
The CFAA stays intact, which means this is not a 'letters of marque' framework — it's a deputization model where companies operate under federal contracts and case-by-case authorization rather than statutory right. That distinction matters: it preserves the government's ability to revoke authority without legislative action, but it also means every offensive operation requires federal sign-off, which creates a bottleneck if demand outpaces the coordination center's capacity.
This memo opens the legal pathway for private cyber firms to conduct offensive operations domestically — a capability previously restricted to government agencies — but stops short of amending the CFAA, which means participating companies operate under explicit federal authorization rather than statutory exemption.
Justice Department and DHS now control the gating mechanism for private offensive cyber work, which shifts enforcement discretion from the legislative framework to executive-branch contract authority and creates a precedent for rapid scaling of private-sector cyber operations if threat definitions expand. Watch the first contract awards and vetting criteria — those documents will reveal whether the coordination center interprets 'transnational criminal organizations' narrowly (drug trafficking, ransomware) or broadly enough to capture state-adjacent actors the memo technically excludes.
Does the memo define 'transnational criminal organizations' with enough precision to prevent scope creep toward state-sponsored actors, or does it leave that definition to the coordination center and participating companies?
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.