Open by design: How Elastic supports MOSA, the DoD's Modular Open Systems Approach
Congress made openness the law for defense acquisition. Here's what that looks like at the data and analytics layer.
.jpg)
Since 2019, US federal law has required major defense acquisition programs to be designed around a Modular Open Systems Approach (MOSA). In 2021, the requirement grew to cover defense acquisition programs across the board (10 U.S.C. 4401 through 4403). The statute spells out what it wants: modular designs, major system interfaces built on widely supported consensus-based standards, and severable components that can be added, removed, or replaced over the life of the system.
If you work in a program office, you already know this isn't paperwork. Every component you propose now has to answer the same question: Does it help us implement MOSA or is it the piece we'll never be able to pull back out?
The spirit of MOSA
To be clear, there's (currently) no such thing as a MOSA-certified product. DoD assesses MOSA at the program level, and the MOSA Implementation Guidebook tells programs to run a business-case analysis when applying MOSA requirements to commercial components. If a vendor tells you their product "is MOSA compliant," it's probably bluster. Ask instead whether the component will let your program hit the tenets DoD actually measures, including modularity, openness, scalability, flexibility, and reusability.
Given the Elastic platform often sits in a position where organizational data gets operationalized, the answers to those questions are even more important to address.
Severability works both ways
The hardest MOSA test is also the simplest: Can you remove the thing? Elastic comes into a program as a data and analytics module that lands alongside your existing estate and proves itself on live workloads before anything gets retired. And since instrumentation rides on OpenTelemetry (the CNCF standard), you could swap out Elastic later without touching the systems that produce the data. We're comfortable saying that out loud because easy removal is the real test of openness.
The interfaces are standards you already know
Take the integration points your program office would designate as major system interfaces and inspect them one by one. Each runs on an open standard no single vendor controls:
Ingestion: OpenTelemetry wire protocols with the Elastic Common Schema contributed to the OpenTelemetry Semantic Conventions
Security content: OCSF, STIX, and TAXII interoperability
Query and management: REST and JSON with published, versioned, and machine-readable API specifications
Identity: SAML, OIDC, and PKI, including smart card workflows
Storage: the S3 object storage API for snapshots and low-cost data tiers
Orchestration: Kubernetes through Elastic Cloud on Kubernetes
That's what the statute means by consensus-based standards. And it's checkable because the specs are public.
Competition shouldn't end at contract award
MOSA exists to keep competition alive for the life of a program, long after source selection ends. Elastic's open source roots help here. The engine is built on Apache Lucene, and in 2024 we added the OSI-approved AGPL v3 license option to Elasticsearch and Kibana, putting the core back under open source. Add the free tier, open client libraries and standard wire protocols, and the government keeps a credible exit the whole way through. We'd rather earn the renewal than block the exit.
Yes, we sell commercial subscription features. MOSA doesn't prohibit proprietary elements; it asks that they be modular, documented, and reachable through open interfaces. Ours sit behind the same published APIs as the open features, the feature-to-tier boundaries are public, and your data stays exportable through standard APIs and snapshots. Nothing we sell takes the data hostage.
Scoring it against all 5 tenets
Severability and open interfaces carry most of the story, but the guidebook names five tenets. Here's the full map:
Modularity: The platform is a severable module from the program's point of view, and it's modular inside too. Node roles, data tiers, and the security, observability, and search solutions are all separate consumers of one engine. You add or remove them independently.
Openness: Every designated interface rides a public standard, the API specs are machine-readable, and the core is open source. Covered above and verifiable without taking our word for it.
Scalability: The same architecture runs as a three-node cluster and as a federated mesh of domain clusters queried as one estate. You grow by adding nodes, tiers, or clusters. You never rearchitect, and you never reinstrument.
Flexibility: One software base deploys to FedRAMP-authorized cloud (Moderate or High), on-premises data centers, air-gapped enclaves, and the tactical edge. Changing where you run it is a deployment decision. Nothing gets redesigned.
Reusability: Detection rules, dashboards, integrations, data schemas, and analyst skills carry across programs and missions. The second use case on the platform inherits the data, governance, and muscle memory the first one built.
What's still yours to do
Two jobs stay with the program office: designating key interfaces in your interface control documentation and government reference architecture and doing the data rights analysis required for commercial software (10 U.S.C. 3771). There’s one more scoping note because it comes up in RFPs: FACE, SOSA, and CMOSS are embedded frameworks for avionics, sensors, and vehicle electronics. They were never meant to measure an enterprise data platform. Elastic's MOSA story lives at the data, analytics, and command-and-control software layer.
The bottom line
MOSA asks you to buy architectures, not products. So, judge a component by its interfaces, how cleanly it can be removed, and whether it keeps your future options open. That's how Elastic has built for more than a decade in the open and on open standards. If your program is working through MOSA at the data layer, our public sector team is easy to find. We'll walk the interface inventory with you, whether you run in FedRAMP-authorized cloud or an air-gapped enclave, and share the reference architecture behind it.
Learn more about Elastic for defense agencies
The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.