{"schema_version":"1.0","slug":"cyber-electronic-warfare","number":5,"title":"Cyber & electronic warfare","evidence_cutoff":"August 5, 2026","overall":{"score":-0.25,"label":"Contested","confidence":"Moderate","judgment":"The cyber and electromagnetic contest is genuinely unresolved. The United States fields a large, mission-ready Cyber Mission Force and benefits from an unmatched private-sector and allied defense ecosystem, but the PRC has demonstrated persistent access to U.S. telecommunications and critical infrastructure, can exploit a vast and uneven defense supply chain, and integrates cyber and electronic warfare within a theater-focused information architecture.","composition_note":"The judgment separates force size from protected mission output. U.S. Cyber Command reports its presented forces mission ready, while GAO documents nearly 440 DOD cyber organizations and 61,000 personnel. Those are real strengths, but not proof that mobilization, weapons, logistics, or spectrum-dependent missions survive attack. Observed PRC pre-positioning, CMMC's incomplete three-year rollout across a 200,000-company industrial base, organizational overlap, and immature comparative EW measures prevent a U.S. edge."},"takeaways":[{"eyebrow":"Strongest U.S. advantage","title":"Talent, operations, and allied/private depth","body":"A large cyber force, world-class technology sector, threat-sharing institutions, and close intelligence allies give the United States many defensive and offensive pathways."},{"eyebrow":"Most dangerous PRC leverage","title":"Persistent access before crisis","body":"Volt Typhoon, Salt Typhoon, and compromised edge devices show a strategy of living inside civilian and military-adjacent networks that enable mobilization."},{"eyebrow":"Binding U.S. weakness","title":"The attack surface is larger than verified defense","body":"DOD depends on roughly 200,000 companies while certification, zero trust, asset visibility, and small-business assistance remain incomplete."},{"eyebrow":"Decision","title":"Measure recovered mission output","body":"Grade cyber and EW by whether priority operational threads continue and recover under representative compromise—not by compliance, headcount, or software installed."}],"drivers":[{"id":"CY-D1","name":"Persistent access & offensive positioning","score":-1.25,"label":"PRC edge","confidence":"High","judgment":"Publicly attributed PRC campaigns demonstrate long-lived access to telecommunications, critical infrastructure, and edge devices intended to support espionage and potential disruption before conflict.","contrary":"Public reporting exposes discovered campaigns, not the full balance of access; U.S. offensive operations and adversary losses are mostly classified.","source_ids":["CY-S1","CY-S2","CY-S3"]},{"id":"CY-D2","name":"Cyber force readiness & operational mastery","score":0.75,"label":"U.S. edge","confidence":"Moderate","judgment":"U.S. Cyber Command reports mission-ready forces with current operational integration, and DOD maintains a large professional cyber structure.","contrary":"The commander also states the force is insufficiently scaled for the threat, while public readiness measures do not establish effect quality or persistence.","source_ids":["CY-S5","CY-S6"]},{"id":"CY-D3","name":"DIB and critical-infrastructure resilience","score":-1.0,"label":"PRC edge","confidence":"High","judgment":"A 200,000-company defense industrial base and essential civilian infrastructure create a broad, uneven attack surface that current certification and assistance programs have not yet covered.","contrary":"CMMC, Project Spectrum, NSA services, sector regulation, and strong private defenders provide a scalable response; PRC access does not guarantee destructive effect.","source_ids":["CY-S2","CY-S4"]},{"id":"CY-D4","name":"Mission-network architecture & zero trust","score":-0.25,"label":"Contested","confidence":"Moderate","judgment":"DOD has made substantial zero-trust and cyber-planning progress, but gaps remain in business systems and cross-organizational command-and-control integration.","contrary":"Twenty of 24 assessed major IT business programs reported a zero-trust implementation plan, and operational networks may outperform the sampled business portfolio.","source_ids":["CY-S5","CY-S7"]},{"id":"CY-D5","name":"Electromagnetic sensing, attack & reprogramming","score":-0.25,"label":"Contested","confidence":"Low","judgment":"The PLA deliberately integrates cyber, electronic warfare, and technical reconnaissance. The United States possesses advanced systems but public evidence does not show comparative threat-to-field update time or joint spectrum outcome under attack.","contrary":"The Air Force is funding integrated reprogramming and DOD has created joint spectrum governance and training mechanisms; classified performance may be stronger.","source_ids":["CY-S1","CY-S8","CY-S9"]},{"id":"CY-D6","name":"Detection, response & mission recovery","score":0.0,"label":"Contested","confidence":"Low–moderate","judgment":"U.S. public-private defenders regularly expose PRC campaigns, but discovery after prolonged access and the lack of mission-recovery metrics make comparative resilience uncertain.","contrary":"Joint advisories, threat intelligence, endpoint defense, and exercise networks create learning advantages that static breach counts understate.","source_ids":["CY-S2","CY-S3","CY-S4","CY-S6"]}],"threads_heading":"Five mission threads determine usable cyber and spectrum power.","threads_intro":"Cyber and EW do not form one serial pipeline. Persistent access, force employment, industrial defense, spectrum adaptation, and recovery act in parallel and intersect at specific mission dependencies. Each is therefore adjudicated independently.","threads":[{"id":"CY-T1","name":"Pre-crisis access to mobilization infrastructure","decisive_node":"Detect and evict adversary persistence before activation","mission_effect":"Keep telecommunications, energy, transportation, water, and logistics available to mobilize and deploy forces.","scope":"Confirmed access, affected sectors, persistence, detection, segmentation, and recovery—not speculative worst cases.","priority":"Remove PRC latent leverage","score":-1.25,"label":"PRC edge","confidence":"High","judgment":"Observed Volt and Salt Typhoon activity demonstrates that PRC actors have achieved strategic access in networks the U.S. would need during crisis; the public record does not show complete eviction or assured mission continuity.","mitigation":"Joint intelligence, mandatory logging, phishing-resistant identity, segmentation, clean recovery environments, and sector exercises can turn discovery into durable denial.","gap":"The number of still-compromised networks, operational technology reach, access persistence, and U.S. access inside PRC systems are classified or unknown.","nodes":[{"name":"Gain access","status":"prc"},{"name":"Persist & pivot","status":"prc"},{"name":"Detect & contain","status":"mixed"},{"name":"Mission continuity","status":"unknown"}],"source_ids":["CY-S1","CY-S2","CY-S3"],"recommendation_ids":["CY-A1","CY-A2"],"observations":[{"id":"CY-O01","driver_ids":["CY-D1","CY-D3"],"node":"Critical infrastructure access","observation":"U.S. and allied agencies confirmed Volt Typhoon compromises in communications, energy, transportation, and water systems, including U.S. territories, and assessed with high confidence that the access supported potential disruptive effects during crisis.","value":"4","unit":"named critical-infrastructure sectors","metric":"Pre-positioned access to mobilization dependencies","applied_rule":"Confirmed persistent access across multiple required civilian sectors is a current strategic exposure even before destructive action occurs.","bucket":"Confirmed PRC pre-positioning","effect":"Creates the strongest PRC leverage in the cyber assessment.","as_of":"2024 joint advisory; reaffirmed in 2025 report","confidence":"High","limitation":"The advisory does not enumerate every victim or prove operational technology control at all sites.","source_ids":["CY-S1","CY-S2"]},{"id":"CY-O02","driver_ids":["CY-D1"],"node":"Telecommunications persistence","observation":"The 2025 multi-agency advisory attributes a global PRC campaign targeting backbone and edge routers across telecommunications, government, transportation, lodging, and military infrastructure networks and maintaining long-term access.","value":"","unit":"","metric":"Strategic network persistence","applied_rule":"Access to communications infrastructure used by many downstream missions receives greater weight than a single enterprise breach.","bucket":"Systemic communications exposure","effect":"Strengthens the PRC access