The Intersection of COTS and MOSA
Defense acquisition reform now emphasizes the use of commercial products and services to prioritize speed over perfection while maintaining the requirement for a modular open systems approach (MOSA). But speed isn’t just how quickly the system can be acquired, but also how well it can be integrated with other interoperable systems and the speed of adapting and upgrading to changes on the battlefield. This is where MOSA plays a crucial role, ensuring smooth integration and rapid, competitive upgrades to capabilities without breaking the rest of the system. .
The concepts of commercial off-the-shelf (COTS) products and a Modular Open Systems Approach (MOSA) have long histories, and US military acquisition law and practices continue evolving around them.
FY2026 National Defense Authorization Act (NDAA) strengthens the requirement to prioritize commercial products and services.
Connecting policy to practice, the FY2026 National Defense Authorization Act (NDAA) strengthens the requirement to prioritize commercial products and services, as well as non-developmental items. Agencies must now demonstrate, through market research, that no suitable commercial item exists before choosing a non-commercial option. The NDAA also continues to require MOSA for major defense acquisition programs, where practicable, and strengthens the requirement for MOSA by requiring non-proprietary, machine-readable interfaces.
This article examines the compatibility of COTS and MOSA, details the trade-offs between rapid acquisition and system flexibility, and discusses how the intersection of COTS and MOSA can deliver maximum value in defense programs.
COTS and Commercial Items
According to Part 2 of the Federal Acquisition Regulation (FAR), a “commercial item” is any product or service that is customarily used by the general public or nongovernmental entities for non-governmental purposes. This is a fairly broad category that can include:
- Products that have received minor modifications to meet DoD requirements
- Standalone services offered and sold competitively, in substantial quantities, in the commercial marketplace
- A non-developmental item (i.e., an item developed exclusively for governmental purposes), if the item was developed exclusively at private expense and sold in substantial quantities, on a competitive basis, to multiple State and local governments
The official definition of COTS is much narrower than that of "commercial items.” For an item to be designated as COTS, it must meet specific regulatory criteria:
- Customarily used by the general public or by non-governmental entities for purposes other than governmental purposes, AND
- Sold in substantial quantities in the commercial marketplace; AND
- Offered to the Government without modification
In the early days of COTS, there was also the category of modified off-the-shelf (MOTS). Today, MOTS would just be called a commercial item. The rest of this article uses the broader term “commercial item” to encompass COTS, MOTS, and related services.
Pros and Cons of Commercial Items
The primary benefits of using commercial items include faster procurement, lower procurement costs, and access to the latest technology. That contrasts with custom military procurements that take years to develop and rely on technology available at the start of the development cycle.
Although commercial products are typically designed to integrate easily with other compatible products, the interfaces can be modifications of common standards or even completely proprietary. Combined with restricted access to design information and intellectual property, that can limit the government’s ability to modify, repair, and upgrade the equipment, resulting in vendor lock-in. If the government requires source code or technical data to avoid vendor lock-in, then those require a separately negotiated price and schedule that can partially negate the advantages of selecting a commercial product. If the commercial items were not developed with military requirements in mind, there is likely an increase in security vulnerabilities, higher supply chain risk, and laxer configuration control.
Approach and Architecture
A Modular Open Systems Approach (MOSA) is an integrated business and technical strategy to achieve competitive and affordable acquisition and sustainment throughout the system life cycle. MOSA relies on a technical design that adopts open standards for system interfaces and supports a modular system architecture with highly cohesive, loosely coupled, and severable modules. To eliminate ambiguity and ensure interoperability, the interface definition needs to be documented in a machine-readable format, preferably defined using a formal data modeling language. With severability and verified open standard interfaces, modules can be competed separately and acquired from independent vendors.
MOSA also helps limit the amount of technical data required by the government to prevent vendor lock-in. Although the government still requires Government Purpose Rights (GPR) or Unlimited Rights for data defining all modular system interfaces (MSIs), MOSA eliminates the need to acquire the rights for implementation of the module inside of the MSI. The government does not need to know the inner proprietary physics or source code of a component to swap it out; it only needs to know how it connects. The published specification for an MSI should include all the information required for an interoperable implementation, such as data formats or a full data model, protocols, and performance/timing, as well as electrical and mechanical.
