R-2A Activity · President's Budget PB2027

Prevent Malicious Cyber Activity

FY2027 Request
$150.1M
◆ New start in FY2027
HitchAI read

This activity requests $150.1M in FY2027, 55% of project MC30 — a new start with no prior-year and no current-year money. The R-2A exhibit describes it across FY2027, including what the FY2027 money is planned to buy.

New start

This activity requests $150.1M in FY2027 with no prior-year and no current-year funding. There is no incumbent line to compare it with — it did not exist before this President's Budget.

FY2027 Request
$150.1M
No FY2026 funding
FY2026 Enacted
$0.0M
No FY2025 funding
FY2025 Actual
$0.0M
Prior year
Planned work

What the FY2027 request buys

Verbatim from the R-2A exhibit for project MC30 of PE 0603890C. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.

FY2027 planned work

- Extend Comply-to-Connect and Zero Trust services and capabilities to network infrastructure across RDT&E environments. - Implement DevSecOps environments/infrastructure. - Expand Agency Identity and Credentialed Access Management. - Expand Cloud environments. - Implement mandated DoW CIO cryptographic technical refresh to address evolving threat landscape and increasingly stringent security standards.

FY2026 to FY2027 change

Increase from FY 2026 to FY 2027 provides for realignment of cybersecurity requirements to new OMB Cybersecurity Taxonomy. Increase also provides for extended comply-to-connect and Zero Trust services and capabilities to network infrastructure across RDT&E environments, implements DevSecOps environments and infrastructure, expands Agency Identity and Credentialed Access Management, and expands Cloud environments and implements mandated DoW CIO cryptographic technical refresh. President Trump's Cybersecurity Strategy for America, March 2026, direction requires the MDA to significantly enhance its cybersecurity posture through several key initiatives, including overhauling network access control in critical RDT&E environments to enforce device compliance with Zero Trust principles and a continuous verification for access capability. MDA must now ensure security throughout the software development lifecycle via DevSecOps environments and pipelines, which automates security practices in order to reduce vulnerabilities and accelerate secure application deployment. The MDA must also significantly upgrade and change the technological implementation of all Identity and Credentialed Access Management services to include enhanced Multi-Factor Authentication, Single Sign-On (SSO), and Privileged Access Management, this is required to meet Zero Trust implementation mandates and timelines. This increase provides for the secure expansion of cloud environments while undertaking a mandated cryptographic technical refresh from the CIO. This refresh ensures all data, especially in the cloud, is protected with the latest, federally approved cryptographic standards, safeguarding sensitive defense information against evolving threats.

Money

Three years, and no five-year plan

An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.

5010015000.0FY25ACTUAL0.0FY26ENACTED150.1FY27REQUEST
Actual Enacted Request
Fiscal YearEstimate TypeAmount ($M)
FY2025Actual0.0
FY2026Enacted0.0
FY2027Request150.1

This activity is 55% of project MC30's FY2027 request and 10% of PE 0603890C's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.

Where this sits

7 activities in project MC30

Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the project page.

Prevent Malicious Cyber Activity — this activity$150.1M NEW
Detect, Analyze and Mitigate Intrusions$100.6M ▲ 128%
Planning, Policy Development, Workforce Training & Force Management$12.5M ▲ 354%
Cybersecurity Risk Management$9.2M NEW
Facility Related Control Systems (FRCS)$1.1M ▲ 17%
Preventing Malicious Cybersecurity Activity$0.0M ▼ 100%
Continuous Monitoring$0.0M ▼ 100%
Source
FY2027 Office of the Secretary of Defense RDT&E Budget Justification · Exhibit R-2A · PE 0603890C, project MC30 (President's Budget PB2027). Congressional marks are recorded on the program element, never on an activity.
Machine access
Markdown twin /programs/0603890C/MC30/a6.md · MCP mcp.hitchintel.combudget_get_activity