
Washington, United States: The US Government Accountability Office (GAO) has identified significant shortcomings in the Federal Aviation Administration’s (FAA) aviation cybersecurity program, warning that weaknesses in planning, budget reporting, Zero Trust implementation and role definition could leave critical aviation systems increasingly vulnerable to cyber threats despite stronger collaboration between the FAA and Transportation Security Administration (TSA).
The findings were published in the GAO’s July 16, 2026 report, Aviation Cybersecurity: FAA and TSA Are Collaborating on Cybersecurity but Need to Address Key Shortfalls, following a nearly two-year audit conducted between August 2024 and July 2026. The review was mandated under the FAA Reauthorization Act of 2024 to examine how the FAA and TSA define and manage their respective cybersecurity responsibilities across aircraft, airports, and the National Airspace System (NAS).
The GAO said that while the two agencies have substantially improved coordination through the Aviation Cybersecurity Initiative (ACI), important gaps remain in FAA’s cybersecurity governance and TSA’s strategic planning that could affect the long-term resilience of the US aviation ecosystem.
Cybersecurity has become one of aviation’s fastest-growing safety concerns as aircraft, airports, navigation infrastructure, and air traffic management systems become increasingly interconnected. Modern aircraft rely on digital avionics, satellite navigation, communications networks, weather systems and operational technology that continuously exchange data with FAA ground infrastructure. While this connectivity has significantly improved operational efficiency and safety, it has also expanded the number of potential cyberattack pathways available to malicious actors.
The report notes that recent intelligence from the Cybersecurity and Infrastructure Security Agency (CISA) shows aviation has experienced attacks from state-sponsored actors, financially motivated cybercriminals and hacktivist groups. Among the incidents cited was activity linked to a state-sponsored cyber actor associated with the People’s Republic of China targeting the aviation subsector during 2024.
The GAO also highlighted recurring vulnerabilities exploited across aviation systems, including poor software patch management, internet-accessible operational technology, outdated operating systems, weak network segmentation, insecure supply chains, default credentials and inadequate cybersecurity training. Successful exploitation of these weaknesses could result in unauthorized access to avionics, manipulation of cockpit data, disruption of air traffic communications, GPS spoofing, radio-frequency jamming and interference with critical flight operations.
As co-sector risk management agencies for transportation critical infrastructure, the Department of Transportation and Department of Homeland Security share responsibility for protecting aviation systems. Within those departments, the FAA leads aviation safety while TSA oversees transportation security. The FAA operates cybersecurity across four operational environments administrative, mission critical, mission essential and research and development with responsibility distributed among several internal organizations, including the Air Traffic Organization, Aviation Safety, Information Security and Privacy Service, Finance and Management, Airports, Commercial Space Transportation, Security and Hazardous Materials Safety, and formerly the NextGen Office before its transition to the Airspace Modernization Office under the FAA Reauthorization Act of 2024.
One of the report’s key findings is that the FAA has clearly defined cybersecurity responsibilities within its organizational structure. As of February 2026, the agency’s Cybersecurity Strategy assigned responsibilities for securing internal information systems, protecting the National Airspace System, overseeing cybersecurity during aircraft certification and collaborating with aviation stakeholders. Seven FAA entities were specifically identified as responsible for implementing the strategy, providing clearer accountability across the agency.
The GAO reached a different conclusion regarding TSA. Although TSA’s broader strategic documents describe agency-wide goals and organizational responsibilities, they do not clearly define cybersecurity-specific roles and responsibilities for aviation. The report found that TSA’s 2018 Cybersecurity Roadmap has become outdated and no longer aligns with the Department of Homeland Security’s current cybersecurity strategy. Furthermore, the roadmap does not identify which TSA offices are responsible for implementing aviation cybersecurity objectives or clearly explain TSA’s oversight responsibilities for airports and aircraft operators.
