What the FY2027 request buys
Verbatim from the R-2A exhibit for project MC30 of PE 0603890C. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.
- Extend Comply-to-Connect and Zero Trust services and capabilities to network infrastructure across RDT&E environments. - Implement DevSecOps environments/infrastructure. - Expand Agency Identity and Credentialed Access Management. - Expand Cloud environments. - Implement mandated DoW CIO cryptographic technical refresh to address evolving threat landscape and increasingly stringent security standards.
Increase from FY 2026 to FY 2027 provides for realignment of cybersecurity requirements to new OMB Cybersecurity Taxonomy. Increase also provides for extended comply-to-connect and Zero Trust services and capabilities to network infrastructure across RDT&E environments, implements DevSecOps environments and infrastructure, expands Agency Identity and Credentialed Access Management, and expands Cloud environments and implements mandated DoW CIO cryptographic technical refresh. President Trump's Cybersecurity Strategy for America, March 2026, direction requires the MDA to significantly enhance its cybersecurity posture through several key initiatives, including overhauling network access control in critical RDT&E environments to enforce device compliance with Zero Trust principles and a continuous verification for access capability. MDA must now ensure security throughout the software development lifecycle via DevSecOps environments and pipelines, which automates security practices in order to reduce vulnerabilities and accelerate secure application deployment. The MDA must also significantly upgrade and change the technological implementation of all Identity and Credentialed Access Management services to include enhanced Multi-Factor Authentication, Single Sign-On (SSO), and Privileged Access Management, this is required to meet Zero Trust implementation mandates and timelines. This increase provides for the secure expansion of cloud environments while undertaking a mandated cryptographic technical refresh from the CIO. This refresh ensures all data, especially in the cloud, is protected with the latest, federally approved cryptographic standards, safeguarding sensitive defense information against evolving threats.
Three years, and no five-year plan
An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.
| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 0.0 |
| FY2026 | Enacted | 0.0 |
| FY2027 | Request | 150.1 |
This activity is 55% of project MC30's FY2027 request and 10% of PE 0603890C's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.
7 activities in project MC30
Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the project page.