional cyber structure.

Contrary evidence and caveat

The commander also states the force is insufficiently scaled for the threat, while public readiness measures do not establish effect quality or persistence.

CY-D3 · High confidence

DIB and critical-infrastructure resilience

PRC edge
PRC advantageU.S. / credible-allied advantage

A 200,000-company defense industrial base and essential civilian infrastructure create a broad, uneven attack surface that current certification and assistance programs have not yet covered.

Contrary evidence and caveat

CMMC, Project Spectrum, NSA services, sector regulation, and strong private defenders provide a scalable response; PRC access does not guarantee destructive effect.

CY-D4 · Moderate confidence

Mission-network architecture & zero trust

Contested
PRC advantageU.S. / credible-allied advantage

DOD has made substantial zero-trust and cyber-planning progress, but gaps remain in business systems and cross-organizational command-and-control integration.

Contrary evidence and caveat

Twenty of 24 assessed major IT business programs reported a zero-trust implementation plan, and operational networks may outperform the sampled business portfolio.

CY-D5 · Low confidence

Electromagnetic sensing, attack & reprogramming

Contested
PRC advantageU.S. / credible-allied advantage

The PLA deliberately integrates cyber, electronic warfare, and technical reconnaissance. The United States possesses advanced systems but public evidence does not show comparative threat-to-field update time or joint spectrum outcome under attack.

Contrary evidence and caveat

The Air Force is funding integrated reprogramming and DOD has created joint spectrum governance and training mechanisms; classified performance may be stronger.

CY-D6 · Low–moderate confidence

Detection, response & mission recovery

Contested
PRC advantageU.S. / credible-allied advantage

U.S. public-private defenders regularly expose PRC campaigns, but discovery after prolonged access and the lack of mission-recovery metrics make comparative resilience uncertain.

Contrary evidence and caveat

Joint advisories, threat intelligence, endpoint defense, and exercise networks create learning advantages that static breach counts understate.

Applied causal analysis

Five mission threads determine usable cyber and spectrum power.

Cyber and EW do not form one serial pipeline. Persistent access, force employment, industrial defense, spectrum adaptation, and recovery act in parallel and intersect at specific mission dependencies. Each is therefore adjudicated independently.

Decisive threads5

Consequence-selected mission or capability chains drive the call.

Applied observations15

Each fact is connected to a rule, bucket, and comparative effect.

Unknown / unscored2

Missing or incomparable evidence stays visible instead of becoming zero.

01 · CY-T1
Pre-crisis access to mobilization infrastructureDetect and evict adversary persistence before activation
PRC edgeHigh confidence

Mission effectKeep telecommunications, energy, transportation, water, and logistics available to mobilize and deploy forces.

Analytical scopeConfirmed access, affected sectors, persistence, detection, segmentation, and recovery—not speculative worst cases.

Action priorityRemove PRC latent leverage

  1. 01Gain access
  2. 02Persist & pivot
  3. 03Detect & contain
  4. 04Mission continuity
Judgment

Observed Volt and Salt Typhoon activity demonstrates that PRC actors have achieved strategic access in networks the U.S. would need during crisis; the public record does not show complete eviction or assured mission continuity.

What offsets it

Joint intelligence, mandatory logging, phishing-resistant identity, segmentation, clean recovery environments, and sector exercises can turn discovery into durable denial.

What remains unknown

The number of still-compromised networks, operational technology reach, access persistence, and U.S. access inside PRC systems are classified or unknown.

Observation → applied rule → condition → driver effect3 observations
CY-O01 · Critical infrastructure access

U.S. and allied agencies confirmed Volt Typhoon compromises in communications, energy, transportation, and water systems, including U.S. territories, and assessed with high confidence that the access supported potential disruptive effects during crisis.

4 named critical-infrastructure sectors
Pre-positioned access to mobilization dependencies

Confirmed persistent access across multiple required civilian sectors is a current strategic exposure even before destructive action occurs.

