Futuristic military command scene with tanks, helicopters, drones, networked maps, and digital battlefield analytics.
The U.S. Army’s Next Generation Command and Control program is being presented as a faster way to turn field experimentation into engineering and acquisition decisions. Its testing organization, the Army Test and Evaluation Command (ATEC), says it delivered assessment reports within one to two weeks after recent division-level events—a sharp contrast with the months-long reporting cycles associated with traditional test processes.

That speed is meaningful, but it should not be confused with proof that a new command-and-control stack is ready for broad deployment. The Army has now chosen a common data-layer baseline and preserved separate operational leads at two divisions, yet government oversight has raised unresolved questions about the schedule and lifecycle costs of scaling the effort. Public reporting has also left important cybersecurity remediation details unclear.

A faster feedback loop for command-and-control software​

NGC2 is an Army effort to modernize the systems that move operational information among commanders, units, applications, networks, and sensors. In practical technology terms, the goal is not simply a new application. It is an interoperable stack spanning applications, data, infrastructure, and transport, intended to make command systems more adaptable than long-lived, isolated programs of record.

ATEC’s reported turnaround is the most concrete recent indication of a change in how the Army wants to develop the system. For the 4th Infantry Division’s Ivy Sting and Ivy Mass events, and the 25th Infantry Division’s Lightning Surge events, ATEC says data-driven assessments reached decision-makers one to two weeks after each event ended.

Traditional military test reports can take months to mature because the work often involves data collection, analysis, formal reporting, and sequential review. Compressing that interval potentially gives developers and program leaders a chance to make changes while Soldier observations, technical telemetry, and mission context are still current. For a software-heavy program, that is closer to a continuous delivery feedback loop than a conventional hardware acquisition cycle.

The key caveat is that rapid reporting measures the speed of assessment, not necessarily the quality of the underlying product or the durability of the findings. Fast feedback can reveal defects sooner, but it does not automatically establish that fixes work across different networks, missions, threat conditions, or units. It also cannot by itself settle questions about sustainment cost, security, governance, and interoperability at Army scale.

Two division efforts are complementary, not a vendor race​

It is tempting to frame NGC2 as a head-to-head contest between Anduril Industries and Lockheed Martin. The Army’s own description is more nuanced. It says two vendor teams developed complementary architectural approaches with the 4th and 25th Infantry Divisions, and that the teams share feedback and data rather than compete.

Anduril was selected in July 2025 to lead an NGC2 prototype team under a contract valued at $99.6 million. Its work with the 4th Infantry Division encompassed a prototype architecture across applications, data, infrastructure, and transport. Lockheed Martin’s 25th Infantry Division effort initially emphasized an integrated data-layer capability and NGC2 software options.

The distinction matters. A competition can encourage differentiation, but it can also result in incompatible implementation choices. The Army’s cross-pollination model appears designed to preserve useful experimentation at two operational units while avoiding permanent divergence. Soldier feedback and technical evidence from one division can inform the other team’s work.

That arrangement does not mean the systems are identical, nor does it mean integration problems are solved. Rather, it reflects a program choice: test more than one approach while sharing evidence, then use a common baseline to reduce fragmentation where it matters most.

The common data layer is a consolidation move​

On June 22, 2026, the Army announced a common NGC2 data-layer baseline. Anduril is responsible for leading that common-baseline initiative, while remaining the full-stack operational lead for the 4th Infantry Division. Lockheed Martin remains the full-stack operational lead at the 25th Infantry Division.

A data layer is the connective foundation through which applications and participants can access, exchange, organize, and govern information. Standardizing it is a practical response to a recurring enterprise-software problem: different tools may work well in isolation but become costly, slow, and fragile when each has its own data definitions, interfaces, permissions model, and integration path.

For NGC2, a common data baseline could make it easier to carry lessons and capabilities between units without rebuilding every connection. It may also help the Army avoid locking each division into a distinct vendor-specific implementation. Those are plausible benefits of the announced approach, not outcomes yet demonstrated publicly.

The announcement should not be read as an award of a single, complete Army-wide command-and-control system to one company. The Army retained different full-stack leads at the two divisions. In other words, the data foundation is being aligned while operational implementation continues in two related tracks.

Do not confuse the NGC2 data layer with ATEC’s Data Mesh​

One potentially confusing detail is the use of similar data terminology for two different things.

The NGC2 common data layer is an operational program baseline: the Army’s effort to align how the future command-and-control architecture handles information. ATEC’s Data Mesh, by contrast, is a distinct test-and-evaluation platform. It is hosted on Microsoft Azure and accredited up to the Secret level.

