# Project CY50W1 — Cyber Weapons/Tools

**Program element:** 0306250JCY — Cyber Operations Technology Support  
**Project:** CY50W1  
**Component:** Defense-Wide  
**Appropriation:** 0400 — RDT&E, Defense-Wide  
**Budget Activity:** 7 — Operational System Development  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0306250JCY/CY50W1  
**Parent:** https://hitchintel.com/programs/0306250JCY

## Summary

Project CY50W1 — Cyber Weapons/Tools requests $192.8M in FY2027, 15% of the $1.30B requested for program element 0306250JCY, up 0.7% on FY2026. 5 R-2A activities decompose the request.

## Funding profile

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 271.8 |
| FY2026 | Enacted | 191.4 |
| FY2027 | Request | 192.8 |
| FY2028 | Outyear | 233.6 |
| FY2029 | Outyear | 239.5 |
| FY2030 | Outyear | 253.9 |
| FY2031 | Outyear | 259.0 |

> Estimate types are not summed. This project is one leaf of PE 0306250JCY; the PE total is the sum of its projects, never added to them.

## What project CY50W1 buys

The Cyber Weapons and Tools portfolio funds and directs the development of tailored software and hardware capabilities that enable United States Cyber Command (USCYBERCOM) personnel to gain access to, and deliver effects against, key foreign adversary cyberspace systems at enterprise scale while operating under the strategy of persistent engagement. The portfolio provides the means to: • Acquire or develop new payloads, including implants, exploits, and other effect generating components • Architect and implement Joint Common Services that automate and scale intelligence driven cyber operations • Test, adapt, and harden payloads and Joint Common Services in response to rapidly evolving cyberspace environments and adversary threat behaviors • Maintain and advance a Joint Development Environment (JDE) for cyber weapons and tools across multiple security levels and geographic locations • Provide programmatic and technical support to ensure sustained capability development and integration These activities are interdependent and require continuous integration to ensure cyber weapons, tools, and services remain synchronized, scalable, and operationally relevant. The portfolio’s investments collectively enable USCYBERCOM to deliver timely, precise, and persistent cyberspace effects in support of national objectives.

**R-3 lines of work:** Product Development.

## Activities (R-2A) — 5

| Activity | FY2025 | FY2026 | FY2027 | Move | Page |
|---|---|---|---|---|---|
| Cyber Weapon Payloads (e.g., implants, exploits, and associated modules) | 127.0 | 98.6 | 134.0 | +36% | [a0](https://hitchintel.com/programs/0306250JCY/CY50W1/a0) |
| Joint Development Environment (e.g., build, manage, and test both payload and common services) | 61.2 | 56.5 | 53.1 | −6% | [a2](https://hitchintel.com/programs/0306250JCY/CY50W1/a2) |
| Joint Cyber Weapons Common Services | 59.3 | 36.3 | 5.6 | −84% | — |
| Data Management | 3.8 | — | — | — | — |
| Cyber Weapons Tools/Hard Targets | 20.4 | — | — | — | — |

> Activities carry the prior, current and budget year only — no five-year plan. In the request year they partition this project exactly; in earlier years they can under-cover it.

### Cyber Weapon Payloads (e.g., implants, exploits, and associated modules)

$134.011M in FY 2027 funding enables the Cyber Weapon Payloads program to expand the scale and scope of payload development to gain new accesses while maintaining existing accesses to critical adversary systems. Integration of hundreds of classified capabilities into Joint Cyber Weapons Common Services will continue, increasing the…

Full year-by-year narrative: https://hitchintel.com/programs/0306250JCY/CY50W1/a0

### Joint Development Environment (e.g., build, manage, and test both payload and common services)

In FY 2027, $53.120M will enable the JDE program to continue supporting approximately 2,500 users across the JDE U and JDE TS environments. The program will maintain connectivity and interoperability across existing environments to ensure timely capability deliveries to the Cyber Mission Force.

Full year-by-year narrative: https://hitchintel.com/programs/0306250JCY/CY50W1/a2

### Joint Cyber Weapons Common Services

**FY2027 planned work.** In FY 2027, $5.633M will enable the Joint Cyber Weapons Common Services program to conduct minimal updates to existing mission applications, focusing on select critical operational needs required to gain and maintain persistent access to adversary systems. Efforts will prioritize sustainment and targeted enhancements rather than broad modernization.

**FY2026 to FY2027 change.** The decrease from reflects Department level prioritization decisions that shift resources toward higher priority mission areas. As a result, the Joint Cyber Weapons Common Services program will focus on sustaining essential capabilities and addressing only the most critical operational requirements.

**FY2026 plans — current year.** In FY 2026, the $36.280M enables the Joint Cyber Weapons Common Services program to deliver mission critical updates to the existing twenty-two mission applications that support infrastructure orchestration, access generation, and data analytics for targeting. The program will also execute a science and technology transfer through a partnership with the Defense Advanced Research Projects Agency to transition prototypes that enhance mission planning and coordination.

**FY2025 accomplishments.** Funding for Joint Cyber Weapons Common Services continues to improve on its prior services but expands the capabilities incorporating new data and analytics providing for improved protection of offensive capabilities and increased capacity for intelligence-based targeting. The focus will be on new and expanded Common Services that provide increased capability on technical transfer of prototypes emerging from S&T efforts in this area.

### Data Management

**FY2025 accomplishments.** Continued expansion of Gap analysis (developing a risk informed Integrated Priority List); Risk analysis, Statistical evaluation of risk – Scope, Assemble, Score, Relate and Enforce (SASR-E), the methodology for conducting threat and terrain informed analysis in support of DOD’s Vulnerability Management (VM) efforts and Mission Relevant Terrain-Cyber (MRT-C) decomposition. CNMF Data and Analytics will continue to select commercial data tool license(s) and evaluate/adopt new tools to add options for CNMF analytic and technical team members for unclassified and classified applications.

### Cyber Weapons Tools/Hard Targets

**FY2025 accomplishments.** Funding will prepare skill sets, facilities, infrastructure and processes to begin planning and positioning to implement acquisition materials and processes to integrate, develop, and sustain HTPMO’s unique services and capabilities. This funding will also support labor and materials to enable the planning for new and operational services to be leveraged by Combatant Commanders. By the end of FY 2025, the Strategic Capabilities Office (SCO) and the Defense Advanced Research Projects Agency (DARPA) will each transition one program, which will need to be integrated, operationalized, and continuously maintained for use by USCYBERCOM. Additional efforts include the transition of future capability increments from DARPA, as well as additional capabilities from other external partners.

## What is NOT on this page

Congressional marks, the R-2 mission description and acquisition strategy, the industry vs government split of the whole request, and related program elements are recorded at **program-element** grain — an NDAA mark lands on a PE, never on a project. They are at https://hitchintel.com/programs/0306250JCY.

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibits R-2/R-2A/R-3, PE 0306250JCY project CY50W1 (PB PB2027).
- **MCP:** `mcp.hitchintel.com` — `budget_get_program_element(pe="0306250JCY")`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*