The Missile Manufacturing Bottleneck Isn't Steel or Propellant. It's Procedure Execution.
The demand for American-made missiles and munitions is surging. The constraint isn't steel and propellant. It's the execution layer underneath them — the procedures that move work across every organization that touches a round.
The numbers, up front:
| Signal | Figure |
|---|---|
| Sentinel ICBM cost overrun, concentrated in integration and ground segment — not the missile | +81% ($78B → $141B) |
| GAO-reported annual cost growth across 30 major programs | $49.3B/yr |
| Average time to field a major program vs. a planned 8 years — roughly half the slip absorbed between organizations | 12 years |
| F-35 mission-capable rate, FY21 → FY25 (full-MC 38% → 25%) | 67% → 44% |
| Defense, aerospace, and manufacturing professionals whose task instructions are not digitized | 46% |
| Who hand finished work to the next team by hand | 42% |
| Whose cross-team communication still runs on email, spreadsheet, or phone | 50% |
| Gen Z respondents reporting non-digitized task instructions vs. 33% of Baby Boomers | 57.5% |
| Confidence gap between C-suite and individual contributors on absorbing sudden change | 32 points |
The demand signal now has numbers attached
For years the case for expanding munitions capacity was made in the abstract. It isn't abstract anymore.
The FY27 defense bill funds historic munitions mass. A June 24 award quadruples THAAD production. PAC-3 output triples in the same North Texas plant. $836M goes to new-entrant low-cost munitions. Precision-guided stockpiles drawn down during recent high-tempo operations need years to refill.
Building the hardware was never the hard part. Reaching and holding that cadence is — and the cadence problem punishes legacy primes carrying decades of incompatible systems and deep supplier webs, and new entrants who can't plug into each prime's walled environment, alike.
When demand spikes, the instinct is to look at inputs: propellants, energetics, titanium, the rare earths embedded in guidance and seeker assemblies. Those constraints are real. They are also not the binding one.
Why this is a coordination problem, not a materials problem
The clearest evidence sits in the cost data.
The Sentinel ICBM program breached Nunn-McCurdy with an 81% overrun — $78B to $141B. The growth was not concentrated in the missile. It was concentrated in the integration and ground segment: the work of connecting organizations, facilities, and systems to each other. GAO puts total cost growth across 30 major programs at $49.3B per year.
The schedule data tells the same story. Average time to field a major program has stretched from a planned 8 years to 12 — and GAO attributes roughly half of that slip to time absorbed between organizations rather than inside any one of them.
And the readiness data closes the loop. F-35 mission-capable rates fell from 67% to 44% between FY21 and FY25, with full-mission-capable rates dropping from 38% to 25%, even as lifetime sustainment cost estimates reached $1.6T. DoD walked away from performance-based logistics on the program partly over data quality.
Cost growth in the integration segment. Schedule loss between organizations. Readiness decline traced to data quality. Three different failure modes, one shared cause: the coordination work is done by hand.
Where the coordination actually breaks
The US defense industrial base is not a single integrated supply chain. It's a layered ecosystem — government program offices, primes, sub-tier suppliers, raw material producers — each on its own timeline, budget cycle, and visibility horizon. The friction at the seams between those layers doesn't just slow production. It can stop it.
The procurement clock doesn't match operational tempo. Requirement definition to contract award to initial production runs in years. Emergency supplemental funding doesn't compress the machinery of obligation, contracting, and delivery proportionally. Continuing resolutions leave program offices without finalized spending authority for months. Suppliers can't hire, tool, or expand against money that hasn't been obligated.
Primes carry accountability without authority. A prime is accountable to the government for delivery but often lacks direct visibility into — let alone leverage over — the sub-tier suppliers manufacturing critical components. A single-source supplier producing a specific guidance component or propellant grain may be running at 60% capacity not for lack of orders, but for lack of workforce, or because of aging equipment, or because a capital expenditure their commercial customer base won't underwrite is sitting unmade. The prime can escalate. It cannot force investment.
Supplier planning horizons don't align with national need. Many second- and third-tier suppliers are small and medium manufacturers built around predictable, long-cycle orders. When the government needs output doubled, the calculation is straightforward: capital required to expand may not be recoverable if the surge order doesn't repeat. Without multi-year commitments or investment guarantees, rational suppliers don't build for demand that may evaporate after one appropriations cycle.
