R-2A Activity · President's Budget PB2027

Cyber Resiliency & Cybersecurity Policy

Activity a0·Project 145 — Cyber Resiliency & Cybersecurity Policy·PE 0606771D8Z·Defense-Wide
FY2027 Request
$30.7M
▲ 121% vs FY2026
HitchAI read

This activity requests $30.7M in FY2027, 100% of project 145, up 121% on FY2026. The R-2A exhibit describes it across FY2025–FY2027, including what the FY2027 money is planned to buy.

FY2027 Request
$30.7M
▲ 121% vs FY2026
FY2026 Enacted
$13.9M
▼ 64% vs FY2025
FY2025 Actual
$38.8M
Prior year
Planned work

What the FY2027 request buys

Verbatim from the R-2A exhibit for project 145 of PE 0606771D8Z. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.

FY2027 planned work

Assess: Conduct Cyber Risk Assessments in support of CCMDs: - Mission Resilience (MR) Games: Complete MR V with a Focus on Missile Defense in support of Golden Dome for America. Develop enhanced Cyber Attack/Cyber Defense Scenarios for Golden Dome. Prepare for MR VI with CCMDs. - Cyber Risk Assessments (CRAs): Perform multiple CRAs for Mission Partners across the DoW in support Department priorities, with an enhanced focus on Missile Defense and Production Lines Installation Critical Infrastructure (ICI) for priority DoW programs. Inventory/Prioritize: Cyber Risk Information Management: - Enhance functionality of CRMT on JWICS. - Focus on adding Service datasets, vulnerability data, threat reporting, and other datasets to meet stakeholder needs, as appropriate. - Fully integrate CCMA impact data in CRMT at all classification levels that are FOC. - Expand use and integration of CRMT at strategic (JS, SCP), operational (MLCRA, CCMDs), and tactical levels (services, and program offices). - Refine impact and risk models to ensure that data collected is accurate, agile, and reflects changes to priorities and current senior leader strategies. Complete model to SCP prioritization of mission impact to select systems for SCP assessment and integrate into the enterprise tool, CRMT. - Develop tailored cyber risk scorecards/dashboards for the Missile Defense Mission in support of Golden Dome for America. Mitigate: - Lead the Department’s Strategic Cybersecurity Program (SCP) to continue critical weapon systems and defense critical infrastructure cybersecurity assessments and mitigations. - Conduct cybersecurity posture sustainment for priority C2 and data processing nodes aligned with Golden Dome. - Provide oversight of the mitigation of cyber vulnerabilities and the modernization of control systems in ICI on DoW bases that support Golden Dome. - Enhance cybersecurity of Commercial Critical Infrastructure supporting Golden Dome and provide oversight for funded mitigations. - Develop, update, and refine cybersecurity Policy. - Support cybersecurity reviews of Major Defense Acquisition Programs (MDAPs) where USW(A&S) is the MDA. - Enable USW(A&S) cybersecurity reviews across programs to inform milestone decision authority determinations. - Codify USW(A&S) cybersecurity policy and implementation guides for DoW installations, facilities, and DoW-owned critical infrastructure. - Codify USW (A&S) Cybersecurity Supply Chain Risk Management (C-SCRM) policy and implementation guides in coordination with DoW CIO and USW Intelligence and Security (I&S) for programs and procurement. - Support identification of knowledge, skills, and abilities required of personnel to implement cybersecurity policy, plans, and initiatives to defend DoW’s critical infrastructure, installations, and facilities. - Conduct future Critical Infrastructure Cybersecurity Workshops in support of CCMDs and others in support of DoW priorities. Enhance Governance: - Conduct Integrated Acquisition Portfolio Reviews for Cyber Defense of Priority DoW missions, with a focus on the Missile Defense Mission in support of Golden Dome for America. Weapon System Cyber Security - Cybersecurity Supply Chain Risk Management(C-SCRM): - Prioritize Golden Dome assets for enhanced C-SCRM initiatives. - Continue to update C-SCRM Policy and Best Practices. - Contribute to implementation DoW Sector Risk Management Agency responsibilities. Capability Portfolio Management for Cyberspace Operations: - As the OUSW(A&S) Cyberspace Operations Enterprise Portfolio Manager, drive strategic alignment across planning, requirements, technology, acquisition, sustainment, programming, budgeting, and execution to improved cyber lethality and readiness to operate in a cyber-contested environment. Reform key processes to improve the effectiveness of USCYBERCOM requirements generation, mission engineering, and capability prioritization for cyberspace operations capabilities enabling National Security objectives. Collaborate with the acquisition community and Department stakeholders to reform acquisition strategies and processes and adopt modern software practices. Conduct USW(A&S) chaired Cyberspace Operations Enterprise Integrated Acquisition Portfolio Review (IAPR) and support other IAPRs by providing cyber-related insights, conducting mission engineering analysis to identify capability gaps impacting priority cyberspace operations such as the Cyber National Mission Force missions to Defend the Homeland including support to Golden Dome. The results will inform OSW Programming Guidance and fiscal year 2028 Program Budget Review.

