ics-ottrade-pressNewsThe Broadside2 min read

FY27 NDAA would reshape DoD cyber oversight around mission survival

The House bill's CORA reporting requirement asks whether systems can fight through an attack, not whether the paperwork is in order.


TL;DR

The FY2027 NDAA's House proposal would mandate semiannual Cyber Operational Readiness Assessment (CORA) reporting from installation to combatant-command level, explicitly scoped to OT environments, mission-critical systems, weapon platforms, and industrial control systems. Reporting would flow through the DoD CIO and the commander of DoD Cyber Defense Command. The shift marks the first time Congress has moved to bring cyber and OT readiness into the department's formal reporting cadence, asking a question compliance metrics can't answer: can the mission survive when the network is under attack?

FY27 NDAA would reshape DoD cyber oversight around mission survival
Editorial illustration · drawn by The Broadside

The FY2027 National Defense Authorization Act contains a provision that, if enacted, would change the question Congress asks about DoD cybersecurity. The House bill would require semiannual Cyber Operational Readiness Assessment (CORA) reporting (from installation up through combatant commands) scoped to include OT environments, mission-critical systems, weapon platforms, industrial control systems, and supporting infrastructure. It's the fourth consecutive NDAA to push in this direction, but the first to demand that the department demonstrate operational readiness rather than report compliance artifacts.

The progression tells its own story. Over four NDAAs, Congress moved from directing studies to requiring pilots, then integrating OT into readiness reporting, and now assigning enterprise accountability. Each step reflected growing frustration that repeated direction produced incremental administrative change rather than measurable operational improvement. The FY27 proposal asks a question the department has never been able to answer with confidence: can the U.S. military keep fighting if the network is under attack?

What CORA measures that compliance can't

CORA was built to answer that question. It measures whether the department can see everything on the network, stop an attacker quickly, and maintain mission-essential functions during a cyber incident. Compliance asks whether you followed the rules and passed inspection. Readiness asks whether the mission survives. Adversaries don't breach administrative categories, they exploit the seams between them.

The threat environment makes the timeline stark. Vedere Labs tracked an 84% surge in OT protocol attacks in 2025, with threat actors linked to China, Russia, and Iran dominating the activity. Volt Typhoon spent years pre-positioning inside U.S. critical infrastructure without detection. Iranian IRGC cyber operatives have compromised more than 75 industrial control systems across U.S. water infrastructure.

What's still missing

The FY27 NDAA does not resolve a question that has lingered since FY19: who within the Defense Department is accountable for OT cybersecurity enterprise-wide? Neither chamber's proposal designates a single executive with enterprise-wide authority. Accountability without authority is just paperwork with a signature, and it's a large part of why the last four NDAAs produced so little operational change.

Industry has its own gap to close. The tools (Comply-to-Connect, continuous asset visibility, authentication, automated policy enforcement) already exist. The standard the FY27 proposal establishes is not whether products satisfy technical requirements, but whether they improve operational outcomes: readiness, resilience, and mission assurance. That's what industry should be building toward.


Published ·Deep Fathom