Printed from https://fiscalreceipts.com/program/0303140F/ — data as of July 28, 2026. Every figure is citation-backed; see the page online for per-number provenance.
Information Systems Security Program
Budget Figures
FY2026 award data is a partial year — USASpending awards are reported on a rolling basis and the fiscal year does not close until September 30. why partial FY2026 data? →
- FY24
- $89.2M
- FY25
- $94.4M
- FY26
- $98.4M
● actuals (line) · ○ enacted · ◇ request — gaps are editions the program is absent from, never interpolated.
| Series | FY15 | FY16 | FY17 | FY18 | FY19 | FY20 | FY21 | FY22 | FY23 | FY24 | FY25 | FY26 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Actuals | $65.0M | $44.6M | $36.1M | $41.1M | $35.8M | $26.7M | $9.59M | $12.8M | $63.0M | $89.2M | ||
| Enacted | $46.3M | $46.4M | $43.0M | $34.0M | $27.7M | $10.4M | $8.03M | $70.3M | $95.5M | $94.4M | ||
| Request | $46.4M | $43.0M | $34.6M | $27.7M | $10.4M | $8.03M | $70.6M | $95.5M | $94.4M | $98.4M |
blank = series not published for this year; – = absent from that edition.
Asked vs spent: the PB2017 book requested $46.4M for FY2017; the PB2019 book reports $36.1M actually spent — $10.3M below the request.
Program Lineage
No predecessor/successor lineage was recorded for this program element — no FY-to-FY transfer into or out of this line was stated in the ingested J-books, and none was inferred from the program structure.
Description
Mission — Cryptographic Modernization
The DAF Cryptographic Modernization (CM) effort modernizes cryptographic devices protecting critical national security information across multi-domain operations. This DAF effort supports an integrated effort across the cyber domain to transform to next-generation cryptographic capabilities. It provides U.S. forces and multinational and interagency partners the multi-domain security needed to protect the flow and exchange of strategic, operational, and tactical information in accordance with national and international policy/standards, and the validated requirements of decision makers, warfighters, and the intelligence community. The AF Cryptographic Modernization 2 (CM2) effort is required by Chairman Joint Chiefs of Staff Notice (CJCSN) 6510 and NSA Decertification Messages (CED-31-15/037-21/032-16) for the need to add quantum resistance to the existing high assurance cryptographic products. This effort will allow protection against advanced & evolving quantum computing threats. All existing crypto devices will be vulnerable and must be modernized to be quantum resilient. The majority of the development effort includes hardware changes to the existing crypto devices. The CM effort is a holistic DAF-wide "modern” cryptographic strategy to provide long-term, evolving protection of NC3, ISR, PKI, KME, and nearly all AF platforms and ground networks. CM will provide the required enhanced security for all DAF voice, data, and video capabilities on the battlefield and throughout the DoD enterprise and will enable the integration of new capabilities to DAF users through development of a new DoD CM2 Initial Capabilities Document (ICD) dated 15 July 2021. This program element may include necessary civilian pay expenses required to manage, execute, and deliver weapon system capability. The use of such programs funds would be in addition to the civilian pay expenses budgeted in program element 0605829F, 0605831F, 0605833F, or 0605898F. In FY 2024 2.074M was expended for civilian pay expenses in this program element, and in FY 2025 3.894M is forecasted for civilian pay expenses in this program element.
