NADAC implementation estimate
United States
335M population · US$85,000 GDP/capita · high CI exposure · Tiers 1–4 · 36 months · 100% coverage
36-month total
US$521.7M – US$1.04B
Central case US$782.6M
Annual run-rate
US$260.9M
US$296.9M capital · US$485.6M recurring
Per capita
US$2.34
0.0027% of GDP over the programme
vs paper benchmark
3.48×
Relative to US$225M central case at 50M population
For a country of ~50 million population with moderate critical-infrastructure exposure, cumulative three-year expenditure of US$150–300M is consistent with the NADAC specification. This estimate scales that anchor by population (6.70× reference), local cost level, exposure and existing maturity. Annual run-rate is 0.002% of general government expenditure.
Budget
Where the money goes
Cost distributed across the four NADAC tiers and by expenditure category.
By tier
- T1Foundational Cyber HygieneUS$462.4M · 59%
- T2AI-Specific Technical ControlsUS$174.4M · 22%
- T3Institutional CapabilityUS$137.6M · 18%
- T4International CoordinationUS$8.2M · 1%
By category
Capital expenditure US$296.9M (38%) versus recurring US$485.6M.
Control ledger
Cost per NADAC control
Each line pairs the paper's threat category and numeric target with a scaled cost for this country.
| ID | Control | Phase | Cost |
|---|---|---|---|
| T1T1.1 | Phishing-resistant MFA (FIDO2/WebAuthn) | P1 | US$92.9M |
| T1T1.2 | ASM/EASM continuous inventory | P1 | US$32.2M |
| T1T1.3 | KEV-aligned patch SLA | P1 | US$55.7M |
| T1T1.4 | Zero-trust OT/IT segmentation | P1 | US$150.5M |
| T1T1.5 | 24/7 security operations with SLA | P1 | US$131.0M |
| T2T2.1 | Prompt-injection testing in CI | P2 | US$21.3M |
| T2T2.2 | Agent tool-permission scoping | P2 | US$16.2M |
| T2T2.3 | Model SBOM (M-SBOM) | P2 | US$12.2M |
| T2T2.4 | Deepfake detection at chokepoints | P2 | US$57.2M |
| T2T2.5 | Out-of-band transaction verification | P2 | US$17.2M |
| T2T2.6 | Dual-LLM quarantine pattern | P2 | US$18.8M |
| T2T2.7 | Shadow-AI discovery | P1 | US$31.5M |
| T3T3.1 | National AI-CSIRT unit | P1 | US$58.6M |
| T3T3.2 | Mandatory AI-linked breach reporting | P1 | US$9.0M |
| T3T3.3 | National bug bounty with AI scope | P2 | US$24.3M |
| T3T3.4 | Defensive AI (AIxCC open-source) | P3 | US$35.6M |
| T3T3.5 | ISAC AI-misuse intelligence channel | P3 | US$10.1M |
| T4T4.1 | Frontier model provider MoUs | P2 | US$2.6M |
| T4T4.2 | Allied AI-misuse sharing channel | P2 | US$2.5M |
| T4T4.3 | UN OEWG AI-in-cyber track | P3 | US$1.5M |
| T4T4.4 | Cross-border MLAT evidence protocols | P3 | US$1.5M |
Roadmap
Phased delivery
Phase sequencing is not arbitrary: higher-tier controls assume the operational maturity of lower-tier controls.
P1 Foundations
0–12 mo.
US$374.3M – US$748.6M
≈ US$561.4M per year
T1.1–T1.5 rollout audit; T3.1 AI-CSIRT stand-up; T3.2 reporting regulation enacted; T2.7 shadow-AI baseline established.
T1.1 · T1.2 · T1.3 · T1.4 · T1.5 · T2.7 · T3.1 · T3.2
P2 AI controls
12–24 mo.
US$114.9M – US$229.8M
≈ US$172.4M per year
T2.1–T2.6 deployed in regulated sectors; T4.1 MoUs signed with top 5 model providers; T3.3 bug bounty operational.
T2.1 · T2.2 · T2.3 · T2.4 · T2.5 · T2.6 · T3.3 · T4.1 · T4.2
P3 Diffusion
24–36 mo.
US$32.5M – US$65.0M
≈ US$48.8M per year
T3.4 AIxCC OSS deployed to ≥ 60% federal software; T4.2 Five Eyes+ channel operational; T4.3 OEWG outputs; T4.4 MLAT protocols.
T3.4 · T3.5 · T4.3 · T4.4
Spend curve
Resources
Workforce and materiel
Headcount and unit volumes implied by the control targets at this country's scale.