Confirmed PRC pre-positioning

Creates the strongest PRC leverage in the cyber assessment.

2024 joint advisory; reaffirmed in 2025 report · High confidence

The advisory does not enumerate every victim or prove operational technology control at all sites.

CY-O02 · Telecommunications persistence

The 2025 multi-agency advisory attributes a global PRC campaign targeting backbone and edge routers across telecommunications, government, transportation, lodging, and military infrastructure networks and maintaining long-term access.

Strategic network persistence

Access to communications infrastructure used by many downstream missions receives greater weight than a single enterprise breach.

Systemic communications exposure

Strengthens the PRC access edge and creates cross-domain consequences.

September 2025 · High confidence

Targeting and access do not establish successful wartime disruption or complete provider compromise.

CY-O03 · Obfuscation infrastructure

The Defense Department reported a 2024 PRC operation that infected approximately 200,000 internet devices to create infrastructure useful for hiding and routing cyber operations.

200000 compromised internet devices
Distributed operational infrastructure

A six-figure compromised-device network materially improves evasion and scale, while device count is not treated as mission effect.

Large PRC enabler network

Raises detection and attribution burden on U.S. defenders.

2024 activity reported in 2025 · Moderate–high confidence

The report does not disclose how many devices remained controlled or operationally useful.

02 · CY-T2
Military cyber-force employmentReady teams deliver repeatable operational effects
U.S. edgeModerate confidence

Mission effectDefend assigned terrain, support combatant commands, disrupt adversary systems, and integrate cyber effects with joint operations.

Analytical scopePresented mission teams, staffing, training, command, tools, and observed operational integration—not total personnel alone.

Action priorityExploit the U.S. edge

  1. 01Personnel & skills
  2. 02Tools & access
  3. 03Joint integration
  4. 04Repeatable effect
Judgment

The United States has the more transparent, mature, and globally integrated operational cyber force, but scale and organizational complexity keep it below a lead.

What offsets it

Service-like authorities, direct readiness reporting, role-based training, and AI-enabled tooling can increase team output without simply adding headquarters.

What remains unknown

Cyber effects, access, mission success, tool reliability, and PLA force readiness are mostly classified and not symmetrically measurable.

Observation → applied rule → condition → driver effect3 observations
CY-O04 · Force readiness

The Cyber Command commander reported in 2026 that all service cyber components and presented forces remained mission ready and that readiness data feed the Defense Readiness and Reporting System.

Presented cyber-force readiness

Command-certified mission readiness with formal reporting is direct force evidence, but is bounded by the lack of public outcome and scale metrics.

Mission-ready U.S. force

Supports a U.S. edge in operational cyber forces.

June 2026 · Moderate–high confidence

Commander testimony is official self-reporting and omits classified standards and shortfalls.

CY-O05 · Force scale

GAO identified nearly 440 DOD organizations with about 61,000 military and civilian personnel plus more than 9,500 contractors conducting cyberspace operations.

~61000 + >9500 personnel and contractors
Cyber-force institutional depth

A large, specialized force is a comparative enabler, not a performance score; readiness and effect must be demonstrated separately.

Substantial U.S. capacity

Provides depth behind the U.S. operational edge.

September 2025 report · High confidence

The count includes diverse organizations and DODIN functions and is not comparable to opaque PLA staffing.

CY-O06 · Sufficiency

Cyber Command stated that the current force meets readiness standards but is insufficiently scaled for the threat environment.

Ready capacity versus demand

A ready force explicitly assessed below threat-driven scale receives an edge, not a lead.

Ready but underscaled

Caps the U.S. force advantage.

June 2026 · High confidence

The size and type of unmet demand are not public.

03 · CY-T3
Defense industrial base protectionVerified control implementation across critical suppliers
PRC edgeHigh confidence

Mission effectProtect designs, production, maintenance, logistics, and software dependencies from theft or disruption.

Analytical scopeRelevant suppliers, verified controls, assessors, secure services, incident sharing, and continuity—not compliance paperwork alone.