Mission — Information Systems Security Program
Information Systems Security Program (ISSP) - Includes resources, manpower authorizations, necessary facilities and equipment required to develop, deliver, and sustain Cryptographic Modernization (CM) capabilities to nearly all Department of the Air Force (DAF) weapon systems that encrypt/decrypt sensitive information. CM ensures confidentiality, integrity, and availability of the information and the systems. The CM work done in the Information Systems Security Program (ISSP) ensures that DAF systems receive cryptographic capabilities that are compliant with National Security Agency (NSA) mandates and that commanders can confidently leverage for Joint All Domain Command and Control (JADC2) capabilities. The ISSP Element and associated CM activities provide a foundational Communications Security (COMSEC) capability that is the first and last line of cyber defense against adversary exploitation. The DAF and the DoD require the capability to securely collect, process, store, and disseminate an uninterrupted flow of information, while denying an adversary the ability to intercept, collect, destroy, interpret, or manipulate our information flows. CM provides secure communication to allow the DoD to achieve and maintain decision superiority, the key to successful application of the military instrument of national power in modern full-spectrum operations. DAF COMSEC equipment protects sensitive information such as warfighter positions, mission planning, target strikes, commanders' orders, intelligence, force strength, and force readiness. When an adversary is capable of interpretation, manipulation, or destruction of the information used by the warfighter, DoD military forces will suffer significant and/or devastating mission degradation that can result in loss of life and resources and/or exceptionally grave damage to national security. The advanced threats and capabilities of near-peer adversaries will necessitate the exclusion of weapon systems with obsolete cryptography from Combatant Commander Areas of Responsibility (AORs)—diminishing the ability of the DAF to communicate securely in a high-end fight. The 2021 National Defense Authorization Act (NDAA) mandates the services begin reporting on their CM activities and status of obsolete products starting in Jan 2022, as well as the National Security Memorandum 10 (4 May 2022) which identifies the need for quantum-resistant crypto. These documents highlight the high importance of ISSP efforts. The overall focus of the Research, Development, Test, and Evaluation (RDT&E) efforts within the ISSP program is to transform current CM devices to protect against current technology threats, which include quantum computing. The modernization effort is required by Chairman Joint Chiefs of Staff Notice (CJCSN) 6510 and NSA Decertification Messages (CED-31-15/037-21/032-16) from FY23 for the need to add Quantum Resilience (QR) to the existing high assurance cryptographic products. This effort will allow protection against advanced & evolving quantum computing threats. All existing crypto devices will be vulnerable and must be modernized to be quantum resilient. These efforts are driven by the NSA requirements to implement newly developed Quantum Resistant Algorithms (QRAs). The NSA requires an inventory of cryptographic devices that are more resilient to future threats through full software re-programmability. This will enable protection against near peer adversary exploitation and provide the ability to rapidly adapt against newer threats. This program element may include necessary civilian pay expenses required to manage, execute, and deliver weapon system capability. The use of such program's funds would be in addition to the civilian pay expenses budgeted in program element 0605829F, 0605831F, 0605833F, or 0605898F. In FY 2024 2.074M was expended for civilian pay expenses in this program element, and in FY 2025 3.894M is forecasted for civilian pay expenses in this program element. This program is in Budget Activity 7, Operational System Development because this budget activity includes development efforts to upgrade systems that have been fielded or have received approval for full rate production and anticipate production funding in the current or subsequent fiscal year.
Mission — Cryptographic Modernization 2 (CM2)
The Department of the Air Force (DAF) Cryptographic Modernization 2 (CM2) effort modernizes cryptographic devices protecting critical national security information across multi-domain operations. This DAF effort supports an integrated effort across the cyber domain to transform to next-generation cryptographic capabilities. It provides U.S. forces and multinational and interagency partners the multi-domain security needed to protect the flow and exchange of strategic, operational, and tactical information in accordance with national and international policy/standards, and the validated requirements of decision makers, warfighters, and the intelligence community. CM2 modernization is required by Chairman Joint Chiefs of Staff Notice (CJCSN) 6510 and National Security Agency (NSA) Decertification Messages (CED-31-15/037-21/032-16) from FY23 for the need to add Quantum Resilience (QR) to the existing high assurance cryptographic products. This effort will allow protection against advanced & evolving quantum computing threats. All existing crypto devices will be vulnerable and must be modernized to be quantum resilient. The CM2 effort is a holistic Air Force wide "modern” cryptographic strategy to provide long-term, evolving protection of Nuclear Command, Control, and Communications (NC3), Intelligence, Surveillance, Reconnaissance (ISR), Public Key Infrastructure (PKI), Key Management Enterprise (KME), and nearly all DAF platforms, ground and space networks. CM2 will provide the required enhanced security for all DAF voice, data, and video capabilities on the battlefield and throughout the DoD enterprise. In addition to the development /modernization of the devices, this effort requires studies, proof of concepts, and prototype efforts to accurately address the evolving quantum computing threats in the years to come and ramp up efforts accordingly. This program element may include necessary civilian pay expenses required to manage, execute, and deliver weapon system capability. The use of such program's funds would be in addition to the civilian pay expenses budgeted in program element 0605829F, 0605831F, 0605833F, or 0605898F. In FY 2024 2.074M was expended for civilian pay expenses in this program element, and in FY 2025 3.894M is forecasted for civilian pay expenses in this program element.
