Table of Contents
Gap: protection of nuclear command, control and communications
As of 1 October 2026. Information only, not legal advice – see the disclaimer.
| Full title | No specific instrument protecting nuclear command, control and communications (NC3) against cyber operations |
|---|---|
| Type | Regulatory gap |
| Adopted by | – |
| Adopted | – |
| Legal status | No treaty, political commitment or other instrument specifically addresses cyber operations against nuclear command, control and communications systems |
| Official text | – |
| Subject area | Regulatory gaps; Use of force, intervention and cyber operations |
Overview
Nuclear command, control and communications (NC3) systems comprise the infrastructure used to plan, warn of, authorise and execute the use of nuclear weapons, including early-warning, communication and decision-support systems. There is no international instrument that specifically regulates cyber operations directed at, or affecting, such systems; commentators note that no existing treaty refers to NC3 as such. General rules of international law – including the UN Charter, international humanitarian law and the voluntary norms of responsible State behaviour in the use of ICTs – apply according to their terms. Governments, research institutes and experts have described risks that cyber operations affecting NC3 could lead to misperception, escalation or unauthorised use, and have put forward proposals ranging from dialogue and national measures to norms of restraint and a code of conduct.
Provisions relevant to the cyber and information sphere
Nearby instruments and commitments (none specific to NC3):
- UN Charter, Arts 2(4) and 51 – prohibition of the threat or use of force; right of self-defence (charter).
- UN framework of responsible State behaviour in the use of ICTs – voluntary norms including norm 13(f) (no ICT activity that intentionally damages critical infrastructure) as set out in the 2015 GGE report (A/70/174) and endorsed by the General Assembly (ict_norms).
- Additional Protocol I, Art. 56 – protection of works and installations containing dangerous forces, including nuclear electrical generating stations, in international armed conflict (ap1).
- P5 Joint Statement of 3 January 2022 – the leaders of China, France, Russia, the United Kingdom and the United States affirmed that “a nuclear war cannot be won and must never be fought” and stated that each would maintain and further strengthen national measures to prevent unauthorized or unintended use of nuclear weapons. The statement does not refer to cyber operations.
- United States–China, 16 November 2024 – at a meeting in Lima, the two presidents “affirmed the need to maintain human control over the decision to use nuclear weapons” (White House readout as reported). The statement does not refer to cyber operations.
- UN General Assembly resolution 80/23 (1 December 2025; 118 in favour, 9 against, 44 abstentions) – “Possible risks of the integration of artificial intelligence into command, control and communications systems of nuclear weapons”. The resolution concerns artificial intelligence in nuclear command, control and communications; it does not specifically address cyber operations (military_ai).
Application to cyber and information operations
Proposals and analyses (selection, chronological):
- Chatham House (B. Unal, P. Lewis), Cybersecurity of Nuclear Weapons Systems: Threats, Vulnerabilities and Consequences, January 2018 – analysis of cyber vulnerabilities across nuclear weapons systems, including command and control.
- Nuclear Threat Initiative (NTI), Nuclear Weapons in the New Cyber Age, report of a study group chaired by former officials, September 2018 – describes risks of false warnings, unauthorised use and erosion of confidence in deterrent systems.
- UNIDIR (W. Wan, A. Kastelic, E. Krabill), The Cyber–Nuclear Nexus: Interactions and Risks, 2021 – proposes strengthening national cybersecurity of the nuclear enterprise, deepening common understandings, enhancing restraint in cyberspace, including norms against targeting nuclear-related systems, and building on existing risk-reduction frameworks and UN processes.
- E. Crawford, The Need for an International Law-Informed Code of Conduct for Nuclear Command, Control and Communication (NC3), Nautilus Institute, March 2026 (also in the Journal for Peace and Nuclear Disarmament) – proposes a non-binding code of conduct, modelled in part on the Hague Code of Conduct against Ballistic Missile Proliferation, combining legal obligations and best practices.
Intergovernmental processes. The Eleventh Review Conference of the Treaty on the Non-Proliferation of Nuclear Weapons (New York, 27 April – 22 May 2026) ended without a consensus outcome document. No negotiating process on an NC3-specific instrument is under way.
Recent developments
- 2024-11-16: United States–China leaders' statement on maintaining human control over the decision to use nuclear weapons (as reported).
- 2025-12-01: UN General Assembly adopts resolution 80/23 on possible risks of the integration of artificial intelligence into nuclear command, control and communications systems (UN Digital Library).
- 2026-03-16: Nautilus Institute publishes proposal for an NC3 code of conduct (E. Crawford).
- 2026-05-22: NPT Review Conference ends without a consensus outcome (UN press release DC/3912).
Related entries
Sources
- Chatham House, Cybersecurity of Nuclear Weapons Systems (January 2018), accessed 2026-09-27
- NTI, Nuclear Weapons in the New Cyber Age (September 2018), accessed 2026-09-27
- UNIDIR, The Cyber–Nuclear Nexus: Interactions and Risks (2021), accessed 2026-09-27
- United Nations, 2026 NPT Review Conference, accessed 2026-09-27
Change log
- 2026-09-27: Entry created (draft).
- 2026-09-30: Entry reviewed and finalised.
- 2026-10-01: GA resolution 80/23 added.
