Skip to content

Satellite Orbits Supply Chain

EGV Level: 2 — Global · Geometric | Date: July 2026 | Version: 5.5
Reference: EGV White Paper V7.0 (GGOS, January 2026) · Guiding Principles v2.1 · 1st Joint Development Plan
Supersedes: Version 5.4 (July 2026)

PPTD (People, Process, Technology, Data) scores: State of Geodesy 2026 — A baseline maturity assessment (UN-GGCE, 16 March 2026)[^sog2026]
Tier Risk Scores: UN-GGCE Supply Chain Risk Assessment, 2026

Audience

This document serves two readerships: (1) UN-GGCE leadership and technical counterparts already familiar with this engagement; and (2) UN-GGCE staff and Member State stakeholders new to this specific analysis. Readers new to the engagement should read this Purpose & Reading Guide; the tier-by-tier detail that follows supports the summary findings reported in the Work Assignment 2 and Work Assignment 3 reports.

Purpose & Reading Guide

This is one of five technical workflow descriptions supporting Work Assignment 2 of the UN-GGCE Global Geodesy Supply Chain Assessment (Terms of Reference 2). It maps, tier by tier, how the GNSS Satellite Orbits product is produced — the institutions involved, the capabilities each step depends on, and where the production chain is most exposed to failure.

Companion Documents

Readers new to this engagement should start with the Critical Product Mapping Report (Work Assignment 2), which explains the risk scoring framework and includes a key terms glossary; the tier and data-level structure used throughout is defined in the EGV Data Levels and Supply Chain Tiers appendix (Work Assignment 1 Appendix).


Overview

The Satellite Orbits Essential Geodetic Variable (EGV) sits at Level 2 in the GGOS EGV framework — it is a processed, combined product derived from raw observation data and delivered as an input to the full suite of Level 3 EGVs. Within the Level 2 category, this supply chain specifically produces the GNSS Satellite Orbits, Clocks and Biases (GOCB) product set: three-dimensional orbital trajectories for all operational GNSS satellites and sub-nanosecond clock corrections for each satellite.

These products are Primary or Important inputs to ten of fourteen Level 3 EGVs, including Global Reference Frames (ITRF), Sea Surface, Sea Level, Ice Sheets, Terrestrial Water Storage, and Atmosphere. The complete dependency matrix is documented in the EGV Product Mapping working document maintained for this engagement.

Critical circular dependency: ITRF is simultaneously a consumer of Satellite Orbits (GNSS data must use precise orbits before contributing to ITRF combination) and a prerequisite for Satellite Orbits production (SPOCC uses Helmert transformations anchored to the current ITRF). A sustained failure of this pipeline does not merely degrade Satellite Orbits — it progressively weakens the ITRF itself, cascading to every EGV with a Primary or Important dependency on Global Reference Frames.


Co-Produced EGVs

The same Tier 2–3 processing that generates Satellite Orbits simultaneously produces several additional EGV products as natural computational byproducts. The Tier 3 ACC/SPOCC bottleneck identified later in this document is therefore a multi-EGV resilience gap, not merely a risk to orbit products alone.

EGVLevelMechanism
Station Positions and Variations2AC solutions include station coordinate time series (SPTS) in the same computational step
Integrated Water Vapour (IWV)3 inputTropospheric delay parameters from orbit determination yield IWV directly
Global Ionosphere Maps (GIM)3 inputIonospheric delay estimation during dual-frequency GNSS processing
Earth Orientation Parameters (EOP)3 inputPolar motion and LOD estimated as part of GNSS combination at Tier 3

Governance

InstitutionRoleRisk LevelGovernance Gap
IGS Governing Board (IGB) — incoming Chair: Scott Luthcke (NASA GSFC)Strategic direction and policy authority for the IGS. IAG holds voting membership on the IGB (confirmed by IAG President Richard Gross, May 2026).MediumNo formal multi-stakeholder representation for space agencies or the private sector as governance actors. No single body is formally designated as accountable for supply chain reliability.
IGS Central Bureau (NASA — co-hosted JPL & GSFC)Operational coordination hub; manages station metadata (CBIS)MediumNo formal MoU governing CB hosting at JPL; best-effort institutional arrangement.
IGS Infrastructure CommitteeTechnical standards for tracking network and data flowMediumStandards improvement is reactive — triggered by failure rather than proactive lifecycle management.
GGOS / IAGScientific coordination and EGV framework definitionLowIAG coordinates science through GGOS but holds no formal seat at IGS operational governance. Scientific leadership and operational accountability remain structurally disconnected.
IERSValidates combined orbits against ITRFMediumNo formal SLA monitoring loop reporting validation results back to UN-GGCE or GGOS. Tier 4 is not in the current UN-GGCE risk register.
UN-GGCEAdvocacy for supply chain resilience; reports to UN Statistical Commission/ECOSOCLowCurrently holds observer status only within IGS governance. This limits the UN-GGCE's ability to enforce JDP Objective 1.1 requirements or mandate remediation when SLA thresholds are breached.

