Skip to content
Fiscal Receipts

Information Systems Security Program

Air ForceRDT&EReconciledPE0303140F
What it is
Information Systems Security Program (0303140F) is an Air Force research & development line funded in the Research, Development, Test and Evaluation, Air Force account. Its J-book detail breaks the line into 2 projects.
What changed
+$3.99M FY25→26 R-1 TOA · PB2026
Who gets it
No single contractor is published as this line's leader. 1 linked award record is listed below. This line's high-confidence links do not clear the floor for a published concentration index — at least 3 awards across 2 contractor families holding positive obligations, with positive net linked dollars. Why the crosswalk is partial.

Budget figures

FY24 Actuals
$89.2MR-1 TOA · PB2026
FY25 Total
$94.4MR-1 TOA · PB2026
FY26 Request
$98.4MR-1 TOA · PB2026
FY25→26 Change
+$3.99MR-1 TOA · PB2026
Data coverage

FY2026 award data is a partial year — USAspending reports awards on a rolling basis, and this corpus runs through 2026-09-04. why partial FY2026 data? →

Budget trajectory

The program's 3 summary figures for FY24 to FY26, plotted in fiscal-year order: this line ends higher than it starts. The points are the summary cards above, not a separate derivation; the table beside the chart carries each figure with its own citation.
The program's 3 summary figures for FY24 to FY26, plotted in fiscal-year order: this line ends higher than it starts. The points are the summary cards above, not a separate derivation; the table beside the chart carries each figure with its own citation.FY24: $89.2MFY25: $94.4MFY26: $98.4MFY24FY25FY26
Budget trajectory: one row per fiscal year, carrying the summary figure the sparkline plots. Every figure opens its own citation.
Fiscal yearAmount
FY24$89.2M
FY25$94.4M
FY26$98.4M

All series figures: R-1 TOA · PB2026

Decade view

P-1/R-1 workbook TOA basis, shown compact in $B/$M (the workbook records USD thousands); each figure cites its own President's Budget edition

12 fiscal years of this program as published (FY2015–FY2026): a line through the actuals (filled dots), with the enacted (hollow circles) and request (diamonds) markers each edition reported. Read it for direction, not for precision — this program's actuals line rises across the span. The grid below is the same data as text, one cited figure per cell.
12 fiscal years of this program as published (FY2015–FY2026): a line through the actuals (filled dots), with the enacted (hollow circles) and request (diamonds) markers each edition reported. Read it for direction, not for precision — this program's actuals line rises across the span. The grid below is the same data as text, one cited figure per cell.FY2015 actuals — PB2017 editionFY2016 actuals — PB2018 editionFY2017 actuals — PB2019 editionFY2018 actuals — PB2020 editionFY2019 actuals — PB2021 editionFY2020 actuals — PB2022 editionFY2021 actuals — PB2023 editionFY2022 actuals — PB2024 editionFY2023 actuals — PB2025 editionFY2024 actuals — PB2026 editionFY2016 enacted — PB2017 editionFY2017 enacted — PB2018 editionFY2018 enacted — PB2019 editionFY2019 enacted — PB2020 editionFY2020 enacted — PB2021 editionFY2021 enacted — PB2022 editionFY2022 enacted — PB2023 editionFY2023 enacted — PB2024 editionFY2024 enacted — PB2025 editionFY2025 enacted — PB2026 editionFY2017 request — PB2017 editionFY2018 request — PB2018 editionFY2019 request — PB2019 editionFY2020 request — PB2020 editionFY2021 request — PB2021 editionFY2022 request — PB2022 editionFY2023 request — PB2023 editionFY2024 request — PB2024 editionFY2025 request — PB2025 editionFY2026 request — PB2026 editionFY15FY18FY20FY22FY24FY26

The vertical scale does not start at zero: the baseline sits just below this program’s smallest year, so a low point on this line is not a small amount. Read the shape for direction and the grid below for the figures.

● actuals (line)  ·  ○ enacted  ·  ◇ request — gaps are editions the program is absent from, never interpolated.

Decade series values by fiscal year and President's Budget edition: one row per series (actuals, enacted, request), one column per fiscal year. Every figure opens its own citation.
SeriesFY15FY16FY17FY18FY19FY20FY21FY22FY23FY24FY25FY26
Actuals$65.0M$44.6M$36.1M$41.1M$35.8M$26.7M$9.59M$12.8M$63.0M$89.2M
Enacted$46.3M$46.4M$43.0M$34.0M$27.7M$10.4M$8.03M$70.3M$95.5M$94.4M
Request$46.4M$43.0M$34.6M$27.7M$10.4M$8.03M$70.6M$95.5M$94.4M$98.4M

blank = series not published for this year; – = absent from that edition.

