# Cyber Resiliency & Cybersecurity Policy

**R-2A activity** of project 145 — Cyber Resiliency & Cybersecurity Policy  
**Program element:** 0606771D8Z — Cyber Resiliency & Cybersecurity Policy  
**Component:** Defense-Wide · **Budget Activity:** 6  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0606771D8Z/145/a0  
**Parent:** https://hitchintel.com/programs/0606771D8Z

## Summary

This activity requests $30.7M in FY2027, 100% of project 145, up 121% on FY2026. The R-2A exhibit describes it across FY2025–FY2027, including what the FY2027 money is planned to buy.

## What the FY2027 request buys

**FY2027 planned work.** Assess: Conduct Cyber Risk Assessments in support of CCMDs: - Mission Resilience (MR) Games: Complete MR V with a Focus on Missile Defense in support of Golden Dome for America. Develop enhanced Cyber Attack/Cyber Defense Scenarios for Golden Dome. Prepare for MR VI with CCMDs. - Cyber Risk Assessments (CRAs): Perform multiple CRAs for Mission Partners across the DoW in support Department priorities, with an enhanced focus on Missile Defense and Production Lines Installation Critical Infrastructure (ICI) for priority DoW programs. Inventory/Prioritize: Cyber Risk Information Management: - Enhance functionality of CRMT on JWICS. - Focus on adding Service datasets, vulnerability data, threat reporting, and other datasets to meet stakeholder needs, as appropriate. - Fully integrate CCMA impact data in CRMT at all classification levels that are FOC. - Expand use and integration of CRMT at strategic (JS, SCP), operational (MLCRA, CCMDs), and tactical levels (services, and program offices). - Refine impact and risk models to ensure that data collected is accurate, agile, and reflects changes to priorities and current senior leader strategies. Complete model to SCP prioritization of mission impact to select systems for SCP assessment and integrate into the enterprise tool, CRMT. - Develop tailored cyber risk scorecards/dashboards for the Missile Defense Mission in support of Golden Dome for America. Mitigate: - Lead the Department’s Strategic Cybersecurity Program (SCP) to continue critical weapon systems and defense critical infrastructure cybersecurity assessments and mitigations. - Conduct cybersecurity posture sustainment for priority C2 and data processing nodes aligned with Golden Dome. - Provide oversight of the mitigation of cyber vulnerabilities and the modernization of control systems in ICI on DoW bases that support Golden Dome. - Enhance cybersecurity of Commercial Critical Infrastructure supporting Golden Dome and provide oversight for funded mitigations. - Develop, update, and refine cybersecurity Policy. - Support cybersecurity reviews of Major Defense Acquisition Programs (MDAPs) where USW(A&S) is the MDA. - Enable USW(A&S) cybersecurity reviews across programs to inform milestone decision authority determinations. - Codify USW(A&S) cybersecurity policy and implementation guides for DoW installations, facilities, and DoW-owned critical infrastructure. - Codify USW (A&S) Cybersecurity Supply Chain Risk Management (C-SCRM) policy and implementation guides in coordination with DoW CIO and USW Intelligence and Security (I&S) for programs and procurement. - Support identification of knowledge, skills, and abilities required of personnel to implement cybersecurity policy, plans, and initiatives to defend DoW’s critical infrastructure, installations, and facilities. - Conduct future Critical Infrastructure Cybersecurity Workshops in support of CCMDs and others in support of DoW priorities. Enhance Governance: - Conduct Integrated Acquisition Portfolio Reviews for Cyber Defense of Priority DoW missions, with a focus on the Missile Defense Mission in support of Golden Dome for America. Weapon System Cyber Security - Cybersecurity Supply Chain Risk Management(C-SCRM): - Prioritize Golden Dome assets for enhanced C-SCRM initiatives. - Continue to update C-SCRM Policy and Best Practices. - Contribute to implementation DoW Sector Risk Management Agency responsibilities. Capability Portfolio Management for Cyberspace Operations: - As the OUSW(A&S) Cyberspace Operations Enterprise Portfolio Manager, drive strategic alignment across planning, requirements, technology, acquisition, sustainment, programming, budgeting, and execution to improved cyber lethality and readiness to operate in a cyber-contested environment. Reform key processes to improve the effectiveness of USCYBERCOM requirements generation, mission engineering, and capability prioritization for cyberspace operations capabilities enabling National Security objectives. Collaborate with the acquisition community and Department stakeholders to reform acquisition strategies and processes and adopt modern software practices. Conduct USW(A&S) chaired Cyberspace Operations Enterprise Integrated Acquisition Portfolio Review (IAPR) and support other IAPRs by providing cyber-related insights, conducting mission engineering analysis to identify capability gaps impacting priority cyberspace operations such as the Cyber National Mission Force missions to Defend the Homeland including support to Golden Dome. The results will inform OSW Programming Guidance and fiscal year 2028 Program Budget Review.

