The IEEE Standards Association approved P3536, the Standard for Space System Cybersecurity Design, on March 26 after four years of drafting. It is the first international technical standard to embed security controls into satellite architecture from the start rather than treating cybersecurity as a post-launch add-on.
The standard defines controls across four technical modules: the ground system, the space vehicle, the link segment connecting them, and an integration layer covering APIs, data links and test environments. A fifth subcommittee addresses user-segment devices such as handsets, base stations and navigation applications.
Gregory Falco, the Cornell aerospace engineering professor who chaired the working group, framed the standard as a way to rule out entire categories of attack through engineering choices rather than layering monitoring onto insecure designs.
The timing reflects the scale of what is now in orbit: more than 12,000 active satellites transmitting data over laser crosslinks. The 2022 Viasat KA-SAT denial-of-service attack, the 2025 Israel-Iran conflict and the Golden Dome missile defense program have all pushed space cybersecurity higher on the priority list for both industry and government.
P3536 sits alongside existing frameworks from NIST, CISA and ESA but is specifically scoped for the unique constraints of space systems.