Asked vs spent: the PB2017 book requested $46.4M for FY2017; the PB2019 book reported $36.1M as actual total obligation authority — $10.3M below the request. 36.1 − 46.4 = -10.3 USD millions — the compact figures above are rounded for reading.

Program lineage

No predecessor/successor lineage was recorded for this program element — no FY-to-FY transfer into or out of this line was stated in the ingested J-books, and none was inferred from the program structure.

Description

Mission — Information Systems Security Program

Information Systems Security Program (ISSP) - Includes resources, manpower authorizations, necessary facilities and equipment required to develop, deliver, and sustain Cryptographic Modernization (CM) capabilities to nearly all Department of the Air Force (DAF) weapon systems that encrypt/decrypt sensitive information. CM ensures confidentiality, integrity, and availability of the information and the systems. The CM work done in the Information Systems Security Program (ISSP) ensures that DAF systems receive cryptographic capabilities that are compliant with National Security Agency (NSA) mandates and that commanders can confidently leverage for Joint All Domain Command and Control (JADC2) capabilities. The ISSP Element and associated CM activities provide a foundational Communications Security (COMSEC) capability that is the first and last line of cyber defense against adversary exploitation. The DAF and the DoD require the capability to securely collect, process, store, and disseminate an uninterrupted flow of information, while denying an adversary the ability to intercept, collect, destroy, interpret, or manipulate our information flows. CM provides secure communication to allow the DoD to achieve and maintain decision superiority, the key to successful application of the military instrument of national power in modern full-spectrum operations. DAF COMSEC equipment protects sensitive information such as warfighter positions, mission planning, target strikes, commanders' orders, intelligence, force strength, and force readiness. When an adversary is capable of interpretation, manipulation, or destruction of the information used by the warfighter, DoD military forces will suffer significant and/or devastating mission degradation that can result in loss of life and resources and/or exceptionally grave damage to national security. The advanced threats and capabilities of near-peer adversaries will necessitate the exclusion of weapon systems with obsolete cryptography from Combatant Commander Areas of Responsibility (AORs)—diminishing the ability of the DAF to communicate securely in a high-end fight. The 2021 National Defense Authorization Act (NDAA) mandates the services begin reporting on their CM activities and status of obsolete products starting in Jan 2022, as well as the National Security Memorandum 10 (4 May 2022) which identifies the need for quantum-resistant crypto. These documents highlight the high importance of ISSP efforts. The overall focus of the Research, Development, Test, and Evaluation (RDT&E) efforts within the ISSP program is to transform current CM devices to protect against current technology threats, which include quantum computing. The modernization effort is required by Chairman Joint Chiefs of Staff Notice (CJCSN) 6510 and NSA Decertification Messages (CED-31-15/037-21/032-16) from FY23 for the need to add Quantum Resilience (QR) to the existing high assurance cryptographic products. This effort will allow protection against advanced & evolving quantum computing threats. All existing crypto devices will be vulnerable and must be modernized to be quantum resilient. These efforts are driven by the NSA requirements to implement newly developed Quantum Resistant Algorithms (QRAs). The NSA requires an inventory of cryptographic devices that are more resilient to future threats through full software re-programmability. This will enable protection against near peer adversary exploitation and provide the ability to rapidly adapt against newer threats. This program element may include necessary civilian pay expenses required to manage, execute, and deliver weapon system capability. The use of such program's funds would be in addition to the civilian pay expenses budgeted in program element 0605829F, 0605831F, 0605833F, or 0605898F. In FY 2024 2.074M was expended for civilian pay expenses in this program element, and in FY 2025 3.894M is forecasted for civilian pay expenses in this program element. This program is in Budget Activity 7, Operational System Development because this budget activity includes development efforts to upgrade systems that have been fielded or have received approval for full rate production and anticipate production funding in the current or subsequent fiscal year.