FY2026 to FY2027 change

The increase of $16.847 million from FY 2026 to FY 2027 is due to additional funding to support Golden Dome efforts.

Before the request year

FY2025–FY2026: what came before

Prior-year accomplishments and current-year plans from the same exhibit. Context for the FY2027 plan, not a series — an activity partitions its project exactly in the request year, but can under-cover it in earlier years.

FY2026 plans — current year

Assess: Conduct Cyber Risk Assessments in support of CCMDs: - Mission Resilience (MR) Games: Complete MR IV with a Focus on Missile Defense in support of Golden Dome for America. Develop enhanced Cyber Attack/Cyber Defense Scenarios for Golden Dome. Prepare for MR V with CCMDs. - Cyber Risk Assessments (CRAs): Perform multiple CRAs for Mission Partners across the DoW in support Department priorities, with an enhanced focus on Missile Defense and Production Lines Installation Critical Infrastructure (ICI) for priority DoW programs. Inventory/Prioritize: Cyber Risk Information Management: - Achieve full operating capacity (FOC) on the JWICS instance of the CRMT. - Focus on adding Service datasets, vulnerability data, threat reporting, and other datasets to meet stakeholder needs, as appropriate. - Fully integrate CCMA impact data in CRMT at all classification levels that are FOC. - Expand use and integration of CRMT at strategic (JS, SCP), operational (MLCRA, CCMDs), and tactical levels (services, and program offices). - Refine impact and risk models to ensure that data collected is accurate, agile, and reflects changes to priorities and current senior leader strategies. Complete model to SCP prioritization of mission impact to select systems for SCP assessment and integrate into the enterprise tool, CRMT. - Develop tailored cyber risk scorecards/dashboards for the Missile Defense Mission in support of Golden Dome for America. Mitigate: - Lead the Department’s Strategic Cybersecurity Program (SCP) to continue critical weapon systems and defense critical infrastructure cybersecurity assessments and mitigations. - Conduct cybersecurity posture sustainment for priority C2 and data processing nodes aligned with Golden Dome. - Provide oversight of the mitigation of cyber vulnerabilities and the modernization of control systems in ICI on DoW bases that support Golden Dome. - Enhance cybersecurity of Commercial Critical Infrastructure supporting Golden Dome and provide oversight for funded mitigations. - Develop, update, and refine cybersecurity Policy. - Support cybersecurity reviews of Major Defense Acquisition Programs (MDAPs) where USW(A&S) is the MDA. - Enable USW(A&S) cybersecurity reviews across programs to inform milestone decision authority determinations. - Codify USW(A&S) cybersecurity policy and implementation guides for DoW installations, facilities, and DoW-owned critical infrastructure. - Codify USW (A&S) Cybersecurity Supply Chain Risk Management (C-SCRM) policy and implementation guides in coordination with DoW CIO and USW Intelligence and Security (I&S) for programs and procurement. - Support identification of knowledge, skills, and abilities required of personnel to implement cybersecurity policy, plans, and initiatives to defend DoW’s critical infrastructure, installations, and facilities. - Conduct future Critical Infrastructure Cybersecurity Workshops in support of CCMDs and others . Enhance Governance: - Conduct Integrated Acquisition Portfolio Reviews for Cyber Defense of Priority DoW missions, with a focus on the Missile Defense Mission in support of Golden Dome for America. Weapon System Cyber Security - Cybersecurity Supply Chain Risk Management(C-SCRM): - Prioritize Golden Dome assets for enhanced C-SCRM initiatives. - Continue to update C-SCRM Policy and Best Practices. - Contribute to implementation DoW Sector Risk Management Agency responsibilities. Capability Portfolio Management for Cyberspace Operations: - As the OUSW(A&S) Cyberspace Operations Enterprise Portfolio Manager, drive strategic alignment across planning, requirements, technology, acquisition, sustainment, programming, budgeting, and execution to improved cyber lethality and readiness to operate in a cyber-contested environment. Reform key processes to improve the effectiveness of USCYBERCOM requirements generation, mission engineering, and capability prioritization for cyberspace operations capabilities enabling National Security objectives. Collaborate with the acquisition community and Department stakeholders to reform acquisition strategies and processes and adopt modern software practices. Conduct USW(A&S) chaired Cyberspace Operations Enterprise Integrated Acquisition Portfolio Review (IAPR) and support other IAPRs by providing cyber-related insights, conducting mission engineering analysis to identify capability gaps impacting priority cyberspace operations such as the Cyber National Mission Force missions to Defend the Homeland including support to Golden Dome. The results will inform OSW Programming Guidance and fiscal year 2027 Program Budget Review.