edge and creates cross-domain consequences.","as_of":"September 2025","confidence":"High","limitation":"Targeting and access do not establish successful wartime disruption or complete provider compromise.","source_ids":["CY-S3"]},{"id":"CY-O03","driver_ids":["CY-D1","CY-D6"],"node":"Obfuscation infrastructure","observation":"The Defense Department reported a 2024 PRC operation that infected approximately 200,000 internet devices to create infrastructure useful for hiding and routing cyber operations.","value":"200000","unit":"compromised internet devices","metric":"Distributed operational infrastructure","applied_rule":"A six-figure compromised-device network materially improves evasion and scale, while device count is not treated as mission effect.","bucket":"Large PRC enabler network","effect":"Raises detection and attribution burden on U.S. defenders.","as_of":"2024 activity reported in 2025","confidence":"Moderate–high","limitation":"The report does not disclose how many devices remained controlled or operationally useful.","source_ids":["CY-S1"]}]},{"id":"CY-T2","name":"Military cyber-force employment","decisive_node":"Ready teams deliver repeatable operational effects","mission_effect":"Defend assigned terrain, support combatant commands, disrupt adversary systems, and integrate cyber effects with joint operations.","scope":"Presented mission teams, staffing, training, command, tools, and observed operational integration—not total personnel alone.","priority":"Exploit the U.S. edge","score":0.75,"label":"U.S. edge","confidence":"Moderate","judgment":"The United States has the more transparent, mature, and globally integrated operational cyber force, but scale and organizational complexity keep it below a lead.","mitigation":"Service-like authorities, direct readiness reporting, role-based training, and AI-enabled tooling can increase team output without simply adding headquarters.","gap":"Cyber effects, access, mission success, tool reliability, and PLA force readiness are mostly classified and not symmetrically measurable.","nodes":[{"name":"Personnel & skills","status":"us"},{"name":"Tools & access","status":"unknown"},{"name":"Joint integration","status":"us"},{"name":"Repeatable effect","status":"unknown"}],"source_ids":["CY-S5","CY-S6"],"recommendation_ids":["CY-A3"],"observations":[{"id":"CY-O04","driver_ids":["CY-D2"],"node":"Force readiness","observation":"The Cyber Command commander reported in 2026 that all service cyber components and presented forces remained mission ready and that readiness data feed the Defense Readiness and Reporting System.","value":"","unit":"","metric":"Presented cyber-force readiness","applied_rule":"Command-certified mission readiness with formal reporting is direct force evidence, but is bounded by the lack of public outcome and scale metrics.","bucket":"Mission-ready U.S. force","effect":"Supports a U.S. edge in operational cyber forces.","as_of":"June 2026","confidence":"Moderate–high","limitation":"Commander testimony is official self-reporting and omits classified standards and shortfalls.","source_ids":["CY-S6"]},{"id":"CY-O05","driver_ids":["CY-D2"],"node":"Force scale","observation":"GAO identified nearly 440 DOD organizations with about 61,000 military and civilian personnel plus more than 9,500 contractors conducting cyberspace operations.","value":"~61000 + >9500","unit":"personnel and contractors","metric":"Cyber-force institutional depth","applied_rule":"A large, specialized force is a comparative enabler, not a performance score; readiness and effect must be demonstrated separately.","bucket":"Substantial U.S. capacity","effect":"Provides depth behind the U.S. operational edge.","as_of":"September 2025 report","confidence":"High","limitation":"The count includes diverse organizations and DODIN functions and is not comparable to opaque PLA staffing.","source_ids":["CY-S5"]},{"id":"CY-O06","driver_ids":["CY-D2"],"node":"Sufficiency","observation":"Cyber Command stated that the current force meets readiness standards but is insufficiently scaled for the threat environment.","value":"","unit":"","metric":"Ready capacity versus demand","applied_rule":"A ready force explicitly assessed below threat-driven scale receives an edge, not a lead.","bucket":"Ready but underscaled","effect":"Caps the U.S. force advantage.","as_of":"June 