# DIB Cyber security initiative

**R-2A activity** of project 334 — Securing the DIB: CMMC  
**Program element:** 0305104D8Z — Securing the DIB: CMMC  
**Component:** Defense-Wide · **Budget Activity:** 7  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0305104D8Z/334/a0  
**Parent:** https://hitchintel.com/programs/0305104D8Z

## Summary

This activity requests $17.1M in FY2027, 100% of project 334, up 60% on FY2026. The R-2A exhibit describes it across FY2025–FY2027, including what the FY2027 money is planned to buy.

## What the FY2027 request buys

**FY2027 planned work.** Continue to assess the feasibility and support emerging commercial services, tools, and platforms that provide insights into DIB and DoW supply chain relevant cybersecurity threats and vulnerabilities. Continue to partner with the DIB sector, DoW Components, and other government agencies to demonstrate cost-effective and scalable cybersecurity services that augment and/or enhance existing commercial capabilities and services. Continue with FY 2026 base initiatives. Begin the CMMC Phase 2 implementation, focusing on CMMC third party assessment organizations (C3PAO) certification assessments. Continue to sustain and enhance CMMC eMASS (on NIPR), the Dow's enterprise tool to support CMMC assessment management needs and metrics tracking. Develop and deploy a SIPR CMMC eMASS instantiation, to include integrating and using cross domain solutions. Continue to revise the CMMC requirements as required to incorporate changes to NIST cybersecurity guidelines. Continue efforts to integrate CMMC eMASS with the Suppliers Performance Risk System (SPRS). Continue to develop and promote short training videos and other training material to clarify key aspects of the CMMC program implementation. Expand training as required to incorporate the 32 CFR and 48 CFR changes.

**FY2026 to FY2027 change.** Increase in FY 2027 request is due to level setting of funding due to increased DIB requirements.

## Before the request year

**FY2026 plans — current year.** Amend publication of 32 Code of Federal Regulations (CFR) CMMC program rule to incorporate latest revision to National Institute of Standards and Technology (NIST) cybersecurity guidelines. Continue FY 2025 base program initiatives. Phased CMMC program implementation in FY 2026 will result in additional initiatives. Update the CMMC Enterprise Mission Assurance Support Service (eMASS) database on non-secure internet protocol router (NIPR) and finalize initial develop and deploy a secure internet protocol router (SIPR) instantiation, to include integrating and using cross-domain solutions. Analyze and track CMMC performance metrics to ensure effective program management and identify potential operational impacts to the CMMC ecosystem. Partner with the military departments and other agencies and their initiatives to improve DIB CS.

**FY2025 accomplishments.** FY 2025 plans continue base program initiatives from the prior budget year. Additional initiatives are due to anticipated CMMC program transition to operational status in FY 2025, resulting in program scope change. - Operationalize the CMMC eMASS infrastructure. - Manage and update the CMMC eMASS database. - Update the CMMC requirements to remain in sync with the National Institute of Standards and Technology standards. - Initiate the CMMC performance metrics collection. - Partnerships on new and existing DoD initiatives and pilots to enhance DIB cybersecurity.

## Funding

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 15.0 |
| FY2026 | Enacted | 10.7 |
| FY2027 | Request | 17.1 |

> Prior, current and budget year only — an R-2A activity carries no five-year plan. It sums exactly into its project in the request year and not necessarily in any other.

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibit R-2A, PE 0305104D8Z project 334 (PB PB2027). Narrative is the government's own text.
- **No marks, no contractors at this grain** — congressional marks land on the program element and R-3 performers on the project.
- **MCP:** `mcp.hitchintel.com` — `budget_get_activity`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*