Supply Chain

Tier 0 — Data Acquisition and First-Mile Telemetry

Data level: Basis — Geodetic Infrastructure. The global GNSS tracking network (106 of the 107 ITRF Core Sites carry a GNSS receiver, plus 553 standard contributing GNSS sites — 659 GNSS sites total) constitutes the Geodetic Infrastructure Basis EGV. Raw observations become Level 1 EGV (Geodetic Observations) upon ingestion to agreed RINEX standards.

Raw GNSS signals are acquired continuously by physical tracking stations and transmitted via push telemetry to Operational Data Centres (ODCs). The primary ODCs are operated by GFZ (Germany), CNES REGINA (France), and NGS/NOAA (USA).

Accountable institutions for individual tracking sites include national geodetic agencies, research institutions, and universities — among them Geoscience Australia, BKG, IGN, and many others across the 107 ITRF Core Sites (106 of which carry a GNSS receiver) and 553 standard contributing GNSS sites, for 659 GNSS-capable sites overall.[^gnss-site-count] While the site network itself is geographically distributed, responsibility for first-mile delivery is fragmented across these many operators, with coordination managed through the IGS Infrastructure Committee.

The first-mile connection between a physical observatory and its ODC is a known vulnerability. Many Reference Frame stations lack redundant upload paths. If the primary ODC connection fails, data is buffered locally, introducing latency that degrades real-time and ultra-rapid orbital products. Based on official IGS Network Data Flow topologies, all three primary ODCs are located in the northern hemisphere — a geographic concentration that is unaddressed in current operational risk registers but conflicts directly with (Principle 1: Geographic Distribution for Technical Performance). JDP Objective 1.2 requires regional hubs in under-represented regions, particularly the southern hemisphere.

The IGS Central Bureau (CB), co-hosted at NASA (Jet Propulsion Laboratory and Goddard Space Flight Center), USA, is the operational coordinator for the entire pipeline — managing the network, maintaining the Central Bureau Information System (CBIS) for station metadata, and ensuring adherence to IGS standards. CB hosting at JPL rests on no formal MoU; it is a best-effort institutional arrangement. Administrative disruption at JPL would not stop orbit production immediately but would degrade the IGS's capacity to manage station changes, quality issues, and long-term network governance. JDP Objective 1.1 requires a formal hosting agreement. This arrangement is inconsistent with (Principle 3: Centralised Accountability through Multilateral Governance), which requires that critical operational functions be backed by formalised, multilateral agreements rather than institutional goodwill. Key CB personnel are Léo Martire (Director — confirmed as permanent Director 2026-04-16; succession gap resolved) and Robert Khachikyan (Information Systems Manager), who leads the technical management of CBIS, the critical metadata registry.

The IGS Infrastructure Committee (IC) is responsible for standards and coordination of the physical tracking network (Tier 0) and the archiving data flow (Tier 1). IC personnel include Markus Bradke (GFZ, Germany — IC Chair, infrastructure strategy), Ryan Ruddick (Geoscience Australia — IC Vice-Chair, cross-tier coordination), David Maggert (EarthScope, USA — Network Coordinator, Tier 0 observatory network health), Ignacio Romero (ESA/ESOC, Germany — RINEX standards lead, data interoperability), and Patrick Michael (NASA GSFC/CDDIS, USA — IGS Data Center Coordinator and CDDIS Manager). The IC relies on best-effort contributions from these key individuals. Loss of institutional support for any of these roles — for example, a funding change at EarthScope or GFZ — would immediately degrade global capacity to coordinate the raw data pipeline. No succession plans are documented for any IC role.

Risk: Medium — The first-mile connection from observatory to ODC is a known vulnerability; all three primary ODCs are in the northern hemisphere, a geographic concentration that conflicts with (Principle 1: Geographic Distribution for Technical Performance).

Tier Risk Score: 8.00 / 25 — Significant (PPTD Gap: 2.67 × Criticality: 3)
(UN-GGCE Supply Chain Risk Assessment, 2026)

CapabilityPeopleProcessTechnologyDataAvg (NA = 0)Risk
Ground-Based Asset Management3.002.002.003.002.50 ⚠Phase 1
Equipment Calibration and Maintenance4.003.003.002.50 ⚠Phase 2
Network Operations2.002.001.003.002.00 ⚠Phase 2
Tier average2.33

Note on this table: these are the three capabilities that feed Tier 0's PPTD Gap (5 − 2.33 = 2.67, matching the Tier Risk Score above). GNSS, SLR, and DORIS Data Acquisition and Storage are physically first-mile capabilities and belong to this tier operationally, but the score for each is carried on the storage half of the capability, which is scored as an input to Tier 1's Gap instead (GNSS Data Acquisition and Storage appears there). Network Operations is shared between Tier 0 and Tier 1's computations, in the same way Knowledge Management is shared between Tier 2 and Tier 3.

(Source: State of Geodesy 2026, capability-maturity graph as of sog2026-score-revision)


Tier 1 — Global Archiving and Data Hierarchy

Data level: Level 1 EGV (Geodetic Observations) — RINEX files; geo-located time series with geophysical corrections applied, formatted to agreed IGS standards.