2026","confidence":"High","limitation":"The size and type of unmet demand are not public.","source_ids":["CY-S6"]}]},{"id":"CY-T3","name":"Defense industrial base protection","decisive_node":"Verified control implementation across critical suppliers","mission_effect":"Protect designs, production, maintenance, logistics, and software dependencies from theft or disruption.","scope":"Relevant suppliers, verified controls, assessors, secure services, incident sharing, and continuity—not compliance paperwork alone.","priority":"Close the coverage gap","score":-1.0,"label":"PRC edge","confidence":"High","judgment":"The breadth of the DIB exceeds current verified defense. CMMC is now rolling out, but the three-year phase and external assessor constraints leave a large, heterogeneous exposure.","mitigation":"Shared secure cloud services, free NSA defense, Project Spectrum, priority-tier sequencing, and contract-enforced reporting can concentrate protection where compromise matters most.","gap":"Public data do not show how many critical suppliers meet each control level, actual incident rates, or PRC access inside the DIB.","nodes":[{"name":"Supplier inventory","status":"prc"},{"name":"Verified controls","status":"prc"},{"name":"Detection & sharing","status":"mixed"},{"name":"Production continuity","status":"unknown"}],"source_ids":["CY-S4"],"recommendation_ids":["CY-A1"],"observations":[{"id":"CY-O07","driver_ids":["CY-D3"],"node":"Attack surface","observation":"DOD relies on roughly 200,000 private companies for goods and services, many of which store sensitive information in their own systems.","value":"200000","unit":"DIB companies","metric":"Supplier cyber exposure","applied_rule":"A six-figure supplier base with decentralized systems creates a structural defense challenge unless criticality and verified controls are known.","bucket":"Very broad attack surface","effect":"Supports a PRC edge in exploitable industrial exposure.","as_of":"March 2026 report","confidence":"High","limitation":"Not every company holds the same data or supports the same mission criticality.","source_ids":["CY-S4"]},{"id":"CY-O08","driver_ids":["CY-D3"],"node":"Certification coverage","observation":"CMMC implementation began as a three-year phased rollout, while GAO found DOD had not fully assessed external factors such as whether enough private assessors would be available.","value":"3","unit":"years in planned rollout","metric":"Verified control implementation","applied_rule":"A multi-year verification rollout with unresolved assessor capacity is a current coverage gap, not evidence that unassessed firms are insecure or secure.","bucket":"Verification incomplete","effect":"Preserves the DIB resilience weakness while recognizing active remediation.","as_of":"September 2025 plans; March 2026 report","confidence":"High","limitation":"Contract phasing and required CMMC level vary by company.","source_ids":["CY-S4"]},{"id":"CY-O09","driver_ids":["CY-D3","CY-D6"],"node":"Small-business assistance","observation":"Project Spectrum had 21,535 registered participants as of July 2025, and NSA's Cybersecurity Collaboration Center served approximately 1,600 participants across its services as of August 2025.","value":"21535 / ~1600","unit":"registered participants","metric":"Defensive assistance reach","applied_rule":"Participation demonstrates scalable mitigation but cannot be treated as secured coverage, because programs provide partial assistance and populations overlap.","bucket":"Mitigation with limited reach","effect":"Shows U.S. defensive depth without erasing the coverage gap.","as_of":"July–August 2025","confidence":"High","limitation":"Registration is not control implementation; participant populations are not directly comparable or additive.","source_ids":["CY-S4"]}]},{"id":"CY-T4","name":"Mission-network and electromagnetic adaptation","decisive_node":"Update defensive and EW behavior faster than the threat changes","mission_effect":"Keep command links, sensors, seekers, platforms, and spectrum access effective as adversaries exploit or change signatures.","scope":"Zero trust, network segmentation, mission data, EW reprogramming, spectrum planning, distribution, and field loading.","priority":"Shorten threat-to-field time","score":-0.25,"label":"Contested","confidence":"Low–moderate","judgment":"The United States has advanced