Cyberspace Operations: Missions, Authorities, and Forces

Military cyberspace operations are the activities U.S. armed forces conduct in or through cyberspace to achieve military objectives, and Joint Publication 3-12 defines them as the “employment of cyberspace capabilities where the primary purpose is to achieve objectives in or through cyberspace.”1International Institute of Humanitarian Law. Joint Publication 3-12, Cyberspace Operations They can run on their own or alongside operations on land, at sea, in the air, and in space. Inside the Department of Defense, they are directed by U.S. Cyber Command and executed by tens of thousands of military personnel, civilians, and contractors organized around a common set of missions and authorities.

The Three Mission Categories

Every U.S. military cyber mission fits into one of three buckets. What separates them is intent, not tooling.

Offensive Cyberspace Operations (OCO) project power in and through foreign cyberspace. They may target an adversary’s networks directly or cause cascading effects in the physical world, from disrupting communications to interfering with command systems or critical infrastructure. Any operation conducted outside friendly networks for a purpose other than defeating an active threat is offensive.2Air Force Doctrine. AFDP 3-12, Cyberspace Operations

Defensive Cyberspace Operations (DCO) preserve friendly cyberspace capabilities by defeating active or imminent threats. They split in two: internal defensive measures on friendly networks, and response actions taken outside the defended network, in foreign cyberspace, to counter a threat at its source.2Air Force Doctrine. AFDP 3-12, Cyberspace Operations

Department of Defense Information Network (DODIN) Operations are the standing job of securing, configuring, operating, and maintaining DoD’s network infrastructure. Unlike defensive operations, which react to specific threats, DODIN work is proactive and threat-agnostic, aimed at hardening the environment before any attack.3U.S. Government Accountability Office. DOD Cyberspace Operations

Who Runs Military Cyber Operations

U.S. Cyber Command (USCYBERCOM) is the unified combatant command that directs and synchronizes these missions. It was stood up in 2009 and elevated to a full unified combatant command in May 2018, and it is headquartered at Fort Meade, Maryland.4Congressional Research Service. Defense Primer: Cyberspace Operations Its commander, General Joshua M. Rudd, also serves as Director of the National Security Agency under a longstanding “dual-hat” arrangement.5U.S. Cyber Command. Mission and Vision

USCYBERCOM’s mission has three pillars: defending DoD networks, supplying cyber capabilities to combatant commanders worldwide, and strengthening the nation’s ability to withstand and respond to cyberattacks.5U.S. Cyber Command. Mission and Vision Under Enhanced Budgetary Control authority granted by Congress, it now manages nearly $4 billion of the defense budget.6U.S. Cyber Command. Posture Statement of General Joshua M. Rudd

Two sub-unified commands do the frontline work. The Cyber National Mission Force (CNMF), created in 2014 and elevated to sub-unified command status in December 2022, defends the nation from foreign malicious cyber actors.7DefenseScoop. Cyber National Mission Force Declared Sub-Unified Command The Department of Defense Cyber Defense Command (DCDC), established in May 2025 to replace the former Joint Force Headquarters-DODIN, secures, operates, and defends the DoD information network.8DefenseScoop. JFHQ-DODIN Redesignated as DCDC Sub-Unified Command

Each service contributes forces through its own component: Army Cyber Command, Fleet Cyber Command/Tenth Fleet, 16th Air Force, and Marine Corps Forces Cyberspace Command.9Congressional Research Service. Defense Primer: Cyberspace Operationsa>10U.S. Space Force. Space Delta 6 Fact Sheet11Space Systems Command. USSF Announces Formation of Defensive Cyber Squadrons The Coast Guard also serves as a USCYBERCOM component under the Department of Homeland Security.6U.S. Cyber Command. Posture Statement of General Joshua M. Rudd

The Cyber Mission Force

The operational muscle of USCYBERCOM is the Cyber Mission Force (CMF), the joint pool of teams that actually conduct operations. The CMF reached full operational capability in 2018 with 133 teams and about 6,200 personnel drawn from across the services.12U.S. Cyber Command. Cyber 101: Cyber Mission Force Its teams fall into four types: Cyber Protection Teams that defend DoD networks and hunt for threats, Combat Mission Teams that conduct offensive operations for combatant commands, National Mission Teams inside the CNMF that defend the homeland, and support teams handling intelligence, planning, and analysis.13DefenseScoop. New Cyber Mission Force Teams: 12 of 14 Now Established