With MOSA, the government requires the technical data only for the modular system interface, not the internal design and IP of the modular system component.
MOSA relies on an open business model that permits risk sharing, maximizes asset reuse, and reduces ownership costs. The combination of the open business model and the modular architecture using open standard interfaces enables adding, modifying, and replacing system components across the acquisition life cycle. This accelerates the fielding of new warfighting capabilities by enabling greater flexibility, competition, and innovation.
MOSA Challenges
The biggest challenges of applying MOSA include:
- Different programs can adopt different approaches or select different open standards, leading to redundant development efforts and reduced cross-program interoperability and component reuse
- If the defined modules do not already exist, the acquisition time will be extended and may require some government funding to start development
- The initial adoption phase can present a significant technical learning curve, requiring teams to evaluate multiple open standards to select suitable interface specifications for the program and to develop expertise to accurately define the interfaces between system modules
- Lax enforcement of applying MOSA can significantly reduce the benefits. Examples of lax enforcement include not verifying compliance to the open standards selected, not applying MSIs throughout the system, and delaying the implementation of MSIs to accelerate the schedule of the lead platform at the expense of the broader enterprise
Intersection of COTS and MOSA
Many commercial systems lack modular design and open standard interfaces. While those systems may still offer initial value and quick delivery, these benefits come at the cost of increased integration challenges and higher long-term costs due to limited upgradability and potential vendor lock-in. Without open, modular interfaces, upgrades, servicing, and sourcing become costly and slow, creating a trade-off between initial speed and long-term flexibility to increase capabilities.
Conversely, MOSA can be implemented without commercial items. However, using open standards that lack industry adoption risks delayed fielding of capabilities while contractors develop new products or adapt existing products to meet the standard.
This highlights a trade-off between leveraging established open standards with a broad commercial ecosystem and selecting a new standard that may require further development of both the standard and custom solutions to meet it.
The use of commercial items that conform to MOSA-enabling open standards mitigates many of the challenges and potential disadvantages of both using commercial items and a modular open system approach each on their own. MOSA systems that leverage commercial items can achieve faster procurement, lower procurement costs, and access to the latest technology, thereby delivering new capabilities to the warfighter in a timely manner. Commercial products that conform to MOSA-enabling open standards promote competition and reuse, resulting in lower lifecycle costs and speedier upgrades.
Concrete Example: the FACE® Technical Standard and Ecosystem
A premier example of a MOSA-enabling open standard is the FACE Technical Standard and related ecosystem. The FACE Technical Standard is the result of collaboration among government, industry, and academia to develop and evolve a software reference architecture focused on modularity, portability, and reuse of software components across both mission-critical and safety-critical software systems.
First published in 2012, the FACE Technical Standard continues to evolve to increase compatibility with other open standards and to meet new and emerging mission requirements. One significant evolution was the definition of the FACE Data Architecture - a framework of interrelated data models, technical specifications, and data governance policies that enable interoperable data exchange. It uses the UDDL formal data modeling language to document the meaning, context, and identity of data in a machine-readable form. This enables consistent understanding of the data across organizations, tools, and systems throughout a program's lifecycle and into sustainment.
As a result of the maturity of the FACE Technical Standard and collaboration with industry, the FACE Registry lists more than 50 commercial software products that have been certified conformant to one of the five segments in the FACE Reference Architecture.
The FACE Reference Architecture defines a layered architecture composed of five segments connected by three interfaces (aka “Key Interfaces” per a MOSA). Together, the FACE Technical Standard and business practices address all five principles of MOSA.
Green Hills Software is proud to be a founding member of the FACE Consortium and has been the co-lead of the Operating Systems Subcommittee for the entire duration. Green Hills Software has six certified products listed in the FACE Registry, including the first ones to meet the multicore requirements of operating systems in the FACE Technical Standard, Edition 3.X. Those products are the INTEGRITY-178 tuMP RTOS for Arm, Intel, and PowerPC. INTEGRITY-178 tuMP is the perfect example of the intersection of COTS and MOSA, providing a commercially available solution with industry standard interfaces that speed integration, reduce schedule risk, and encourage software reuse.

