How Cyberteering Will Actually Work
A speculative but evidence-based look at the application process, vetting, and operational workflow.
Jeff Gray · August 13, 2026 · 3 min read
Ephemera · Control Systems Security
The presidential memorandum "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" creates a program. It doesn't tell you how to apply to it. That comes later — and the gap between "here's what we're doing" and "here's how you participate" is where the real questions live.
Here's how the application process will likely work, based on what the memo actually says.
The 60-Day Clock
The memo gives the co-Executive Directors (one from DOJ, one from DHS) 60 days to publish consensus operating procedures. That's the master document. Until it drops, nobody can apply because the rules don't exist yet.
Expect that guidance to cover: eligibility criteria, application format, vetting standards, bonding procedures, operational deconfliction protocols, and reporting requirements.
Who Will Apply
The memo explicitly says the program must enable participation by both large companies and smaller, more agile companies. That's intentional — it prevents any single firm from becoming a chokepoint.
Expect applicants to fall into three buckets:
- Prime contractors — CrowdStrike, Mandiant, Booz Allen, Leidos. Already hold federal cyber contracts. Already have cleared personnel. Already know the compliance machinery.
- Specialized boutiques — Smaller firms with specific offensive cyber capabilities, threat intel operations, or niche technical skills. These are the "agile companies" the memo references.
- Non-traditional entrants — Companies that haven't done federal cyber work but have relevant capabilities. Higher barrier, but the memo's language leaves the door open.
The Vetting Standards
The memo lists them explicitly. Participating Companies must demonstrate:
- Technical proficiency — proven capability in cyber operations
- Proven performance — track record, not theoretical capacity
- Facility security — cleared spaces for classified work
- Personnel vetting — background checks, likely TS/SCI for some roles
- Competence and reliability — judgment calls left to the directors
- "Other factors" — catch-all for whatever the directors determine is necessary
This isn't a web form. This is government contracting with contractual, financial, and criminal liability backing every step.
The Bond
Minimum $1 million bond or escrow. Forfeited if you violate your agreement. That's your compliance guarantee — and it's a meaningful barrier for smaller firms that can't easily post seven-figure bonds.
The Operational Workflow
Based on the memo's unclassified text and the existence of a classified annex, the likely flow is:
- Threat intake — Participating Companies receive threat information from private sector entities and federal/state/local agencies
- Operation proposal — Companies propose specific cyber operations to the NCC
- Review and deconfliction — NCC coordinates across federal law enforcement, State Department, and intelligence community
- Approval or denial — Co-Executive Directors must both agree to approve
- Execution under supervision — Approved operations are conducted exclusively on behalf of and under federal supervision
- Post-operation reporting — Outcomes documented, deconfliction records maintained
What Companies Can't Do
- Operate without NCC approval
- Target domestic entities
- Accept direct tasking from private clients (threat intel flows in, but operations must be NCC-approved)
- Escalate to use of force or actions that endanger life without higher authorization
- Act outside the scope of their approved contractual agreement
Timeline
Projected Timeline
That's the projection. The reality could be faster or slower depending on interagency coordination, classification decisions, and political priorities.
For the full policy analysis and the coining of the term "cyberteering," see the main article: Cyberteering: The Return of the Letter of Marque in Cyberspace.