The Modular Open Systems Architecture Bet: Why MOSA Is the Defense Tech Investment Thesis You Can't Afford to Ignore
S. VanceThe Pentagon has a vendor lock-in problem that it has spent decades creating and is now spending billions trying to undo. Modular Open Systems Architecture, known as MOSA, is the policy lever being used to fix it. For investors paying attention, the downstream effects are significant.
Photo by Tima Miroshnichenko on Pexels.
Since the 2017 National Defense Authorization Act first codified MOSA requirements, the DoD has been pushing program offices to design major systems so that components can be swapped, upgraded, and competed independently. The F-35's sensor fusion suite cannot be easily replaced by a competitor. The Army's legacy command-and-control software ties dozens of programs to a single integrator. MOSA is the bet that future platforms won't repeat those mistakes.
What does this mean in practice? A program built to MOSA standards exposes interfaces. Subsystems must conform to published standards so that a new entrant can compete on the next upgrade cycle without rebuilding the entire stack. For prime contractors, that's a threat. For well-positioned startups, it's the opening they've been waiting for.
Here's the investment logic. When a platform is locked, the incumbent prime captures nearly all of the lifecycle revenue. When a platform is modular, individual subsystem slots become contestable markets. A startup that builds a best-in-class EO/IR payload, an edge-compute module, or a waveform library to open standards can compete for insertion into existing platforms rather than winning a new program from scratch. That changes the sales motion, the capital requirements, and the risk profile substantially.
Consider the shift happening in electronic warfare. Programs like the Navy's Consolidated Afloat Networks and Enterprise Services (CANES) and the Army's Integrated Tactical Network have both adopted open architecture principles. Third-party software vendors can now bid for specific capability inserts. That's a structurally different market than five years ago.
Not every startup can play here, though. MOSA compliance has real technical requirements. Startups must conform to standards bodies like FACE (Future Airborne Capability Environment) for avionics, SOSA (Sensor Open Systems Architecture) for sensor payloads, or HOST (Hardware Open Systems Technologies) for shipboard systems. Each standard has a conformance testing process. Getting a product through that process takes time, money, and engineers who understand both the standard and the underlying hardware. Founders who underestimate this routinely burn twelve to eighteen months and several million dollars before their first contract.
The diligence question for investors is therefore specific: has this team mapped their product to the relevant standards body, and do they have a conformance roadmap with actual milestones? Vague claims about being "MOSA-compatible" are a yellow flag. The standards are public. The conformance requirements are detailed. A team that has done the work can show you exactly where they are in the process.
graph TD
A[Startup Product] --> B{Relevant Standard?}
B --> C[FACE - Avionics]
B --> D[SOSA - Sensors]
B --> E[HOST - Shipboard]
C --> F(Conformance Testing)
D --> F
E --> F
F --> G[Program Insertion Opportunity]
There's a second-order effect worth watching. MOSA creates recurring revenue opportunities that didn't exist under the old model. When a prime owns the interface, the startup sells once and hopes for follow-on. When the interface is open and standardized, the startup can compete on every upgrade cycle for the life of the platform. A naval vessel with a thirty-year service life becomes a multi-decade addressable market rather than a single contract. That changes exit math meaningfully.
The risk is regulatory patience. MOSA adoption varies by service branch and by program office. Some PMs have embraced it; others are dragging their feet because open standards genuinely complicate program management. A startup betting on MOSA insertion into a program that never fully adopts the standard is in trouble. Part of the investment thesis has to include a realistic read on which programs are committed versus which are going through the motions.
Primes are also adapting. Several of the large systems integrators have stood up internal open-architecture divisions specifically to compete in the subsystem market they used to control entirely. Startups need to differentiate on performance, not just openness. Being MOSA-compliant is table stakes; being the best payload in the slot is the actual competitive position.
For investors focused on defense tech, MOSA represents one of the few areas where policy has created a durable structural opening for non-traditional entrants. The mandate exists. The standards exist. The program insertions are happening. What's missing is a generation of startups that have done the compliance work rigorously enough to actually sit at the table when contract decisions get made. That gap is where the opportunity lives.
Get Critical Tech Ventures in your inbox
New posts delivered directly. No spam.
No spam. Unsubscribe anytime.