RDT&E Program Element · President's Budget PB2027

Insider Threat

PE 0305327N·U.S. Navy·Approp. 1319 — RDT&E·BA6 — RDT&E Management Support
FY2027 Request
$2.2M
Navy · RDT&E
HitchAI read

U.S. Navy funding falls 17% to a $2.2M request in FY2027, sustained across the five-year plan. In the FY2027 defense authorization, the House funded it in full; the Senate funded it in full; House appropriators funded it in full.

FY2027 Request
$2.2M
▼ 17% vs FY2026
FY2026 Enacted
$2.7M
▼ 9.1% vs FY2025
FY2025 Actual
$2.9M
Prior year

For fiscal year 2027, the U.S. Navy is requesting $2.2M for Insider Threat under RDT&E program element 0305327N, down 17% from FY2026.

Funding trajectory

Funding profile, FY2025–FY2031

Prior years are actuals, the budget year is the request, and the outyears are the FYDP plan. Estimate types are colored and never summed into one figure.

02.9FY25ACTUAL2.7FY26ENACTED2.2FY27REQUEST2.3FY282.3FY292.4FY302.4FY31
Actual Enacted Request Outyear (FYDP)
Fiscal YearEstimate TypeAmount ($M)
FY2025Actual2.9
FY2026Enacted2.7
FY2027Request2.2
FY2028Outyear2.3
FY2029Outyear2.3
FY2030Outyear2.4
FY2031Outyear2.4
Where it sits

Acquisition lifecycle

This program is funded in RDT&E Budget Activity 6 — RDT&E Management Support.

Complete
Research
BA 1–2
Complete
Advanced Technology
BA 3
Complete
Prototyping
BA 4
Current
Development & Fielding
BA 5–7
Inside the program element

1 project rolls up into PE 0305327N

Projects are the summable leaves — the PE total is their sum, never added to it. Program elements and projects carry the full five-year plan; activities stop at the budget year. This PE moves -17% overall, which can hide much larger swings below.

Project 3442

Insider Threat

$2.2MFY2027 request ▼ 17%
FY2025 actual$2.9M
FY2026 enacted$2.7M
FY2027 request$2.2M

Executive Order 13587 and the National Insider Threat Policy mandate all United States Government departments and agencies to implement insider threat programs that monitor user activity on all classified networks and provide an insider threat analytical and response capability. The Counter Insider Threat Capability (CITC) is the Department of the Navy's implementation of this requirement. CITC's mission is to prevent, deter, detect, and respond to the threat from witting and unwitting insiders. The Platform for Risk Evaluation and Engagement to Neutralize Threat (PREVENT) is the materiel solution required to support the CITC mission and consists of two parts: (1) User Activity Monitoring (UAM), which monitors user activity on classified Navy networks, and (2) an Integrated Tool Suite (ITS), which provides the Information Technology platform for the analytic and response capabilities. The PREVENT system provides the technology required by the Navy Insider Threat Analytic Hub to comply with the National mandates and to protect Navy data, equipment, and personnel from insider threats. RDT&E,N funding is required to develop future, long-term, capability; integrate; and perform testing and evaluation of this capability.

Accomplishments / planned programs (R-2A) — prior, current and budget year only
Counter Insider Threat Capability (CITC)▼ 17%
FY2025 actual$2.9M
FY2026 enacted$2.7M
FY2027 request$2.2M

FY2027 planned work - Continue testing of Integrated Tool Suite (ITS) major upgrades to current ITS solution. - Continue testing and evaluation of UAM and ITS capability on JWICS and SIPRNet. - Continue assessment and accreditation efforts of Platform for Risk Evaluation and Engagement to Neutralize Threat (PREVENT) capability in on NCE cloud broker environment. - Continue testing of User Activity Monitoring (UAM) major upgrades to current UAM solution including testing across multiple networks with existing UAM capabilities and cloud environment. - Continue testing, evaluation, and integration efforts on Secret Internet Protocol Router Network (SIPRNet) afloat networks (CANES). - Continue research…

FY2026 to FY2027 change Funding: The FY27 budget control decrease of $0.439M is attributed to efficiencies realized following the identification of essential Cloud environment services for FY27.

FY2026 plans — current year - Continue testing of Integrated Tool Suite (ITS) major upgrades to current ITS solution. - Continue testing and evaluation of UAM and ITS capability on JWICS and SIPRNet. - Continue assessment and accreditation efforts of Platform for Risk Evaluation and Engagement to Neutralize Threat (PREVENT) capability in on NCE cloud broker environment. - Continue testing of User Activity Monitoring (UAM) major upgrades to current UAM solution including testing across multiple networks with existing UAM capabilities and cloud environment. - Continue testing, evaluation, and integration efforts on Secret Internet Protocol Router Network (SIPRNet) afloat networks (CANES). - Continue research…

Congressional action

Congressional marks

Committee marks on the FY2027 request. Adds and cuts are reconciled in conference before they become law.

RequestPresident's Budget
$2.2M
House NDAA (HASC)HASC
$2.2M full · +$0
Senate NDAA (SASC)SASC
$2.2M full · +$0
House Approps (HAC-D)HAC_D
$2.2M full · +$0
unresolved as of 2026-07-27. These are FY2027 authorization marks (NDAA); appropriations and the conference agreement may differ.
Program detail

Mission & acquisition strategy

Executive Order 13587 and the National Insider Threat Policy mandate all United States Government departments and agencies to implement insider threat programs that monitor user activity on all classified networks and provide an insider threat analytical and response capability. The Counter Insider Threat Capability (CITC) is the Department of the Navy's implementation of this requirement. CITC's mission is to prevent, deter, detect, and respond to the threat from witting and unwitting insiders.

Project 3442 — Insider Threat
Ask Hitch

Ask this program element

Answers are generated from the figures on this page — the FY2027 justification exhibits and the marks tracked above — and nothing else is consulted. Confirm any figure against the cited exhibit before you use it externally.

H
Questions this page can answer
How does the FY2027 request compare with FY2026, and what does the five-year plan show?What did the FY2027 NDAA committees do to this request?In plain terms, what is this program element for and how is it being acquired?

This page carries the budget justification and the NDAA marks — nothing else. For what a contractor has actually been obligated, the ledger is at hitchintel.com/vendors; for live solicitations, hitchintel.com/opportunities. Both are member surfaces.

Provenance

Cite this page

Sources
FY2027 Department of the Navy RDT&E Budget Justification · Exhibits R-2 / R-3 · PE 0305327N (President's Budget PB2027) — and FY2027 NDAA committee marks, as tracked 2026-07-27.
Suggested citation
HitchAI, "Insider Threat (PE 0305327N)," federal budget intelligence, PB2027 vintage. hitchintel.com/programs/0305327N
Machine access
Markdown twin /programs/0305327N.md · MCP mcp.hitchintel.combudget_get_program_element, budget_get_cong_marks