Tier 1 is the ingestion and long-term storage layer, structured as a two-level hierarchy. Regional Data Centres (RDCs) — including BKG (Germany), Geoscience Australia, KASI (South Korea), and SOPAC (USA) — act as geographic consolidators that gather data from multiple ODCs within a region. Above them, the three apex repositories — CDDIS (NASA GSFC, USA), IGN (France), and SIO (Scripps, USA) — form the Global Data Centres (GDCs), which mirror data via a continuous equalization protocol, maintaining synchronised archives across three institutions. Accountable personnel include Patrick Michael (NASA GSFC/CDDIS) as Data Center Coordinator and Ignacio Romero (ESA/ESOC) for RINEX interoperability standards, both reporting through the IGS Infrastructure Committee.

The three GDCs run a data equalization protocol that is architecturally designed to provide resilience against a single GDC-site failure: if CDDIS becomes unavailable, Analysis Centres are intended to be able to pull identical data from IGN or SIO. This mechanism has been invoked at least once: in 2007, following a CDDIS hardware fault, the CDDIS manager directed users to the IGN and SIO mirrors by name.[^cddis-2007] However, no deliberate failover drill, disaster-recovery exercise, or business-continuity test of the equalization protocol appears anywhere in the IGS Technical Reports or the IGS mailing list archive, and no documented instance of an Analysis Centre switching from CDDIS to IGN or SIO was found during any of the three confirmed CDDIS-affecting disruptions covered in this assessment (2013, 2018–2019, 2025).[^gdc-failover-search] This is an absence of evidence, not proof that the failover path would fail if invoked — a station-level switch could occur without being reported to the community, and no usage statistics exist anywhere that would allow this to be checked directly.[^gdc-failover-search] But it means the redundancy has not been demonstrated under the disruption conditions this assessment is concerned with, and at least one other GDC has openly reported having no disaster-recovery capability at all.[^bkg-no-dr] There is a critical need for the equalization protocol to be actively tested and for alternative sources to be made known to operational stakeholders, rather than assumed to be available by default. During a U.S. government shutdown, while automated servers may remain active, the lack of manual support means an untested failover path may not function as intended if it is ever needed.

The equalization protocol operates between GDCs. It cannot recover data that was never delivered to the GDC level in the first place. The correct characterisation of the 2018–2019 shutdown evidence is that the system proved resilient to single GDC-site outage (verified by architecture) but not resilient to ODC/RDC-level data gaps caused by upstream institutional disruption. During that shutdown (35 days), NASA GSFC staff furloughs caused some latency and CDDIS access issues for U.S.-operated sources (e.g., NOAA NGS Analysis Centre disruptions). However, because the Analysis Centre Coordinator (ACC) and other international ACs (e.g., ESA, CODE) remained operational, the global combination was successful. (Source: IGS 2018 Technical Report; no IGSMAIL message specific to the Dec 2018–Jan 2019 shutdown was found in the archive.)

A further concentration risk exists at the political level: CDDIS and SIO are both U.S.-hosted institutions. The GDC network spans only two political jurisdictions (USA, France), which conflicts with (Principle 2: Political Resilience and Distributed Operational Control) and JDP Objective 1.2. There is a critical need for more Global Data Centres with synchronised holdings outside the current U.S./France footprint to ensure geographic and political diversity.

Risk: Medium — The GDC equalization protocol is architecturally designed to provide resilience against single-site failure, but this redundancy is unverified: no failover drill or documented switch to IGN/SIO was found in the historical record, and at least one other GDC (BKG) has openly reported having no disaster-recovery capability at all.[^bkg-no-dr] The network also spans only two political jurisdictions. The absence of FAIR-compliant, publicly documented data source registries and of any tested contingency plan conflicts with (Principle 4: Technical Interoperability and Data Accessibility) and (Principle 6: Transparency and Performance Accountability).

Tier Risk Score: 10.80 / 25 — Significant (PPTD Gap: 2.70 × Criticality: 4)
(UN-GGCE Supply Chain Risk Assessment, 2026)
Step Criticality basis: Raised from 3 to 4. The equalization protocol provides real architectural redundancy, but no failover drill or documented switch to IGN/SIO was found in the historical record, and BKG has openly reported having no disaster-recovery capability of its own.[^bkg-no-dr] Untested redundancy is scored as a partial, not full, mitigating pathway.

CapabilityPeopleProcessTechnologyDataAvg (NA = 0)Risk
GNSS Data Acquisition and Storage4.004.003.003.003.50Phase 3
Network Operations2.002.001.003.002.00 ⚠Phase 2
Data Quality Management2.002.001.003.002.00 ⚠Phase 2
Metadata Management2.002.001.003.002.00 ⚠Phase 2
Data Preservation2.002.002.002.002.00 ⚠Phase 2
Tier average2.30

Note on this table: these are the five capabilities that feed Tier 1's PPTD Gap (5 − 2.30 = 2.70, matching the Tier Risk Score above). GNSS Data Acquisition and Storage is listed here rather than at Tier 0 because its score reflects storage/archiving, not first-mile acquisition — see the note on Tier 0's table. Network Operations is shared between the two tiers' computations. The Technology dimension of Network Operations, Data Quality Management, and Metadata Management all score 1.00 — the weakest score anywhere in this tier, reflecting the absence of automated failover, formal monitoring infrastructure, and documented recovery procedures at the GDC/RDC layer.

