Military
PLA Modernisation Seen Through US Munitions and Cyber Gaps

In this episode
- Opening
- CNAS on munitions and affordable mass
- CFR on the cyber gap
- What to watch
Two September 2026 reports take the measure of PLA modernisation from the outside in. CNAS's Philip Sheers and Stacie Pettyjohn argue that cheap drones and cruise missiles should supplement rather than replace high-end munitions in a Taiwan fight, saturating air defences and attriting an invasion fleet but leaving hardened and deep-inland targets untouched; CFR's Matthew Ferren, Adam Segal and Rush Doshi describe a widening cyber asymmetry in which Chinese state-sponsored operations threaten the systems Washington needs to fight and govern. We read both for what they assume about PLA force structure and capability, and note how much of the analysis is framed as US shortfall rather than direct assessment of China's own programmes and defence industrial base.
Reports discussed
- Drones, Missiles, and the U.S. Munitions Shortage: The Role of Affordable Mass in a Taiwan Conflict
- The Cyber Gap
Read along with the audio
Opening
Welcome to today's China report. Today the subject is People's Liberation Army modernisation and the defence industry, except that isn't quite what either report is about, and I want to say that plainly up front. Both of these are American reports about American gaps, and the picture of the Chinese military arrives sideways, as the thing the gap gets measured against. One is from the Center for a New American Security, on munitions and cheap drones. The other is from the Council on Foreign Relations, on cyber deterrence. Two reports is a thin crop this week, usually there are more, and a quiet month in this literature is itself worth noticing.
CNAS on munitions and affordable mass
So. "Drones, Missiles, and the U.S. Munitions Shortage," published on the eighteenth of September by CNAS, written by Philip Sheers and Stacie Pettyjohn.
The claim is a corrective. Cheap expendable drones and cruise missiles should supplement high-end missiles, not replace them. The starting point is that the United States burned through its long-range precision-guided munitions in five months of Operation Epic Fury against Iran, which began on the twenty-eighth of February this year, and the stockpile was already thin before that. Against China, the report says, there are well over two thousand potential military targets.
How it argues. Two worked examples: attacking a Chinese cruiser at sea, and suppressing a Chinese air base. In each one the authors build what they call a Weapon Quality Index, accuracy times survivability times lethality, and then ask how many munitions you need for a ninety-five percent chance of killing the target. The mechanism is saturation. A cheap drone's survivability against an alert defence is 0.05 in their model. Send scouts and decoys in first, and it becomes 0.75. Fifteen-fold. That one number is what makes mixed salvos beat pure ones, and it drives the headline: servicing four hundred combat ships with cheap weapons costs about four billion dollars less than doing it with exquisite ones.
What it rests on. Not a wargame, not classified modelling. This is a spreadsheet built on open-source Chinese air defence orders of battle, standard blast-effect functions, and the authors' own judgement about weapon performance. And they say so, the analysis is, in their words, indicative rather than predictive, and they invite you to change the parameters yourself. That's honest, and I'd take it over false precision. But notice what it means. The saturation coefficient isn't measured. It's chosen. And on the two-thousand-target figure, which is what the whole scale problem hangs on, the report prints no derivation and no source at all. I went looking for an independent count from the Japanese and Singaporean institutes that do this kind of work, and I couldn't find one.
The prediction is borrowed rather than made. The Department of War's goal of fielding over ten thousand low-cost munitions in three years. That's a date with a number on it. Twenty twenty-nine.
And here's where it gets awkward, using the report's own arithmetic. Its cheapest air base option, runways and exposed aircraft only, sixteen aimpoints, takes roughly two hundred and forty cheap drones plus eight high-end cruise missiles. About forty million dollars. For one base. And a few pages earlier the report notes that Chinese forces can repair runways within hours. So ten thousand munitions divided by two hundred and forty is about forty-one attacks. Not forty-one airfields held down, forty-one attacks, each good for an afternoon, against a target set the report itself puts at more than eight hundred within drone range. The case at sea is strong, because sinking a ship only has to work once. The airfield case is the one the report leans on for land attack, and its own numbers say affordable mass there doesn't buy persistence. It buys one afternoon. The report also never addresses what launches all this. Two hundred and forty-eight munitions against a single base is a delivery problem as much as a procurement one, and it isn't in the paper.
CFR on the cyber gap
"The Cyber Gap," published on the tenth of September by the Council on Foreign Relations, Matthew Ferren, Adam Segal and Rush Doshi.
The argument is that China can threaten the systems the United States needs to fight and to govern, and Washington has neither adequate defence nor credible deterrence. The evidence for the threat is two named campaigns. Volt Typhoon, sitting inside American water, energy, telecoms and transport systems for at least five years before anyone noticed. And Salt Typhoon, inside at least nine major US carriers, reaching the systems that carry court-ordered wiretaps.
The logic chain is a chain of failures. The twenty fifteen Xi–Obama agreement produced a temporary dip and then Beijing resumed. Sanctions and indictments changed nothing. Offensive operations disrupted individual campaigns, the FBI cleaning malware off hundreds of routers in December twenty twenty-three, without degrading capacity at all. So episodic action fails, and only structural reform works: visibility, cost imposition, resilience, rebuilding government capacity. Four pillars, and the authors are explicit that none of them works alone.
What it rests on is worth being precise about. No interviews. No original dataset. It's government advisories, the intelligence community's annual threat assessment, and vendor telemetry. The load-bearing activity number, China-based activity up thirty-eight percent from twenty twenty-five to twenty twenty-six, is CrowdStrike's, and vendor telemetry measures what that vendor's sensors happen to see, which also grows when the vendor grows. The hardest numbers in the report are the American ones: federal cybersecurity spending due to fall nine point six percent in fiscal twenty twenty-seven, to eleven point seven billion dollars, and CISA, the federal cyber defence agency, down roughly a third of its workforce since January twenty twenty-five. Those come from budget documents. They're solid.
The forecast is a window rather than a date. The US leads China in frontier artificial intelligence by, they say, months, and they point to two Chinese models released this June and July to make the case. But no date is attached to when that window shuts, which means it can never be caught out.
Now the challenge, and it's aimed at pillar two. Cost imposition depends on coordinated allied measures, joint sanctions, export controls, a shared menu of consequences. Every single incident the report names was found and attributed by the United States. So I went and looked at a close partner instead. Singapore's Cyber Security Agency published its own account in February this year of a campaign against all four of its telecoms operators: over a hundred defenders, more than eleven months, the largest cyber operation that government has ever mounted. Commercial researchers call that actor China-linked. Singapore's government did not name a state. Not once. I tried to read Singapore's RSIS commentaries on why, and I couldn't get them open, so I'll leave the reasons alone. But the fact stands, and it's a hole in pillar two. A strategy of graduated, coordinated allied punishment needs allies willing to say out loud who did it, and the report never asks whether they will.
What to watch
The nearest testable thing here lands in twenty twenty-nine: ten thousand low-cost munitions fielded, or not. Watch the contract awards, not the speeches. Sooner than that, the fiscal twenty twenty-seven budget either confirms that nine point six percent cut or it doesn't, and that one line will tell you more about American cyber policy than any strategy document will. And if an allied government, Tokyo, Canberra, Singapore, names Beijing directly for an intrusion on its own infrastructure, that's the CFR report's hardest problem beginning to ease.