FY2025 accomplishments

Conduct Cyber Risk Assessments in support of CCMDs: Mission Resilience (MR) Games: Prepare for MR IV with CCMD and complete MR III. Deep Cyber Resiliency Assessments: Perform multiple DCRAs for Mission Partners across the DoD in support Department priorities. Conduct Cyber Risk Assessments of priority DoD Assets Cybersecurity for Weapon Systems and Defense Critical Infrastructure (DCI): - Lead the Department’s Strategic Cybersecurity Program (SCP) to continue critical weapon systems and defense critical infrastructure cybersecurity assessments and mitigations. - Develop, update, and refine cybersecurity Policy. - Support cybersecurity reviews of MDAPs where USD(A&S) is the MDA. - Enable USD(A&S) cybersecurity reviews across programs to inform milestone decision authority determinations. - Codify USD(A&S) cybersecurity policy and implementation guides for DoD installations, facilities, and DoD-owned critical infrastructure. - Codify USD(A&S) cyber Supply Chain Risk Management policy and implementation guides in coordination with DoD CIO and USD(I&S) for programs and procurement. - Support identification of knowledge, skills, and abilities required of personnel to implement cybersecurity policy, plans, and initiatives to defend DoD’s critical infrastructure, installations, and facilities. Cyber Risk Information Management: - With both classified versions of the CRMT at full operational capability and datasets being loaded automatically via machine-to-machine interface, focus will be placed on adding Service datasets, threat reporting, and other datasets to meet stakeholder needs, as appropriate. - CRMT use will further expand within the Cyber Warfare Directorate to incorporate all section information and expand tool use in wargames and at CCMDs. Develop Cybersecurity Scorecards for Priority DoD Missions Weapon System Cyber Security - Cybersecurity Supply Chain Risk Management(C-SCRM): -Conduct Phase II of Weapon System C-SCRM Pilots (+$15 million in FY 2025). Demonstrate the efficacy of C-SCRM capabilities and continue to develop and refine C-SCRM best practices. Capability Portfolio Management for Cyber Capabilities: - Continue to advance and mature capabilities for conducting mission engineering for cyberspace operations. - Manage the portfolio of Joint Cyber Warfighting Architecture (JCWA) components to enable the cyber mission force to efficiently and effectively conduct offensive and defensive cyber missions. Support offensive and defensive architecture development and portfolio management in collaboration with USCYBERCOM. - As the OUSD(A&S) Cyberspace Operations Enterprise portfolio manager OPR, assess the effectiveness of USCYBERCOM requirements generation, mission engineering, and capability prioritization for cyberspace operations capabilities acquisition. In support of the calendar year 2025 USD(A&S)-chaired Cyberspace Operations Enterprise Integrated Acquisition Portfolio review (IAPR) meeting, conduct mission engineering analysis to identify capability gaps across the priority cyberspace operations mission thread. The results will inform OSD fiscal year 2026 Program Budget Review.

Money

Three years, and no five-year plan

An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.

25038.8FY25ACTUAL13.9FY26ENACTED30.7FY27REQUEST
Actual Enacted Request
Fiscal YearEstimate TypeAmount ($M)
FY2025Actual38.8
FY2026Enacted13.9
FY2027Request30.7

This activity is 100% of project 145's FY2027 request and 100% of PE 0606771D8Z's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.

Where this sits

1 activity in project 145

Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the program-element page.

Cyber Resiliency & Cybersecurity Policy — this activity$30.7M ▲ 121%
Source
FY2027 Office of the Secretary of Defense RDT&E Budget Justification · Exhibit R-2A · PE 0606771D8Z, project 145 (President's Budget PB2027). Congressional marks are recorded on the program element, never on an activity.
Machine access
Markdown twin /programs/0606771D8Z/145/a0.md · MCP mcp.hitchintel.combudget_get_activity