Action priorityClose the coverage gap

  1. 01Supplier inventory
  2. 02Verified controls
  3. 03Detection & sharing
  4. 04Production continuity
Judgment

The breadth of the DIB exceeds current verified defense. CMMC is now rolling out, but the three-year phase and external assessor constraints leave a large, heterogeneous exposure.

What offsets it

Shared secure cloud services, free NSA defense, Project Spectrum, priority-tier sequencing, and contract-enforced reporting can concentrate protection where compromise matters most.

What remains unknown

Public data do not show how many critical suppliers meet each control level, actual incident rates, or PRC access inside the DIB.

Observation → applied rule → condition → driver effect3 observations
CY-O07 · Attack surface

DOD relies on roughly 200,000 private companies for goods and services, many of which store sensitive information in their own systems.

200000 DIB companies
Supplier cyber exposure

A six-figure supplier base with decentralized systems creates a structural defense challenge unless criticality and verified controls are known.

Very broad attack surface

Supports a PRC edge in exploitable industrial exposure.

March 2026 report · High confidence

Not every company holds the same data or supports the same mission criticality.

CY-O08 · Certification coverage

CMMC implementation began as a three-year phased rollout, while GAO found DOD had not fully assessed external factors such as whether enough private assessors would be available.

3 years in planned rollout
Verified control implementation

A multi-year verification rollout with unresolved assessor capacity is a current coverage gap, not evidence that unassessed firms are insecure or secure.

Verification incomplete

Preserves the DIB resilience weakness while recognizing active remediation.

September 2025 plans; March 2026 report · High confidence

Contract phasing and required CMMC level vary by company.

CY-O09 · Small-business assistance

Project Spectrum had 21,535 registered participants as of July 2025, and NSA's Cybersecurity Collaboration Center served approximately 1,600 participants across its services as of August 2025.

21535 / ~1600 registered participants
Defensive assistance reach

Participation demonstrates scalable mitigation but cannot be treated as secured coverage, because programs provide partial assistance and populations overlap.

Mitigation with limited reach

Shows U.S. defensive depth without erasing the coverage gap.

July–August 2025 · High confidence

Registration is not control implementation; participant populations are not directly comparable or additive.

04 · CY-T4
Mission-network and electromagnetic adaptationUpdate defensive and EW behavior faster than the threat changes
ContestedLow–moderate confidence

Mission effectKeep command links, sensors, seekers, platforms, and spectrum access effective as adversaries exploit or change signatures.

Analytical scopeZero trust, network segmentation, mission data, EW reprogramming, spectrum planning, distribution, and field loading.

Action priorityShorten threat-to-field time

  1. 01Detect threat
  2. 02Develop response
  3. 03Distribute & load
  4. 04Mission effect
Judgment

The United States has advanced cyber and EW technology and is modernizing reprogramming, but public evidence does not establish joint threat-to-field speed or mission performance against the PLA's integrated cyber/EW force.

What offsets it

Open interfaces, common reprogramming equipment, software delivery, and the Joint Electromagnetic Spectrum Operations Center create practical pathways.

What remains unknown

Actual update latency, signature coverage, platform loading, spectrum denial, and operational effectiveness are classified.

Observation → applied rule → condition → driver effect3 observations
CY-O10 · Zero-trust planning

Of 24 major DOD IT business programs assessed by GAO, 20 reported plans to implement zero trust, while four had not developed plans and two lacked an approved cybersecurity strategy.

20 of 24 programs with zero-trust implementation plans
Mission-network defense architecture

Broad but incomplete planning is a positive current condition; plans without implementation or outcome do not establish resilient service.

Substantial progress / gaps remain

Keeps network architecture contested.

March 2025 data · High confidence

The sample covers major business systems, not all combat networks or weapon systems.

CY-O11 · EW reprogramming modernization

The Air Force's fiscal 2026 Electromagnetic Warfare Integrated Reprogramming effort is a $5.24 million new start intended to repair and modernize existing reprogramming programs and the wider EW enterprise.

