# System of Systems (SoS) Cybersecurity and Capability Engineering

**R-2A activity** of project 2144 — Space & Elec Warfare Engineering  
**Program element:** 0606355N — Warfare Innovation Management  
**Component:** U.S. Navy · **Budget Activity:** 6  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0606355N/2144/a1  
**Parent:** https://hitchintel.com/programs/0606355N/2144

## Summary

This activity requests $22.8M in FY2027, 100% of project 2144, down 8.6% on FY2026. The R-2A exhibit describes it across FY2026–FY2027, including what the FY2027 money is planned to buy.

## What the FY2027 request buys

**FY2027 planned work.** - Continue key efforts to develop technical architectures, tools, standards, and best practices to advance the Navy's integrated plan for effective implementation of resilient cybersecurity. These critical Cyber Security Technical Authority (CS TA) artifacts: (1) leverage CS TA Cyber Risk Assessments (CRA) to account for emerging cyber threats and advances in technology, (2) drive the use of Risk Management Framework (RMF) Rapid Assess and Incorporate (A&I) Software Engineering (RAISE) process for inheritance to reduce redundant cybersecurity investments, lower operational risk and significantly improve delivery times for emerging capabilities. - Continue to perform holistic Cyber Risk Assessments (CRA) that evaluate Navy systems in the context of warfighting missions across tabletop, lab, and operational environments. The results of the CS TA Tabletop Mission Cyber Risk Assessments (TMCRA), which examine access vectors and likelihood of adversary exploit, are tested in NAVWAR's IW Capability Testing environment, and are then used to support Navy-wide Live, Virtual, and Constructive (LVC) Information Warfare (IW) capability tests and Fleet experimentation. This holistic set of assessments allows Program Managers to include to mitigate existing risks across the system lifecycle as well as strengthen the cybersecurity design of future system variants. - Continue to develop automation of the RMF process, leveraging integrated digital engineering models that will streamline data and analytics to provide assessment results. The automated process includes integrating various RMF roles, data entry, and continued auditing/validating RMF steps (control selection, assessment, and authorization). Implement cyber operational risk threat assessments and continuous monitoring. Perform DON CISO Cyber Figure of Merit (CFOM) acquisition gate assessments, system of systems Cyber Risk to Mission (CRTM) assessments, develop and update cybersecurity technical standards, all of which support better understanding of and mitigation of cyber risk across the Navy. Advance the Continuous Monitoring (CONMON) and cyber operational picture capability required to meet Fleet Cyber Command (FCC) objectives. - Continue to perform Systems Engineering Technical Reviews (SETRs) across Command, Control, Communications, Computers, Intelligence, Surveillance, Reconnaissance (C4ISR) and Digital Enterprise Services (DES); Manpower, Logistics, and Business Solutions (MLB) programs to ensure compliance with statutory and regulatory directives, as well as implementing applicable Information Technology (IT) and Cybersecurity (CS) Technology Authority (TA) architectures, specifications, standards, policies, processes and profiles. Continue efforts to integrate digital engineering advances as applicable to accelerate and automate SETR reviews to better support programs leveraging Agile or DevSecOps frameworks to support the Adaptive Acquisition Framework pathways. - Continue digital reviews for program certifications and technical reviews of formal acquisition and engineering documentation through enhanced design and testing analysis. - Working to establish Enterprise Architecture to support design, development and delivery of integrated Navy Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR), Business Information Technology (IT), and Space System capabilities. Perform mission-based system-of-systems kill chain and business thread analysis to ensure integration and interoperability and validate end-to-end warfighting capabilities to address emerging threats.

**FY2026 to FY2027 change.** SEW (Project 2144) Decrease of $2.148M between FY26 and FY27 can be attributed to funding higher Departmental priorities resulting in decreased requirements for cyber capabilities to support technical analyses, program planning, and enterprise-level investment decisions across Information Warfare (IW) capabilities on both ashore and afloat platforms.

## Before the request year

**FY2026 plans — current year.** - Continuing key efforts to develop technical architectures, tools, standards, and best practices to advance the Navy's integrated plan for effective implementation of resilient cybersecurity. These critical Cyber Security Technical Authority (CS TA) artifacts: (1) leverage CS TA Cyber Risk Assessments (CRA) to account for emerging cyber threats and advances in technology, (2) drive the use of Risk Management Framework (RMF) Rapid Assess and Incorporate (A&I) Software Engineering (RAISE) process for inheritance to reduce redundant cybersecurity investments, lower operational risk and significantly improve delivery times for emerging capabilities. - Continuing to perform holistic Cyber Risk Assessments (CRA) that evaluate Navy systems in the context of warfighting missions across tabletop, lab, and operational environments. The results of the CS TA Tabletop Mission Cyber Risk Assessments (TMCRA), which examine access vectors and likelihood of adversary exploit, are tested in NAVWAR's IW Capability Testing environment, and are then used to support Navy-wide Live, Virtual, and Constructive (LVC) Information Warfare (IW) capability tests and Fleet experimentation. This holistic set of assessments allows Program Managers to include to mitigate existing risks across the system lifecycle as well as strengthen the cybersecurity design of future system variants. - Continuing to develop automation of the RMF process, leveraging integrated digital engineering models that will streamline data and analytics to provide assessment results. The automated process includes integrating various RMF roles, data entry, and continued auditing/validating RMF steps (control selection, assessment, and authorization). Implement cyber operational risk threat assessments and continuous monitoring. Perform DON CISO Cyber Figure of Merit (CFOM) acquisition gate assessments, system of systems Cyber Risk to Mission (CRTM) assessments, develop and update cybersecurity technical standards, all of which support better understanding of and mitigation of cyber risk across the Navy. Advance the Continuous Monitoring (CONMON) and cyber operational picture capability required to meet Fleet Cyber Command (FCC) objectives. - Continuing to perform Systems Engineering Technical Reviews (SETRs) across Command, Control, Communications, Computers, Intelligence, Surveillance, Reconnaissance (C4ISR) and Digital Enterprise Services (DES); Manpower, Logistics, and Business Solutions (MLB) programs to ensure compliance with statutory and regulatory directives, as well as implementing applicable Information Technology (IT) and Cybersecurity (CS) Technology Authority (TA) architectures, specifications, standards, policies, processes and profiles. Continue efforts to integrate digital engineering advances as applicable to accelerate and automate SETR reviews to better support programs leveraging Agile or DevSecOps frameworks to support the Adaptive Acquisition Framework pathways. - Continuing digital reviews for program certifications and technical reviews of formal acquisition and engineering documentation through enhanced design and testing analysis. - Working to establish Enterprise Architecture to support design, development and delivery of integrated Navy Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR), Business Information Technology (IT), and Space System capabilities. Perform mission-based system-of-systems kill chain and business thread analysis to ensure integration and interoperability and validate end-to-end warfighting capabilities to address emerging threats.

## Funding

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 25.3 |
| FY2026 | Enacted | 25.0 |
| FY2027 | Request | 22.8 |

> Prior, current and budget year only — an R-2A activity carries no five-year plan. It sums exactly into its project in the request year and not necessarily in any other.

## Other activities in project 2144

- Advanced Manufacturing (AdvM) — FY2027 0.0

## Source & machine access

- **Source:** FY2027 Department of the Navy RDT&E Budget Justification, Exhibit R-2A, PE 0606355N project 2144 (PB PB2027). Narrative is the government's own text.
- **No marks, no contractors at this grain** — congressional marks land on the program element and R-3 performers on the project.
- **MCP:** `mcp.hitchintel.com` — `budget_get_activity`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*