What the FY2027 request buys
Verbatim from the R-2A exhibit for project 976 of PE 0604256A. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.
Sustainment of existing threat-based Red Team capabilities, including previously developed toolsets and distributed operations infrastructure. Maintain Red Team Certification and Accreditation (C&A) required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat training. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers (C4) Intelligence, Surveillance and Reconnaissance (C4ISR) and Enterprise Business Systems. Development of threat targets and networks as new real-world targets sets and capabilities evolve.
Funding decrease reduces planned threat assessments to focus on the highest priorities.
FY2025–FY2026: what came before
Prior-year accomplishments and current-year plans from the same exhibit. Context for the FY2027 plan, not a series — an activity partitions its project exactly in the request year, but can under-cover it in earlier years.
Execute information and decision advantage threat simulation to support Army critical program information protection. Provide Army Programs with quantifiable information regarding risks to critical information within the public domain. Assess effectiveness of measures and countermeasures employed within OPSEC and program protection plans. Plan, execute and provide threat assessments to prioritized systems and activities spanning key areas of concern across Army. Advancement of existing threat-based Red Team capabilities, including previously developed toolsets and distributed operations infrastructure. Maintain Red Team Certification and Accreditation required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat training. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers Intelligence, Surveillance and Reconnaissance and Enterprise Business Systems. Development of threat targets and networks as new real-world targets sets and capabilities evolve. Continued development and employment of intelligence validated LVC dynamic Commercial, Multi-National & Military (Red and Gray) Environments required for Army and Joint Offensive Cyber Operations and Defensive Cyber Operations-Response Actions program development; Test and Evaluation (e.g., Joint Common Access Platform OT); and mission rehearsal/capabilities assessments in support of Army and Joint Multi-Domain Operations ranges. Conduct Foreign Commercial Aquisition and Foreign Commercial Purchase actions.
Development of existing threat-based Red Team capabilities, including previously developed toolsets and the Red Team Shared Infrastructure (RTSI) - a distributed operations infrastructure. Infrastructure hardware refresh. Maintain Red Team Certification and Accreditation required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat test and evaluation. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers (C4), Intelligence, Surveillance and Reconnaissance (C4ISR), and Enterprise Business Systems. Persistently replicates Advance Persistent Threats from near-peer actors across the materiel enterprise (into operations) which threaten Army modernization and readiness. Development of threat targets and networks as new real-world targets sets and capabilities evolve.
Three years, and no five-year plan
An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.
| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 21.4 |
| FY2026 | Enacted | 28.8 |
| FY2027 | Request | 11.4 |
This activity is 19% of project 976's FY2027 request and 19% of PE 0604256A's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.
3 activities in project 976
Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the program-element page.