Mission — Cryptographic Modernization

The DAF Cryptographic Modernization (CM) effort modernizes cryptographic devices protecting critical national security information across multi-domain operations. This DAF effort supports an integrated effort across the cyber domain to transform to next-generation cryptographic capabilities. It provides U.S. forces and multinational and interagency partners the multi-domain security needed to protect the flow and exchange of strategic, operational, and tactical information in accordance with national and international policy/standards, and the validated requirements of decision makers, warfighters, and the intelligence community. The AF Cryptographic Modernization 2 (CM2) effort is required by Chairman Joint Chiefs of Staff Notice (CJCSN) 6510 and NSA Decertification Messages (CED-31-15/037-21/032-16) for the need to add quantum resistance to the existing high assurance cryptographic products. This effort will allow protection against advanced & evolving quantum computing threats. All existing crypto devices will be vulnerable and must be modernized to be quantum resilient. The majority of the development effort includes hardware changes to the existing crypto devices. The CM effort is a holistic DAF-wide "modern” cryptographic strategy to provide long-term, evolving protection of NC3, ISR, PKI, KME, and nearly all AF platforms and ground networks. CM will provide the required enhanced security for all DAF voice, data, and video capabilities on the battlefield and throughout the DoD enterprise and will enable the integration of new capabilities to DAF users through development of a new DoD CM2 Initial Capabilities Document (ICD) dated 15 July 2021. This program element may include necessary civilian pay expenses required to manage, execute, and deliver weapon system capability. The use of such programs funds would be in addition to the civilian pay expenses budgeted in program element 0605829F, 0605831F, 0605833F, or 0605898F. In FY 2024 2.074M was expended for civilian pay expenses in this program element, and in FY 2025 3.894M is forecasted for civilian pay expenses in this program element.

Mission — Cryptographic Modernization 2 (CM2)

The Department of the Air Force (DAF) Cryptographic Modernization 2 (CM2) effort modernizes cryptographic devices protecting critical national security information across multi-domain operations. This DAF effort supports an integrated effort across the cyber domain to transform to next-generation cryptographic capabilities. It provides U.S. forces and multinational and interagency partners the multi-domain security needed to protect the flow and exchange of strategic, operational, and tactical information in accordance with national and international policy/standards, and the validated requirements of decision makers, warfighters, and the intelligence community. CM2 modernization is required by Chairman Joint Chiefs of Staff Notice (CJCSN) 6510 and National Security Agency (NSA) Decertification Messages (CED-31-15/037-21/032-16) from FY23 for the need to add Quantum Resilience (QR) to the existing high assurance cryptographic products. This effort will allow protection against advanced & evolving quantum computing threats. All existing crypto devices will be vulnerable and must be modernized to be quantum resilient. The CM2 effort is a holistic Air Force wide "modern” cryptographic strategy to provide long-term, evolving protection of Nuclear Command, Control, and Communications (NC3), Intelligence, Surveillance, Reconnaissance (ISR), Public Key Infrastructure (PKI), Key Management Enterprise (KME), and nearly all DAF platforms, ground and space networks. CM2 will provide the required enhanced security for all DAF voice, data, and video capabilities on the battlefield and throughout the DoD enterprise. In addition to the development /modernization of the devices, this effort requires studies, proof of concepts, and prototype efforts to accurately address the evolving quantum computing threats in the years to come and ramp up efforts accordingly. This program element may include necessary civilian pay expenses required to manage, execute, and deliver weapon system capability. The use of such program's funds would be in addition to the civilian pay expenses budgeted in program element 0605829F, 0605831F, 0605833F, or 0605898F. In FY 2024 2.074M was expended for civilian pay expenses in this program element, and in FY 2025 3.894M is forecasted for civilian pay expenses in this program element.

Justification

Accomplishments & Planned Programs (13)

Technology Development (TD)

Technology Development (TD) provides the technical maturation efforts needed to posture for the current and upcoming quantum computing threats, as well as comply with NSA threat timelines. The maturation of these efforts will provide an enterprise approach to modular open system architectures.

Identification Friend or Foe (IFF) Mode 5

Modernization of IFF Mode 5 devices enables the warfighter to engage and accurately identify friendly or enemy forces as friend or foe. It prevents fratricide during target engagements and provides authentication and encryption/decryption services. The modernized devices will be quantum resilient and prevent enemy disruption of IFF functions. They will enhance the needed security for interrogations and response. These encryption devices operate within military aircraft, fixed, and transportable ground stations when connected to an interrogator and/or transponder. The IFF Mode 5 crypto modules KIV-77 and KIV-78 requires permanent modification. The modification of these devices is required to address quantum threats, producibility and algorithm reprogrammability mandated by the NSA and the 2019 CJCSN 6510.

Algorithm Transition Compliance and Support

Supports Air Combat Command (AF lead for Cyber Superiority) in Algorithm Transition Compliance and provides Information Assurance (IA) support by investigating and analyzing all utilized cryptographic algorithms and hundreds of cryptographic equipment types to support the transformation effort in becoming quantum resilient. This includes the development of prototyping efforts to include the development of a software program of a centralized near real-time accountability of AF COMSEC equipment that reports compliance to AF/DoD Leadership. In addition, it will provide automated software updates to crypto devices (networked & non-networked), and field modernized cryptography, algorithms, and quantum computing.