During interviews conducted for the audit, several aviation stakeholders including airlines, avionics manufacturers and industry associations told GAO they remained uncertain about TSA’s role in aviation cybersecurity. Some expressed confusion following TSA’s March 2023 Joint Emergency Amendment imposing cybersecurity requirements on covered airports and aircraft operators, believing such requirements fell under FAA authority. While FAA and TSA subsequently issued clarifying guidance stating that aircraft airworthiness systems fall exclusively under FAA oversight, GAO concluded that greater clarity is still needed to avoid regulatory ambiguity and improve accountability across the aviation sector.
Despite these concerns, GAO praised collaboration between the FAA and TSA through the Aviation Cybersecurity Initiative. The initiative, jointly led by the Departments of Transportation, Homeland Security and Defense, fully satisfied all eight of GAO’s leading practices for effective interagency collaboration. According to the report, the agencies established common objectives, clearly documented governance structures, involved relevant federal agencies and private-sector stakeholders, and developed collaborative projects aimed at reducing cyber risks across the aviation ecosystem. Activities under the initiative include cyber tabletop exercises, aviation cybersecurity summits and industry information-sharing programs involving organizations such as Airlines for America, Airports Council International-North America, the Aerospace Industries Association, Garmin, MITRE and the Air Line Pilots Association.
The GAO also scrutinized FAA funding for cybersecurity. Analysis of the President’s budget requests showed significant variation among the seven FAA organizations responsible for implementing the Cybersecurity Strategy. The Air Traffic Organization received the largest funding requests, increasing from approximately $9.9 billion in fiscal year 2024 to nearly $10.9 billion in fiscal year 2026, while Aviation Safety, Finance and Management and other organizations also received substantial appropriations.
Separate cybersecurity programs included funding for the National Airspace System Critical Infrastructure Cyber Enhancement Program, Information Systems Security Enhancement, Information Security/Cybersecurity research activities and the Office of Financial Management’s Cybersecurity Program, which supports FAA’s Security Operations Center and transition toward Zero Trust architecture.
However, GAO found that the FAA failed to report all cybersecurity spending to the Office of Management and Budget (OMB). Specifically, the agency omitted spending associated with its Information Security/Cybersecurity Program supporting research and development from previous OMB cyber budget submissions. According to FAA officials, these expenditures were expected to be included in the fiscal year 2027 reporting cycle, but GAO found insufficient evidence that complete reporting had occurred during the audit period.
The watchdog concluded that the FAA’s internal budget reporting process only captured pre-populated investments and did not require program offices to report additional cybersecurity activities, increasing the risk that Congress and policymakers lack a complete picture of FAA cybersecurity spending when making future funding decisions.
Another major focus of the audit was the FAA’s implementation of Zero Trust architecture. The report found that FAA’s overall Cybersecurity Strategy generally aligns with federal laws, NIST’s Cybersecurity Framework 2.0 and recognized industry practices governing cybersecurity risk management for avionics and National Airspace System infrastructure.
The FAA has established processes for identifying risks, selecting security controls, implementing safeguards, assessing effectiveness, authorizing systems and continuously monitoring cybersecurity throughout system life cycles. The agency also incorporates cybersecurity considerations into aircraft certification, including the use of special conditions for novel aircraft designs when existing regulations do not adequately address cybersecurity risks.
Nevertheless, GAO determined that FAA’s Zero Trust Implementation Plan does not fully conform to NIST guidance. The agency’s transition plan lacked several elements recommended by NIST for successful enterprise-wide Zero Trust implementation, limiting FAA’s ability to fully modernize cybersecurity protections as cyber threats continue evolving.
Overall, the report concludes that while the United States has made meaningful progress in coordinating aviation cybersecurity efforts, both agencies must strengthen governance to keep pace with increasingly sophisticated cyber threats targeting one of the world’s most complex transportation systems.
GAO issued five recommendations, four directed to the FAA and one to TSA to improve strategic planning, clarify organizational responsibilities, strengthen cybersecurity budget reporting and better align Zero Trust implementation with federal best practices. The Departments of Transportation and Homeland Security generally agreed with the recommendations.

