cyber and EW technology and is modernizing reprogramming, but public evidence does not establish joint threat-to-field speed or mission performance against the PLA's integrated cyber/EW force.","mitigation":"Open interfaces, common reprogramming equipment, software delivery, and the Joint Electromagnetic Spectrum Operations Center create practical pathways.","gap":"Actual update latency, signature coverage, platform loading, spectrum denial, and operational effectiveness are classified.","nodes":[{"name":"Detect threat","status":"mixed"},{"name":"Develop response","status":"unknown"},{"name":"Distribute & load","status":"mixed"},{"name":"Mission effect","status":"unknown"}],"source_ids":["CY-S1","CY-S7","CY-S8","CY-S9"],"recommendation_ids":["CY-A2","CY-A4"],"observations":[{"id":"CY-O10","driver_ids":["CY-D4"],"node":"Zero-trust planning","observation":"Of 24 major DOD IT business programs assessed by GAO, 20 reported plans to implement zero trust, while four had not developed plans and two lacked an approved cybersecurity strategy.","value":"20 of 24","unit":"programs with zero-trust implementation plans","metric":"Mission-network defense architecture","applied_rule":"Broad but incomplete planning is a positive current condition; plans without implementation or outcome do not establish resilient service.","bucket":"Substantial progress / gaps remain","effect":"Keeps network architecture contested.","as_of":"March 2025 data","confidence":"High","limitation":"The sample covers major business systems, not all combat networks or weapon systems.","source_ids":["CY-S7"]},{"id":"CY-O11","driver_ids":["CY-D5"],"node":"EW reprogramming modernization","observation":"The Air Force's fiscal 2026 Electromagnetic Warfare Integrated Reprogramming effort is a $5.24 million new start intended to repair and modernize existing reprogramming programs and the wider EW enterprise.","value":"$5.24M","unit":"FY2026 RDT&E request","metric":"Threat-to-field update capacity","applied_rule":"A new-start modernization effort identifies an existing operational need but remains an enabler until update latency and fielded effect improve.","bucket":"Remediation initiated","effect":"Shows a U.S. response without changing the current EW rating.","as_of":"FY2026 request","confidence":"High","limitation":"Budget request is not delivered software, equipment, or measured reprogramming speed.","source_ids":["CY-S8"]},{"id":"CY-O12","driver_ids":["CY-D5"],"node":"Comparative spectrum outcome","observation":"The 2025 PRC report assigns cyber, electronic warfare, and technical reconnaissance to the Cyberspace Force; no public source provides comparable U.S./PLA time-to-reprogram or mission success in a representative contested spectrum.","value":"","unit":"","metric":"Electromagnetic mission adaptation","applied_rule":"Organizational integration establishes adversary intent and capacity, but mission superiority requires measured operational outcomes.","bucket":"Unknown comparison","effect":"Prevents either side from receiving an EW lead from organizational claims alone.","as_of":"2025 assessment","confidence":"Moderate","limitation":"Both sides protect detailed EW performance and reprogramming metrics.","source_ids":["CY-S1","CY-S9"]}]},{"id":"CY-T5","name":"Detection, containment and mission recovery","decisive_node":"Restore trusted operational service, not just clean devices","mission_effect":"Continue or rapidly restore priority military and infrastructure functions after compromise and disruption.","scope":"Asset knowledge, telemetry, containment, clean recovery, manual alternatives, data integrity, exercises, and mission restoration time.","priority":"Make resilience observable","score":0.0,"label":"Contested","confidence":"Low–moderate","judgment":"U.S. defenders demonstrate strong campaign discovery and sharing, but long adversary dwell and limited public mission-recovery evidence prevent a defensive advantage.","mitigation":"Allied advisories, commercial telemetry, central logging, clean-room recovery, and operational continuity exercises create learning and substitution advantages.","gap":"Time-to-detect, time-to-evict, reinfection, restored mission service, and PRC defensive performance are not publicly comparable.","nodes":[{"name":"Observe","status":"us"},{"name":"Contain","status":"mixed"},{"name":"Recover