(Source: State of Geodesy 2026, capability-maturity graph as of sog2026-score-revision)


Tier 2 — Analysis Centres and the Software Ecosystem

Data level: Level 1 → Level 2 (intermediate) — individual AC precise orbit and clock solutions; processed from Level 1 data but not yet combined into the authoritative EGV product.

As registered with the IGS Central Bureau, approximately 12 independent Analysis Centres pull data from the Tier 1 GDC archives and process it to generate independent orbital trajectories and clock corrections. Key Analysis Centres include:

Analysis CentreInstitutionSoftwareMethodology
JPLNASA / Caltech, USAGipsyX (Proprietary)Kalman Filter
CODEUniv. Bern / AIUB, SwitzerlandBerneseBatch Least Squares
ESA/ESOCEuropean Space Agency, GermanyNAPEOSBatch Least Squares
GFZGerman Research Centre for GeosciencesEPOS.P8Batch Least Squares
Wuhan UniversityChinaPANDABatch Least Squares
+ 7 or more othersVariousVariousVarious

While algorithmic diversity across approximately 12 ACs is high, core applications like GipsyX (owned by Caltech) are proprietary and closed-source. This creates a proprietary dependency in Tier 2 — the source code is not available for independent maintenance or inspection. The application is distributed, but the architectural knowledge is not. Algorithmic diversity is encouraged and different software for different regions and purposes is appropriate; however, the closed-source status of GipsyX represents a specific supply chain vulnerability that distinguishes it from the open or published-method tools used by other ACs.

Intermediate solutions produced by individual ACs should be independently archived in accordance with FAIR Principle 4 — ensuring that the authoritative combination at Tier 3 can, in principle, be reconstructed or audited from component parts. This is not currently a documented operational requirement. This gap is directly addressed by (Principle 4: Technical Interoperability and Data Accessibility), which requires FAIR-compliant data practices and verifiable interoperability across all contributing centres.

Knowledge fragility exists across AC teams. These centres are typically led by small specialist groups within academic or research institutions, with no guaranteed funding continuity and no documented succession planning. The retirement or departure of key scientific staff at any major AC could degrade that centre's contribution quality without any formal remediation pathway. (Principle 5: Minimum Capability Maturity Standards) requires that entities on the critical path demonstrate verifiable workforce resilience including documented succession planning before they may be designated as primary providers.

Risk: Medium — Algorithmic diversity across ~12 ACs is a strength, but GipsyX (JPL/Caltech) is proprietary and closed-source; key-person risk exists across AC teams with no documented succession planning.

Tier Risk Score: 8.00 / 25 — Significant (PPTD Gap: 2.67 × Criticality: 3)
(UN-GGCE Supply Chain Risk Assessment, 2026)

CapabilityPeopleProcessTechnologyDataAvg (NA = 0)Risk
GNSS Data Processing and Analysis4.004.003.004.003.75Phase 3
Geodetic Software and Tools2.003.001.002.002.00 ⚠Phase 2
Knowledge Management1.002.001.001.001.25 ⚠Phase 2
Tier average2.33

Note on this table: these are the three capabilities that feed Tier 2's PPTD Gap (5 − 2.33 = 2.67, matching the Tier Risk Score above). Knowledge Management is shared with Tier 3's computation. The Process dimension of GNSS Data Processing and Analysis scores 4.00 at the pipeline level; however, succession planning is not formalised across AC teams. JDP Objective 1.4 directly applies. This baseline of 3.75 is what actually feeds the published Tier Risk Score above — the Satellite-Orbits-specific departure to 3.50 asserted this session for Principle 4 (§1 of the walkthrough) has not been propagated into this tier's Gap calculation.

(Source: State of Geodesy 2026, capability-maturity graph as of sog2026-score-revision)


Tier 3 — EGV Combination — Critical Bottleneck

Data level: Level 2 EGV (Satellite Orbits — GNSS Satellite Orbits, Clocks and Biases/GOCB) — the official, authoritative combined product. This is the boundary at which intermediate AC solutions become the recognised EGV.