Justification
Accomplishments & Planned Programs (13)
Classified Data at Rest (CDAR)
Classified Date at Rest (CDAR) will provide the capability to render stored classified data ("at rest") unusable to adversaries if data storage is captured or compromised, eliminating policy compliance shortfalls via a small family of solutions made up of the KSV-270 Single-channel Inline Media Encryptor and KSV-271 Multi-channel Inline Media Encryptor. The development of CDAR is a set of NSA approved modernized cryptographic solution(s) for use in 45 Air Force platforms/systems exposed to hostile/uncontrolled environments. The enterprise cryptographic solution will encrypt/decrypt Top Secret and Below (TSAB) data at rest residing in a wide variety of data storage environments. KSV-271 will use FY26 funds to meet Security Evaluation Requirements Document 2.0 (SERD 2.0) requirements as mandated by the NSA. If not funded to implement these mandates, existing contractual work will not be certified by NSA, ultimately delaying the fielding of the Multi-channel CDAR (MCCDAR) solution to AF users that do not currently protect data at rest.
Identification Friend or Foe (IFF) Mode 5
Modernization of the IFF Mode 5 devices enables the warfighter to engage and accurately identify friendly or enemy forces as friend or foe. It prevents fratricide during target engagements and provides authentication and encryption/decryption services. The modernized devices will be quantum resilient and prevent enemy disruption of IFF functions. They will enhance the needed security for interrogations and response. These encryption devices operate within military aircraft, fixed, and transportable ground stations when connected to an interrogator and/or transponder. The IFF Mode 5 crypto modules KIV-77 and KIV-78 requires permanent modification. Alternative solutions shall be considered and not impact the existing form, fit, and function and shall follow NSA guidance for certification. The modification of these devices is required to address quantum threats (CM2), producibility and algorithm reprogrammability mandated by NSA and the 2019 Chairman of the Joint Chiefs of Staff Notice (CJCSN) 6510.
Technology Development (TD)
Technology Development (TD) provides the technical maturation efforts needed to posture for the current and upcoming quantum computing threats, as well as comply with NSA threat timelines. The maturation of these efforts will provide an enterprise approach to modular open system architectures.
Identification Friend or Foe (IFF) Mode 5
Modernization of IFF Mode 5 devices enables the warfighter to engage and accurately identify friendly or enemy forces as friend or foe. It prevents fratricide during target engagements and provides authentication and encryption/decryption services. The modernized devices will be quantum resilient and prevent enemy disruption of IFF functions. They will enhance the needed security for interrogations and response. These encryption devices operate within military aircraft, fixed, and transportable ground stations when connected to an interrogator and/or transponder. The IFF Mode 5 crypto modules KIV-77 and KIV-78 requires permanent modification. The modification of these devices is required to address quantum threats, producibility and algorithm reprogrammability mandated by the NSA and the 2019 CJCSN 6510.
Algorithm Transition Compliance and Support
Supports Air Combat Command (AF lead for Cyber Superiority) in Algorithm Transition Compliance and provides Information Assurance (IA) support by investigating and analyzing all utilized cryptographic algorithms and hundreds of cryptographic equipment types to support the transformation effort in becoming quantum resilient. This includes the development of prototyping efforts to include the development of a software program of a centralized near real-time accountability of AF COMSEC equipment that reports compliance to AF/DoD Leadership. In addition, it will provide automated software updates to crypto devices (networked & non-networked), and field modernized cryptography, algorithms, and quantum computing.
Space Modular Common Crypto (SMCC)
SMCC architecture is being studied for quantum resilient impacts.
Classified Data At Rest (CDAR)
CDAR will provide the capability to render classified data at rest unusable to adversaries if data storage is captured or compromised, eliminating policy compliance shortfalls. The development of CDAR is an NSA approved modernized cryptographic solution(s) for use in 45 Air Force platforms/systems exposed to hostile/uncontrolled environments. The enterprise cryptographic solution will encrypt/decrypt Top Secret and Below (TSAB) data at rest residing in a variety of data storage environments.
Technology Development (TD)
CM2 TD will provide crypto devices with enterprise solutions that are more robust, modular, scalable, and provide durability to existing cryptographic end items, as well as updating midterm aging/unsupportable crypto equipment. All existing crypto devices will be vulnerable and must be modernized to be QR. The development efforts include hardware and software changes to the existing crypto devices while identifying new efforts necessary for development to address the refined CM2 Threshold Requirements and NSA Security Evaluation Requirements Document (SERD).