**FY2026 to FY2027 change.** The increase of $16.847 million from FY 2026 to FY 2027 is due to additional funding to support Golden Dome efforts.

## Before the request year

**FY2026 plans — current year.** Assess: Conduct Cyber Risk Assessments in support of CCMDs: - Mission Resilience (MR) Games: Complete MR IV with a Focus on Missile Defense in support of Golden Dome for America. Develop enhanced Cyber Attack/Cyber Defense Scenarios for Golden Dome. Prepare for MR V with CCMDs. - Cyber Risk Assessments (CRAs): Perform multiple CRAs for Mission Partners across the DoW in support Department priorities, with an enhanced focus on Missile Defense and Production Lines Installation Critical Infrastructure (ICI) for priority DoW programs. Inventory/Prioritize: Cyber Risk Information Management: - Achieve full operating capacity (FOC) on the JWICS instance of the CRMT. - Focus on adding Service datasets, vulnerability data, threat reporting, and other datasets to meet stakeholder needs, as appropriate. - Fully integrate CCMA impact data in CRMT at all classification levels that are FOC. - Expand use and integration of CRMT at strategic (JS, SCP), operational (MLCRA, CCMDs), and tactical levels (services, and program offices). - Refine impact and risk models to ensure that data collected is accurate, agile, and reflects changes to priorities and current senior leader strategies. Complete model to SCP prioritization of mission impact to select systems for SCP assessment and integrate into the enterprise tool, CRMT. - Develop tailored cyber risk scorecards/dashboards for the Missile Defense Mission in support of Golden Dome for America. Mitigate: - Lead the Department’s Strategic Cybersecurity Program (SCP) to continue critical weapon systems and defense critical infrastructure cybersecurity assessments and mitigations. - Conduct cybersecurity posture sustainment for priority C2 and data processing nodes aligned with Golden Dome. - Provide oversight of the mitigation of cyber vulnerabilities and the modernization of control systems in ICI on DoW bases that support Golden Dome. - Enhance cybersecurity of Commercial Critical Infrastructure supporting Golden Dome and provide oversight for funded mitigations. - Develop, update, and refine cybersecurity Policy. - Support cybersecurity reviews of Major Defense Acquisition Programs (MDAPs) where USW(A&S) is the MDA. - Enable USW(A&S) cybersecurity reviews across programs to inform milestone decision authority determinations. - Codify USW(A&S) cybersecurity policy and implementation guides for DoW installations, facilities, and DoW-owned critical infrastructure. - Codify USW (A&S) Cybersecurity Supply Chain Risk Management (C-SCRM) policy and implementation guides in coordination with DoW CIO and USW Intelligence and Security (I&S) for programs and procurement. - Support identification of knowledge, skills, and abilities required of personnel to implement cybersecurity policy, plans, and initiatives to defend DoW’s critical infrastructure, installations, and facilities. - Conduct future Critical Infrastructure Cybersecurity Workshops in support of CCMDs and others . Enhance Governance: - Conduct Integrated Acquisition Portfolio Reviews for Cyber Defense of Priority DoW missions, with a focus on the Missile Defense Mission in support of Golden Dome for America. Weapon System Cyber Security - Cybersecurity Supply Chain Risk Management(C-SCRM): - Prioritize Golden Dome assets for enhanced C-SCRM initiatives. - Continue to update C-SCRM Policy and Best Practices. - Contribute to implementation DoW Sector Risk Management Agency responsibilities. Capability Portfolio Management for Cyberspace Operations: - As the OUSW(A&S) Cyberspace Operations Enterprise Portfolio Manager, drive strategic alignment across planning, requirements, technology, acquisition, sustainment, programming, budgeting, and execution to improved cyber lethality and readiness to operate in a cyber-contested environment. Reform key processes to improve the effectiveness of USCYBERCOM requirements generation, mission engineering, and capability prioritization for cyberspace operations capabilities enabling National Security objectives. Collaborate with the acquisition community and Department stakeholders to reform acquisition strategies and processes and adopt modern software practices. Conduct USW(A&S) chaired Cyberspace Operations Enterprise Integrated Acquisition Portfolio Review (IAPR) and support other IAPRs by providing cyber-related insights, conducting mission engineering analysis to identify capability gaps impacting priority cyberspace operations such as the Cyber National Mission Force missions to Defend the Homeland including support to Golden Dome. The results will inform OSW Programming Guidance and fiscal year 2027 Program Budget Review.