In 2021, the Secretary of Defense ordered 14 more teams built by September 2028. Twelve had been established as of May 2025, with two still in progress across the Air Force, Army, and Navy.13DefenseScoop. New Cyber Mission Force Teams: 12 of 14 Now Established

The CMF is not the whole story. A September 2025 Government Accountability Office audit counted 434 organizations across DoD conducting cyberspace operations, with roughly 61,000 military and civilian personnel and more than 9,500 contractors. GAO flagged redundant training courses and overlap among DoD’s 23 cybersecurity service providers, and recommended consolidation reviews in both areas. DoD concurred and committed to finishing those assessments by September 2026.14U.S. Government Accountability Office. DOD Cyberspace Operations

Defend Forward and Hunt-Forward Operations

Since 2018, USCYBERCOM has operated under a “Defend Forward” strategy: disrupt malicious cyber activity at its source rather than wait for it to reach American networks. The idea covers activity below the threshold of armed conflict as well as wartime scenarios.4Congressional Research Service. Defense Primer: Cyberspace Operations

The most visible piece is the hunt-forward program, in which CNMF teams deploy to partner countries by invitation to search those nations’ networks for adversary activity. By mid-2023, the CNMF had run 47 deployments to 22 countries covering more than 70 networks.15U.S. Cyber Command. U.S., Canada, and Latvia Conclude Defensive Hunt Operation The force conducts roughly two dozen such operations a year and has, for a stretch, run active operations simultaneously across every geographic combatant command.16DefenseScoop. Cybercom Finds Chinese Malware in South America

Publicly acknowledged deployments include Ukraine, where cyber teams hardened networks ahead of the 2022 Russian invasion; Latvia, where a joint operation with Canadian forces identified Russian-linked malware; and countries across the Balkans and Baltics including Albania, Estonia, Lithuania, Croatia, Montenegro, and North Macedonia.15U.S. Cyber Command. U.S., Canada, and Latvia Conclude Defensive Hunt Operation Hunt-forward teams have also found Chinese government-linked malware on networks in Latin America within U.S. Southern Command’s area of responsibility.16DefenseScoop. Cybercom Finds Chinese Malware in South America The operations have put more than 90 malware samples in the hands of the broader cybersecurity community.

One threat driving this effort is Volt Typhoon, a Chinese state-sponsored group that a February 2024 U.S. advisory said had been pre-positioning on American critical infrastructure networks—communications, energy, transportation, and water systems—for at least five years. The group used “living off the land” techniques to avoid detection while positioning for potential disruptive attacks in a future crisis. The Department of Justice disrupted a botnet the group had been using to conceal its access.17CISA. PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure

Legal Authorities

Military cyber operations rest on a layered mix of constitutional authority, statutes, presidential directives, and international law. There is no single legal checklist; military lawyers synthesize domestic law, international law, and classified policy for each operation.18U.S. Army TJAGLCS. Operational Law Handbook, Chapter 9: Cyberspace Operations

Domestic Authorities

Congress first formally affirmed DoD’s authority to conduct offensive cyber operations in Section 954 of the FY2012 National Defense Authorization Act, which required presidential direction and kept operations subject to the law of armed conflict and the War Powers Resolution.19Harvard International Law Journal. Some Considerations for Conducting Legal Reviews of U.S. Military Cyber Operations The FY2019 NDAA expanded those authorities. Section 1632 classified clandestine military cyber activities as “traditional military activities,” exempting them from the covert action reporting requirements of 50 U.S.C. § 3093, and Section 1642 authorized operations to disrupt, defeat, and deter malicious campaigns by Russia, China, North Korea, and Iran.4Congressional Research Service. Defense Primer: Cyberspace Operations

The core presidential directive since 2018 is National Security Presidential Memorandum 13 (NSPM-13), which replaced the Obama-era Presidential Policy Directive 20. NSPM-13 delegated authority to the Secretary of Defense to conduct time-sensitive military operations in cyberspace without a full National Security Council consensus, enabling faster decision-making. The Biden administration refined the memorandum around 2022, requiring the Pentagon to keep the White House and State Department informed of USCYBERCOM’s rationale for offensive operations after concerns that cyber actions routed through third-party nations could interfere with diplomatic relationships.20Lawfare. President Biden’s Policy Changes for Offensive Cyber Operations

