# Project MC11 — Cyber Operations

**Program element:** 0603884C — Ballistic Missile Defense Sensors  
**Project:** MC11  
**Component:** Defense-Wide  
**Appropriation:** 0400 — RDT&E, Defense-Wide  
**Budget Activity:** 4 — Advanced Component Development & Prototypes  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0603884C/MC11  
**Parent:** https://hitchintel.com/programs/0603884C

## Summary

Project MC11 — Cyber Operations requests $21.7M in FY2027, 2.5% of the $865.4M requested for program element 0603884C, up 19% on FY2026. 1 R-2A activity decomposes the request. RTX / Raytheon is the largest named R-3 performer at $10.6M, 49% of the project's FY2027 R-3 total.

**Markets:** Cyber, C2 & Networks (programs) — matched on the project title only, and no market size is quoted.

## Funding profile

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 18.8 |
| FY2026 | Enacted | 18.3 |
| FY2027 | Request | 21.7 |
| FY2028 | Outyear | 21.5 |
| FY2029 | Outyear | 22.3 |
| FY2030 | Outyear | 22.6 |
| FY2031 | Outyear | 23.0 |

> Estimate types are not summed. This project is one leaf of PE 0603884C; the PE total is the sum of its projects, never added to them.

## What project MC11 buys

Sustain the Department of Defense Instruction (DoDI) 8510.01 Risk Management Framework (RMF) for Department of War (DoW) Information Technology (IT) requirement for the MDA and conduct Security Control Assessments (SCA) activities, analysis of validation results, risk assessments, and reviews of proposed Program Manager/Information System Security Manager (PM/ISSM) Plans of Action and Milestones (POA&M) for the Missile Defense Agency (MDA) Ground Sensors mission and support systems. It also includes support for external cybersecurity assessments and penetration testing of the Ground Sensors mission systems, both in laboratory developmental testing and during ground test activities, in accordance with Director, Operational Test and Evaluation directives and the Integrated Master Test Plan. It maintains the Assessment and Authorization (A&A) data repository, capturing the RMF documentation (artifacts, validation results, Cybersecurity Risk Assessment results, cybersecurity scorecard, and Authorizing Official (AO) authorization decisions) and POA&M for all MDA information systems. It positions Ground Sensors assets to complete the transition to National Institute of Standards and Technology Special Publication 800-53 Revision 5 requirements (i.e. RMF 2.0) once DoW requirements and timelines are finalized. This project supports aligning, developing, and implementing an integrated Tier 2 Cyber Security Service Provider (CSSP) capability on the Ground Sensors mission systems under the DoW Cybersecurity Discipline Implementation Plan and DoDI 8530.01 Cybersecurity Activities Support to DoW Information Network Operations. Provides the monitoring, prioritization, and tracking of Cybersecurity mitigation detailed in Information Technology security POA&Ms. The activities include preparation of A&A documentation and accreditation recommendations to the MDA Senior Information Security Officer/SCA and AO. Independent Verification and Validation team actions ensure the availability, integrity, authentication, confidentiality, and non-repudiation of the MDA mission, test, and administrative systems. These activities are necessary to comply with the Federal Information Security Management Act.

**R-3 lines of work:** Product Development; Support.

## Named R-3 performers

| Performer | $M | Share of this project's FY2027 R-3 total |
|---|---|---|
| RTX / Raytheon | 10.6 | 49% |
| Lockheed Martin | 3.8 | 17% |
| GRYPHON | 3.0 | 14% |
| Rothe Ares JV | 1.2 | 5.6% |

> Budget-justification contract funding, not obligations. Shares need not reach 100% — unnamed and government work is in the denominator.

## Activities (R-2A) — 1

| Activity | FY2025 | FY2026 | FY2027 | Move | Page |
|---|---|---|---|---|---|
| Network / System Certification and Accreditation (C&A) | 18.8 | 18.3 | 21.7 | +19% | [a0](https://hitchintel.com/programs/0603884C/MC11/a0) |

> Activities carry the prior, current and budget year only — no five-year plan. In the request year they partition this project exactly; in earlier years they can under-cover it.

### Network / System Certification and Accreditation (C&A)

- Ensure compliance with cyber security mandates to maintain continued authorization to operate. - Assess, implement, document, and validate cybersecurity control families for representative systems comprising computing and logic bearing components to support the Development, Test, Training, and Operational Systems.

Full year-by-year narrative: https://hitchintel.com/programs/0603884C/MC11/a0

## What is NOT on this page

Congressional marks, the R-2 mission description and acquisition strategy, the industry vs government split of the whole request, and related program elements are recorded at **program-element** grain — an NDAA mark lands on a PE, never on a project. They are at https://hitchintel.com/programs/0603884C.

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibits R-2/R-2A/R-3, PE 0603884C project MC11 (PB PB2027).
- **MCP:** `mcp.hitchintel.com` — `budget_get_program_element(pe="0603884C")`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*