What the FY2027 request buys
Verbatim from the R-2A exhibit for project IA3 of PE 0303140K. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.
Public Key Infrastructure: RDT&E funding will continue integration testing of key PKI Technical Capabilities as directed/mandated by the DoW CIO for continued evolution of the DoW PKI Infrastructure Cryptographic Algorithm. Additional funding will continue PKI Modernization Development, Integration, Performance. Funds will also support critical Cryptographic Modernization (Algorithm Evolution) to transition the DoW PKI to stronger cryptographic algorithms (RSA 3072/4096 and SHA-384) by the 2027 deadline, ensuring compliance with NSA standards and enhanced security. This involves building and testing the infrastructure to support these new algorithms across various environments (Development, O&M, test, and production). This will include investigating alternative PKI solutions. PKI Modernization (Hybrid Cloud Platform): RDT&E Funds will continue migration efforts and associated Test and Evaluation Efforts required to migrate the DoW PKI to a hybrid cloud environment, addressing emerging requirements (like Global Gray and SIPR mobile credentialing) and reducing operational costs. This includes testing the platform with the NSA, updating PKI policies, and migrating existing systems to the new modernized platform. The current infrastructure only supports sustainment and lacks the flexibility for modernization. DoW PKI Public Trust: RDT&E Funds will continue Sustainment of a Public Trust Certificate Authority, enabling automated issuance and renewal of publicly trusted TLS certificates for DoW and Federal Government systems. This will ensure that visitors trust the confidentiality of their communications with these systems without requiring government-specific trust chains.
The increase of +$10.065 million from FY 2026 to FY 2027 is attributed to increased RDT&E requirements for continued requirements to align with the Department of War's (DoW) Strategic Objectives for modernizing its Cryptographic Infrastructure. Increase is also attributed to continued PKI Modernization Efforts that will provide a Hybrid Cloud Environment that provides automation and migrates remaining Legacy PKI Infrastructure to the Hybrid Cloud. Funding enables alignment to Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) timelines and Zero Trust alignment efforts.
FY2025–FY2026: what came before
Prior-year accomplishments and current-year plans from the same exhibit. Context for the FY2027 plan, not a series — an activity partitions its project exactly in the request year, but can under-cover it in earlier years.
Public Key Infrastructure: RDT&E funding will support integration testing of key PKI Technical Capabilities as directed/mandated by the DoW CIO for continued evolution of the DoW PKI Infrastructure Cryptographic Algorithm. Additional funding will continue PKI Modernization Development, Integration, Performance. Cryptographic Modernization (Algorithm Evolution): Funding is needed to transition the DoW PKI to stronger cryptographic algorithms (RSA 3072/4096 and SHA-384) by the 2027 deadline, ensuring compliance with NSA standards and enhanced security. This involves building and testing the infrastructure to support these new algorithms across various environments (Development, O&M, test, and production). PKI Modernization (Hybrid Cloud Platform): RDT&E is required to migrate the DoW PKI to a hybrid cloud environment, addressing emerging requirements (like Global Gray and SIPR mobile credentialing) and reducing operational costs. This includes testing the platform with the NSA, updating PKI policies, and migrating existing systems to the new modernized platform. The current infrastructure only supports sustainment and lacks the flexibility for modernization. DoW PKI Public Trust: Funding will establish and sustain a Public Trust Certificate Authority, enabling automated issuance and renewal of publicly trusted TLS certificates for DoW and Federal Government systems. This will ensure that visitors trust the confidentiality of their communications with these systems without requiring government-specific trust chains.
RDT&E funding for the DoD PKI directly supports the requirements/mandate from DoD CIO that the DoD PKI infrastructure Cryptographic Algorithm had to change from (RSA)-2048 to 3072- and 4098-bit algorithm by December 2027. Not only is this requirement for the entire DoD to transition to these stronger Algorithms, but the PKI PMO is responsible for creating the entire infrastructure that the DoD will leverage. This funding supports the procurement, building, testing and evaluation of the Algorithms Evolution (AE) capability for production. DISA will stand up and procure Certificate Authorities for test and evaluation on the SIPRNet to include leveraging the Online Certificate Status Protocol Capabilities and perform token testing to ensure that the DoD Tokens are interoperable with the 4K CA's.
Three years, and no five-year plan
An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.
| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 6.9 |
| FY2026 | Enacted | 19.7 |
| FY2027 | Request | 29.8 |
This activity is 89% of project IA3's FY2027 request and 89% of PE 0303140K's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.
4 activities in project IA3
Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the program-element page.