The independent orbital solutions from the 12 Analysis Centres are mathematically combined to produce the official Satellite Orbits EGV, distributed as three product types:

ProductLatencyUse Case
Ultra-Rapid≤ 15 minutesReal-time navigation, space weather
Rapid≤ 17 hoursRapid response geodesy, daily EOP
Final12–18 daysITRF combination, science reprocessing

This combination involves two closely related but distinct roles. It is important to distinguish between the many Analysis Centres and the single Analysis Centre Coordinator: there are approximately 12 independent Analysis Centres globally (ESA/ESOC, CODE, JPL, GFZ, Natural Resources Canada, MIT, TU Graz, AIUB, and others), each independently producing its own orbit and clock solution from raw GNSS data. The Analysis Centre Coordinator (ACC) is a single, unique IGS-wide role — there is only one ACC globally — responsible for receiving all individual AC solutions, applying statistical weighting, performing quality control, and running the SPOCC combination software to produce the one authoritative IGS combined product. The ACC manages AC submissions, assigns statistical weights, oversees quality control, and runs the SPOCC software. The ACC role is currently operated by Salim Masoumi (Geoscience Australia) and Tom Herring (MIT) as Co-Leads for daily combination operations. It is transitioning from GA/MIT to GA/NASA GSFC (full operational capability expected late 2025), with the transition managed by Taylor Yates (NASA GSFC). The ACC environment is deployed on AWS (EC2 and S3, multiple geographic regions), providing infrastructure-level resilience. The Software for Precise Orbit and Clock Combination (SPOCC) is a Python-based tool developed by GFZ and deployed by the ACC. SPOCC is a proprietary tool; it is not an open-source community project. The ACC operates SPOCC, but GFZ retains deep architectural knowledge of the software, meaning that a significant software failure or major feature requirement would depend on GFZ expertise to resolve regardless of who is running the combination day-to-day.

Key SPOCC personnel at GFZ are Benjamin Männel (SPOCC Project Lead), Radoslaw Zajdel (orbit combination algorithms), and Ghazal Mansur (clock combination and VCE algorithms).

All decentralised redundancy from Tiers 0–2 converges through this single pipeline. The risk has three distinct components. First, there is no formal backup ACC: no designated successor exists if GA or its partner withdraws. The 2013 ad hoc response involving NRCan and ESA/ESOC demonstrated that a contingency exists in practice, but it has never been formalised, contracted, or rehearsed. Second, proprietary software knowledge is concentrated at GFZ: the ACC operates SPOCC day-to-day, but GFZ holds the deep architectural knowledge. No independent reimplementation exists. A major software failure or significant capability requirement would require GFZ involvement regardless of who is running the combination. This is a software key-person risk, not a software monopoly in the operational sense. Third, the ACC transition reintroduces political risk: moving the ACC back to NASA GSFC (a U.S. civil service centre) reintroduces vulnerability to U.S. federal appropriations lapses. Moving the ACC back to GSFC without a formalised, internationally governed "break-glass" protocol reintroduces a known single point of failure that the GA/MIT structure, hosted outside U.S. federal jurisdiction, had successfully mitigated.

The historical evidence is unambiguous. In the 2013 U.S. Government Shutdown, the ACC (then solely at NOAA/NGS) faced significant administrative disruption. While core IGS products continued through automated scripts and minimal excepted personnel (IGSMAIL-6826), the impact was visible in the governance record: the NGS/ACC was unable to submit its annual report to the technical record for that year. Previous characterisations of an "emergency transfer" to ESA/NRCan have been clarified as a conflation with the unrelated launch of the Real-Time Service. In the 2018–2019 U.S. Government Shutdown (35 days), the ACC (then GA/MIT) remained operationally available because it was hosted outside U.S. federal jurisdiction. While NASA GSFC staff furloughs caused CDDIS access issues and halted submissions from U.S.-funded Analysis Centres (e.g., NGS), the final global orbit products were not degraded. SPOCC successfully generated the orbits using the remaining international Analysis Centres (e.g., ESA, CODE). This proved the decentralised model works when the ACC itself is not compromised. (Source: IGS 2018 Technical Report; no IGSMAIL message specific to the Dec 2018–Jan 2019 shutdown was found in the archive.)

The 2025-2026 period represents the most severe sustained disruption to US-hosted IGS infrastructure since 2018-2019 — and it coincides directly with the ACC transition to NASA GSFC. In January 2025, the Los Angeles wildfires caused a confirmed six-day disruption to data deliveries from JPL (co-host of the IGS Central Bureau) (IGSMAIL-8553). From February 2025 onward, DOGE-related workforce reductions removed approximately 25% of staff at NOAA/NGS (an IGS Analysis Centre), approximately 32% of civil servants at NASA GSFC (which hosts CDDIS — the primary Global Data Centre), and approximately 25% of the total workforce at JPL across four rounds of layoffs. The US government shutdown of 1 October to 12 November 2025 (42 days) furloughed approximately 15,000 NASA civil servants, including GSFC staff sustaining CDDIS and the Space Geodesy Project, during the same period in which the ACC transition to GSFC was under active preparation. No IGS product delivery failure has been attributed to any of these events in the mail archive — consistent with the 2018-2019 pattern in which automated data flows continued even as human oversight capacity degraded — but the administrative impact of the 2025 shutdown specifically will only be visible once the 2025 IGS Technical Report is published. (The 2024 IGS Technical Report was published in May 2025 IGSMAIL-8593; the 2025 report was announced for early 2026 IGSMAIL-8637. JPL wildfire: IGSMAIL-8553/-8555; DOGE workforce reductions: Wired 21 May 2025, Space.com, SpaceNews; Oct–Nov 2025 shutdown: NASA Shutdown Page, Planetary Society 12 Nov 2025.)

