Your weapon system has its own servers, its own storage, its own operating environment, its own security staff, its own authorization, and its own patching cadence. It has had all of this for as long as anyone on the program can remember.
How much does that infrastructure cost?
In most program offices, nobody knows — not because the information is hidden, but because the cost is embedded in a sustainment contract that doesn't break it out well. The program office sees a total sustainment number. The IT infrastructure cost is somewhere inside it. And because it's been there since the system was fielded, it's treated as fixed — a cost of doing business rather than a spending decision.
It is a spending decision. And making it well requires seeing the number.
How the cost became invisible
Most IT-enabled weapon systems — command and control platforms, sensor processing systems, early warning networks — were built before enterprise IT environments existed in their current form. When these systems were fielded, dedicated hardware was the only option. The processing ran on purpose-built servers at purpose-built sites, maintained by dedicated staff under dedicated contracts.
Over time, industry trends and hardware modernization cycles have made it plausible — and in many cases likely — that these systems virtualized their processing. Operator consoles that once required dedicated hardware can run as software on standard servers. Central processing that ran on custom boards can migrate to standard compute. Where this has happened, the applications became software — but the infrastructure stayed dedicated.
The Total System Performance Responsibility (TSPR) acquisition model reinforced this. Under TSPR, the prime took responsibility for the total system — including the IT infrastructure. This was a reasonable approach at the time: the contractor had the expertise, and the model simplified management for the program office. But a natural consequence was that the program office's organic understanding of what the infrastructure cost — and whether that cost was still proportionate — shifted to the contractor over time.
The GAO has documented this across the weapon system portfolio. Operating and support costs represent approximately 70% of a weapon system's total lifecycle cost. Fourteen of 36 systems reviewed in fiscal years 2023-2024 showed critical cost growth — at least a 25% increase over the lifecycle estimate. The Department estimates software sustainment funding alone will total at least $15 billion over the next five fiscal years. And the F-35's lifetime sustainment estimate grew 44% — from $1.1 trillion to $1.58 trillion — driven in part by a TSPR structure where cost visibility naturally shifted away from the program office over time.
What dedicated infrastructure includes
A weapon system running its own IT environment at geographically distributed sites carries costs that are significant when itemized, even if they're invisible when bundled:
Hardware refresh. Server and storage hardware at each site requires replacement every 3-5 years. For a system with processing at multiple locations, each refresh is a procurement, installation, migration, and revalidation effort — repeated at every site, on every cycle.
Dedicated authorization. Each weapon system carries its own Authority to Operate. That ATO requires its own System Security Plan, risk assessment, control implementation narratives, annual reviews, and ISSO. Authorization maintenance is a recurring cost that scales with the number of independent systems, not with the complexity of the mission.
This cost extends beyond the program office. The Authorizing Official's organization has to assess and accept risk for each system independently — and that organization has a finite staff. An AO managing a portfolio of N stovepiped weapon systems needs N independent security control assessments, performed by Security Control Assessors who are shared across the portfolio. In practice, this means program offices wait — sometimes months — for an available SCA to begin their assessment. Every system on its own authorization competes for the same limited pool of assessors. The weapon system's cost model accounts for its own ISSO and security staff, but it doesn't account for the capacity constraint it imposes on the AO's office — a cost that's real, shared across the enterprise, and invisible in any individual program's budget.
Every system that consolidates onto an enterprise platform is one fewer standalone authorization competing for SCA availability — which frees assessment capacity for the systems that genuinely require it.
Dedicated security operations. Vulnerability scanning, log management, incident response procedures, and security monitoring — staffed by cleared personnel who understand that specific system's architecture. At cleared cybersecurity labor rates ($175/hr GSA Schedule to $325/hr commercial market), a security team for a single weapon system runs $400K-$1M annually.
Dedicated patching. Operating system patches, middleware updates, and application fixes must be tested against the weapon system's specific configuration before deployment. Because the system runs on its own infrastructure with its own dependencies, each patch cycle is a standalone engineering effort with its own test plan and its own risk assessment.
Dedicated network infrastructure. Circuits, routers, firewalls, and encryption devices connecting distributed sites — maintained, monitored, and refreshed on the weapon system's own schedule, independent of the enterprise network that often runs alongside it.
The Department's IT Enterprise Strategy described this directly: each IT program "delivered unique, largely redundant and tremendously costly network and computing infrastructures" with "unique configurations significantly driving up life cycle support costs."
What the numbers look like
The pattern is consistent across domains:
The Air Force awarded an $866 million, five-year contract to sustain and modernize six early warning radar sites — approximately $29 million per site per year. A significant portion of that cost is IT infrastructure sustainment: servers, processing, storage, networking, and the staff to maintain it.
The ISC2 modernization — a $1.5 billion, 15-year effort — is integrating approximately 40 stovepiped systems under an open, standards-based architecture. Forty independent IT environments, each with its own hardware, security, authorization, and staff. The modernization cost is large — but it reflects how much redundant infrastructure accumulated when each system operated independently.
Space ground systems show the same pattern at larger scale. The SBIRS ground system — dedicated infrastructure for missile warning satellite operations — carries a $1 billion, five-year sustainment contract with a single prime. The satellite communication portfolio is even more fragmented: AEHF, Milstar, WGS, and DSCS each operated their own ground infrastructure independently until the Space Force consolidated them under the CCS-C sustainment contract — four stovepiped ground systems, each with its own servers, security, authorization, and staff, doing fundamentally similar work independently. And the GPS ground control system's attempt to modernize its stovepiped architecture grew from $1.5 billion to over $6 billion and 10 years of delays before being canceled entirely — a measure of how much complexity accumulates when dedicated infrastructure operates long enough.
For a single weapon system with processing at 3-5 distributed sites, the IT infrastructure cost — hardware, storage, security, authorization, patching, staffing — typically runs $10-15 million annually. This is a modeled estimate based on the component costs above, not a published figure, because most program offices don't have a published figure. That's the problem.
The first step is visibility
The decision about whether to migrate any workload to an enterprise platform starts with understanding what the current infrastructure costs. Not the total sustainment number — the itemized IT infrastructure cost, broken out by function:
- Compute and storage hardware (by site)
- Operating system and middleware licensing
- Security operations staffing
- Authorization maintenance
- Patching and configuration management
- Network infrastructure
- Hardware refresh schedule and projected cost
If the program office can produce this breakdown, it's in a position to evaluate alternatives. If it can't — because the cost is embedded in a TSPR-style sustainment contract that doesn't separate IT infrastructure from everything else — then the first step isn't migration planning. It's cost visibility.
This assessment is specific to each weapon system. Every system has a different architecture, different site distribution, different availability requirements, and different contractual structure. An honest evaluation of what the infrastructure costs — and what could change — requires looking at the specific system, not applying a generic template.
Robert Burckner is the founder of Millabs Corporation, a Service-Disabled Veteran-Owned Small Business. He has served as ISSM and ISSE for legacy weapon systems at the Air Force Lifecycle Management Center — maintaining authorizations for systems whose IT infrastructure had outgrown its original architecture — and as Division Chief at the Space Warfighting Analysis Center (USSF/NRO).
If your program maintains dedicated IT infrastructure for a weapon system and nobody has itemized what that infrastructure costs, contact Millabs. This assessment can be performed independently on behalf of the program office through existing government contract vehicles.