Summary

Defense budgets are climbing, yet the enterprises that spend them still take a decade to field a capability. NATO members now target 2% of GDP on defense, and many exceed it, but appropriations do not convert to deployed systems fast enough to matter against pacing threats. The tension is speed versus accountability: acquisition rules built for battleships now govern software that changes weekly. Stratenity treats defense programs as governed decision artifacts, where every trade study, milestone, and requirement is versioned, traceable, and approval-gated, so leaders move faster without losing the audit trail that Congress and allies demand.

01 CORE CHALLENGE

Rising budgets collide with a fielding cycle measured in decades

The defense sector is not short of money. It is short of speed. A major weapons program still averages roughly 10 to 16 years from a validated requirement to initial operational capability, while adversary systems iterate on far tighter loops. The result is a structural mismatch: appropriations rise, threat timelines compress, and the delivered capability lands late against a target that has already moved.

The root causes are institutional, not technical. The requirements process locks specifications years before contract award, so programs optimize for a threat picture that is stale by first flight. Cost-plus contracting rewards activity over delivery. And the milestone review structure, with its Milestone A, B, and C gates, was designed for hardware that changes slowly, not for software-defined systems that should update continuously. Primes and program offices know this. What they lack is a way to move faster that still survives a Government Accountability Office review and a Nunn-McCurdy breach test.

  • Requirements freeze early and drift late, so 30 to 40 percent of program cost growth traces to changes after Milestone B.
  • Software is governed like hardware, forcing quarterly or annual release cadences on systems that could ship monthly.
  • Test and evaluation is a serial gate at the end, not a continuous activity, adding 18 to 24 months to many programs.
02 FINANCIAL SUSTAINABILITY

The economics of programs, not just contracts

Defense financial health is judged at the program level, where the gap between authorized funding and obligated, delivered value is the number that matters. A program can be fully funded and still failing if obligation rates lag and unit costs breach thresholds. The Nunn-McCurdy statute forces a report to Congress when unit cost grows 15 percent, and program termination consideration at 25 percent, so cost discipline is not optional hygiene, it is survival.

Financial signalHealthy bandWarning zoneStrategic action
Unit cost growth vs baselineUnder 10%15% (Nunn-McCurdy)Rebaseline and re-cost before the breach report
Obligation rate, first yearOver 80%Under 60%Fix contracting throughput, not just funding
Cost performance index (CPI)0.95 to 1.05Under 0.90Recovery plan tied to earned value data
Sustainment share of lifecyclePlanned 60 to 70%Unplanned surgeModel total ownership cost, not flyaway cost

The strategic error is optimizing flyaway cost while sustainment, which is 60 to 70 percent of lifecycle cost, is treated as someone else's budget line. Programs that model total ownership cost from Milestone A make different design choices and survive the out-year budget drills.

03 TALENT AND WORKFORCE

Cleared talent is the binding constraint

The scarce resource in defense is not engineers, it is cleared engineers. A Secret clearance takes months and a Top Secret with SCI access can take a year or more, so a program cannot simply hire its way out of a staffing gap. The cleared software workforce is aging, and the primes compete with each other and with a commercial sector that pays more and clears no one.

  • Clearance backlog: adjudication timelines of 6 to 12 months mean a hire made today is productive on classified work in the next fiscal year, not this one.
  • Skills mismatch: the workforce is deep in systems engineering and thin in modern software, DevSecOps, and machine learning operations.
  • Retention: cleared professionals command a 10 to 20 percent premium and are poached across the primes, so attrition in a key program is a schedule risk, not just an HR metric.

The move that works is decoupling clearance from productivity: structure work so uncleared talent builds against unclassified interfaces and synthetic data, and reserve the cleared bottleneck for the genuinely classified integration.

04 TECHNOLOGY AND DATA READINESS

Software-defined systems on a hardware-defined backbone

The defense technology agenda is dominated by a single shift: from platforms to software-defined, networked capability. Joint All-Domain Command and Control (JADC2) assumes that sensors, shooters, and decision nodes share data in near real time. Most legacy systems were never built to do that. They hold data in proprietary formats, on air-gapped networks, behind interfaces that were never designed for interoperability.

The practical readiness gap is data. An AI targeting or logistics model is only as good as the labeled, current, accredited data it can reach, and in most programs that data is trapped. The organizations moving fastest are standing up a data layer with common standards before they chase AI use cases, because a model on top of ungoverned data is a liability, not an asset.