International Law

There is broad international consensus that existing international law applies to state conduct in cyberspace, but significant disagreement about exactly how. The most influential scholarly effort to map the rules is the Tallinn Manual, a non-binding academic work produced under the auspices of the NATO Cooperative Cyber Defence Centre of Excellence. Tallinn Manual 2.0, published in 2017, laid out 154 “black letter” rules covering sovereignty, state responsibility, human rights, and the conduct of hostilities.21Cambridge University Press. Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations Tallinn Manual 3.0 was launched in 2021 as a five-year project to incorporate emerging state practice.22NATO CCDCOE. Tallinn Manual States remain divided on core questions such as when a cyber operation violates sovereignty or constitutes a use of force, and the prevailing view among experts is that interpreting existing law, rather than drafting new treaties, is the right path.23Lieber Institute at West Point. Law of Cyber Conflict: Quo Vadis

CYBERCOM 2.0 and the Cyber Force Debate

How cyber forces are recruited, trained, and retained has become the central structural argument in the field. Historically, each service handled these functions on its own, which critics said produced inconsistent personnel policies, fragmented career paths, and readiness gaps.

In November 2025, the Pentagon announced “CYBERCOM 2.0,” a revised force generation model giving USCYBERCOM greater influence over those functions. Three new organizations anchor the model: a Cyber Talent Management Organization for recruiting and retention, an Advanced Cyber Training and Education Center for mission-specific training, and a Cyber Innovation Warfare Center for capability development.24Department of War. Department of War Establishes CYBERCOM 2.0 The training center is projected to reach initial operational capability in 2028 and full operational capability in 2031.25Lawfare. Implementing Cybercom 2.0 Should Not Postpone Establishing a Cyber Force Senior Pentagon officials said the model preserves “presidential and congressional decision space” on whether to eventually create a separate cyber service.26DefenseScoop. DOD Revised Cyber Force Generation Model: Expert Reaction

That larger question is still open. In June 2026, a commission organized by the Center for Strategic and International Studies and the Cyber Solarium Commission 2.0 project at the Foundation for Defense of Democracies recommended establishing a standalone U.S. Cyber Force of roughly 30,000 personnel with a $10 to $11 billion budget, funded by realigning existing cyber spending across the services.27Breaking Defense. A Cyber Force Budget Would Require at Least $10 Billion The commission, co-chaired by former Army Cyber Command leader Lt. Gen. Ed Cardon, argued that the current model leaves the United States behind its adversaries.28CSIS. CSIS Commission on U.S. Cyber Force Generation Senator Kirsten Gillibrand has signaled plans to introduce an amendment to the FY2027 NDAA to create such a force, though earlier legislative attempts have failed or been scaled back.

The FY2026 NDAA, with a $901 billion topline, held the dual-hat arrangement between USCYBERCOM and NSA in place by prohibiting defense funds from being used to diminish the USCYBERCOM commander’s responsibilities or authorities. It also gave USCYBERCOM $73 million for cyberspace operations and $314 million for headquarters operations and maintenance.29Nextgov/FCW. Defense Authorization Bill Includes Billions for Cyber, Intelligence Matters The same bill directed DoD to harmonize cybersecurity regulations across the defense industrial base by June 2026, required cybersecurity training to address artificial intelligence threats, and ordered the deployment of behavioral health specialists with appropriate clearances to USCYBERCOM and the CMF.30CyberScoop. FY2026 NDAA Cybersecurity Provisions

Who Actually Does the Work

Cyber operators come from dedicated career fields in each service. In the Air Force, Cyberspace Operations Officers (the 17X field) manage weapons systems, lead crews, and advise commanders on technology risk. They need a bachelor’s degree in a STEM discipline and complete Undergraduate Cyber Training at Keesler Air Force Base, followed by advanced cyber warfare operations courses. Graduates earn certifications including CompTIA Security+ and the SANS GIAC Network Forensic Analyst credential.31U.S. Air Force. Cyberspace Operations Officer32108th Wing, Air National Guard. Positions Available to Become Cyber Warfare Operations Officers

The Army’s 17C Cyber Operations Specialist is a representative enlisted path. These soldiers conduct both offensive and defensive operations, doing penetration testing, digital forensics, malware analysis, and incident response. Training runs 10 weeks of basic combat training and 36 weeks of advanced individual training covering Windows and Linux, networking, programming, and both attack and defense techniques. Candidates need a 110 General Technical and 112 Skilled Technical score on the ASVAB and must hold a Top Secret clearance.33U.S. Army Cyber Center of Excellence. Cyber Operations Specialist34National Guard. 17C Cyber Operations Specialist