Back to news

Space Force Solicits Cyber Defenses That Run on the Satellite

Share:
Space Force Solicits Cyber Defenses That Run on the Satellite

SpaceWERX, the U.S. Space Force's innovation arm, has published a solicitation asking industry for cybersecurity software that runs on the satellite itself and can respond to an intrusion without waiting for a ground operator. The topic, designated DAF26BX06-DV512 and titled Cyberspace Warfare for Space, opens September 23 and closes October 21, with individual awards worth up to $2 million over 24 months.

From the ground segment to the orbital edge

For most of the satellite era, cyber defense has meant watching a spacecraft from the ground. Operators analyzed telemetry after it arrived, pushed fixes through narrow contact windows, and treated the vehicle as something to be monitored rather than something that could watch itself. This solicitation asks vendors to move part of that job into orbit. One of its eight focus areas calls for a persistent monitor installed directly on the space vehicle, able to flag unauthorized software, firmware, or configuration changes and, in pre-approved cases, act on them in real time.

The monitor would watch traffic on the 1553 data bus and SpaceWire, the internal wiring that shuttles commands between a spacecraft's subsystems, looking for anomalies such as irregular commands, malware uploads, or attempts to manipulate a satellite's power or timing. The Space Force wants all of it in a footprint small enough not to strain a satellite's tight size, weight, and power budget, and it expects vendors to prove the work against a FlatSat, an engineering replica of a spacecraft's electronics laid out on a bench.

Why put the defender in orbit

The reasoning traces back to what made ground stations the softest target in the first place. When defense lives entirely on the ground, an attacker who reaches the command link or an operator's network can move faster than anyone watching from a console, which is roughly how Russia's 2022 attack on Viasat's KA-SAT network played out. An onboard monitor narrows that window. A satellite can catch a malformed command and refuse it, or record the event and alert the ground, without a full round trip. Space Systems Command has been sketching this shift for months, describing how it wants lightweight intrusion detection pushed out to the spacecraft so satellites process their own cyber logs and send back only the anomalies.

Handing a satellite the authority to act on its own bus carries its own risk. A monitor that can block a command or alter a configuration is a component with deep access to the vehicle, and a flawed or subverted one could disrupt the very mission it guards. The solicitation hedges by restricting autonomous response to approved cases and keeping the ground segment in the loop for analysis. It also folds the supply chain into the same effort, with separate focus areas seeking tools that vet open-source and commercial software for hidden malware before it reaches a spacecraft and that trace code back to whoever wrote it.

Selections are expected on or about January 19, 2027, and the topic is structured as a direct-to-Phase-II award, open only to companies that can already demonstrate a working prototype.

News first reported by SpaceNews; solicitation details published by SpaceWERX.