**FY2025 accomplishments.** Conduct Cyber Risk Assessments in support of CCMDs: Mission Resilience (MR) Games: Prepare for MR IV with CCMD and complete MR III. Deep Cyber Resiliency Assessments: Perform multiple DCRAs for Mission Partners across the DoD in support Department priorities. Conduct Cyber Risk Assessments of priority DoD Assets Cybersecurity for Weapon Systems and Defense Critical Infrastructure (DCI): - Lead the Department’s Strategic Cybersecurity Program (SCP) to continue critical weapon systems and defense critical infrastructure cybersecurity assessments and mitigations. - Develop, update, and refine cybersecurity Policy. - Support cybersecurity reviews of MDAPs where USD(A&S) is the MDA. - Enable USD(A&S) cybersecurity reviews across programs to inform milestone decision authority determinations. - Codify USD(A&S) cybersecurity policy and implementation guides for DoD installations, facilities, and DoD-owned critical infrastructure. - Codify USD(A&S) cyber Supply Chain Risk Management policy and implementation guides in coordination with DoD CIO and USD(I&S) for programs and procurement. - Support identification of knowledge, skills, and abilities required of personnel to implement cybersecurity policy, plans, and initiatives to defend DoD’s critical infrastructure, installations, and facilities. Cyber Risk Information Management: - With both classified versions of the CRMT at full operational capability and datasets being loaded automatically via machine-to-machine interface, focus will be placed on adding Service datasets, threat reporting, and other datasets to meet stakeholder needs, as appropriate. - CRMT use will further expand within the Cyber Warfare Directorate to incorporate all section information and expand tool use in wargames and at CCMDs. Develop Cybersecurity Scorecards for Priority DoD Missions Weapon System Cyber Security - Cybersecurity Supply Chain Risk Management(C-SCRM): -Conduct Phase II of Weapon System C-SCRM Pilots (+$15 million in FY 2025). Demonstrate the efficacy of C-SCRM capabilities and continue to develop and refine C-SCRM best practices. Capability Portfolio Management for Cyber Capabilities: - Continue to advance and mature capabilities for conducting mission engineering for cyberspace operations. - Manage the portfolio of Joint Cyber Warfighting Architecture (JCWA) components to enable the cyber mission force to efficiently and effectively conduct offensive and defensive cyber missions. Support offensive and defensive architecture development and portfolio management in collaboration with USCYBERCOM. - As the OUSD(A&S) Cyberspace Operations Enterprise portfolio manager OPR, assess the effectiveness of USCYBERCOM requirements generation, mission engineering, and capability prioritization for cyberspace operations capabilities acquisition. In support of the calendar year 2025 USD(A&S)-chaired Cyberspace Operations Enterprise Integrated Acquisition Portfolio review (IAPR) meeting, conduct mission engineering analysis to identify capability gaps across the priority cyberspace operations mission thread. The results will inform OSD fiscal year 2026 Program Budget Review.

## Funding

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 38.8 |
| FY2026 | Enacted | 13.9 |
| FY2027 | Request | 30.7 |

> Prior, current and budget year only — an R-2A activity carries no five-year plan. It sums exactly into its project in the request year and not necessarily in any other.

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibit R-2A, PE 0606771D8Z project 145 (PB PB2027). Narrative is the government's own text.
- **No marks, no contractors at this grain** — congressional marks land on the program element and R-3 performers on the project.
- **MCP:** `mcp.hitchintel.com` — `budget_get_activity`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*