The Senate Armed Services Committee has greenlit a provision that would, for the first time, formally authorize private contractors to conduct cyber operations on behalf of the US military. The measure, tucked inside the National Defense Authorization Act for Fiscal Year 2027, would create a pilot program letting civilian firms generate and maintain access to foreign computer networks under the watchful eye of US Cyber Command.
The SASC advanced the provision on June 23, 2026, during its markup of the FY2027 NDAA. Under the proposed framework, contractors would use their own infrastructure to carry out access generation and maintenance operations. These are the tedious, resource-intensive tasks of finding pathways into target networks and keeping those pathways viable over time.
The scope is deliberately narrow. Operations would be restricted exclusively to access-related activities. No offensive capabilities, meaning no disrupting enemy systems, no destroying data, no shutting down infrastructure. Contractors would operate under the command and supervision of CYBERCOM, with Department of Defense approval required.
The China math problem
The driving force behind this proposal is a numbers game the US is losing badly. China’s cyber workforce reportedly outnumbers America’s by a ratio of roughly 10 to 1. That gap isn’t just about headcount. It translates directly into operational capacity, because maintaining access to adversary networks is one of the most labor-intensive tasks in cyber operations.







