Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications
The GAO found the Federal Aviation Administration (FAA) has identified electromagnetic spectrum-related threats—including spoofing and jamming—to the National Airspace System (NAS) but has not completed required risk and mitigation assessments, updated security documentation, or established a…
Cabrillo Club
Editorial Team · September 21, 2026 · 5 min read

Also in this intelligence package
TL;DR
The GAO found the Federal Aviation Administration (FAA) has identified electromagnetic spectrum-related threats—including spoofing and jamming—to the National Airspace System (NAS) but has not completed required risk and mitigation assessments, updated security documentation, or established a real-time monitoring and detection capability for all spectrum-related threats. FAA’s collaboration mechanisms partially meet leading practices and lack policies for information sharing and coordination with non-federal partners outside interagency groups. GAO also identified vulnerabilities in text-based aviation communication applications (weak authentication, encryption, and protocol design) that could allow interception or spoofing of critical messages. Without completed assessments, updated security documentation, formalized information-sharing procedures, and real-time monitoring, the FAA may lack the data and processes needed to prioritize and respond to evolving spectrum threats—raising the risk of disrupted communications, degraded situational awareness, and operational impacts. Contractors in cybersecurity, aviation security, RF communications, and related capture teams should treat this as a critical, near-term programmatic driver and prepare for potential FAA and interagency procurement activity focused on threat detection, mitigation, and secure communications hardening.
Key Points
- What happened: GAO reported FAA has identified spectrum-related threats (spoofing, jamming) to the NAS but has not completed risk/mitigation assessments, updated security documentation, or established comprehensive real-time monitoring; collaboration with partners partially meets leading practices; text-based aviation communications are vulnerable to interception and spoofing.
- Who is affected: NAICS 481111, 488111, 488190, 517410, 517919, 541330, 541512, 541513, 541519, 541715, 334220, 334290, 334511, 336411, 336413; Agencies: DOT, FAA, DHS (Department of Homeland Security), CISA, DOD, NIST; Contract vehicles: OASIS+, 8(a) STARS III, Alliant 2, SEWP; Market segments listed under Segmentation (Cybersecurity; Aviation Security; Electromagnetic Spectrum Management; Radio Frequency Communications; Network Security; etc.).
- Timeline: Timeline TBD pending source review.
- What contractors should do NOW: Immediately review and document capabilities for spectrum threat detection and RF resilience; prepare proposals and capture plans emphasizing risk assessments, real‑time monitoring, secure authentication/encryption for text-based aviation communications, and interagency information‑sharing support; map offerings to relevant compliance surfaces (e.g., NIST 800-53, NIST CSF, FISMA, NIST 800-171 (NIST Special Publication 800-171), FAA Order 1370.121, TSA Security Directives); configure alerts for FAA- and GAO-related solicitations and capability requests.
Who Is Affected
Affected segments include contractors and integrators across aviation operations, aircraft systems, RF/wireless communications, cybersecurity services, threat detection and monitoring, and risk/assessment services. Specific NAICS codes, agencies, contract vehicles, and market segments are listed in the Segmentation provided: NAICS 481111; 488111; 488190; 517410; 517919; 541330; 541512; 541513; 541519; 541715; 334220; 334290; 334511; 336411; 336413. Agencies: DOT, FAA, DHS, CISA, DOD, NIST. Contract vehicles: OASIS+, 8(a) STARS III, Alliant 2, SEWP. Compliance regimes noted: NIST 800-53, NIST Cybersecurity Framework, FISMA, NIST 800-171, FAA Order 1370.121, TSA Security Directives, Critical Infrastructure Protection.
Frequently Asked Questions
Q: Did GAO say FAA is already under attack?
A: GAO found FAA has identified electromagnetic spectrum-related threats, including spoofing and jamming, to the NAS. The report states FAA has not completed risk and mitigation assessments or established comprehensive real-time monitoring. For details on incidents or confirmed attacks, pending source review.
Q: Will this trigger new FAA procurement or directives?
A: The GAO review stems from a provision in the Servicemember Quality of Life Improvement and National Defense Authorization Act for Fiscal Year 2025. The Summary does not specify upcoming procurements or directives—Timeline and procurement actions are TBD pending source review.
Q: What technical areas should we highlight in proposals now?
A: Emphasize capabilities in spectrum/RF threat detection and real-time monitoring, risk and mitigation assessment services, secure messaging and authentication for aviation text communications, incident response for aviation systems, and adherence to the listed compliance surfaces (NIST 800-53, NIST CSF, FISMA, NIST 800-171, FAA Order 1370.121, TSA Security Directives). Tailor capture strategies for the named contract vehicles where applicable.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →
Definitions
- National Airspace System (NAS): The network of U.S. airspace, navigation facilities, airports, and air traffic control systems that support civil aviation (term appears in the Summary).
- Spoofing: A type of attack where a malicious actor falsifies signals or messages to trick a receiver or operator (term appears in the Summary).
- Jamming: Intentional transmission of radio signals to disrupt legitimate communications by overpowering or interfering with those signals (term appears in the Summary).
- Electromagnetic spectrum-related threats: Threats that exploit radio frequency signals—such as spoofing and jamming—that affect communications between aircraft and ground systems (term appears in the Summary).
Intelligence Response
- Cabrillo Signals War Room — Already detected this event and delivered this briefing. It continuously monitors regulatory changes, contract vehicles, and policy shifts, and has flagged this GAO finding as CRITICAL.
- Cabrillo Signals Match Engine — Will automatically rescore opportunity pipelines and capture priorities where spectrum security, aviation communications security, and risk assessment services gain relevance.
- Cabrillo Signals Intelligence Hub — Tracks affected agencies, NAICS codes, and contract vehicles and will create saved searches and alerts for FAA, DOT, and related solicitations and GAO/legislative follow-ups on SAM.gov (System for Award Management).
- Proposal Studio (Proposal OS) & Proposal Studio Workflow Tracker — Use Proposal OS to assemble compliance matrices and prebuilt win themes tied to the compliance surfaces cited; use the Workflow Tracker to run an accelerated 9-gate capture process and produce audit-ready documentation.
Who to notify:
- BD / Capture Manager — to reprioritize pursuits and update win strategies.
- Cybersecurity Practice Lead — to map technical solutions to spectrum threat detection and secure comms.
- Proposal Manager / Proposal Studio Owner — to start compliant proposal shells and compliance matrices.
- CTO / Engineering Lead — to assess technical readiness for real-time monitoring and authentication/encryption projects.
- Contracts & Compliance — to ensure alignment with NIST and FAA/TSA guidance and to prepare for potential task orders on named vehicles.
First 48-hour playbook:
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →
- Hour 0–4: Convene notification call with BD, Capture, Cybersecurity Practice Lead, and Proposal Manager. Share this brief and assign immediate owners.
- Hour 4–12: Ingest GAO report documents (source review) and tag in Cabrillo Signals Intelligence Hub; create saved searches for FAA/DOT solicitations on OASIS+, 8(a) STARS III, Alliant 2, SEWP.
- Hour 12–24: Run a gap assessment using Proposal Studio against compliance surfaces (NIST 800-53, NIST CSF, NIST 800-171, FAA Order 1370.121); begin drafting risk-assessment and real-time monitoring capability statements.
- Hour 24–48: Use Signals Match Engine to rescore opportunity pipeline and prioritize 1–2 capture targets; populate Proposal Studio with win themes and coordinate the Proposal Studio Workflow Tracker to start gate 1 activities.
Relevant Cabrillo resources: Winning Federal Contracts Guide (/insights/winning-federal-contracts). For compliance and controlled data handling reference: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.