Cyber-safe Mode

Cyber-safe mode is a dedicated, configuration-controlled spacecraft operating state entered autonomously or by authorized ground command when mission-defined conditions indicate a credible threat to platform integrity. In this state, nonessential functions are shut down or isolated and the spacecraft operates from an integrity-protected, validated software and configuration baseline. Unlike traditional safe mode, which addresses hardware faults and operational anomalies, cyber-safe mode is specifically designed to respond to cyber threats, providing a secure recovery baseline from which the spacecraft can reconstitute compromised functions. Authentication and encryption must remain enabled within cyber-safe mode, ensuring that the reduced operational state does not degrade the security posture of the vehicle. The cyber-safe mode software and configuration must be stored onboard using hardware-based protections that prevent modification by nominal flight software, ordinary commands, and other untrusted execution paths. Where baseline updates are permitted, they must use a separately authorized and integrity-verified maintenance process that preserves a recoverable trusted version. Following entry into cyber-safe mode, the spacecraft must be capable of reconstituting firmware and software functions to pre-attack capability levels, either autonomously through self-healing mechanisms or with ground assistance, and must be capable of replanning operations based on whatever equipment remains available after the cyber event. The primary recovery objective is restoration of full mission capability; where that is not achievable, the spacecraft should attain the maximum reduced mission capability available given the post-attack system state.

Sources

ID: CM0044
Tier: II
Onboard SV CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Where cyber-safe mode is included in the mission security architecture, acquisition requirements should specify cyber-safe mode as a threshold spacecraft capability, distinct from traditional fault management safe mode, with specifications addressing the triggering conditions, the configuration content of the cyber-safe state, the authentication and encryption preservation requirements, the hardware protection of the stored cyber-safe baseline, and the reconstitution capabilities required following mode entry. Requirements should specify that the cyber-safe baseline be stored in hardware-protected memory that cannot be modified through nominal command paths or software operating outside the trusted recovery environment. If authorized baseline updating is supported, the update path must require authenticated authorization, integrity and authenticity verification, anti-rollback protection, and a recoverable prior or fallback baseline. Verification should attempt modification through applicable command, software, debug, and maintenance interfaces. Contract language should require that the cyber-safe mode design be submitted as a security architecture deliverable subject to government review, including the self-healing and ground-assisted reconstitution procedures and the replanning logic available to the spacecraft after a cyber event. Evaluation criteria should assess offerors' proposed cyber-safe mode architectures, their approach to hardware protection of the recovery baseline, their reconstitution and replanning capabilities, and their demonstrated experience designing autonomous cyber recovery functions for space systems. Verification should include scenario-based testing that induces cyber-safe mode entry from simulated threat conditions, confirms security control preservation throughout the mode, and demonstrates successful reconstitution to nominal or reduced mission capability.

Pre-Operations Developer/Supplier

Cyber-safe mode architecture must be defined as a first-class system design requirement from the earliest concept phase, as the hardware memory protection, non-modifiable storage, and reconstitution logic that underpin this capability cannot be effectively retrofitted into a system whose architecture does not reserve the necessary resources. The cyber-safe configuration baseline must be defined through a security engineering process that identifies the minimum trusted software, configuration, communications, and control functions needed to maintain spacecraft safety, preserve secure commandability, assess system integrity, and support reconstitution. Cyber-safe mode may share components or behaviors with traditional safe mode, but its baseline must satisfy the additional security and recovery requirements established for cyber compromise. Hardware protection for the stored cyber-safe baseline must prevent modification through nominal software and command paths. The selected mechanism may use hardware write protection, protected memory regions, immutable boot or recovery code, or equivalent controls. Architectures supporting authorized baseline updates must separate the protected update mechanism from nominal operations and preserve a trusted recovery path if an update fails or is rejected. The self-healing and reconstitution logic must be capable of operating under degraded conditions in which portions of the nominal software environment may be compromised or unavailable, requiring that the reconstitution process itself be implemented within the protected cyber-safe software baseline rather than relying on components that may have been affected by the triggering cyber event. The recovery architecture must support assessment of the hardware, software, communications, and security functions that remain trustworthy and available after a cyber event. Based on that assessment, onboard autonomy, ground operators, or a combination of both must be able to establish an approved configuration that restores full mission capability or the safest achievable reduced capability. Recovery and replanning procedures must be validated against representative degraded and compromised-resource scenarios.