Compliance has never been a substitute for capability. The FY2027 National Defense Authorization Act meaningfully aligns congressional oversight with that reality. The Defense Department does not fight with compliance; it fights with capability. Congress expects the department’s cybersecurity readiness to be evaluated the same way as other weapons capabilities.
Read the FY27 NDAA on operational technology cybersecurity (OT), and you’ll see a requirements-based enforcement mechanism that has been a decade in the making. Over four consecutive NDAAs, Congress progressed from directing studies to requiring pilots, integrating OT into readiness reporting, and ultimately assigning enterprise accountability. The department’s response assigned responsibility but not the authority or resources necessary to drive enterprise-wide implementation. Each successive NDAA reflected growing congressional frustration that repeated direction had produced incremental administrative change at best, rather than measurable operational improvement.
In 2022, Katherine Hennessy Gronberg and Sarah Kuranda Vallone observed that Section 1505 of the FY22 NDAA, which required visibility mapping, command-and-control establishment, and a formal assessment of remediation funding gaps, was “the legislative equivalent of tuition-paying parents telling their college freshman: show me your grades.” Their underlying point was correct: Compliance metrics cannot capture operational readiness. The FY27 NDAA proposals would, for the first time, require the department to demonstrate cyber readiness from the installation to the combatant command level. As military operations become more dependent on cyber-physical systems, Congress is shifting its attention from whether cybersecurity controls exist to whether they support combat capability.
Cyber Operational Readiness Assessment (CORA) reporting is a new provision in the FY2027 NDAA that the department has used to determine risk-based operational readiness across United States military networks, though the results have not been shared with Congress. It was built to answer one question Congress has never been able to answer with confidence: Can the U.S. military keep fighting if the network is under attack? Right now, the department does not consistently know the answer, and neither does Congress. If the answer is no, deterrence fails before the first shot is fired. CORA instead measures what matters: Can we see everything on the network? Can we stop an attacker quickly? Can we maintain mission-essential functions during a cyber incident, and how quickly can we recover?
The department has made real progress: more tools deployed, more systems inventoried, and more audits completed. Yet Volt Typhoon spent years pre-positioning inside U.S. critical infrastructure without detection. Compliance asks the wrong questions: Did you follow the rules? Did you install the tools? Did you pass inspection? Adversaries don’t breach those administrative categories; they exploit the seams between them. Compliance measures effort. Readiness measures whether the mission survives.
For the first time, the FY27 NDAA brings cyber and OT into the department’s readiness reporting cadence. The House bill would require semiannual CORA reporting through the DoD chief information officer and the commander of the DoD Cyber Defense Command, with the reporting explicitly scoped to include OT environments, mission-critical systems, weapon platforms, industrial control systems and supporting infrastructure.
With CORA, Congress gains a unified view of cyber readiness, identification of systemic risks, clear funding priorities and accountability for outcomes. Without it, Congress receives fragmented, tool-based metrics that tell it nothing about whether missions can survive a contested network.
CORA does not stand alone in the FY27 NDAA. Both chambers have called for acceleration of zero trust adoption across OT environments, and Congress increasingly recognizes that when the network fails, the mission fails. That distinction changes what Congress should ask, what the department should measure, and what industry should be expected to deliver. The standard the FY27 NDAA establishes is not whether products satisfy technical requirements, but whether they improve operational outcomes. That is what industry should be building to.
The threat environment makes the timeline stark. Vedere Labs, the cybersecurity research arm of Forescout, tracked an 84% surge in OT protocol attacks in 2025, with threat actors linked to China, Russia and Iran dominating the activity; Volt Typhoon is already pre-positioned within the U.S. electric grid OT, and Iranian Islamic Revolutionary Guard Core (IRGC) cyber operatives have compromised more than 75 industrial control systems across U.S. water infrastructure. CORA was designed for exactly this threat environment.
What the FY27 NDAA does not resolve is a question that has gone unanswered since FY19: Who within the Defense Department is accountable for OT cybersecurity enterprise-wide? Neither chamber designates a single executive with enterprise-wide responsibility. This is more than an organizational gap; it is why the last four NDAAs produced so little. Congress did not fail to be clear, and the department did not fail to understand. What was missing each time was an executive with the authority to compel action and the resources to fund it. Accountability without authority is just paperwork with a signature.
Industry owns its share of the implementation gap. The tools already exist. Comply-to-Connect (C2C), continuous asset visibility, authentication, and automated policy enforcement all support the operational outcomes Congress is demanding. The FY27 NDAA does not ask whether cybersecurity products satisfy technical requirements. It asks whether they improve operational outcomes: readiness, resilience and mission assurance. That is the standard industry must build toward, not as a compliance exercise but as an operational contribution to military capability.
Congress must require OT cybersecurity readiness reporting in posture hearings, alongside force structure, equipment and personnel readiness. That is the logical culmination of four consecutive NDAAs pursuing the same objective.
An adversary doesn’t care whether we passed inspection. It cares whether our networks fail when it matters. Congress has finally begun asking whether the force can continue fighting when its networks are under attack.
The question before the department is no longer whether its cybersecurity programs satisfy compliance requirements. It is whether they produce a force capable of fighting through a cyberattack. An adversary that knows we cannot confidently assess our own network readiness gains an advantage before the first shot is fired. Every military capability is ultimately judged by its contribution to combat effectiveness. Cybersecurity should be no exception.
Alison King is chair of the board of directors at Operational Technology Cybersecurity Coalition and vice president of government affairs at Forescout.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