trust","status":"unknown"},{"name":"Restore mission","status":"unknown"}],"source_ids":["CY-S2","CY-S3","CY-S5","CY-S6"],"recommendation_ids":["CY-A1","CY-A2","CY-A3"],"observations":[{"id":"CY-O13","driver_ids":["CY-D6"],"node":"Campaign discovery","observation":"U.S. and allied agencies published detailed joint technical advisories on Volt and Salt Typhoon activity, including observed tactics and concrete mitigations.","value":"","unit":"","metric":"Collective detection and learning","applied_rule":"Multi-agency, multinational technical attribution demonstrates a defensive learning network, but discovery does not prove full eviction or recovery.","bucket":"Strong collective detection","effect":"Provides a U.S./allied offset in resilience.","as_of":"2024–2025","confidence":"High","limitation":"Public advisories intentionally omit sensitive visibility and victim detail.","source_ids":["CY-S2","CY-S3"]},{"id":"CY-O14","driver_ids":["CY-D2","CY-D6"],"node":"Organizational coordination","observation":"GAO found nearly 440 DOD cyber organizations and potential overlap in service training and administration of 23 cybersecurity service providers.","value":"23","unit":"DOD cybersecurity service providers","metric":"Defensive command and service clarity","applied_rule":"Intentional redundancy can improve resilience, but unmeasured overlap and duplicate services reduce speed and accountability until roles and outcomes are clear.","bucket":"Coordination risk","effect":"Offsets part of the U.S. institutional-depth advantage.","as_of":"September 2025","confidence":"High","limitation":"GAO did not conclude all overlap was unnecessary or harmful.","source_ids":["CY-S5"]},{"id":"CY-O15","driver_ids":["CY-D6"],"node":"Recovered mission output","observation":"Public sources do not report how quickly priority DOD, DIB, and mobilization services return to a trusted minimum level after representative persistent compromise and infrastructure disruption.","value":"","unit":"","metric":"Mission recovery time","applied_rule":"Device remediation, compliance, and exercise participation cannot substitute for end-to-end restored mission service.","bucket":"Unknown recovery performance","effect":"Keeps detection and recovery contested.","as_of":"August 2026","confidence":"High","limitation":"Relevant continuity exercises and operational metrics may be classified or organization-specific.","source_ids":["CY-S2","CY-S5","CY-S6"]}]}],"recommendations":[{"id":"CY-A1","rank":1,"title":"Protect critical suppliers and infrastructure by mission consequence","diagnosis":"A uniform compliance rollout across 200,000 companies cannot protect the most consequential production and mobilization nodes quickly enough.","action":"Map priority mission threads to named suppliers and infrastructure dependencies; sequence verified controls, hunt support, shared secure services, logging, segmentation, and clean recovery around consequence and substitutability.","expected_effect":"Concentrates scarce assessor and defender capacity on compromise paths that could stop mobilization or production.","feasibility":"High","cost_band":"Medium–high","lead_time":"1–4 years","owner":"OSD, services, CISA, NSA, sector agencies and primes","prerequisites":"Authoritative supplier graph, mission criticality tiers, contract data rights, and protected incident sharing.","verification":"Every priority mission thread has verified controls, current telemetry, an exercised clean-recovery path, and a qualified substitute for its highest-consequence dependencies.","thread_ids":["CY-T1","CY-T3","CY-T5"],"source_ids":["CY-S2","CY-S4"]},{"id":"CY-A2","rank":2,"title":"Grade cyber defense on recovered mission service","diagnosis":"Control compliance and device cleanup do not show whether command, logistics, fuel, transportation, and weapons functions continue under attack.","action":"Run persistent-adversary exercises from initial access through operational technology, corrupted data, denied communications, manual fallback, clean restoration, and reinfection; score minimum mission output and recovery time.","expected_effect":"Makes resilience measurable and redirects investment toward the dependencies that actually stop operations.","feasibility":"High","cost_band":"Medium","lead_time":"1–3 years","owner":"USCYBERCOM, combatant commands, services, CISA and infrastructure