Underneath all three is the same mechanical fact. No entity in this system has real-time, end-to-end visibility, because the connective tissue is manual. In a national survey of 513 experienced operators, managers, and executives across manufacturing, aerospace, and defense, 46% said their task instructions are not digitized and 42% said finished work is handed to the next team by hand. Half said cross-team communication still runs on email, spreadsheet, or phone. Defense respondents reported the heaviest structural load of the three industries — 34% still handle regulatory updates manually, 31% say their tools support basic organization but lack the features the work requires.
Every one of those handoffs is latency, error surface, and a place a schedule slips.
The seam that matters most is the one between organizations. Inside a company, the handoff problem is bad. Across organizational boundaries — to subcontractors, to program offices, to regulators — it's usually worse, because the official systems don't extend across the boundary at all. The procedure runs on the prime's system. The subcontractor doesn't have access. So the work gets exported to PDF, emailed, signed by hand, scanned, emailed back, and re-entered. As one operations lead at an energy infrastructure developer described the same pattern: the subcontractor's quality team does the checking, signs off, sends a report, and the receiving team validates it and files it somewhere they'll need it next month — using different software entirely.
That is the execution gap. It is not a productivity quirk. In a program where a missed handoff can halt a line or trigger a non-conformance, it's a structural exposure.
The workforce crisis is an execution crisis
Even if contracting, funding, and coordination were solved tomorrow, defense manufacturing would still face a harder constraint: the people who know how to do this work are leaving, and there aren't enough trained replacements behind them.
The usual framing treats this as a recruiting problem. It isn't. It's an infrastructure problem, and the survey data shows why.
Institutional knowledge doesn't transfer through paper. The skilled trades in defense manufacturing — machinists, welders, precision assemblers, ordnance technicians — hold enormous amounts of undocumented expertise. The tolerances held by feel. The process variations learned to anticipate. The failure modes recognized before they become defects. None of that transfers automatically to a newer hire reading the same work order, because it was never in the work order. It lives in the operator's head and in the parallel system of workarounds built around the official tools.
That workaround economy has three properties that should concern any program office. It's invisible from the top — by the time data reaches the executive layer, it's been cleaned up by the operators in the middle. It doesn't transfer — a workaround leaves when the person who built it leaves. And it scales with experience — the most capable team is also the team with the most fragile institutional memory.
The confidence data makes the invisibility concrete: 71% of C-suite respondents say they're very confident their team can absorb sudden change. Only 39% of the individual contributors doing the work agree. A 32-point gap between what leadership believes about resilience and what the floor reports.
The arriving workforce has a different baseline. Gen Z respondents named insufficient training as a top readiness threat at 4.6× the rate of Baby Boomers. And 57.5% of Gen Z respondents said their task instructions are not digitized, compared to 33% of Boomers — the same shop floors, described very differently. Boomers built their careers around existing workflows. Gen Z is the first cohort entering these industries with a different expectation of what normal looks like. As the older cohort ages out, they take with them not just decades of experience but the institutional tolerance that kept manual systems running.
Clearances and geography compress the hiring pipeline further. Much of what happens inside a defense production facility requires personnel security clearances, and adjudication time is built into the hiring lead time, not just the training pipeline. Structured apprenticeship and vocational programs that once fed skilled tradespeople into defense manufacturing have contracted over the past two decades. Meanwhile the same engineers, technicians, and production planners are being recruited by commercial aerospace, semiconductor fab, EV battery manufacturing, and advanced logistics — sectors offering comparable pay without the security friction, geographic constraints, or funding uncertainty.
And some capabilities exist in exactly one place. Specific solid propellant formulations. Particular explosive fill processes. Certain seeker assembly operations. Performed by one facility, sometimes one shift, sometimes a handful of technicians. These aren't abstract single-point-of-failure risks. They're operational constraints that a larger purchase order does not address.
The fix is not to dumb the system down to match an entry-level operator. It's to bring the system up to match the senior technician — to encode the conditional steps, the recovery paths, and the verifications the twenty-year veteran performs whether the procedure calls for them or not. When infrastructure can express what the most experienced operator already knows, the workaround stops being a personal heroic and becomes a transferable asset. Memory belongs to the company, not to the engineer who happens to hold it.
What fixing the execution layer actually requires
"Digitize the procedures" is not a plan. Programs that have tried it at scale converge on a short list of requirements — and a shorter list of ways it fails.
1. The procedure has to be the primitive. The unit of work in must-work manufacturing is the procedure: the sequence of steps, the verifications, the sign-offs, the conditions that must be true before the next step happens. Project plans, tickets, and Gantt charts are downstream artifacts of procedures, not substitutes for them. Failure mode: treating procedures as paperwork that wraps the work rather than as the work itself.
