The Senate Armed Services Committee voted 18-9 on June 11, 2026 to advance the fiscal year 2027 National Defense Authorization Act, and when the full bill text reached defense press for public analysis beginning June 23, two provisions stood out for the government contracting community: a pilot program authorizing civilian contractors to conduct offensive cyber access operations under direct U.S. Cyber Command control, and a restriction barring defense prime contractors from share repurchases if they fall short of DoD performance requirements. Both provisions now await a full Senate floor vote before conference negotiations with the House can begin.

Background

The National Defense Authorization Act is the annual legislation that sets Pentagon policy and authorizes military spending. Congress has approved an NDAA every year for more than six decades, making it one of the few consistently enacted pieces of federal legislation. The Senate and House each produce their own versions, which a conference committee must reconcile before the bill goes to the president. The Senate Armed Services Committee cleared its FY27 version on June 11, 2026, on an 18-9 vote; the full Senate floor vote remains pending.

The cyber operations pilot responds to a structural asymmetry in how the U.S. conducts offensive cyber operations. U.S. Cyber Command relies primarily on military personnel and National Guard units for most offensive activity, with defense contractors filling support, analytic, and tool-development roles that stop short of direct operations. Adversaries like China draw on a large civilian hacker ecosystem that operates alongside or at the direction of state intelligence services. Closing that capability gap has been a running debate inside and around CYBERCOM for years, and the Senate bill takes the most direct legislative step yet toward enabling contractor participation in live operations.

On stock buybacks, critics of the defense industrial base have long identified a pattern in which major prime contractors return capital to shareholders through share repurchases during periods when flagship programs run over cost or fall behind schedule. Senator Elizabeth Warren, who secured the restriction in the Senate bill, characterized the practice as contractors "cheating our government out of billions in taxpayer dollars" while rewarding shareholders instead of investing in program delivery.

Key Details

The cyber pilot authorizes the Pentagon to partner with civilian contractors to conduct cyber access operations — gaining entry to foreign computer systems — under the direct operational control of U.S. Cyber Command. The provision draws a clear boundary: it explicitly does not authorize contractors to conduct effects operations, defined as disruption, destruction, or manipulation of target systems. Those activities, under the bill as written, would require additional congressional action and separate DoD policy changes before contractors could participate.

Former U.S. Cyber Command deputy commander Charlie Moore backs the expansion, arguing that the U.S. must move beyond what it typically calls partnerships and into "becoming true teammates" to match China's depth of cyber capability.

Not all observers agree. Gary Brown of the National Defense University, who previously served as CYBERCOM's first senior legal counsel, warned that drawing civilian contractors directly into offensive cyber operations risks undermining international norms protecting civilian infrastructure — norms the U.S. has a strategic interest in upholding. Herbert Lin of Stanford's Center for International Security and Cooperation raised questions in the Breaking Defense report about where access operations fall on the legal threshold between unfriendly state activity and an attack — a distinction with direct implications for how adversaries calculate their responses.

The stock buyback restriction directly ties share repurchases to performance outcomes. Under the provision, defense companies cannot conduct buybacks if they fail to meet DoD performance requirements. The bill does not specify which metrics trigger the prohibition; implementing regulations DoD would need to issue would define those thresholds. Warren's framing targets prime contractors that deliver late, over-cost programs while simultaneously returning capital to shareholders.

Beyond the two headline provisions, the Senate bill includes Warrior Right to Repair Act language expanding military access to technical repair data for weapons systems and equipment, holding companies accountable for falsely claiming repair restrictions not grounded in statute, and authorizing DoD to bring in alternative repair providers during wartime or contingency operations when primary manufacturers cannot meet readiness demands. A separate provision addresses competition in government AI acquisitions, directing DoD to take steps to prevent a narrow group of vendors from consolidating AI contract market share in federal agencies.

The full Senate floor vote remains pending. Once the Senate acts, House and Senate negotiators must convene a conference committee to reconcile differences between the two chambers' bills before a final NDAA can reach the president.

What It Means for Contractors

The cyber access operations pilot opens a potential new contract category for defense companies with cleared offensive cyber infrastructure. Firms that have built cyber operations centers, developed intrusion toolsets, or assembled clearance-eligible technical teams should track the provision as it moves through conference. If it survives reconciliation, it could create new task order or contract vehicle mechanisms for operational cyber support roles that extend well beyond today's advisory and development work — alongside new security requirements, operational constraints, and legal exposure for participating companies. Companies not currently engaged in offensive cyber work may also want to assess whether subcontracting paths exist under a potential pilot vehicle.

The stock buyback restriction will draw immediate focus from CFOs and investor relations teams across the defense prime community. Practical impact depends entirely on how DoD defines "performance requirements" in implementing guidance. A broad definition linked to cost and schedule performance data on major programs could simultaneously affect buyback planning at multiple large contractors. Companies should evaluate current program performance records against the likely scope of those regulations before guidance takes shape. Legal teams at large primes should also watch for preliminary rulemaking signals from DoD in the months after enactment.

The Right to Repair provisions could shift the competitive landscape in sustainment contracting. Where DoD obtains expanded technical data rights and authority to engage alternative repair providers during contingencies, sole-source sustainment incumbents may face new competition on major platforms. Companies with data rights positions that currently limit third-party repair should assess whether those positions would withstand the bill's accountability language.

All provisions remain contingent on Senate floor passage and successful House-Senate conference. Contractors should monitor floor amendments and conference committee activity through the fall legislative calendar.

Sources