Build national cyber capacity through CISA, Cyber Command, and a reserve bench, with civil-liberties guardrails before creating a new military service.
Verification Status
AI-researched, unverifiedLast Reviewed
Jul 5, 2026
Cited Sources
10
Implementation, sequencing, safeguards, tradeoffs, and the practical path from principle to policy.
The United States faces a military cyber-readiness problem and a national cyber-resilience problem. They touch, but they are not identical.
The military problem is force generation. U.S. Cyber Command conducts operations, but the military services provide the personnel, training, career paths, and equipment behind those teams. Advocates for a separate Cyber Force argue that the current arrangement leaves cyber operators subordinate to service cultures built around land, sea, air, and space missions, creating uneven readiness and retention. Congress has already moved partway toward this concern by giving Cyber Command enhanced budget, acquisition, and force oversight authorities and by commissioning further study of alternative organizational models.
The national-resilience problem is wider. Most cyber incidents that hurt Americans are not military battles. They hit hospitals, schools, courts, water utilities, local governments, small businesses, and private critical-infrastructure operators. The civilian lead for that space is CISA, supported by the Office of the National Cyber Director, sector risk management agencies, state partners, the FBI, and private operators. Treating every cyber problem as a military problem risks weakening exactly the civilian trust network needed to get incident data, vulnerability reports, and rapid assistance from private and local actors.
This issue does not reject a future Cyber Force. It rejects creating one before Congress has defined the problem it is supposed to solve and before the country has strengthened the domestic capacity a military branch would not replace.
The first capacity move is CISA-led incident reporting that works. CIRCIA, enacted in 2022, requires CISA to create rules for covered critical-infrastructure entities to report covered cyber incidents and ransom payments. As of the latest federal rulemaking notices reviewed for this issue, that final rule has been delayed and refined through additional stakeholder process. The policy goal should be speed and usefulness, not compliance theater. Companies need a clear federal reporting lane; CISA needs timely data it can use; victims need the system to reduce duplication rather than add another paperwork demand during a crisis.
The second capacity move is a National Cyber Reserve. State and local governments often need help at the exact moment private firms are overwhelmed or unaffordable. A reserve bench of vetted civilian experts, pre-cleared for surge work and trained on public-sector incident response, would fill a gap neither active-duty military cyber teams nor ordinary procurement can fill. It should be civilian-led, legally bounded, and integrated with state emergency management rather than improvised after a ransomware event.
The third capacity move is a measured Cyber Force trigger. Congress should require a public three-year readiness assessment: Cyber Mission Force readiness, training consistency, retention, rotation problems, authority gaps, and whether Cyber Command's enhanced authorities changed the picture. If the evidence shows the current structure cannot produce the needed force, create a separate service. If the evidence shows specific authorities or workforce reforms solved the gap, do not create a new bureaucracy to prove seriousness.
Domestic cyber defense depends on trust. A hospital, water utility, school district, or small business will hesitate to share incident data if the federal response feels like military monitoring rather than assistance. That is why the domestic role must remain civilian-led and why any National Cyber Reserve statute must include strict limits on data retention, purpose use, military access to domestic incident data, and monitoring of lawful political activity.
The privacy guardrail is not an add-on. It is operational. Better information sharing depends on organizations believing the government will use shared data to defend systems, not to expand surveillance.
Turn frustration into useful pressure.
If this position misses evidence or a lived consequence, challenge it. If it holds up, help test it locally and connect it to the issues around it.