2. The record has to be generated by the work. Where "task complete" is still a manual signal, the audit trail is whatever the operator remembered to write down. That is not a compliance posture; it's a hope. The as-built has to be captured at the moment of execution, not reconstructed after an audit finding. Failure mode: assembling evidence packages retroactively.
3. It has to cross organizational boundaries without dissolving them. The alternative to controlled, scoped, logged access isn't safety — it's an email thread. Sensitive data still moves; it just moves without controls. Each organization should be a distinct tenant on a shared execution layer, seeing its scope and nothing else. Failure mode: forcing every partner onto the same system, or refusing to share state at all.
It's worth being precise here, because this gets conflated constantly: a FedRAMP authorization certifies that a cloud is safe to use. It does not certify that two clouds can talk. Execution state — status, inputs, outputs, holds — has to be able to move across authorized boundaries at the prime/sub/Government seam. That's a separate problem from accreditation, and it's the one that determines whether a surge order actually flows.
4. It has to be configured, not custom-coded. The graveyard of enterprise software in defense manufacturing is full of platforms that worked in the demo and broke at the second customization: long deployments, a consulting business built around the software, an upgrade path that collapses under accumulated custom code. Surge capacity cannot wait on a multi-year integration project. The system that goes in should be the system still working three years later. Failure mode: treating a long, high-cost deployment as a sign of seriousness rather than a sign of brittleness.
5. It has to work where the work happens. Remote test sites, disconnected facilities, and sites with intermittent connectivity are normal in this industry, not exceptional. Execution has to continue offline and reconcile afterward.
One more thing worth naming, because it shapes every evaluation: the real incumbent is almost never a rival system. It's paper travelers, Excel routers, work instructions in PDF, and an aging homegrown tool somebody built years ago that nobody wants to own. Legacy manufacturing execution systems were built for repetitive, high-volume production. Munitions at surge tempo are high-mix, configuration-heavy, and every-unit-proven. That's a different problem, and it needs infrastructure built for how the work actually runs.
What the compliance gate actually gates
In defense and space work, security authorization is not one criterion among many. It's the gate that eliminates most of the field before capability is ever discussed — and it's the part of an execution-layer decision that program offices most often discover late.
Three things are worth separating, because vendors routinely blur them.
Authorizations held today versus authorizations on a roadmap. FedRAMP Moderate is common. FedRAMP High is rare, and High is what high-sensitivity government workloads require. An authorization that already exists can remove months of security review from a deployment timeline; a promised one adds them back. Very few execution platforms hold a current High authorization at all. The verification takes minutes: ask for the FedRAMP Marketplace listing URL and the impact level it's authorized at. "In process" is a different answer than "authorized."
Authorization versus interoperability. This is the conflation that matters most for surge capacity. A FedRAMP authorization certifies that a cloud environment is safe to use. It does not certify that two authorized environments can exchange anything. Execution state — status, inputs, outputs, holds — has to be able to move across authorized boundaries at the prime/sub/government seam. Accreditation and interoperability are separate problems, and the second one determines whether a doubled order actually flows through the supply chain or piles up at a boundary.
The full compliance surface for defense-industrial-base work. FedRAMP is one line. ITAR handling, SOC 2 Type II, NIST 800-171, and CMMC readiness are others, and the deployment model matters as much as the certificate: commercial cloud, GovCloud, on-premises, and hybrid are not interchangeable when the workload is classified-adjacent or the facility is disconnected. Involve the security organization during evaluation, not after it. Late security engagement is one of the most common avoidable delays in any enterprise rollout, and in defense it is routinely the difference between a two-month and a two-year path to production use.
For reference: Epsilon3 holds FedRAMP High today — not on a roadmap — along with ITAR, SOC 2 Type II, and NIST 800-171, with cloud, GovCloud, on-premises, and hybrid deployment. It is the only MES-category platform that holds a current High authorization.
There is precedent for solving this
Uniformity reforms of exactly this shape have worked before.
Goldwater-Nichols, 1986. In Grenada, Army and Navy radios couldn't communicate, and an 82nd Airborne officer used a calling card from a civilian pay phone to reach Fort Bragg for fire support. Congress mandated uniformity and jointness. The result was the integrated joint force credited with the First Gulf War and every campaign since — one of the most successful defense reforms in modern history. It answered a coordination problem, not a hardware problem.
