FAA cybersecurity covers two very different jobs: protecting the agency’s own air traffic control networks from intrusion, and setting the rules that manufacturers and operators must follow to keep aircraft, drones, and supporting systems safe from cyberattack. The Federal Aviation Administration runs a formal strategy on both fronts, has been given expanding authority by Congress, and is in the middle of rulemakings for airplanes and commercial drones. Recent audits also show real gaps in how it secures its own high-impact systems.
The Five-Goal Strategy
The FAA published its first formal cybersecurity strategy in 2015 and updates it periodically. The current version, mandated by Section 509 of the FAA Reauthorization Act of 2018, was released in August 2020.1FAA. FAA Cybersecurity Strategy It organizes the agency’s work around five goals: governance across FAA divisions, protection of networks and systems, risk management, workforce development, and partnerships with government and industry.2U.S. Department of Transportation. Evolving Cybersecurity Landscape: Federal Perspectives on Securing the Nation’s Infrastructure
A Cybersecurity Steering Committee sets priorities and coordinates implementation across FAA offices. The strategy has been updated to align with the White House’s National Cybersecurity Strategy, issued in March 2023, and to reflect the agency’s growing use of cloud and internet-facing technologies.2U.S. Department of Transportation. Evolving Cybersecurity Landscape: Federal Perspectives on Securing the Nation’s Infrastructure
What Congress Has Required
Successive reauthorization laws have expanded the FAA’s cyber responsibilities. The FAA Reauthorization Act of 2024 (P.L. 118-63), signed in May 2024, is the most significant. It clarified that the FAA has “exclusive authority to impose regulations to assure cybersecurity of civilian aircraft and aircraft systems,” resolving a question about whether other agencies could impose overlapping avionics rules.3EveryCRSReport. FAA Reauthorization Act of 2024 Cybersecurity Provisions It also required the agency to designate a dedicated Cybersecurity Lead and brief Congress on implementation progress.4U.S. House Committee on Transportation and Infrastructure. FAA Reauthorization Act Section-by-Section Summary
Earlier laws set the groundwork. The FAA Extension, Safety, and Security Act of 2016 directed the agency to clarify internal cybersecurity roles, and the 2018 reauthorization mandated the formal strategy, a National Academies workforce study, and interagency collaboration with TSA.2U.S. Department of Transportation. Evolving Cybersecurity Landscape: Federal Perspectives on Securing the Nation’s Infrastructure
New Cybersecurity Rules for Aircraft
For years, FAA airworthiness regulations contained no explicit cybersecurity requirements. The agency handled cyber issues through case-by-case “special conditions” whenever a new aircraft design introduced internet-connected or “e-enabled” systems, an approach that dates back at least to the Boeing 787.5Aviation Today. How DO-326 and ED-202 Are Becoming Mandatory for Airworthiness
On August 21, 2024, the FAA published a Notice of Proposed Rulemaking titled “Equipment, Systems, and Network Information Security Protection” to codify permanent cybersecurity design standards into 14 CFR Parts 25 (transport category airplanes), 33 (engines), and 35 (propellers).6GovInfo. Equipment, Systems, and Network Information Security Protection NPRM Anyone seeking design approval would have to protect these products against “intentional unauthorized electronic interactions,” defined as events with the potential to affect an aircraft through unauthorized access, disruption, modification, or destruction of information or system interfaces. Malware and remote attacks fall within the scope. Physical sabotage and electromagnetic jamming do not.
Applicants would have to identify and assess security risks through formal analyses, implement protective mechanisms or process controls, and develop Instructions for Continued Airworthiness so operators can maintain those protections in service. The comment period closed on October 21, 2024. According to the Spring 2025 Unified Agenda, the FAA was analyzing comments as of mid-2025 and projected a final rule around March 2026.7RegInfo.gov. Unified Agenda Entry for RIN 2120-AL94
A major motivation is alignment with the European Union Aviation Safety Agency, which finalized its own cybersecurity airworthiness provisions in July 2020. Both agencies drew from an Aviation Rulemaking Advisory Committee working group that included EASA representatives and reported in August 2016, with the aim of harmonized standards so manufacturers can design and certify aircraft for both markets without conflict.6GovInfo. Equipment, Systems, and Network Information Security Protection NPRM
New Cybersecurity Rules for Drones
In August 2025, the FAA and TSA jointly published a proposed rule titled “Normalizing Unmanned Aircraft Systems Beyond Visual Line of Sight Operations.” Alongside its many other provisions, it would impose the first formal cybersecurity requirements on the commercial drone ecosystem.8Federal Register. Normalizing UAS BVLOS Operations NPRM The approach is performance-based: it specifies outcomes rather than mandating specific security tools, and it applies to three groups.
