# Prevent Malicious Cyber Activity

**R-2A activity** of project MC30 — Cyber Operations  
**Program element:** 0603890C — BMD Enabling Programs  
**Component:** Defense-Wide · **Budget Activity:** 4  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0603890C/MC30/a6  
**Parent:** https://hitchintel.com/programs/0603890C/MC30

> **NEW START.** $150.1M requested in FY2027 with no prior-year and no current-year funding.

## Summary

This activity requests $150.1M in FY2027, 55% of project MC30 — a new start with no prior-year and no current-year money. The R-2A exhibit describes it across FY2027, including what the FY2027 money is planned to buy.

## What the FY2027 request buys

**FY2027 planned work.** - Extend Comply-to-Connect and Zero Trust services and capabilities to network infrastructure across RDT&E environments. - Implement DevSecOps environments/infrastructure. - Expand Agency Identity and Credentialed Access Management. - Expand Cloud environments. - Implement mandated DoW CIO cryptographic technical refresh to address evolving threat landscape and increasingly stringent security standards.

**FY2026 to FY2027 change.** Increase from FY 2026 to FY 2027 provides for realignment of cybersecurity requirements to new OMB Cybersecurity Taxonomy. Increase also provides for extended comply-to-connect and Zero Trust services and capabilities to network infrastructure across RDT&E environments, implements DevSecOps environments and infrastructure, expands Agency Identity and Credentialed Access Management, and expands Cloud environments and implements mandated DoW CIO cryptographic technical refresh. President Trump's Cybersecurity Strategy for America, March 2026, direction requires the MDA to significantly enhance its cybersecurity posture through several key initiatives, including overhauling network access control in critical RDT&E environments to enforce device compliance with Zero Trust principles and a continuous verification for access capability. MDA must now ensure security throughout the software development lifecycle via DevSecOps environments and pipelines, which automates security practices in order to reduce vulnerabilities and accelerate secure application deployment. The MDA must also significantly upgrade and change the technological implementation of all Identity and Credentialed Access Management services to include enhanced Multi-Factor Authentication, Single Sign-On (SSO), and Privileged Access Management, this is required to meet Zero Trust implementation mandates and timelines. This increase provides for the secure expansion of cloud environments while undertaking a mandated cryptographic technical refresh from the CIO. This refresh ensures all data, especially in the cloud, is protected with the latest, federally approved cryptographic standards, safeguarding sensitive defense information against evolving threats.

## Funding

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 0.0 |
| FY2026 | Enacted | 0.0 |
| FY2027 | Request | 150.1 |

> Prior, current and budget year only — an R-2A activity carries no five-year plan. It sums exactly into its project in the request year and not necessarily in any other.

## Other activities in project MC30

- [Detect, Analyze and Mitigate Intrusions](https://hitchintel.com/programs/0603890C/MC30/a3) — FY2027 100.6
- Planning, Policy Development, Workforce Training & Force Management — FY2027 12.5
- Cybersecurity Risk Management — FY2027 9.2
- Facility Related Control Systems (FRCS) — FY2027 1.1
- Preventing Malicious Cybersecurity Activity — FY2027 0.0
- Continuous Monitoring — FY2027 0.0

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibit R-2A, PE 0603890C project MC30 (PB PB2027). Narrative is the government's own text.
- **No marks, no contractors at this grain** — congressional marks land on the program element and R-3 performers on the project.
- **MCP:** `mcp.hitchintel.com` — `budget_get_activity`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*