A longitudinal review of IGS Technical Reports (2013 and 2018) reveals a persistent pattern of systemic administrative fragility: "No report submitted" entries appear consistently across critical tiers. At Tier 1, SIO, IGN, and KASI consistently failed to submit annual reports in both 2013 and 2018. At Tier 3, critical working groups including Clock Products, Orbit Dynamics, and the foundational Reference Frame Working Group (in 2018) failed to document their activities. This represents a major gap in global network monitoring and is a direct manifestation of low maturity in Network Operations. While the supply chain maintains technical data flow, it lacks the administrative resilience and transparent reporting required for a robust intergovernmental infrastructure — a direct gap against (Principle 6: Transparency and Performance Accountability).

One partial mitigation available to NASA GSFC is the U.S. government's "critical activity" designation: functions formally classified as critical under federal continuity-of-operations rules are exempted from appropriations-lapse shutdowns. If the ACC function at GSFC were to receive this designation, automated operations could continue through a funding lapse. However, this designation has not been confirmed for IGS or ACC functions at GSFC — and the 2013 precedent is instructive: the ACC at NOAA/NGS was not classified as a critical activity and was fully furloughed. Critically, even if the designation were granted, it would remain a unilateral U.S. government decision rather than an internationally governed continuity mechanism, and could be revoked or re-scoped without notice to the international geodetic community. It therefore mitigates but does not resolve the jurisdictional risk.

The NRCan/ESA contingency demonstrated informally in 2013 remains ungoverned. No SLA, MoU, or trigger criteria exist for activating this failover. No regular rehearsal exercises have been conducted. This arrangement directly conflicts with (Principle 2: Political Resilience and Distributed Operational Control) and JDP Objective 1.1. Formalising this contingency and resolving the ACC transition political risk are prerequisites for this tier to meet the standard required by (Principle 3: Centralised Accountability through Multilateral Governance).

Risk: Critical — All decentralised redundancy from Tiers 0–2 converges through this single pipeline. No formal backup ACC exists; SPOCC architectural knowledge is concentrated at GFZ; the ACC transition back to NASA GSFC reintroduces U.S. federal political risk that the GA/MIT structure had successfully mitigated. This tier fails against (Principle 2: Political Resilience), (Principle 3: Centralised Accountability through Multilateral Governance), and (Principle 5: Minimum Capability Maturity Standards) simultaneously.

Tier Risk Score: 18.25 / 25 — High (PPTD Gap: 3.65 × Criticality: 5)
(UN-GGCE Supply Chain Risk Assessment, 2026)
This is the highest tier risk score across all five EGV workflows.

CapabilityPeopleProcessTechnologyDataAvg (NA = 0)Risk
Geodetic Data Products2.003.003.003.002.75 ⚠Phase 3
Performance Management2.002.001.00 ⚠Phase 2
Risk Management1.001.000.50 ⚠Phase 1
Disaster Recovery and Supply Chain Continuity2.002.001.001.25 ⚠Phase 1
Knowledge Management1.002.001.001.001.25 ⚠Phase 2
Tier average1.35

(Source: State of Geodesy 2026, capability-maturity graph as of sog2026-score-revision)

Note on the Avg column: where a dimension is marked "—" (not applicable to that capability, e.g. Risk Management has no distinct Technology or Data practice at supply-chain scale), it is treated as 0 and included in the four-dimension average, per the Tier Risk Score methodology (pptdGap = 5 − straight unweighted 4-dim average, NA = 0). This is a deliberate choice, not an omission: a capability with no applicable Technology or Data dimension at all is treated as having less institutional depth than one scoring 1.0–2.0 across all four, which is the intended, conservative reading for investment prioritisation. Averaging only the applicable dimensions instead would give Performance Management 2.00, Risk Management 1.00, and Disaster Recovery 1.67 — raising the tier average to 1.73 and lowering the Tier Risk Score to 16.35 (still ranked #1, still High, but no longer closer to the Critical threshold). The Tier Risk Score of 18.25 above uses the NA = 0 convention consistently.


Tier 4 — Validation and Distribution

Data level: Level 2 EGV (Satellite Orbits — validated and distributed) — the Satellite Orbits EGV as validated by IERS and distributed through the IGS archive network and NTRIP streams.

Tier 4 represents the terminal stage of the supply chain: independent validation by the International Earth Rotation and Reference Systems Service (IERS) against the current ITRF, followed by public distribution through the IGS archive network and NTRIP streams. Accountable institutions are IERS (multi-agency, coordinated through the IERS Central Bureau at BKG, Germany) and the IGS distribution network partners.

Both validation (IERS) and distribution (IGS) exist and function operationally. However, neither function is governed by formal SLAs, performance targets, or public reporting obligations. Tier 4 does not appear in the current UN-GGCE risk register, which is a gap: if validation is delayed or distribution is degraded, downstream Level 3 EGV pipelines have no formal remediation trigger.

