What project MC11 buys
Sustain the Department of Defense Instruction (DoDI) 8510.01 Risk Management Framework (RMF) for Department of War (DoW) Information Technology (IT) requirement for the MDA and conduct Security Control Assessments (SCA) activities, analysis of validation results, risk assessments, and reviews of proposed Program Manager/Information System Security Manager (PM/ISSM) Plans of Action and Milestones (POA&M) for the Missile Defense Agency (MDA) Ground Sensors mission and support systems. It also includes support for external cybersecurity assessments and penetration testing of the Ground Sensors mission systems, both in laboratory developmental testing and during ground test activities, in accordance with Director, Operational Test and Evaluation directives and the Integrated Master Test Plan. It maintains the Assessment and Authorization (A&A) data repository, capturing the RMF documentation (artifacts, validation results, Cybersecurity Risk Assessment results, cybersecurity scorecard, and Authorizing Official (AO) authorization decisions) and POA&M for all MDA information systems. It positions Ground Sensors assets to complete the transition to National Institute of Standards and Technology Special Publication 800-53 Revision 5 requirements (i.e. RMF 2.0) once DoW requirements and timelines are finalized. This project supports aligning, developing, and implementing an integrated Tier 2 Cyber Security Service Provider (CSSP) capability on the Ground Sensors mission systems under the DoW Cybersecurity Discipline Implementation Plan and DoDI 8530.01 Cybersecurity Activities Support to DoW Information Network Operations. Provides the monitoring, prioritization, and tracking of Cybersecurity mitigation detailed in Information Technology security POA&Ms. The activities include preparation of A&A documentation and accreditation recommendations to the MDA Senior Information Security Officer/SCA and AO. Independent Verification and Validation team actions ensure the availability, integrity, authentication, confidentiality, and non-repudiation of the MDA mission, test, and administrative systems. These activities are necessary to comply with the Federal Information Security Management Act.
- Product Development
- Support
Project MC11 funding, FY2025–FY2031
Prior years are actuals, the budget year is the request, and the outyears are the FYDP plan. Estimate types are colored and never summed into one figure. Projects carry the full five-year plan; the activities inside them stop at the budget year.
| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 18.8 |
| FY2026 | Enacted | 18.3 |
| FY2027 | Request | 21.7 |
| FY2028 | Outyear | 21.5 |
| FY2029 | Outyear | 22.3 |
| FY2030 | Outyear | 22.6 |
| FY2031 | Outyear | 23.0 |
1 accomplishment / planned program
The R-2A exhibit — the only level of the budget that describes work that has not happened yet. Activities carry the prior, current and budget year only, no five-year plan. Each describes FY2027 work in enough detail to have its own page; the rest are shown here in full. Coverage is partial across the corpus, so count activities, never total them.
- Ensure compliance with cyber security mandates to maintain continued authorization to operate. - Assess, implement, document, and validate cybersecurity control families for representative systems comprising computing and logic bearing components to support the Development, Test, Training, and Operational Systems.
Read the FY2027 plan →Named performers on project MC11
Performers named in the R-3 exhibit under this project. Share is of the project's whole FY2027 R-3 total — the same denominator the program-element split uses, so the two read on one scale and will not sum to 100% when unnamed or government work is in the mix. Budget-justification contract funding, not obligations.