What the FY2027 request buys
Verbatim from the R-2A exhibit for project 677824 of PE 0208088F. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.
• Will continue to develop and execute a phased integration of identified DCO systems into the IDCS ecosystem, prioritizing systems with the highest operational impact and lowest integration complexity. • Will continue to develop, test, and deploy cloud-based threat hunting and deception capabilities within the IDCS environment, including the implementation of honeypots, decoy systems, and automated threat intelligence feeds. • Will continue to research and assess interfaces and data exchange requirements for full integration with ABMS/JCWA. Will develop, test, and implement necessary interface adapters and data transformation processes. • Will continue to develop, test, and implement an advanced analytics platform within the Integrated Defensive Cyberspace System (IDCS) environment, capable of processing and analyzing large volumes of data to identify trends, patterns, and anomalies. Will deploy initial analytics dashboards. • Will continue to develop and deploy a federated query mechanism that allows users to query data across all endpoint Local Tactical Access Controller (LTAC) instances, while maintaining data security and access control. • Will continue to develop, test, and implement decentralized data retention that allows tactical edge platforms to retain critical Defensive Cyberspace Operations (DCO) data locally, ensuring continued operations in disconnected or degraded network environments. • Will continue to develop, configure, and integration test a DCO System Integration Lab environment. • Will continue to develop and implement automated Continuous Integration/Continuous Deployment (CI/CD) pipelines for IDCS, enabling the rapid deployment of 95% of patches and security updates, minimizing operational disruption and increasing system cyber readiness. • Will continue to integrate and exercise Development, Security, and Operations (DevSecOps) framework across the cyber test squadrons, including automated security testing and vulnerability management.
The decrease from FY2026 to FY2027 is due to acceleration of autonomous recovery requirements in FY2026, completion of Firestarter requirements, and re-phasing of DCO requirements to align with DAF cyber priorities.
FY2026: the year under way
Prior-year accomplishments and current-year plans from the same exhibit. Context for the FY2027 plan, not a series — an activity partitions its project exactly in the request year, but can under-cover it in earlier years.
• Develop and execute a phased integration of identified Defensive Cyberspace Operations systems into the IDCS ecosystem, prioritizing systems with the highest operational impact and lowest integration complexity. • Develop, test, and deploy cloud-based threat hunting and deception capabilities within the IDCS environment, including the implementation of honeypots, decoy systems, and automated threat intelligence feeds. • Research and assess interfaces and data exchange requirements for full integration with Air Battle Management System/Joint Cyber Warfighting Architecture (ABMS/JCWA). Will develop, test, and implement necessary interface adapters and data transformation processes. • Develop, test, and implement an advanced analytics platform within the Integrated Defensive Cyberspace System (IDCS) environment, capable of processing and analyzing large volumes of data to identify trends, patterns, and anomalies. Will deploy initial analytics dashboards. • Develop and deploy a federated query mechanism that allows users to query data across all endpoint Local Tactical Access Controller (LTAC) instances, while maintaining data security and access control. • Develop, test, and implement decentralized data retention that allows tactical edge platforms to retain critical Defensive Cyberspace Operations (DCO) data locally, ensuring continued operations in disconnected or degraded network environments. • Develop, configure, and integration test a DCO System Integration Lab environment. • Develop and implement automated Continuous Integration/Continuous Deployment (CI/CD) pipelines for IDCS, enabling the rapid deployment of 95% of patches and security updates, minimizing operational disruption and increasing system cyber readiness. • Integrate and exercise Development, Security, and Operations (DevSecOps) framework across the cyber test squadrons, including automated security testing and vulnerability management.
Three years, and no five-year plan
An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.
| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 75.3 |
| FY2026 | Enacted | 84.0 |
| FY2027 | Request | 76.8 |
This activity is 100% of project 677824's FY2027 request and 100% of PE 0208088F's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.
1 activity in project 677824
Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the project page.