Space Modular Common Crypto (SMCC)

SMCC architecture is being studied for quantum resilient impacts.

Classified Data At Rest (CDAR)

CDAR will provide the capability to render classified data at rest unusable to adversaries if data storage is captured or compromised, eliminating policy compliance shortfalls. The development of CDAR is an NSA approved modernized cryptographic solution(s) for use in 45 Air Force platforms/systems exposed to hostile/uncontrolled environments. The enterprise cryptographic solution will encrypt/decrypt Top Secret and Below (TSAB) data at rest residing in a variety of data storage environments.

Technology Development (TD)

CM2 TD will provide crypto devices with enterprise solutions that are more robust, modular, scalable, and provide durability to existing cryptographic end items, as well as updating midterm aging/unsupportable crypto equipment. All existing crypto devices will be vulnerable and must be modernized to be QR. The development efforts include hardware and software changes to the existing crypto devices while identifying new efforts necessary for development to address the refined CM2 Threshold Requirements and NSA Security Evaluation Requirements Document (SERD).

Information Assurance (IA) Support

Supports Air Combat Command (the AF lead for Cyber Superiority) in Algorithm Transition Compliance and provides IA support by investigating and analyzing all utilized cryptographic algorithms and hundreds of cryptographic equipment types to support the transformation effort in becoming quantum resilient. This includes the development of prototyping efforts to include the development of software program of a centralized near real-time accountability of DAF COMSEC equipment that reports compliance to DAF/DoD Leadership. In addition, it will provide automated software updates to crypto devices (networked & non-networked), and field modernized cryptography, algorithms, and quantum computing.

Crypto Enterprise Management

Cryptographic Enterprise Management (CEM) will lead the continuous software development of an asset management and information system/application. The purpose of this application is to streamline current USAF NSA Controlled Cryptographic Item (CCI) management capabilities and provide enhanced traceability, accountability, and status. The effort will integrate data from currently fielded USAF logistics and supply chain management systems and then provide a holistic, connected enterprise view.

Remote Rekey Next Generation (RRK-NG), nicknamed Black Arrow

RRK-NG will lead development of a key distribution/management system providing the transmission of key material to control sites and unmanned remote sites. The development of RRK-NG is an NSA approved modernized cryptographic solution for use by the North American Aerospace Defense Command (NORAD) Tactical Air Defense mission for Eastern & Western defense sectors, Federal Aviation Administration (FAA) Air Traffic Control mission, with the capability to be releasable for foreign military sales.

Classified Data at Rest (CDAR)

Classified Date at Rest (CDAR) will provide the capability to render stored classified data ("at rest") unusable to adversaries if data storage is captured or compromised, eliminating policy compliance shortfalls via a small family of solutions made up of the KSV-270 Single-channel Inline Media Encryptor and KSV-271 Multi-channel Inline Media Encryptor. The development of CDAR is a set of NSA approved modernized cryptographic solution(s) for use in 45 Air Force platforms/systems exposed to hostile/uncontrolled environments. The enterprise cryptographic solution will encrypt/decrypt Top Secret and Below (TSAB) data at rest residing in a wide variety of data storage environments. KSV-271 will use FY26 funds to meet Security Evaluation Requirements Document 2.0 (SERD 2.0) requirements as mandated by the NSA. If not funded to implement these mandates, existing contractual work will not be certified by NSA, ultimately delaying the fielding of the Multi-channel CDAR (MCCDAR) solution to AF users that do not currently protect data at rest.

Identification Friend or Foe (IFF) Mode 5

Modernization of the IFF Mode 5 devices enables the warfighter to engage and accurately identify friendly or enemy forces as friend or foe. It prevents fratricide during target engagements and provides authentication and encryption/decryption services. The modernized devices will be quantum resilient and prevent enemy disruption of IFF functions. They will enhance the needed security for interrogations and response. These encryption devices operate within military aircraft, fixed, and transportable ground stations when connected to an interrogator and/or transponder. The IFF Mode 5 crypto modules KIV-77 and KIV-78 requires permanent modification. Alternative solutions shall be considered and not impact the existing form, fit, and function and shall follow NSA guidance for certification. The modification of these devices is required to address quantum threats (CM2), producibility and algorithm reprogrammability mandated by NSA and the 2019 Chairman of the Joint Chiefs of Staff Notice (CJCSN) 6510.