operators","prerequisites":"Representative environments, safety controls, shared mission metrics, and authority to test cross-organization dependencies.","verification":"Priority mission threads sustain or restore trusted output inside specified thresholds with primary networks and external services compromised.","thread_ids":["CY-T1","CY-T4","CY-T5"],"source_ids":["CY-S2","CY-S6","CY-S7"]},{"id":"CY-A3","rank":3,"title":"Convert cyber headcount into role-based ready capacity","diagnosis":"A large force and nearly 440 organizations can mask critical skill gaps, duplicate services, and slow mission ownership.","action":"Map operational demand to standardized work roles, qualification, tool access, deployable teams, and outcome ownership; eliminate or deliberately justify overlapping training and service-provider functions.","expected_effect":"Increases usable team output, reduces duplication, and directs scarce experts to threat-driven shortfalls.","feasibility":"Moderate–high","cost_band":"Low–medium","lead_time":"1–3 years","owner":"USCYBERCOM and military services","prerequisites":"Common work-role data, mission demand, readiness standards, and authority to realign services.","verification":"Critical role fill, qualification, and mission throughput improve while unnecessary duplicate services and handoffs decline.","thread_ids":["CY-T2","CY-T5"],"source_ids":["CY-S5","CY-S6"]},{"id":"CY-A4","rank":4,"title":"Build a threat-to-field EW reprogramming pipeline","diagnosis":"Platform sophistication is wasted when signatures, techniques, software, distribution, and loading cannot update at operational speed.","action":"Use common data contracts, government-accessible interfaces, automated verification, distributed labs, secure delivery, and platform telemetry to measure every step from observed emitter change to fielded mission data.","expected_effect":"Improves survival and spectrum effectiveness across existing platforms faster than replacing hardware.","feasibility":"Moderate","cost_band":"Medium–high","lead_time":"2–5 years","owner":"Joint Staff, services, intelligence community and STRATCOM","prerequisites":"Releasable signature data, interface rights, test capacity, configuration control, and allied distribution agreements.","verification":"Representative threat changes produce validated and loaded multi-platform updates inside the required operational latency under degraded communications.","thread_ids":["CY-T4"],"source_ids":["CY-S8","CY-S9"]}],"methodology":{"scope":"The assessment evaluates current cyber and electronic-warfare capacity using credible public evidence through August 5, 2026. Discovered access, verified force readiness, and fielded defenses receive more weight than strategy, planned controls, or requested software.","selection_rule":"Threads are included when they represent distinct operational outcomes: pre-crisis access, force employment, industrial defense, cyber/EW adaptation, and mission recovery.","composition_rule":"Offense, defense, resilience, and spectrum adaptation are parallel contributors with mission-specific dependencies. Personnel, breaches, controls, and organizations are not averaged into a black-box score.","evidence_rule":"Confirmed campaigns, independent oversight, official readiness reporting, and observed defensive mechanisms are distinguished from inferred access, compliance plans, and budget intent.","unknown_rule":"Classified offensive effects, accesses, readiness criteria, EW performance, and recovery exercises remain unknown. Publicly exposed PRC campaigns do not imply absent U.S. access, and that unknown is not scored."},"limitations":["Cyber operations and electronic-warfare outcomes are heavily classified, preventing symmetric comparison of access, effects, readiness, and loss.","Public breach reporting is detection-biased: observed PRC campaigns do not reveal the full balance of undisclosed U.S. or PRC access.","DIB company counts, registrations, and certifications do not measure mission criticality or actual security performance.","EW organization and funding do not establish threat-to-field latency or combat effectiveness.","Allied and private capacity is credited only where formal sharing, joint attribution, or operational integration is public."],"sources":[{"id":"CY-S1","title":"2025 Military and Security Developments Involving the PRC","url":"https://media.defense.gov/2025/Dec/23/2003849070/-1/-1/1/ANNUAL-REPORT-TO-CONGRESS-MILITARY-AND-SECURITY-DEVELOPMENTS-INVOLVING-THE-PEOPLES-REPUBLIC-OF-CHINA-2025.PDF","publisher":"U.S. Department of Defense","date":"December 2025","evidence_tier":"Tier 1","primary_use":"PRC cyber campaigns, force organization, EW integration, device infrastructure, and conflict objectives.","limitation":"Unclassified threat assessment; accesses, methods, readiness, and U.S. comparisons are partly undisclosed."