$5.24M FY2026 RDT&E request
Threat-to-field update capacity

A new-start modernization effort identifies an existing operational need but remains an enabler until update latency and fielded effect improve.

Remediation initiated

Shows a U.S. response without changing the current EW rating.

FY2026 request · High confidence

Budget request is not delivered software, equipment, or measured reprogramming speed.

CY-O12 · Comparative spectrum outcome

The 2025 PRC report assigns cyber, electronic warfare, and technical reconnaissance to the Cyberspace Force; no public source provides comparable U.S./PLA time-to-reprogram or mission success in a representative contested spectrum.

Electromagnetic mission adaptation

Organizational integration establishes adversary intent and capacity, but mission superiority requires measured operational outcomes.

Unknown comparison

Prevents either side from receiving an EW lead from organizational claims alone.

2025 assessment · Moderate confidence

Both sides protect detailed EW performance and reprogramming metrics.

05 · CY-T5
Detection, containment and mission recoveryRestore trusted operational service, not just clean devices
ContestedLow–moderate confidence

Mission effectContinue or rapidly restore priority military and infrastructure functions after compromise and disruption.

Analytical scopeAsset knowledge, telemetry, containment, clean recovery, manual alternatives, data integrity, exercises, and mission restoration time.

Action priorityMake resilience observable

  1. 01Observe
  2. 02Contain
  3. 03Recover trust
  4. 04Restore mission
Judgment

U.S. defenders demonstrate strong campaign discovery and sharing, but long adversary dwell and limited public mission-recovery evidence prevent a defensive advantage.

What offsets it

Allied advisories, commercial telemetry, central logging, clean-room recovery, and operational continuity exercises create learning and substitution advantages.

What remains unknown

Time-to-detect, time-to-evict, reinfection, restored mission service, and PRC defensive performance are not publicly comparable.

Observation → applied rule → condition → driver effect3 observations
CY-O13 · Campaign discovery

U.S. and allied agencies published detailed joint technical advisories on Volt and Salt Typhoon activity, including observed tactics and concrete mitigations.

Collective detection and learning

Multi-agency, multinational technical attribution demonstrates a defensive learning network, but discovery does not prove full eviction or recovery.

Strong collective detection

Provides a U.S./allied offset in resilience.

2024–2025 · High confidence

Public advisories intentionally omit sensitive visibility and victim detail.

CY-O14 · Organizational coordination

GAO found nearly 440 DOD cyber organizations and potential overlap in service training and administration of 23 cybersecurity service providers.

23 DOD cybersecurity service providers
Defensive command and service clarity

Intentional redundancy can improve resilience, but unmeasured overlap and duplicate services reduce speed and accountability until roles and outcomes are clear.

Coordination risk

Offsets part of the U.S. institutional-depth advantage.

September 2025 · High confidence

GAO did not conclude all overlap was unnecessary or harmful.

CY-O15 · Recovered mission output

Public sources do not report how quickly priority DOD, DIB, and mobilization services return to a trusted minimum level after representative persistent compromise and infrastructure disruption.

Mission recovery time

Device remediation, compliance, and exercise participation cannot substitute for end-to-end restored mission service.

Unknown recovery performance

Keeps detection and recovery contested.

August 2026 · High confidence

Relevant continuity exercises and operational metrics may be classified or organization-specific.

Improve the advantage

4 actions tied to diagnosed nodes.

Lead time is an implementation attribute—not a forecasted future rating. Every action has an owner, prerequisite, and observable completion test.

CY-A101
Recommendation

Protect critical suppliers and infrastructure by mission consequence

A uniform compliance rollout across 200,000 companies cannot protect the most consequential production and mobilization nodes quickly enough.

Map priority mission threads to named suppliers and infrastructure dependencies; sequence verified controls, hunt support, shared secure services, logging, segmentation, and clean recovery around consequence and substitutability.

Implementation test

PrerequisitesAuthoritative supplier graph, mission criticality tiers, contract data rights, and protected incident sharing.