(Principle 6: Transparency and Performance Accountability) and JDP Objective 1.1 require formal SLA-based performance monitoring at Tier 4 with published targets for validation turnaround and distribution uptime; a defined escalation process when targets are not met; and integration of Tier 4 metrics into the GGOS/UN-GGCE performance reporting cycle.

Until this governance is established, Tier 4 represents an unmonitored tail risk — adequate under normal operating conditions but without formal accountability if it degrades.

Risk: Not Currently Governed — Validation and distribution exist operationally but are absent from the UN-GGCE risk register. Neither function is covered by SLAs, performance targets, or a formal accountability mechanism. Tier 4 has no formal home in the current risk governance framework; under (Principle 6: Transparency and Performance Accountability) and JDP Objective 1.1, this tier requires explicit SLA-based monitoring before it can be assessed.

Tier Risk Score: 4.67 / 25 — Minor (PPTD Gap: 2.33 × Criticality: 2)
(UN-GGCE Supply Chain Risk Assessment, 2026)

CapabilityPeopleProcessTechnologyDataAvg (NA = 0)RiskFeeds Gap?
Geodetic Services2.002.002.002.002.00 ⚠Phase 1Yes
Regulatory Compliance3.003.003.003.003.00Phase 3Yes
Standards Development and Promotion3.003.003.003.003.00Phase 3Yes
Tier average2.67
Data Distribution2.002.001.003.002.00Phase 2No

Note on this table: the three "Yes" capabilities feed Tier 4's PPTD Gap (5 − 2.67 = 2.33, matching the Tier Risk Score above). Data Distribution was scored in the June 2026 verification of the capability scores, closing the Tier 4 baseline gap — but it isn't currently included in this tier's Gap computation, despite belonging operationally to Tier 4 (distribution through the IGS archive network and NTRIP streams). No documented reason was found for the exclusion; flagging rather than silently adding it, since including it would raise the tier average to 2.50 and lower the Gap to 2.50 (Risk Score 5.00, still Minor).

(Source: State of Geodesy 2026, capability-maturity graph as of sog2026-score-revision)


Workflow Diagram


JDP Alignment

Pipeline ElementCurrent StateGapJDP Objective
CB hosting at NASA JPLNo MoU; best-effort arrangementSole institutional host with no formal agreement or continuity plan1.1 — SLAs and MoUs for all critical functions
ACC operational agreement (GA + MIT → GA + NASA GSFC)Informal coordination; no SLATwo Co-Leads with no succession plan; transition back to U.S. federal jurisdiction reintroduces political risk1.1 — Formalised long-term operational agreements
NRCan/ESA contingency failover (Tier 3)Theoretical failover path; unrehearsedNot a governed protocol; no trigger criteria, MoU, or rehearsal1.1 — Formal backup agreements
Global Network MonitoringInconsistent administrative reporting across GDCs and Working Groups (2013, 2018)Persistent reporting gap; supply chain blind to silent degradation1.1 — Network Operations and Monitoring maturity
Tier 4 performance monitoringIERS validates operationally; not in risk registerNo SLA-based monitoring, public reporting cycle, or escalation trigger1.1 — Transparent accountability mechanisms
ODC/RDC geographic distribution (Tier 0)All three primary ODCs in northern hemisphereNo southern hemisphere primary archiving path1.2 — Regional hubs in under-represented regions
GDC equalization (Tier 1)Active synchronisation across CDDIS, IGN, SIOCDDIS and SIO both U.S.-hosted; only two political jurisdictions represented1.2 — Political distribution of critical functions
FAIR compliance and ISO Geodetic Register (Tier 1–2)RINEX format widely adoptedInteroperability not formally assessed; ISO Geodetic Register not linked to operational compliance1.2 — FAIR data principles and ISO Geodetic Register
AC software maintenance (Tier 2)Academic teams; no guaranteed funding continuityKey-person risk with no succession or succession funding mechanism1.3 — Formalised national backing for critical capabilities
CB Director — Léo MartireConfirmed permanent Director 2026-04-16Succession gap resolved ✓1.4 — Mandated succession planning
ACC Co-Leads — Masoumi, Herring (Tier 3)No documented succession planTwo individuals accountable for global critical-path combination; no transfer programme1.4 — Continuous knowledge transfer
SPOCC architecture — Männel, Zajdel, Mansur (Tier 3)GFZ institutional knowledge; no formal continuity programmeCore engine understood by ~3 people; no independent reimplementation1.4 — Succession planning for specialised expertise

Stakeholder Accountability Matrix

Key individuals whose departure or institutional disruption would have a direct, immediate impact on supply chain continuity. PPTD scores are proxied from the nearest capability matrix entry. ⚠ = succession gap explicitly flagged.