Information Assurance (IA) Support
Supports Air Combat Command (the AF lead for Cyber Superiority) in Algorithm Transition Compliance and provides IA support by investigating and analyzing all utilized cryptographic algorithms and hundreds of cryptographic equipment types to support the transformation effort in becoming quantum resilient. This includes the development of prototyping efforts to include the development of software program of a centralized near real-time accountability of DAF COMSEC equipment that reports compliance to DAF/DoD Leadership. In addition, it will provide automated software updates to crypto devices (networked & non-networked), and field modernized cryptography, algorithms, and quantum computing.
Crypto Enterprise Management
Cryptographic Enterprise Management (CEM) will lead the continuous software development of an asset management and information system/application. The purpose of this application is to streamline current USAF NSA Controlled Cryptographic Item (CCI) management capabilities and provide enhanced traceability, accountability, and status. The effort will integrate data from currently fielded USAF logistics and supply chain management systems and then provide a holistic, connected enterprise view.
Remote Rekey Next Generation (RRK-NG), nicknamed Black Arrow
RRK-NG will lead development of a key distribution/management system providing the transmission of key material to control sites and unmanned remote sites. The development of RRK-NG is an NSA approved modernized cryptographic solution for use by the North American Aerospace Defense Command (NORAD) Tactical Air Defense mission for Eastern & Western defense sectors, Federal Aviation Administration (FAA) Air Traffic Control mission, with the capability to be releasable for foreign military sales.
KG-3XA (Nuclear Command, Control, and Communications (NC3) Very Low Frequency (VLF) Capability)
KG-3XA 1067 modification will provide a transmit and receive quantum resilient compliant NSA approved cryptographic solution for the Very Low Frequency (VLF) Enterprise (KGV-363) and modernize legacy KG-3X cryptographic device (KG-333) to support Nuclear Command, Control, and Communications Center (NC3) missions. The KG-3XA development effort will deliver form, fit function cryptographic capabilities employed in air and group equipment to securely process emergency action messages. KGV-363 will use FY26 funds to meet Support Equipment Recommendation Data 2.0 (SERD 2.0) requirements as mandated by the NSA. If not funded to implement these mandates, existing contractual work will not be certified by the National Security Agency ultimately delaying the fielding of the QR upgrade for the VLF community.
Space COMSEC / Space Modular Common Crypto (SMCC)
Implements CM2 across space enterprise devices including Space Ground Operating Equipment (GOE) and orbital Aerospace Vehicle Equipment (AVE) supporting satellites of all sizes. These Space CM2 efforts will also increase the performance envelope for space crypto to support the emerging growth of space-based communications by increasing data throughput and number of channels supported per device. KG-210 GOE will use FY26 funds to meet Security Evaluation Requirements Document 2.0 (SERD 2.0) requirements as mandated by NSA. If not funded to implement these mandates, existing contractual work will not be certified by the NSA, ultimately delaying the fielding of the QR upgrade for the Space COMSEC community.
Budget Line Items(workbook-cited)
Exhibit R-1
| Account | Org | Type | Amount |
|---|---|---|---|
| Research, Development, Test and Evaluation, Air Force | F | FY24 Actuals | $89.2M |
| Research, Development, Test and Evaluation, Air Force | F | FY25 Enacted | $94.4M |
| Research, Development, Test and Evaluation, Air Force | F | FY25 Total | $94.4M |
| Research, Development, Test and Evaluation, Air Force | F | FY26 Disc. Request | $98.4M |
| Research, Development, Test and Evaluation, Air Force | F | FY26 Total | $98.4M |
Budget Details(R-2/P-40 facts)
| Project | All Prior Years | FY24 Actuals | FY25 Total | FY26 Base | FY26 Request |
|---|---|---|---|---|---|
| Program Element | $0 | $89.2M | $94.4M | $98.4M | $98.4M |
| 675100: Cryptographic Modernization | $0 | $56.8M | $0 | $0 | $0 |
| 675200: Cryptographic Modernization 2 (CM2) | $0 | $32.4M | $94.4M | $98.4M | $98.4M |
No follow-the-dollar view — this program's awards haven't been crosswalked at high confidence (flows cover 17 of 1741 programs). why coverage is partial? →
Awards
No awards are linked to this program element at high confidence — the budget→award crosswalk only asserts links it can defend, and this line has none yet.
Lobbying Mentions
No Senate LDA lobbying filing in the tracked data mentions this program element by code or alias.
No research dossier for this program — dossiers cover 50 of 1741 programs, the largest fully J-book-detailed lines by FY2026 requested dollars. why no dossier here? →