  • Adopt open mission systems standards so capabilities are modular, not welded to one prime's stack.
  • Accredit a data pipeline before funding models, because accreditation, not algorithm, is the long pole.
  • Treat AI outputs as decision support with human oversight, aligned to Department of Defense responsible AI principles.
05 GOVERNANCE AND COMPLIANCE

The regulatory perimeter is the operating environment

In defense, compliance is not overhead, it is the price of admission. The Defense Federal Acquisition Regulation Supplement (DFARS) governs contracting. Cybersecurity Maturity Model Certification (CMMC) 2.0 now gates eligibility: a contractor handling Controlled Unclassified Information must meet Level 2, aligned to NIST SP 800-171, and third-party assessment is phasing in across contracts. Miss it and you are ineligible to bid, regardless of technical merit.

Layered on top are International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR), which govern who can touch technical data, and the Federal Acquisition Regulation itself. A single ITAR violation can trigger civil penalties over 1 million dollars per infraction and debarment. Governance failures here are existential, not correctable in the next quarter.

  • CMMC 2.0 Level 2: NIST 800-171 controls, third-party assessed, required to hold CUI.
  • ITAR and EAR: technical data access controls, with per-violation penalties in the seven figures.
  • DFARS 252.204-7012: incident reporting within 72 hours of discovery.
06 CUSTOMER OUTCOMES AND RELIABILITY

The customer is the warfighter, and the metric is mission

Defense outcomes are measured in operational availability and mission effectiveness, not customer satisfaction surveys. A system that is 95 percent capable but available only 60 percent of the time has failed the warfighter. Readiness rates, mean time between critical failures, and sortie generation are the true scorecard, and they are unforgiving.

A worked example: a fleet with an operational availability target of 80 percent but actual readiness of 62 percent is not a maintenance problem, it is a design and sustainment problem set at Milestone B. The programs that hit readiness targets designed for maintainability early, invested in the supply chain for spares, and instrumented the platform so failures were predicted, not discovered.

07 ECOSYSTEM AND PARTNERSHIPS

Primes, nontraditionals, and the allied industrial base

The defense ecosystem is bifurcating. The traditional primes hold integration scale and clearance depth. The nontraditional entrants, funded by venture capital and using commercial development practices, hold speed. The programs that win pair them: prime-led integration and accreditation, with commercial-speed software from nontraditionals brought in through Other Transaction Authority (OTA) agreements that sidestep the slowest parts of the FAR.

  • Use OTA and commercial solutions openings to bring nontraditionals in without a decade of qualification.
  • Build allied industrial base partnerships (AUKUS, NATO co-development) to share cost and expand production.
  • Structure subcontract flow-down so CMMC and ITAR obligations are enforced, not just referenced.
08 STRATENITY LENS: PATH FORWARD

Programs as governed decision artifacts

Stratenity's view is that the defense speed problem is a governance architecture problem. Every consequential program decision, a requirement change, a trade study, a milestone recommendation, should be a typed, versioned artifact with explicit inputs, constraints, assumptions, and an approval gate. When the trade space is captured as governed artifacts rather than static briefings, a program can move faster because the audit trail is automatic, not reconstructed after a GAO inquiry. Speed and accountability stop being a trade-off. The same artifact that lets a program office decide in weeks is the record that survives the Nunn-McCurdy review.

09 MANAGEMENT CONSULTING GUIDANCE

Five moves for defense leaders

  • Rebaseline programs against total ownership cost, not flyaway cost, before the out-year budget drill forces it.
  • Decouple clearance from productivity by structuring uncleared work against unclassified interfaces and synthetic data.
  • Accredit a governed data layer before funding any AI use case, because accreditation is the long pole.
  • Bring nontraditionals in through OTA agreements while keeping prime-led integration and CMMC enforcement.
  • Move requirements and trade decisions into versioned artifacts so speed does not cost you the audit trail.
10 EXECUTION LEVERS FOR DEFENSE

Levers that move the fielding curve

  • Modular open systems: target 50 percent of subsystems on open interfaces to cut integration time and vendor lock.
  • Continuous authority to operate: move from annual to continuous accreditation to release software monthly, not yearly.
  • Earned value discipline: hold CPI between 0.95 and 1.05 with monthly recovery triggers below 0.90.
  • CMMC readiness: reach Level 2 assessment 12 months before it gates the target contract, not the week of.
  • Readiness by design: set operational availability at 80 percent or higher and instrument for predictive maintenance from Milestone B.