KG-3XA (Nuclear Command, Control, and Communications (NC3) Very Low Frequency (VLF) Capability)

KG-3XA 1067 modification will provide a transmit and receive quantum resilient compliant NSA approved cryptographic solution for the Very Low Frequency (VLF) Enterprise (KGV-363) and modernize legacy KG-3X cryptographic device (KG-333) to support Nuclear Command, Control, and Communications Center (NC3) missions. The KG-3XA development effort will deliver form, fit function cryptographic capabilities employed in air and group equipment to securely process emergency action messages. KGV-363 will use FY26 funds to meet Support Equipment Recommendation Data 2.0 (SERD 2.0) requirements as mandated by the NSA. If not funded to implement these mandates, existing contractual work will not be certified by the National Security Agency ultimately delaying the fielding of the QR upgrade for the VLF community.

Space COMSEC / Space Modular Common Crypto (SMCC)

Implements CM2 across space enterprise devices including Space Ground Operating Equipment (GOE) and orbital Aerospace Vehicle Equipment (AVE) supporting satellites of all sizes. These Space CM2 efforts will also increase the performance envelope for space crypto to support the emerging growth of space-based communications by increasing data throughput and number of channels supported per device. KG-210 GOE will use FY26 funds to meet Security Evaluation Requirements Document 2.0 (SERD 2.0) requirements as mandated by NSA. If not funded to implement these mandates, existing contractual work will not be certified by the NSA, ultimately delaying the fielding of the QR upgrade for the Space COMSEC community.

Budget line items(workbook-cited)

P-1/R-1 workbook Total Obligation Authority basis (USD thousands) · PB2026.

Exhibit R-1

AccountOrgTypeAmount
Research, Development, Test and Evaluation, Air ForceFFY24 Actuals$89.2M
Research, Development, Test and Evaluation, Air ForceFFY25 Enacted$94.4M
Research, Development, Test and Evaluation, Air ForceFFY25 Total$94.4M
Research, Development, Test and Evaluation, Air ForceFFY26 Disc. Request$98.4M
Research, Development, Test and Evaluation, Air ForceFFY26 Total$98.4M

Budget Details(R-2/P-40 facts)

J-book detail basis (R-2/P-40, USD millions) · PB2026 — a different accounting basis from the P-1/R-1 workbook TOA above; where the two disagree, the reconciliation strip under Budget figures shows both.

Wider than this screen — swipe the table sideways for the remaining fiscal-year columns.

ProjectAll Prior YearsFY24 ActualsFY25 TotalFY26 BaseFY26 Request
Program Element$0$89.2M$94.4M$98.4M$98.4M
675100: Cryptographic Modernization$0$56.8M$0$0$0
675200: Cryptographic Modernization 2 (CM2)$0$32.4M$94.4M$98.4M$98.4M

Follow the dollar

No follow-the-dollar view — none of this program's high-confidence awards records a positive obligation at any place of performance (flows cover 312 of 1,938 programs). why coverage is partial? →

Related awards

Award linkage is shown for 32 of 200 profiled companies — high- and medium-confidence USAspending matches, each row labeled; medium is the weaker evidence. why partial award coverage? →

RecipientPIIDConfidence
RAYTHEON COMPANYFA830717D0015high

Contractor concentration

No concentration index is published for this line. This line's high-confidence links do not clear the floor for a published concentration index — at least 3 awards across 2 contractor families holding positive obligations, with positive net linked dollars. An index below that floor is a fact about the sample, not about the market. Whatever further links this line carries are medium-confidence, and what each medium evidence path does and does not establish is set out in the methodology. Both bases are in the downloadable warehouse.

Lobbying mentions

No Senate LDA lobbying filing in the tracked data mentions this program element by code or alias.

Oversight

Department-level designation (not specific to this program)

GAO lists 5 high-risk areas for DOD as a whole. That designation covers the department, not Information Systems Security Program. No program-specific GAO finding for this line is in the ingested data. See the DOD oversight record.

Program dossier

No research dossier for this program — dossiers cover 50 of 1,938 programs, the largest fully J-book-detailed lines by FY2026 requested dollars. why no dossier here? →

Primary sources

Open any budget figure for its exact receipt. Verified line items lead with the highlighted government PDF; original spreadsheets download with their budget edition and exhibit in the filename.

Budget totals · TOA sources

Detailed budget justification

The related TOA spreadsheets above use a different accounting basis from R-2/P-40 detail. Their amounts are not assumed to match these detailed sources.