},{"id":"CY-S2","title":"PRC State-Sponsored Actors Compromise and Maintain Access to U.S. Critical Infrastructure","url":"https://www.cisa.gov/sites/default/files/2024-02/aa24-038a-jcsa-prc-state-sponsored-actors-compromise-us-critical-infrastructure_1.pdf","publisher":"CISA, NSA, FBI and international partners","date":"February 2024","evidence_tier":"Tier 1","primary_use":"Confirmed Volt Typhoon access, targeted sectors, assessed intent, and mitigations.","limitation":"Victim and operational details are limited; publication date precedes later remediation."},{"id":"CY-S3","title":"Countering PRC State-Sponsored Network Compromise Worldwide","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a","publisher":"CISA and international partners","date":"September 2025","evidence_tier":"Tier 1","primary_use":"Salt Typhoon-related backbone and edge-router activity, persistence, affected sectors, and mitigations.","limitation":"Technical advisory does not quantify all victims, dwell time, or full remediation status."},{"id":"CY-S4","title":"Defense Contractor Cybersecurity: DOD Should Address External Factors","url":"https://www.gao.gov/products/gao-26-107955","publisher":"U.S. Government Accountability Office","date":"March 2026","evidence_tier":"Tier 1","primary_use":"DIB size, CMMC rollout, assessor risk, Project Spectrum, and NSA service participation.","limitation":"Program participation and rollout plans do not directly measure company security or mission consequence."},{"id":"CY-S5","title":"DOD Cyberspace Operations: About 500 Organizations Have Roles, With Potential Overlap","url":"https://files.gao.gov/reports/GAO-25-107121/index.html","publisher":"U.S. Government Accountability Office","date":"September 2025","evidence_tier":"Tier 1","primary_use":"Cyber organization, personnel, contractor, team, service-provider, and overlap evidence.","limitation":"Organizational counts include varied missions and do not measure operational effectiveness."},{"id":"CY-S6","title":"Posture Statement of the Commander, U.S. Cyber Command","url":"https://www.cybercom.mil/Media/News/Article/4509631/posture-statement-of-general-joshua-m-rudd/","publisher":"U.S. Cyber Command","date":"June 2026","evidence_tier":"Tier 1","primary_use":"Force readiness, scale, operational integration, authorities, and current priorities.","limitation":"Commander self-assessment omits classified standards, effects, and detailed shortfalls."},{"id":"CY-S7","title":"IT Systems Annual Assessment: DOD Needs Better Reporting and Cybersecurity Planning","url":"https://www.gao.gov/products/gao-25-107649","publisher":"U.S. Government Accountability Office","date":"June 2025","evidence_tier":"Tier 1","primary_use":"Zero-trust planning, cybersecurity strategy, software, and performance-reporting evidence.","limitation":"Sample covers 24 major business programs rather than all operational or weapon networks."},{"id":"CY-S8","title":"FY2026 Air Force RDT&E: Electromagnetic Warfare Integrated Reprogramming","url":"https://www.saffm.hq.af.mil/LinkClick.aspx?fileticket=tzM3UxGZI3Q%3D&portalid=84","publisher":"U.S. Air Force","date":"June 2025","evidence_tier":"Tier 1","primary_use":"EW reprogramming modernization, program scope, new-start status, and requested funding.","limitation":"Budget request and program intent do not establish delivered speed or operational effect."},{"id":"CY-S9","title":"Spectrum Management: DOD and NTIA Should Improve External Collaboration","url":"https://files.gao.gov/reports/GAO-26-107873/index.html","publisher":"U.S. Government Accountability Office","date":"May 2026","evidence_tier":"Tier 1","primary_use":"Joint spectrum governance, JEC responsibilities, training, operational gap analysis, and external coordination.","limitation":"Governance and planning structures do not provide comparative EW performance metrics."}]}