Verify successEvery priority mission thread has verified controls, current telemetry, an exercised clean-recovery path, and a qualified substitute for its highest-consequence dependencies.

Linked threadsCY-T1 · CY-T3 · CY-T5

Expected effectConcentrates scarce assessor and defender capacity on compromise paths that could stop mobilization or production.

FeasibilityHigh

Cost bandMedium–high

Lead time1–4 years

OwnerOSD, services, CISA, NSA, sector agencies and primes

CY-A202
Recommendation

Grade cyber defense on recovered mission service

Control compliance and device cleanup do not show whether command, logistics, fuel, transportation, and weapons functions continue under attack.

Run persistent-adversary exercises from initial access through operational technology, corrupted data, denied communications, manual fallback, clean restoration, and reinfection; score minimum mission output and recovery time.

Implementation test

PrerequisitesRepresentative environments, safety controls, shared mission metrics, and authority to test cross-organization dependencies.

Verify successPriority mission threads sustain or restore trusted output inside specified thresholds with primary networks and external services compromised.

Linked threadsCY-T1 · CY-T4 · CY-T5

Expected effectMakes resilience measurable and redirects investment toward the dependencies that actually stop operations.

FeasibilityHigh

Cost bandMedium

Lead time1–3 years

OwnerUSCYBERCOM, combatant commands, services, CISA and infrastructure operators

CY-A303
Recommendation

Convert cyber headcount into role-based ready capacity

A large force and nearly 440 organizations can mask critical skill gaps, duplicate services, and slow mission ownership.

Map operational demand to standardized work roles, qualification, tool access, deployable teams, and outcome ownership; eliminate or deliberately justify overlapping training and service-provider functions.

Implementation test

PrerequisitesCommon work-role data, mission demand, readiness standards, and authority to realign services.

Verify successCritical role fill, qualification, and mission throughput improve while unnecessary duplicate services and handoffs decline.

Linked threadsCY-T2 · CY-T5

Expected effectIncreases usable team output, reduces duplication, and directs scarce experts to threat-driven shortfalls.

FeasibilityModerate–high

Cost bandLow–medium

Lead time1–3 years

OwnerUSCYBERCOM and military services

CY-A404
Recommendation

Build a threat-to-field EW reprogramming pipeline

Platform sophistication is wasted when signatures, techniques, software, distribution, and loading cannot update at operational speed.

Use common data contracts, government-accessible interfaces, automated verification, distributed labs, secure delivery, and platform telemetry to measure every step from observed emitter change to fielded mission data.

Implementation test

PrerequisitesReleasable signature data, interface rights, test capacity, configuration control, and allied distribution agreements.

Verify successRepresentative threat changes produce validated and loaded multi-platform updates inside the required operational latency under degraded communications.

Linked threadsCY-T4

Expected effectImproves survival and spectrum effectiveness across existing platforms faster than replacing hardware.

FeasibilityModerate

Cost bandMedium–high

Lead time2–5 years

OwnerJoint Staff, services, intelligence community and STRATCOM

Analytical audit trail

The machinery is available—but subordinate.

The finding comes first. Open this section to inspect composition rules, evidence limitations, and every source record.

Methods & evidenceInspect how the current judgment was reached
Scope rule

Current evidence only.

The assessment evaluates current cyber and electronic-warfare capacity using credible public evidence through August 5, 2026. Discovered access, verified force readiness, and fielded defenses receive more weight than strategy, planned controls, or requested software.

Selection rule

Consequence before convenience.

Threads are included when they represent distinct operational outcomes: pre-crisis access, force employment, industrial defense, cyber/EW adaptation, and mission recovery.

Composition rule

No black-box average.

Offense, defense, resilience, and spectrum adaptation are parallel contributors with mission-specific dependencies. Personnel, breaches, controls, and organizations are not averaged into a black-box score.

Evidence rule

Observation, inference, and unknown stay separate.