Electronic health records, 2004. A President called out the absurdity of running 21st-century medicine on a 19th-century paper system and created a coordinating office by executive order. The standard moved a fragmented, paper-bound enterprise from roughly 17% electronic adoption to about 80% of hospitals inside five years. The piece it left unfinished — true interoperability between systems — is precisely the piece to get right from the start in defense.
Both cases share a structure: a common standard for how work moves between organizations, measured against outcomes rather than compliance. Applied here, that means a common standard for the reliable, safe electronic execution and documentation of critical procedures across the manufacturing, test, and sustainment of major weapon systems — measured against mission-capable rates and delivered rounds, not against a new reporting burden on the workforce.
It also means confronting the data-rights question honestly. The DFARS clauses governing technical data were written for hardware deliverables, when the intellectual property was in the drawings. They don't cleanly distinguish proprietary content from shareable execution state — status, interfaces, inputs, outputs, holds. Until they do, sharing the interface of work looks like a trade-secret risk, and rational companies will keep defaulting to the PDF.
Why this moment is different
The argument that the defense industrial base needs modernization is not new. It's been made after every post-Cold War conflict, every strategic review, every industrial base assessment for thirty years. What's different is the convergence that compresses the response window.
Stockpile drawdowns are happening at pace. Adversary production rates aren't standing still. The workforce retirement wave isn't a forecast — it's underway, and the cohort replacing it has a documented, measurably different tolerance for manual systems. And the geopolitical environment makes the cost of a production gap visible in real time rather than in a classified briefing.
The constraints that were always present in this system are now load-bearing. A defense industrial base designed for steady-state procurement, managed through a peacetime acquisition process, and staffed by a workforce trained in an era of larger industrial programs is being asked to perform at a tempo and scale it was not built for.
The materials will be sourced. The funding, eventually, will be appropriated. The harder work — connecting the program offices, the primes, the sub-tier suppliers, and the people doing the work into something that functions as an integrated production enterprise — is the problem that hasn't yet been seriously solved.
That's the execution gap. In the current environment, it's the one that matters most.
Frequently Asked Questions (FAQ)
-
Cross-organization coordination. Materials and workforce constraints are real, but the cost and schedule data point elsewhere: program overruns concentrate in integration rather than in the hardware itself, and GAO attributes roughly half of the slip in fielding timelines to time absorbed between organizations. The coordination work moving production across prime, subcontractor, and government seams is still largely manual.
-
Procedure execution software runs the actual work — the sequence of steps, verifications, sign-offs, and conditions that must hold before the next step — in a system rather than on paper or in a PDF, so the as-built record is generated as a byproduct of doing the work instead of reconstructed afterward. Traditional MES was built to track and schedule repetitive, high-volume production; procedure execution treats the procedure itself as the primitive. The distinction matters for high-mix, configuration-heavy, every-unit-proven work like munitions and spacecraft, where no two units run identically. A platform can do both, but most legacy MES products stop at the shop floor and at the company boundary.
-
The criteria that predict success in must-work environments, in rough priority order: whether the procedure is the system's primitive rather than a document attached to it; whether the audit trail is generated at execution rather than assembled afterward; whether execution state can cross organizational boundaries under scoped access; whether the platform is configured in-product rather than custom-coded by an integrator; whether it holds the security authorizations your compliance environment requires today; and whether it keeps running at disconnected sites. Score any candidate against your own real procedures and your own failure modes rather than a demo path.
-
The requirement is that the trail be a byproduct of execution rather than a separate reporting step — timestamps, step results, operator attribution, pause and restart events, and linked non-conformances captured as the work happens. For defense-industrial-base work, also confirm the authorizations held today: FedRAMP impact level (High, not Moderate, for high-sensitivity government workloads), ITAR handling, NIST 800-171, CMMC readiness, and the available deployment models. Ask for the FedRAMP Marketplace listing URL; a real authorization is verifiable in minutes.
-
No. A FedRAMP authorization certifies that a cloud environment is safe to use. It does not certify that two authorized environments can exchange execution state. Interoperability across the prime/sub/government seam is a separate requirement, and it's the one that determines whether work actually flows when an order doubles.
-
Undocumented expertise doesn't transfer. When the conditional steps, recovery paths, and habitual verifications of a twenty-year technician live only in that person's head, retirement removes capacity permanently. Survey data also shows the arriving cohort has a sharply different baseline: 57.5% of Gen Z respondents report task instructions that aren't digitized, versus 33% of Baby Boomers, and Gen Z names insufficient training as a top readiness threat at 4.6× the Boomer rate.