R-2A Activity · President's Budget PB2027

DIB Cyber security initiative

Activity a0·Project 334 — Securing the DIB: CMMC·PE 0305104D8Z·Defense-Wide
FY2027 Request
$17.1M
▲ 60% vs FY2026
HitchAI read

This activity requests $17.1M in FY2027, 100% of project 334, up 60% on FY2026. The R-2A exhibit describes it across FY2025–FY2027, including what the FY2027 money is planned to buy.

FY2027 Request
$17.1M
▲ 60% vs FY2026
FY2026 Enacted
$10.7M
▼ 29% vs FY2025
FY2025 Actual
$15.0M
Prior year
Planned work

What the FY2027 request buys

Verbatim from the R-2A exhibit for project 334 of PE 0305104D8Z. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.

FY2027 planned work

Continue to assess the feasibility and support emerging commercial services, tools, and platforms that provide insights into DIB and DoW supply chain relevant cybersecurity threats and vulnerabilities. Continue to partner with the DIB sector, DoW Components, and other government agencies to demonstrate cost-effective and scalable cybersecurity services that augment and/or enhance existing commercial capabilities and services. Continue with FY 2026 base initiatives. Begin the CMMC Phase 2 implementation, focusing on CMMC third party assessment organizations (C3PAO) certification assessments. Continue to sustain and enhance CMMC eMASS (on NIPR), the Dow's enterprise tool to support CMMC assessment management needs and metrics tracking. Develop and deploy a SIPR CMMC eMASS instantiation, to include integrating and using cross domain solutions. Continue to revise the CMMC requirements as required to incorporate changes to NIST cybersecurity guidelines. Continue efforts to integrate CMMC eMASS with the Suppliers Performance Risk System (SPRS). Continue to develop and promote short training videos and other training material to clarify key aspects of the CMMC program implementation. Expand training as required to incorporate the 32 CFR and 48 CFR changes.

FY2026 to FY2027 change

Increase in FY 2027 request is due to level setting of funding due to increased DIB requirements.

Before the request year

FY2025–FY2026: what came before

Prior-year accomplishments and current-year plans from the same exhibit. Context for the FY2027 plan, not a series — an activity partitions its project exactly in the request year, but can under-cover it in earlier years.

FY2026 plans — current year

Amend publication of 32 Code of Federal Regulations (CFR) CMMC program rule to incorporate latest revision to National Institute of Standards and Technology (NIST) cybersecurity guidelines. Continue FY 2025 base program initiatives. Phased CMMC program implementation in FY 2026 will result in additional initiatives. Update the CMMC Enterprise Mission Assurance Support Service (eMASS) database on non-secure internet protocol router (NIPR) and finalize initial develop and deploy a secure internet protocol router (SIPR) instantiation, to include integrating and using cross-domain solutions. Analyze and track CMMC performance metrics to ensure effective program management and identify potential operational impacts to the CMMC ecosystem. Partner with the military departments and other agencies and their initiatives to improve DIB CS.

FY2025 accomplishments

FY 2025 plans continue base program initiatives from the prior budget year. Additional initiatives are due to anticipated CMMC program transition to operational status in FY 2025, resulting in program scope change. - Operationalize the CMMC eMASS infrastructure. - Manage and update the CMMC eMASS database. - Update the CMMC requirements to remain in sync with the National Institute of Standards and Technology standards. - Initiate the CMMC performance metrics collection. - Partnerships on new and existing DoD initiatives and pilots to enhance DIB cybersecurity.

Money

Three years, and no five-year plan

An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.

015.0FY25ACTUAL10.7FY26ENACTED17.1FY27REQUEST
Actual Enacted Request
Fiscal YearEstimate TypeAmount ($M)
FY2025Actual15.0
FY2026Enacted10.7
FY2027Request17.1

This activity is 100% of project 334's FY2027 request and 100% of PE 0305104D8Z's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.

Where this sits

1 activity in project 334

Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the program-element page.

DIB Cyber security initiative — this activity$17.1M ▲ 60%
Source
FY2027 Office of the Secretary of Defense RDT&E Budget Justification · Exhibit R-2A · PE 0305104D8Z, project 334 (President's Budget PB2027). Congressional marks are recorded on the program element, never on an activity.
Machine access
Markdown twin /programs/0305104D8Z/334/a0.md · MCP mcp.hitchintel.combudget_get_activity