The Pentagon’s inspector general recently released an audit concerning the security of the military’s clocks.
Then it classified essentially everything interesting about it.
All 10 recommendations in the September 9 audit are classified. No redacted public version of the report is available. What remains publicly visible is little more than the title, administrative metadata and one particularly intriguing fact…the investigation began because somebody made allegations to the Department of Defense Hotline.
These, however, are not ordinary clocks.
The Military Has Some Very Important Clocks
Defense Regional Clocks are part of the Pentagon’s Critical Time Dissemination program, a geographically distributed precision-timing capability intended to keep mission-critical systems synchronized when normal external timing sources are degraded or unavailable.
The Defense Department created the Critical Time Dissemination effort after recognizing the vulnerability created by dependence on the Global Positioning System. Modern military operations rely on precise positioning, navigation and timing for far more than telling soldiers what time it is. Communications networks, navigation systems, sensors and other systems can depend on extraordinarily precise synchronization.
The clocks therefore provide part of the resilience needed when GPS or other timing sources are disrupted, jammed, spoofed or lost.
That makes an audit of their security controls considerably less whimsical than its title initially suggests.
A Program Years in the Making
The Critical Time Dissemination program traces back to a fiscal 2012 Defense Department decision intended to address vulnerabilities associated with reliance on GPS.
Its rollout was not particularly clocklike.
Defense Department performance records show Defense Regional Clock installation at 63 percent in 2018 and 85 percent in 2019. The department expected to reach 100 percent installation in fiscal 2021.
It did not.
During fiscal 2020, installation remained at 87 percent through all four quarters. Subsequent Defense Department planning documents continued moving the finish line, eventually targeting completion of initial operational capability by the end of fiscal 2024.
The publicly stated schedule therefore appears to have slipped roughly three years from the earlier fiscal 2021 target.
GAO Finds an Incomplete Business Case
The deployment history was not the only warning sign in the public record.
In 2022, the Government Accountability Office examined several Defense Department programs intended to provide alternatives to GPS-based positioning, navigation and timing. Critical Time Dissemination was among them.
GAO reported that the Office of the DoD Chief Information Officer planned to transition Critical Time Dissemination into the major capability acquisition pathway. But several pieces of its acquisition business case were still unfinished. Requirements were being drafted, and although a technology-risk assessment had been completed, an acquisition strategy, schedule-risk assessment and independent cost estimate had not.
GAO’s formal business-case recommendation concerned Navy alternative-PNT programs rather than Critical Time Dissemination specifically. But the review nevertheless documented that, roughly a decade after the program began, CTD still lacked several elements of a complete acquisition business case.
Then the Modernization Became Classified
Classification surrounding the clock program did not begin with the inspector general’s latest audit.
DISA’s fiscal 2023 budget justification included a $10 million increase for “Critical Time Dissemination Defense Regional Clocks Modernization.”
The public explanation for the increase consisted of one word: “Classified.”
That does not necessarily indicate anything improper. Military timing infrastructure has obvious national-security implications, and publishing technical vulnerabilities, architecture or precise capabilities could itself create risk.
But then somebody called the Hotline.
The Hotline Allegation
On February 20, 2025, the DoD Office of Inspector General announced an audit of security controls protecting Defense Regional Clocks.
The project announcement was unusually explicit about why the audit existed: “We are initiating the subject audit in response to allegations to the DoD Hotline.”
The publicly stated objective was to determine whether security controls protecting the clocks were effective.
The announcement directed work toward the Office of the DoD Chief Information Officer, the U.S. Naval Observatory, the Defense Information Systems Agency and selected Defense Regional Clock locations. It also instructed participating organizations to identify both a knowledgeable GS-15-equivalent point of contact and a Senior Executive Service or General/Flag Officer familiar with DRC security who could engage with senior OIG leadership if necessary.
The allegation itself remains out of public view. The available records do not identify who made it, what specific weakness was alleged or when the underlying concern first arose.
What Happened While OIG Was Looking?
This is where the public chronology becomes particularly interesting.
While the OIG audit was underway, Defense Department budget and procurement records began describing substantial additional work involving the timing infrastructure.
DISA’s fiscal 2027 procurement justification requests more than $20 million for Critical Time Dissemination, including nearly $14 million for a Monitor and Control capability covering 46 Defense Regional Clocks and 30 Timing and Synchronization Support Center suites.
The budget document contains a revealing description of the existing architecture: “The DRCs and TSSCs are currently independent and there is no existing connective network.”
The proposed capability would connect the systems for centralized calibration and monitoring.
Other fiscal 2027 budget material describes funding for a permanent test laboratory supporting system optimization and security compliance, anti-spoofing technology upgrades, GPS-independent time-holding capabilities and additional personnel.
Those personnel would help inspect, operate and upgrade the globally deployed systems and maintain a watch-floor presence monitoring mission-critical timing assets.
In June 2026, meanwhile, the Navy sought a firmware upgrade from FEI-Zyfer for 50 Time and Frequency Reference Measurement Systems supporting the Critical Time Dissemination project at the U.S. Naval Observatory. Procurement records describe capabilities involving additional external timing inputs, processing multiple streams, weighting and prioritizing timing sources and seamless failover.
There is currently no public evidence establishing that these subsequent upgrades resulted from the Hotline allegations or from findings developed during the OIG audit.
The timing is noteworthy, but chronology is not causation.
What the documents do provide is a before-and-after silhouette worth examining further.
Ten Recommendations, Ten Secrets
On September 9, 2026, the DoD OIG finally released the audit.
Sort of.
Oversight.gov lists 10 recommendations associated with the audit. All 10 are classified. All 10 are listed as open. The OIG says the report contains classified information and that no redacted version is available.
The public can therefore establish that allegations were made, that the inspector general considered them sufficient to initiate an audit of security controls, that the audit ran for roughly 19 months and that it resulted in 10 recommendations requiring corrective action.
What the public cannot establish is what OIG found.
The Record That Classification Can’t Erase
There may be entirely legitimate national-security reasons why the vulnerabilities identified by the inspector general cannot be made public. Publishing locations, architectures or exploitable weaknesses in military timing infrastructure would hardly constitute responsible transparency.
But classification does not make the surrounding public record disappear.
That record shows a military timing program created to reduce dependence on GPS; a deployment that missed earlier completion targets; an acquisition effort that GAO found was still missing several business-case elements years after the program began; classified modernization spending; a subsequent Hotline allegation concerning security controls; and, while the resulting audit was underway, plans for centralized monitoring, security-compliance testing, anti-spoofing improvements, additional personnel and firmware upgrades.
None of that tells us what the Hotline complainant alleged.
It tells us why the question is worth asking.
Someone saw enough of a problem with the Defense Regional Clock program to contact the Defense Department Hotline. The inspector general considered the allegations sufficient to launch an audit. That audit ultimately produced 10 recommendations.
The public is permitted to know that much.
What happened in between remains classified.
Bureaucracy.news is continuing to examine the contracting, deployment and security history of the Defense Regional Clock program and the circumstances surrounding the Hotline allegations that prompted the audit.