Confirmed campaigns, independent oversight, official readiness reporting, and observed defensive mechanisms are distinguished from inferred access, compliance plans, and budget intent.

Classified offensive effects, accesses, readiness criteria, EW performance, and recovery exercises remain unknown. Publicly exposed PRC campaigns do not imply absent U.S. access, and that unknown is not scored.

Known limitations

What this public assessment cannot prove.

  • Cyber operations and electronic-warfare outcomes are heavily classified, preventing symmetric comparison of access, effects, readiness, and loss.
  • Public breach reporting is detection-biased: observed PRC campaigns do not reveal the full balance of undisclosed U.S. or PRC access.
  • DIB company counts, registrations, and certifications do not measure mission criticality or actual security performance.
  • EW organization and funding do not establish threat-to-field latency or combat effectiveness.
  • Allied and private capacity is credited only where formal sharing, joint attribution, or operational integration is public.
Public evidence

9 source records; 9 primary or direct records.

CY-S1 · Tier 12025 Military and Security Developments Involving the PRC

Primary use: PRC cyber campaigns, force organization, EW integration, device infrastructure, and conflict objectives.

Known limitation: Unclassified threat assessment; accesses, methods, readiness, and U.S. comparisons are partly undisclosed.

Open public source ↗
CY-S2 · Tier 1PRC State-Sponsored Actors Compromise and Maintain Access to U.S. Critical Infrastructure

Primary use: Confirmed Volt Typhoon access, targeted sectors, assessed intent, and mitigations.

Known limitation: Victim and operational details are limited; publication date precedes later remediation.

Open public source ↗
CY-S3 · Tier 1Countering PRC State-Sponsored Network Compromise Worldwide

Primary use: Salt Typhoon-related backbone and edge-router activity, persistence, affected sectors, and mitigations.

Known limitation: Technical advisory does not quantify all victims, dwell time, or full remediation status.

Open public source ↗
CY-S4 · Tier 1Defense Contractor Cybersecurity: DOD Should Address External Factors

Primary use: DIB size, CMMC rollout, assessor risk, Project Spectrum, and NSA service participation.

Known limitation: Program participation and rollout plans do not directly measure company security or mission consequence.

Open public source ↗
CY-S5 · Tier 1DOD Cyberspace Operations: About 500 Organizations Have Roles, With Potential Overlap

Primary use: Cyber organization, personnel, contractor, team, service-provider, and overlap evidence.

Known limitation: Organizational counts include varied missions and do not measure operational effectiveness.

Open public source ↗
CY-S6 · Tier 1Posture Statement of the Commander, U.S. Cyber Command

Primary use: Force readiness, scale, operational integration, authorities, and current priorities.

Known limitation: Commander self-assessment omits classified standards, effects, and detailed shortfalls.

Open public source ↗
CY-S7 · Tier 1IT Systems Annual Assessment: DOD Needs Better Reporting and Cybersecurity Planning

Primary use: Zero-trust planning, cybersecurity strategy, software, and performance-reporting evidence.

Known limitation: Sample covers 24 major business programs rather than all operational or weapon networks.

Open public source ↗
CY-S8 · Tier 1FY2026 Air Force RDT&E: Electromagnetic Warfare Integrated Reprogramming

Primary use: EW reprogramming modernization, program scope, new-start status, and requested funding.

Known limitation: Budget request and program intent do not establish delivered speed or operational effect.

Open public source ↗
CY-S9 · Tier 1Spectrum Management: DOD and NTIA Should Improve External Collaboration

Primary use: Joint spectrum governance, JEC responsibilities, training, operational gap analysis, and external coordination.

Known limitation: Governance and planning structures do not provide comparative EW performance metrics.

Open public source ↗
Structured current assessment

Reuse the evidence—not just the conclusion.

The public JSON contains the executive judgment, drivers, decisive threads, observations, actions, limitations, and source records.

Assessment boundary

More traceability, not false precision.

This applied layer substantiates the current call without projecting future ratings or silently changing the core ten-area dataset. Compare the core capability record →