- Commercial drone operators would need cybersecurity policies covering infrastructure protection, employee access, and attack mitigation, reviewed annually. Incidents involving loss of control or unauthorized access would have to be reported to the FAA within 96 hours.
- Automated Data Service Providers running UAS traffic management systems would have to protect their networks and data. The FAA identified ISO 27001 as one acceptable compliance path.
- UAS manufacturers would have to protect their products from intentional unauthorized electronic interactions, with the NIST Cybersecurity Framework suggested as an acceptable route. Manufacturers would need to notify the FAA of identified hazards within 10 calendar days.9Crowell & Moring. Hacker No-Fly Zone: FAA and TSA Propose Cybersecurity Rules for Drone Ecosystem
The comment period closed October 6, 2025, after the FAA denied two requests to extend it. The rulemaking drew over one million public comments.8Federal Register. Normalizing UAS BVLOS Operations NPRM
Gaps in the FAA’s Own Systems
The FAA manages 45 information systems classified as “high-impact,” meaning a compromise could have severe or catastrophic consequences for the National Airspace System. An April 2026 audit by the Department of Transportation’s Office of Inspector General found significant security gaps across those systems.10DOT Office of Inspector General. FAA High-Impact System Security Controls Audit
Fifteen of the 45 high-impact systems were still using the outdated NIST SP 800-53 Revision 4 security control baseline rather than the current Revision 5. Across all 45 systems, 1,836 of 16,245 required security controls, roughly 11 percent, had not been fully implemented. The FAA was also not tracking vulnerabilities in the Department of Transportation’s official system of record, Cyber Security Assessment and Management, and was instead using its own internal tool, which limited transparency with DOT leadership. Security documentation was not consistently updated to reflect known vulnerabilities.10DOT Office of Inspector General. FAA High-Impact System Security Controls Audit
The Inspector General issued four recommendations: identify all missing Revision 5 controls and build remediation plans, update system security plans to current standards, migrate vulnerability tracking into the departmental system of record, and track mitigation progress for all controls assessed as not fully implemented. The FAA concurred with all four and pledged to complete the work by December 31, 2026.11Foundation for Defense of Democracies. Audit Finds Federal Aviation Administration Delinquent in Cybersecurity Practices
A 2020 GAO report (GAO-21-86) had already flagged weaknesses in avionics oversight, finding the FAA had not assessed its oversight program for cybersecurity risks, had no dedicated training for inspectors, and had not issued guidance for independent cybersecurity testing of in-service aircraft. The FAA implemented all six recommendations, though it pushed back on independent fleet testing, concluding it could corrupt airplane systems and undermine safety.12GAO. Aviation Cybersecurity: FAA Should Fully Implement Key Practices, GAO-21-86
Aging Air Traffic Infrastructure
Much of the cyber risk in air traffic control comes from the age of the equipment. The FAA’s 21 en-route centers average roughly 61 years old, many legacy systems rely on analog telecommunications from the 1960s, and some equipment still uses components such as floppy disks that experts have identified as potential pathways for attackers.13U.S. Department of Transportation. Brand New Air Traffic Control System Plan A September 2024 GAO investigation found that 105 of 138 air traffic control systems were “unsustainable.”11Foundation for Defense of Democracies. Audit Finds Federal Aviation Administration Delinquent in Cybersecurity Practices
Congress provided over $12 billion in reconciliation funding for modernization. The FAA estimates the full cost at roughly $20 billion more. The agency has hired Peraton as the prime systems integrator and set a three-year framework targeting 2028 for replacing legacy copper circuits with fiber, deploying 27,000 digital radios, installing 450 IP voice switches, and modernizing automation platforms in 89 towers.14Federal News Network. FAA Ramps Up Billions in Spending as Down Payment for Air Traffic Overhaul
Progress is uneven. As of mid-2026, the FAA’s own dashboard shows telecommunications replacement at 51 percent complete, with 2,646 of 5,170 connections replaced. Radio site conversions stand at 18 percent, IP voice switches at 14 percent, and radar modernization at 1 percent.15FAA. Modern Skies Modernization Dashboard Under the agency’s projections, if funding stays flat at about $3 billion per year, many programs will not finish until the mid-2030s or 2040.13U.S. Department of Transportation. Brand New Air Traffic Control System Plan The FAA has said the shift to IP-based telecommunications is needed to “ensure reliability, enhance cybersecurity, and to improve scalability.”
