IC Oversight & Authorities — 2026-06-13

Senate NDAA Proposes New Cyber Under Secretary and Reviews of CYBERCOM Including Private Contractor Offensive Operations Pilot

BLUFBicameral divergence makes the new cyber Under Secretary unlikely to survive NDAA conference, positioning the contractor offensive cyber pilot as the more consequential provision to watch.

The SASC voted 18-9 on June 10 to advance the FY2027 NDAA 1, which proposes a new Under Secretary of Defense for Cyber, Information, and Networks dual-hatted as Department CIO and Principal Cyber Advisor to the Secretary of Defense 234. Committee staffers confirmed the position would also oversee the Chief Digital and Artificial Intelligence Office 3. The bill authorizes a pilot program for contractor-owned, contractor-operated cyber operations covering access generation and maintenance under CYBERCOM operational authority, with direct civilian or military oversight 24. The House NDAA, advanced by its committee June 5, directs DOD to review and reorganize existing cyber and IT responsibilities without creating a new under secretary 3.

Analysis
The Senate's proposed Under Secretary for Cyber, Information, and Networks, which would consolidate the CIO and Principal Cyber Advisor under one official with CDAO oversight, is unlikely to survive NDAA conference by end of FY2027. The House markup directs a reorganization review without creating any new position, and conference historically drops contested structural provisions when chambers propose incompatible architectures. The contractor-owned, contractor-operated offensive cyber pilot under CYBERCOM authority is the provision most likely to clear intact, given bipartisan interest in expanding capacity. The Senate's structural proposal may instead function as a negotiating ceiling, designed to extract a stronger review mandate from the House than its markup contains. Moderate confidence: the bicameral divergence is anchored in primary SASC documents, but conference dynamics remain opaque; rejection locks CIO and Principal Cyber Advisor fragmentation through at least FY2028.
4 sources
  1. SASC Completes Markup of National Defense Authorization Act for Fiscal Year 2027 - Senate Armed Services Committee
  2. Senate NDAA proposes realigning Defense Dept. cyber responsibilities - Inside Cybersecurity
  3. SASC proposes reorganization of Pentagon's IT, cyber leadership - DefenseScoop
  4. FY2027 NDAA Executive Summary - Senate Armed Services Committee

View in full brief →

UNCLASSIFIED // OPEN SOURCE