All battalions
Space cybersecurityComplete and ratified

Battalion 5

Ratified by Nathaniel Dailey, programme chair on 2026-09-03. All 24 candidates passed, each carrying its recorded caveats. The caveats travel with the work and are published here rather than retired.

Every count is a count over an appraised shortlist under a stated protocol. None is a prevalence estimate for the field.

The evidence base

Five systematic reviews conducted under PRISMA 2020, each with a protocol written before screening began. Nine bibliographic sources plus four domain corpora per review.

Retrieved
11,466
Screened
10,433
Eligible
1,666
Appraised in depth
546
Confirmed
357

What the field has not established

Real

The most striking results in this battalion are absences. An absence of evidence, stated with its denominator, is a genuine and citable finding about the state of a literature. Each of these is a count over an appraised shortlist, never a claim about the field at large.

SR-V1Quantum-resistant and privacy-preserving cryptography for space systems

No appraised record examines leakage from the internals of a privacy-preserving computation, through result timing, query pattern, or access pattern. Zero of 45.

One flight demonstration of post-quantum key exchange exists in the appraised corpus, a 2022 nanosatellite key exchange, and it remains the only one. Of the 36 records whose evidence rung could be determined, 30 sit at the two lowest rungs.

Retrieved
2,355
Screened
2,056
Eligible
111
Confirmed
45
SR-V2Attack surface, incident evidence, and assurance of reusable flight software

One first-party, method-disclosed incident report exists for the space segment, out of 66 confirmed records.

Thirty-three of 37 assurance techniques are evaluated by the same people who proposed them.

Retrieved
2,365
Screened
2,130
Eligible
311
Confirmed
91
SR-V3Space cyber governance and the evidence for behavioural effect

No empirical-effect study exists for any space cyber governance instrument. Zero of 109 confirmed space records.

The field does not know whether disclosure regimes change operator behaviour, in either direction.

Retrieved
2,256
Screened
2,082
Eligible
422
Confirmed
109
SR-V4Delegated authority and machine trust in safety-critical space operations

None achieves a complete assurance case.

Ten of 82 systems delegating safety-critical authority document a tested reversion path, six of 41 under a stricter definition. Two of 82 distinguish adversarial injection from benign sensor fault.

Retrieved
2,363
Screened
2,165
Eligible
483
Confirmed
82
SR-V5Cyber effects on space traffic safety and coordination

No confirmed record traces a cyber event through to a quantified space traffic safety outcome. Zero of 85, and zero of the 23 space-anchored records reach even a decision effect.

Only 23 of the 85 confirmed records are space-anchored. The remaining 62 are terrestrial, aviation, automotive or maritime analogues.

Retrieved
3,524
Screened
3,154
Eligible
571
Confirmed
85

A citation-integrity failure, and its repair

The verification tool checked that a cited DOI resolves. It never checked that the cited title and authors matched the record that came back, and a second path marked a citation verified purely because its DOI appeared elsewhere in this programme's own corpus, fetching no authoritative record at all. Under that regime a real, resolving DOI carrying an invented author list passed cleanly.

14 fabricated attributions were found across the battalion, 11 of them in a single candidate, and all were repaired against live Crossref and DataCite records. The check now verifies correspondence, and the sweep covers companion-paper bibliographies that were previously outside it entirely.

Current state: 621 references across 24 candidates, of which 270 come from companion papers that no previous audit could see. 0 flagged.

The lesson generalises beyond this corpus: A resolving identifier is not a verified citation.

The 24 candidates

22 were ratified on the original real-evidence bar. 2 executed their chartered design on proxy data and are ratified as methodology demonstrations. 6 carry a disclosed document-reconciliation caveat, meaning their verdict documents claim more completeness than their artifacts carry.

IDContributionClassCaveat
5V-CYB-001Leakage from privacy-preserving computation internalsReal
5V-CYB-002Crypto-agility under irrecoverabilityReal
5V-CYB-003Provenance and authentication of space traffic dataReal
5V-CYB-004Do disclosure regimes change operator behaviourReal
5V-CYB-005Defect classes in reusable flight softwareReal
5V-CYB-006Delegated authority under cyber ambiguityProxydocument-reconciliation
5V-CYB-007PNT deception propagation into conjunction decisionsReal
5V-CYB-008Supply-chain provenance beyond SBOMReal
5V-CYB-009The absence of cyber from governance instrumentsRealdocument-reconciliation
5V-CYB-010Capstone: the principles, derived and attackedReal
B-1Assurance economics: is space cyber resilience pricedRealdocument-reconciliation, unlifted seat veto
B-2Ground-segment concentration risk as systemic single point of failureReal
B-3Cyber and the debris externality under existing liability regimesReal
B-4Constructing an observable measure of operator security conductReal
B-5Independent comparative evaluation of assurance techniques and casesReal
B-6A reporting standard for delegated authority in space autonomyProxydocument-reconciliation, unlifted seat veto
B-7Transferability of aviation and maritime autonomy assurance precedentReal
B-9Shared adversarial datasets for space security researchReal
B-10An adversary-model reporting standard for space cryptographic workReal
B-11A provenance-graded incident register for the space sectorReal
B-12An instrument map built from the operational layer upwardReal
B-13A reversion doctrine for delegated safety-critical space authorityRealdocument-reconciliation, stale Archivist veto since repaired
B-14Adversarial evaluation of decentralised space traffic coordinationRealdocument-reconciliation
B-15Transferability of terrestrial GNSS spoofing results to the space segmentReal

B-8 Privacy-preserving computation for proximity operations against catalog screening. Released on evidence, 2026-08-29. Its charter recommended against staffing it, the falsification test the charter itself named was then run, and it came back negative.

Caveats that travel with the work

Proxy data is not observed data

Two candidates executed their chartered design on synthetic data because the real data was not obtainable. They are methodology demonstrations. Most candidates that assumed their data was unobtainable turned out to be wrong: real SEC EDGAR filings, real government instruments verified by SHA-256 against archived bytes, and real Crossref and regulatory records all proved reachable once tested.

Six candidates carry a document-reconciliation caveat

Their verdict documents claim more completeness than their artifacts carry. In every case the dispute is about the record rather than the research. They are 5V-CYB-006, 5V-CYB-009, B-1, B-6, B-13 and B-14.

Single-reader appraisal

The five parent reviews were built by one reader. No inter-rater reliability figure exists for any appraisal field. Candidate 5V-CYB-010 makes this its subject and reports that the battalion cannot presently separate a property of the domain from a property of its reader.

Counts are counts over appraised shortlists

Every figure in this battalion describes the records a review actually appraised under a stated protocol. None is a prevalence estimate for the literature at large.

How to read a claim on this site

Real finding
Drawn from real published literature screened and appraised under a stated protocol, or from real verified records. Citable as a finding about the state of the evidence.
Methodology demonstration
The chartered design was executed on proxy data because the real data was not obtainable by this programme. It establishes that the design is constructible, executable and informative, and that commissioning the real study is warranted. It establishes nothing about real space systems.
Charter intent
A stated research intention that has not yet produced a defended result. Read it as a plan, not as an outcome.