logo_tag
Back

Aviation Experts Raise National Security Concerns Over FAA's Consideration of Indra and Thales for New Air Traffic Control Platform

Why It MattersForeign vendor ties to China in a core FAA air traffic control modernization program could reshape procurement scrutiny and vendor vetting across national aviation infrastructure contracts.

Aviation and cybersecurity experts are raising national security concerns as the FAA evaluates vendors with significant ties to China for its new Common Automation Platform (CAP), the centerpiece of U.S. air traffic control modernization. Industry outlet Air Current reported the FAA's shortlist includes U.S.-based Leidos and RTX, Spain's Indra, and France's Thales, with the companies asked to present CAP proposals to FAA officials at the agency's Washington, D.C. headquarters.

Aviation Experts Raise National Security Concerns Over FAA's Consideration of Indra and Thales for New Air Traffic Contr

Madrid-headquartered Indra has operated in China since 1989 through a wholly foreign-owned subsidiary established in 2002, and its air traffic management systems coordinate upper airspace across eight Chinese provinces, an area roughly the size of Western Europe; the company has deployed more than 1,000 air navigational aid systems, equipped over 15 ATC towers, and installed 50 radars in China, with its radar controlling 60 percent of Chinese airspace. Paris-headquartered Thales has maintained a China presence since 1964 and was managing 60 percent of China's air traffic as of 2019, operating under an "In China, For China" strategy; former Thales China CEO Laurent Guyot said in 2018 the company aimed to co-develop and localize R&D technologies with Chinese partners. Thales USA vice president Tony Lo Brutto dismissed national security concerns as a "boogeyman" in a July statement, though he acknowledged Thales would likely not sell China a system comparable to the FAA's CAP given who its customer is.

Between 2020 and 2025, nearly 2,300 cybersecurity incidents in the aviation subsector were reported to the Cybersecurity and Infrastructure Security Agency, and a 2024 CISA threat priorities report flagged threats from malicious cyber actors acting on China's behalf. A separate April Department of Transportation Office of Inspector General report found the FAA had left many high-impact systems vulnerable to cyberattacks that could cause severe or catastrophic effects on the national airspace system, and recommended the FAA update its Zero Trust Architecture plan. The House Appropriations Committee's THUD panel, in its fiscal year 2027 report, directed the FAA to vet third-party CAP vendors with legal or business relationships tied to the Chinese government and to report any related contract actions to Congress. The European Union in 2024 adopted a regulation barring non-EU companies from providing ATC services in EU member states.

Leidos spokesman Greg Hellman said companies with significant ties to China's air traffic ecosystem should face the highest level of national security and cybersecurity scrutiny before being considered for systems that keep America's skies moving, and Leidos has backed an NDAA amendment requiring the FAA to study how a vendor's foreign business ties might undermine national security. Indra and Thales have previously denied their air systems pose a national security risk to the U.S.

Related Coverage · 1 stories

Aviation Experts Sound National Security Alarm as FAA Considers Air Traffic Control Vendors with Strong China Tiesbreitbart.com
Keep Exploring