The existence of an Azure-hosted ATEC platform does not establish that the operational NGC2 capability itself is simply an Azure deployment, or that it is a Windows-based tactical system. The public record supports a narrower conclusion: ATEC uses the Data Mesh as part of its assessment environment.

ATEC’s first Data Layer Assessment ran from October 2025 through February 2026 at Aberdeen Proving Ground’s Combined Joint Systems Integration Laboratory. It assessed architectures in denied, disrupted, intermittent, and limited-connectivity conditions. Those conditions are central to the program’s credibility. A command platform that performs only when bandwidth, cloud reachability, identity services, and backend systems are consistently available would be poorly suited to contested operations.

For enterprise IT readers, the comparison is familiar: an application can appear successful on a well-connected test network yet fail when links drop, synchronization is delayed, access is constrained, or local nodes need to operate independently. The difference is that those failure modes are not merely an availability inconvenience in a military setting; they can affect operational decision-making.

Scaling is the harder test​

ATEC’s quicker assessment process and the common data-layer decision show momentum. They do not resolve the program’s largest acquisition question: whether NGC2 can scale predictably within the Army’s resources.

The Government Accountability Office found that the Army had short-term NGC2 schedules through fiscal year 2027, but lacked the long-term schedule and cost information needed to assess scalability. GAO described a tentative objective to field the full technology stack across 11 divisions and four corps by the end of fiscal year 2032.

That is a substantial target, but it is not the same as a verified commitment to equip every Army division within five years. Nor is it a completed force-wide fielding decision. The distinction is important because scaling a common platform involves more than licensing or installing software. It entails integration, testing, training, operations, cybersecurity, network realities, configuration control, and ongoing support across very different units and locations.

The next steps are not wholly unspecified. GAO reported plans to field equipment to I Corps and the 7th Infantry Division during fiscal year 2027, while continuing work at the 25th Infantry Division. That makes the program’s near-term expansion more concrete than a generic promise of future rollout.

Funding figures require equally careful treatment. GAO identified approximately $3.3 billion requested for NGC2 in the President’s fiscal-year 2026 budget submission. Later reporting described the latest budget request as nearly $4 billion for development and delivery. Those figures refer to different points in time and should not be collapsed into one claimed fiscal-year amount without reconciliation against formal budget documents.

For taxpayers and acquisition observers, GAO’s concern is more important than the headline number alone. A program can receive large near-term funding and still face affordability or schedule problems if it lacks credible lifecycle-cost estimates and a detailed plan for expansion. Faster prototype feedback may reduce some risk, but it cannot substitute for a mature deployment and sustainment plan.

Cybersecurity remains an evidence gap​

The public cybersecurity record supplies another reason for caution. Reporting on an internal Army memo described an early NGC2 prototype as having serious deficiencies, including missing role-based access control, unassessed third-party applications, insufficient security scanning, and data-governance gaps.

Army officials and the involved vendors said the issues had been addressed, and an Army official said Ivy Sting 1 proceeded without delay. But officials did not publicly specify exactly how or when each identified deficiency was remediated. The available public evidence therefore supports neither the claim that the issues remain unaddressed nor the stronger assertion that every finding has been independently validated as resolved.

This is not a procedural footnote. Role-based access control determines which users can view or alter sensitive information. Security scanning and third-party application assessment help establish whether a system’s expanding software ecosystem introduces exploitable weaknesses. Data governance affects whether information is handled according to defined authority, policy, and protection rules. In a system designed to connect more users, applications, and data sources, those controls are foundational.

The program’s accelerated model could help identify security problems earlier if security evidence is included in each test cycle. But speed can also create pressure to treat mitigation statements as closure. The useful public benchmark will be clearer technical and governance evidence that security findings are tracked, tested, and resolved before broader deployment.

What Windows and enterprise IT readers should watch​

NGC2 is a military program, but its design choices mirror issues familiar to large Windows and cloud-connected environments: identity and role management, data interoperability, hybrid connectivity, endpoint and application trust, and the difference between a successful pilot and a supportable enterprise rollout.

The immediate story is not that the Army has completed a new command platform. It is that it has shortened its assessment loop, aligned on a common data-layer baseline, and kept two division implementations active under different operational leads. Those are consequential development steps.

The evidence to watch next is more demanding: whether the common baseline produces interoperable operational outcomes; whether planned fiscal-year 2027 deployments generate repeatable results beyond the initial divisions; whether long-term schedules and lifecycle costs become detailed enough to judge scale; and whether cybersecurity remediation is documented with sufficient specificity to inspire confidence.

ATEC’s one-to-two-week assessment timeline may prove to be one of NGC2’s most valuable process innovations. Yet the program will ultimately be judged less by how quickly it produces post-event reports than by whether it can deliver secure, resilient, manageable command-and-control capability across the units it intends to serve.