IndividualInstitutionRoleTierPPrTDSuccession
Léo MartireNASA JPLCB Director — governance, standards, multilateral coordinationAll3213Confirmed permanent 2026-04-16 ✓
Robert KhachikyanNASA JPLCBIS Manager — station metadata registryAll3213Not documented ⚠
Markus BradkeGFZIC Chair — infrastructure strategyT0, T12313Not documented ⚠
Ryan RuddickGeoscience AustraliaIC Vice-Chair — cross-tier coordinationT0, T12313Not documented ⚠
David MaggertEarthScopeIC Network Coordinator — Tier 0 observatory networkT02313Not documented ⚠
Ignacio RomeroESA/ESOCRINEX standards lead — data interoperabilityT0→T12313Not documented ⚠
Patrick MichaelNASA GSFCGDC / CDDIS Coordinator — Tier 1 archiving standardsT12222Not documented ⚠
Salim MasoumiGeoscience AustraliaACC Co-Lead — daily combination operationsT34434Not documented ⚠
Tom HerringMITACC Co-Lead — daily combination operationsT34434Not documented ⚠
Benjamin MännelGFZSPOCC Project LeadT34434Not documented ⚠
Radoslaw ZajdelGFZ / WrocławSPOCC orbit combination algorithmsT34434Not documented ⚠
Ghazal MansurGFZSPOCC clock and VCE algorithmsT34434Not documented ⚠

Geographic concentration note: All twelve individuals are based in the USA, Europe, or Australia. No representation from Africa, Latin America, South or Southeast Asia, or the broader Global South. This directly conflicts with Principle 1 (Geographic Distribution for Technical Performance) and Principle 3 (Centralised Accountability through Multilateral Governance), and limits the political resilience of the accountability structure.

PPTD scores are proxied from the nearest capability matrix entry: GNSS Data Processing and Analysis average 3.75 for T2/T3 roles; Network Operations average 2.25 for T0/T1 roles; Metadata Management average 2.25 for the CB.


Glossary

AcronymFull Name
ACAnalysis Centre
ACCAnalysis Centre Coordinator — combines independent orbit solutions from multiple Analysis Centres into the single official product (Tier 3); distinct from CDDIS, which only archives and distributes data (Tier 1)
BKGFederal Agency for Cartography and Geodesy (Germany)
CBCentral Bureau (IGS)
CBISCentral Bureau Information System
CDDISCrustal Dynamics Data Information System (NASA GSFC, USA) — one of three Global Data Centres that archive and distribute raw and processed data (Tier 1); does not perform combination
CNESCentre National d'Études Spatiales (France)
CODECenter for Orbit Determination in Europe (Switzerland)
EGVEssential Geodetic Variable
ESAEuropean Space Agency
ESOCEuropean Space Operations Centre (ESA, Germany)
GAGeoscience Australia
GDCGlobal Data Centre
GFZGerman Research Centre for Geosciences
GGOSGlobal Geodetic Observing System (IAG)
GNSSGlobal Navigation Satellite System
GSFCGoddard Space Flight Center (NASA, USA)
IAGInternational Association of Geodesy
ICInfrastructure Committee (IGS)
IERSInternational Earth Rotation and Reference Systems Service
IGNInstitut National de l'Information Géographique et Forestière (France)
IGSInternational GNSS Service
ITRFInternational Terrestrial Reference Frame
JPLJet Propulsion Laboratory (NASA / Caltech, USA)
KASIKorea Astronomy and Space Science Institute
MITMassachusetts Institute of Technology (USA)
NASANational Aeronautics and Space Administration (USA)
NGSNational Geodetic Survey (NOAA, USA)
NOAANational Oceanic and Atmospheric Administration (USA)
NRCanNatural Resources Canada
ODCOperational Data Centre
PPTDPeople, Process, Technology, Data
RDCRegional Data Centre
RINEXReceiver Independent Exchange Format
SIOScripps Institution of Oceanography (USA)
SOPACScripps Orbit and Permanent Array Center (USA)
SPOCCSoftware for Precise Orbit and Clock Combination (GFZ)
UN-GGCEUnited Nations Global Geodetic Centre of Excellence

[^sog2026]: United Nations Global Geodetic Centre of Excellence, 2026, State of Geodesy 2026: A Baseline Maturity Assessment, Bonn, Germany, https://www.un.org/globalgeospatial/sites/default/files/2026-05/stateofgeodesy.pdf [^cddis-2007]: International GNSS Service, 2007, IGSMAIL-5600 "CDDIS server down", https://lists.igs.org/pipermail/igsmail/2007/006971.html [^gdc-failover-search]: Search of the IGS Technical Reports (2013, 2018, 2019) and the IGSMAIL pipermail archive (2013, 2018–2019, 2025 date ranges) for failover drills, contingency exercises, and Analysis Centre reports of switching from CDDIS to IGN or SIO during a disruption. None found. No public usage or access statistics exist for CDDIS, IGN, or SIO that would independently confirm whether traffic shifted between centres during any of the three events. [^bkg-no-dr]: International GNSS Service, IGS 2018 Technical Report, pp. 159–160: "A disaster recovery system for the GDC is not installed and not scheduled currently" (BKG Global Data Centre report), https://files.igs.org/pub/resource/technical_reports/2018_techreport.pdf