Information Technology Posture of the Department of Defense

Defense Posture and Global ThreatsHouse Armed Services Subcommittee on Cyber, Information Technologies, and Innovation · 2026-03-26 · 119th Congress
The House Armed Services Subcommittee on Cyber, Information Technologies, and Innovation held this hearing to examine the state of the Department of Defense's information technology infrastructure, including network modernization, cloud adoption, and cybersecurity of DoD and industrial base assets. Begins at 0:21:33
Transcript
Highlights

Title

DoD Chief Information Officer testifies on IT modernization and cybersecurity

Purpose

The House Armed Services Subcommittee on Cyber, Information Technologies, and Innovation held this hearing to examine the state of the Department of Defense's information technology infrastructure, including network modernization, cloud adoption, and cybersecurity of DoD and industrial base assets. Kirsten Davies, in her first public appearance as DoD Chief Information Officer, testified on her transformation strategy and fielded questions from members on spectrum management, legacy IT, workforce shortages, and CMMC compliance costs for small businesses. Begins at0:21:33

Who spoke

Chairman Don Bacon (R-NE)0:21:33: Opened by describing the hearing's purpose and stressing that DoD's networks are the foundation enabling all other technology, including AI0:21:590:22:18; later asked about industrial base cybersecurity0:31:12, operational technology security0:32:39, and post-quantum cryptography0:33:53, and closed with a question on legacy IT's link to cyber risk1:04:08.

Rep. Chrissy Houlahan (D-PA), Ranking Member0:22:49: Welcomed Davies to her first hearing and listed key CIO priorities including zero trust, network modernization, and cloud adoption0:23:48; asked about workforce effects of the deferred resignation program and hiring freezes0:24:40; later pressed on the zero-trust OT deadline relative to the September 30, 2027 IT deadline and whether workforce reductions could affect it1:05:441:06:33.

Kirsten Davies, DoD Chief Information Officer0:25:38: Outlined a four-pillar transformation strategy — enduring digital foundation, agile digital capabilities, cybersecurity for the warfighting ecosystem, and skills and partnerships0:27:07; said DoD installations have 88% commercial 5G coverage0:39:47; described over 170 scholarships and partnerships with 450+ academic institutions for cyber workforce development0:48:52; said a CMMC ecosystem review is underway with early findings favoring reduced regulatory burden0:53:54; noted the CIO office hasn't been reorganized since 2012-2014 and plans a more "operational" mindset1:08:21.

Rep. Brian Fitzpatrick (R-PA)0:40:18: Described archaic "Oregon Trail"-style legacy software he witnessed at USDA and asked what obstacles block modernization of DoD's legacy IT0:40:480:41:55; pressed on whether a trillion-dollar-a-year private-sector operation would tolerate such systems0:43:15.

Rep. Pat Ryan (D-NY)0:45:52: Asked for an update on the Section 1521 expedited ATO review process required by the last NDAA0:46:10; asked about measurable progress closing the cyber workforce gap0:48:22; asked about DoD cyber performance against Iran's offensive capabilities, deferring further detail to closed session0:49:43.

Rep. Wesley Hunt / "Mr. Crockett" (as transcribed)0:50:41: Raised concerns about CMMC level two requirements imposing over $100,000 in compliance costs on a small defense contractor in his district0:51:350:52:03; cited a GAO finding that DoD had not systematically assessed external factors affecting CMMC goals0:52:23; asked about oversight of fees charged by Cyber AB and C3PAOs0:54:40 and over-classification of CUI basic information0:55:29.

Rep. Eugene Vindman (D-VA)0:55:59: Cited a DoD Inspector General finding of minimal Navy progress mitigating cyber vulnerabilities in critical infrastructure, with unclear system ownership0:56:27; described threats from China, Russia, Iran, and North Korea0:56:53; proposed NDAA language for a digital twin technology pilot program at military installations0:58:07; asked about lessons learned from the Ukraine conflict0:59:21.

A committee member (raising CMMC small-business concerns following up on Rep. Crockett)1:00:31: Asked how DoD balances strong security requirements against preserving a viable small-business defense industrial base1:01:00; proposed grants or low-interest loans to help small businesses afford compliance upgrades1:02:45.

Rep. Marc Veasey (D-TX)1:07:56: Asked Davies what her "most radical idea" is for addressing DoD's biggest IT problems and how Congress can help execute it1:08:21.

Key moments

Davies announced DoD's enterprise IT and cybersecurity functions are being unified under the CIO office as part of Secretary Hegseth's efficiency drive, organized around four pillars0:26:040:26:49.

DoD military installations have commercial 5G infrastructure at 88% of sites, with diversification of that backbone underway0:39:47.

Rep. Crockett cited a small business in his district facing over $100,000 in CMMC level-two compliance costs tied to a single employee's laptop, despite only needing CMMC level one0:51:350:52:03, and a GAO report finding DoD had not systematically documented external factors affecting CMMC goals0:52:23.

Davies said DoD's cyber workforce initiative includes over 170 scholarships and partnerships with more than 450 academic institutions, plus a new rotation internship program0:48:52.

Rep. Fitzpatrick and Davies agreed the federal government would not tolerate legacy IT systems if operating in the private sector at a trillion-dollar budget scale, and that modernization is a "USA common sense issue," not an R&D issue0:43:400:44:03.

Davies confirmed the CIO office has not been reorganized since its creation in 2012-2014 and signaled a shift toward a more "operational" model as her most significant planned change1:08:47.

Rep. Ryan pressed on the Section 1521-mandated expedited ATO review process ahead of its 180-day deadline; Davies acknowledged the ATO process remains "much slower than it needs to be," citing spreadsheet- and email-based management and broken inheritance between assessments0:47:04.

Rep. Vindman cited an IG finding of no clear ownership or risk-management responsibility for known Navy cyber vulnerabilities in critical infrastructure, and Davies agreed to pursue a digital twin pilot program0:56:270:58:21.

Davies confirmed there is currently a September 30, 2027 zero-trust IT deadline and a separate OT deadline she is working to move earlier, in response to Rep. Houlahan1:06:081:06:33.

Davies said DoD's Cyber Crime Center (DC3) and NSA outreach provide the defense industrial base with threat intelligence and indicators of compromise, and that 11 different support capabilities are offered to small businesses1:01:561:03:38.

Metadata

CommitteeHouse Armed Services Subcommittee on Cyber, Information Technologies, and Innovation
Chamber / CongressHouse · 119th Congress
Date2026-03-26
TypeHearing
Witnesses
The Honorable Kirsten Davies — Chief Information Officer, Department of Defense
Videoyoutube
Transcript121 caption blocks · 8,070 words · 1:10:13 runtime
EventCongress.gov 119109