Looking further out, the FAA in March 2026 issued a Request for Information on transitioning NAS, air traffic control, and IT systems to post-quantum cryptography, calling it a “foundational enabler of modernization.”16FedScoop. DOT, FAA Cybersecurity and Quantum Modernization The RFI addressed “harvest-now-decrypt-later” risks, the concern that adversaries are collecting encrypted data now with the expectation of cracking it once quantum machines mature.17R Street Institute. Post-Quantum Cryptography Migration in the United States The FAA acknowledged that integrating post-quantum cryptography into legacy NAS infrastructure would likely require specialized expertise beyond standard product suites.18ExecutiveGov. FAA RFI for NAS Post-Quantum Cryptography
The Threat Picture So Far
As of 2020, per the GAO, there had been no reports of a successful cyberattack on an airplane’s avionics systems.12GAO. Aviation Cybersecurity: FAA Should Fully Implement Key Practices, GAO-21-86 Attacks on aviation ground infrastructure have happened, with limited impact. In 2022, the pro-Russian group Killnet launched distributed denial-of-service attacks against 14 U.S. airports. In early 2023, similar attacks hit seven German airports and Eurocontrol. A former FAA Chief Counsel described these as “nuisance, website disruptions” that did not affect flight operations.19FAA. What a Tangled Web: Aviation Prosperity and Cybersecurity Risk
The broader trend lines are less reassuring. The Cyberspace Solarium Commission 2.0 reported that cyberattacks on the aviation industry rose 32 percent in 2023 over the prior year, and that ransomware incidents in the sector surged 500 percent over the same period.20Foundation for Defense of Democracies. Turbulence Ahead: Navigating the Challenges of Aviation Cybersecurity The GAO has identified five persistent risk categories for avionics: unpatched software, insecure supply chains, malicious software uploads, outdated systems on legacy airplanes, and flight data spoofing.12GAO. Aviation Cybersecurity: FAA Should Fully Implement Key Practices, GAO-21-86
Who Else Is Involved
Aviation cybersecurity is not the FAA’s job alone. The main coordination body is the Aviation Cyber Initiative, a tri-chaired task force of the Department of Transportation (through the FAA), Department of Homeland Security (through CISA and TSA), and Department of Defense. It was established in 2017 to reduce cyber risk across civil and military aviation.21Aviation Today. Homeland Security, DoD, Transportation Officials Focus on Aviation Cyber Security A 2020 DOT Inspector General report found the initiative lacked a dedicated budget, personnel, and a tracking mechanism for its work.20Foundation for Defense of Democracies. Turbulence Ahead: Navigating the Challenges of Aviation Cybersecurity
The FAA also partners with CISA, the FBI, and the Intelligence Community on threat monitoring. Internationally, it serves as the U.S. Panel Member on ICAO’s Cybersecurity Panel, works with EASA on certification harmonization, and collaborates with EUROCONTROL on information security management and digital identity.19FAA. What a Tangled Web: Aviation Prosperity and Cybersecurity Risk
An April 2025 Cyberspace Solarium Commission 2.0 report described the current landscape as “fragmented oversight.” It noted that the split between FAA (airworthiness and safety) and TSA (security of airports, airlines, and organizational systems) can produce unclear delineations, inconsistent regulation, and sometimes duplicative requirements. The report recommended that TSA work with the FAA and CISA to conduct cybersecurity risk assessments at high-impact airports and that the two agencies harmonize their aviation cybersecurity regulations.20Foundation for Defense of Democracies. Turbulence Ahead: Navigating the Challenges of Aviation Cybersecurity
Workforce Pressures
A 2021 National Academies study, mandated by Section 549 of the 2018 FAA Reauthorization Act, found the FAA “on par with other federal agencies” in cyber workforce capacity and diversity but facing the same headwinds as the rest of government. The FAA competes for talent in a market where 82 percent of employers report a cybersecurity skills shortage, per a survey cited in the study. The agency faces additional disadvantages: lower pay than the private sector, a specialized and sometimes less cutting-edge technical environment, and strict citizenship and security clearance requirements.22National Academies. Looking Ahead at the Cybersecurity Workforce at the FAA, Chapter 1
The study recommended broadening the talent pipeline, enhancing diversity, using the FAA’s mission as a recruiting tool, and reskilling existing staff.23National Academies. New Report Charts Path Forward for FAA’s Cybersecurity Workforce In response, the FAA laid out steps including expanded rotation programs across DOT, virtual training labs and a formal mentor program, standardized career maps built on the NICE cybersecurity workforce framework, use of federal hiring flexibilities such as on-the-spot hiring and designation of cyber positions as “mission-critical” for higher pay, and recruitment at industry events including Black Hat and DEF CON.24FAA. FAA Response to National Academy of Sciences Study on FAA Cybersecurity Workforce A looming retirement wave among current technical staff and what the Cyberspace Solarium Commission 2.0 called a “growing shortage of skilled workers” to maintain aging NAS components add urgency.20Foundation for Defense of Democracies. Turbulence Ahead: Navigating the Challenges of Aviation Cybersecurity