National AI-CSIRT
39–65 FTE
Scaled from the paper's 15–25 FTE per 50M population (ENISA / CISA operational envelopes).
24/7 SOC analysts
145 FTE
Rotation sized for MTTD ≤ 4h on high-severity events and MTTR ≤ 24h containment (T1.5).
Regulatory & legal staff
30 FTE
72-hour breach reporting regime, bug-bounty safe harbor, MLAT protocols (T3.2, T3.3, T4.4).
Zero-trust inspection points
3,751
OT/IT boundary coverage to reach ≥ 90% by M24 (T1.4).
FIDO2 hardware credentials
957k
Phishing-resistant MFA across designated critical infrastructure by M12 (T1.1).
Deepfake detection chokepoints
481
Executive video conferencing, IVR-connected treasury lines, media broadcast paths (T2.4).
Training seats (3-year)
37,480
Operator, developer and executive tracks across Tier 1 and Tier 2 controls.
Bug bounty pool
US$24.3M
AI-agent-in-scope minima with legal safe harbor (T3.3).
Feasibility
Overall implementation feasibility
All four NADAC tiers are realistically deliverable on the specified timeline.
96
StrongAffordability
StrongAnnual run-rate is 0.002% of general government expenditure and 0.0027% of GDP over the programme.
Workforce availability
StrongProgramme needs roughly 240 specialist FTE against an estimated national pool of 4,740. The paper notes Tier 3 requires significant human capital.
Regulatory capacity
StrongTier 2 controls require regulatory sophistication and enforcement capacity; institutional capacity is assessed at 90%.
Tier 1 readiness
StrongExisting hygiene maturity of 85% determines how much of T1.1–T1.5 is greenfield build versus uplift.
Tier 2–4 readiness
StrongDelivered nationally. Coalition mode via Five Eyes would reduce Tier 3/4 cost and capacity load.
Measurement
Seven KPIs
Reporting quarterly, with public disclosure of aggregated indicators annually to sustain political accountability.
| ID | Indicator | M12 | M36 |
|---|---|---|---|
| K1 | MTTD for AI-linked intrusionsDetection speed | ≤ 90 days | ≤ 30 days |
| K2 | % KEV CVEs patched within SLA (critical infra)Preventive hygiene | ≥ 85% | ≥ 95% |
| K3 | % critical infra with living-off-the-land detectionPreventive hygiene | ≥ 70% | ≥ 95% |
| K4 | % frontier providers reporting quarterlyIntelligence flow | 100% | 100% |
| K5 | Deepfake fraud loss as share of GDP (quarterly)Societal harm | Baselined | ≥ 50% reduction |
| K6 | % federal software with defensive-AI coverageCapability diffusion | ≥ 20% | ≥ 60% |
| K7 | Prompt-injection CI pass rateAI pipeline hygiene | ≥ 90% | ≥ 95% |
Sensitivity
How the total moves
| Scenario | Total | Change |
|---|---|---|
| Baseline scenario | US$782.6M | — |
| 24-month compressed timeline | US$958.7M | +22.5% |
| 48-month extended timeline | US$743.4M | -5.0% |
| 70% coverage | US$606.5M | -22.5% |
| Tiers 1–2 only | US$636.8M | -18.6% |
| Coalition-delivered Tier 3/4 | US$729.5M | -6.8% |
| High CI exposure | US$782.6M | — |
Appendix
Assumptions and derivation
- Reference anchor
- US$150–300M over 3 years for ~50M population at moderate CI exposure (paper §V)
- Central case
- US$225M at reference, distributed across 21 controls
- Population scaling
- Sublinear, exponent 0.15–0.85 per control (fixed institutional cost)
- Local cost index
- 1.37× reference, from √(GDP per capita ÷ US$45,000)
- Tooling index
- 0.97× reference (globally priced licences)
- CI exposure factor
- 1.28× (high)
- Maturity relief
- 85% maturity, reducing greenfield Tier 1 build
- Timeline factor
- 1.00× for a 36-month roadmap
- Coverage
- 100% of specified control scope
- Uncertainty band
- ±33%, matching the paper's US$150–300M spread
Tier composition: Tier 1 Foundational Cyber Hygiene · Tier 2 AI-Specific Technical Controls · Tier 3 Institutional Capability · Tier 4 International Coordination. Source: A Layered National Defense Framework for AI-Enabled Cyber Warfare: Actionable Controls, Metrics, and Implementation — Shahmeer Amir, Independent Cybersecurity Researcher.