What the FY2027 request buys
Verbatim from the R-2A exhibit for project 334 of PE 0305104D8Z. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.
Continue to assess the feasibility and support emerging commercial services, tools, and platforms that provide insights into DIB and DoW supply chain relevant cybersecurity threats and vulnerabilities. Continue to partner with the DIB sector, DoW Components, and other government agencies to demonstrate cost-effective and scalable cybersecurity services that augment and/or enhance existing commercial capabilities and services. Continue with FY 2026 base initiatives. Begin the CMMC Phase 2 implementation, focusing on CMMC third party assessment organizations (C3PAO) certification assessments. Continue to sustain and enhance CMMC eMASS (on NIPR), the Dow's enterprise tool to support CMMC assessment management needs and metrics tracking. Develop and deploy a SIPR CMMC eMASS instantiation, to include integrating and using cross domain solutions. Continue to revise the CMMC requirements as required to incorporate changes to NIST cybersecurity guidelines. Continue efforts to integrate CMMC eMASS with the Suppliers Performance Risk System (SPRS). Continue to develop and promote short training videos and other training material to clarify key aspects of the CMMC program implementation. Expand training as required to incorporate the 32 CFR and 48 CFR changes.
Increase in FY 2027 request is due to level setting of funding due to increased DIB requirements.
FY2025–FY2026: what came before
Prior-year accomplishments and current-year plans from the same exhibit. Context for the FY2027 plan, not a series — an activity partitions its project exactly in the request year, but can under-cover it in earlier years.
Amend publication of 32 Code of Federal Regulations (CFR) CMMC program rule to incorporate latest revision to National Institute of Standards and Technology (NIST) cybersecurity guidelines. Continue FY 2025 base program initiatives. Phased CMMC program implementation in FY 2026 will result in additional initiatives. Update the CMMC Enterprise Mission Assurance Support Service (eMASS) database on non-secure internet protocol router (NIPR) and finalize initial develop and deploy a secure internet protocol router (SIPR) instantiation, to include integrating and using cross-domain solutions. Analyze and track CMMC performance metrics to ensure effective program management and identify potential operational impacts to the CMMC ecosystem. Partner with the military departments and other agencies and their initiatives to improve DIB CS.
FY 2025 plans continue base program initiatives from the prior budget year. Additional initiatives are due to anticipated CMMC program transition to operational status in FY 2025, resulting in program scope change. - Operationalize the CMMC eMASS infrastructure. - Manage and update the CMMC eMASS database. - Update the CMMC requirements to remain in sync with the National Institute of Standards and Technology standards. - Initiate the CMMC performance metrics collection. - Partnerships on new and existing DoD initiatives and pilots to enhance DIB cybersecurity.
Three years, and no five-year plan
An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.
| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 15.0 |
| FY2026 | Enacted | 10.7 |
| FY2027 | Request | 17.1 |
This activity is 100% of project 334's FY2027 request and 100% of PE 0305104D8Z's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.
1 activity in project 334
Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the program-element page.