Skip to content
Fiscal Receipts

Assessments and Evaluations Cyber Vulnerabilities

ARDT&EFully Reconciled0606942A
What it is
Assessments and Evaluations Cyber Vulnerabilities — a research & development program run by Army.
What changed
-$3.75M FY25→26
Who gets it
No award linkage at high confidence.

Budget Figures

FY24 Actuals
$6.03M
FY25 Total
$10.1M
FY26 Request
$6.35M
FY25→26 Change
-$3.75M

FY2026 award data is a partial year — USASpending awards are reported on a rolling basis and the fiscal year does not close until September 30. why partial FY2026 data? →

Budget Trajectory
FY24: $6.03MFY25: $10.1MFY26: $6.35MFY24FY25FY26
FY24
$6.03M
FY25
$10.1M
FY26
$6.35M
Decade view — each figure cites its own President's Budget edition
FY2017 actuals — PB2019 editionFY2018 actuals — PB2020 editionFY2019 actuals — PB2021 editionFY2020 actuals — PB2022 editionFY2021 actuals — PB2023 editionFY2022 actuals — PB2024 editionFY2023 actuals — PB2025 editionFY2024 actuals — PB2026 editionFY2018 enacted — PB2019 editionFY2019 enacted — PB2020 editionFY2020 enacted — PB2021 editionFY2021 enacted — PB2022 editionFY2022 enacted — PB2023 editionFY2023 enacted — PB2024 editionFY2024 enacted — PB2025 editionFY2025 enacted — PB2026 editionFY2019 request — PB2019 editionFY2020 request — PB2020 editionFY2021 request — PB2021 editionFY2022 request — PB2022 editionFY2023 request — PB2023 editionFY2024 request — PB2024 editionFY2025 request — PB2025 editionFY2026 request — PB2026 editionFY17FY26

● actuals (line)  ·  ○ enacted  ·  ◇ request — gaps are editions the program is absent from, never interpolated.

SeriesFY17FY18FY19FY20FY21FY22FY23FY24FY25FY26
Actuals$0$0$88.3M$4.50M$6.50M$5.47M$5.82M$6.03M
Enacted$0$88.3M$4.50M$6.50M$5.47M$5.82M$6.03M$10.1M
Request$88.3M$4.50M$4.50M$5.47M$5.82M$6.03M$10.1M$6.35M

blank = series not published for this year; – = absent from that edition.

Asked vs spent: the PB2021 book requested $4.50M for FY2021; the PB2023 book reports $6.50M actually spent — $2.00M above the request.

Program Lineage

No predecessor/successor lineage was recorded for this program element — no FY-to-FY transfer into or out of this line was stated in the ingested J-books, and none was inferred from the program structure.

Description

Mission Assessments and Evaluations Cyber Vulnerabilities

This funding line reduces the Army's risk to adversarial cyber intrusions or attacks that could compromise critical weapon/business systems and kill chains. Cyberspace Operational-Resilience Assessment - Platform (CORA-P) is the Army program to improve survivability across Army modernization efforts and maintain readiness of operational capabilities. CORA-P addresses Congressional requirements beginning with FY16 NDAA Section-1647, and through FY24 NDAA Section-1502, which directs the Services to identify and mitigate cyberspace vulnerabilities in critical weapon systems. Under CORA-P, the Army identifies and prioritizes capabilities most-relevant to National Defense Strategy priorities based on input from mission planning, JROC guidance, and sensitive threat intelligence. The Army then reviews the security posture of these critical components, develops remediation strategies, and facilitates delivery of fixes at mission-relevant speed. CORA-P is helping move the DoD from system-oriented compliance to system-of-systems resilience that addresses defensive gaps between individual components; this is necessary to prevent adversaries from denying critical kill chains. CORA-P ensures Army cyberspace remediation investments address areas of highest operational risk.

Mission Cyber Vulnerabilities Assessments and Evaluations

This funding line reduces the Army's risk to adversarial cyber intrusions or attacks that could compromise critical weapon systems and kill chains. Cyberspace Operational-Resilience Assessment - Platform (CORA-P) is the Army program to improve survivability across Army modernization efforts and maintain readiness of operational capabilities. CORA-P addresses the requirements of Section 1502 of the FY24 NDAA, which directed the Services to harmonize the identification and mitigation cyberspace vulnerabilities in critical weapon systems. Headquarters, Department of the Army initially established CORA-P to continue Section 1647 assessments, while expanding to include supply chain risk analysis and electromagnetic spectrum vulnerabilities. CORA-P has since shifted from executing new assessments to harmonizing defensive efforts across existing Army and DoD assessment programs (including the Strategic Cybersecurity Program). CORA-P now focuses on developing and delivering vulnerability remediations that result from these assessments as well as from sensitive threat intelligence and other potential indicators of compromise. Activities include improving the structure and visibility of vulnerability data to improve portfolio risk management, initiating remediation efforts for high-priority, crosscutting issues, and avoiding future risks by driving improvements earlier in materiel development for modernization programs. As part of CORA-P, the Army identifies and prioritizes capabilities most-relevant to National Defense Strategy priorities based on input from mission planning, JROC guidance, and sensitive threat intelligence. This also includes coordinating Army Cyber Command lead Crisis Action Teams, where specific vulnerabilities affect the Army weapon/business systems. A key aspect is integrating efforts across both HQDA and Army Commands to understand total risk exposure while avoiding duplication. The Army then reviews the security posture of these critical components, develops remediation strategies, and facilitates delivery of fixes at mission-relevant speed. This includes working with program offices, capability managers, and resource managers to develop realistic plans of action for manage risk across outyears, and then gaining Army Senior Leader approval as needed. CORA-P ensures Army cyberspace remediation investments address areas of highest operational risk. When applicable, this PE also provides for Red Team enhancement to support Combatant Command mission-level cyber vulnerability assessments.

Justification

Accomplishments & Planned Programs (2)

Red Team

The Army Acquisition Red Team will provide Red Team capability to test emerging and evolving DoD/Army capabilities against operationally relevant and realistic threats. Red Teaming of emerging technologies is critical to testing Army modernization efforts and evaluation of how it will conduct Multi-Domain Operations. The Army Acquisition Red Team provides Persistent Cyber Operations (PCO) at the COCOM mission level, develops adversary techniques, tactics, and procedures (TTPs), conducts broad assessments of Science and Technology (S&T) and acquisition office environments and industrial base assets, as well as provide PCO, Close Access Assessments, and Adversarial Assessments in support of Section 1647 of the 2016 National Defense Authorization Act.

Cyberspace Operational Resiliency Assessment - Platform (CORA-P)

This funding line reduces the Army's risk to adversarial cyber intrusions or attacks that could compromise critical weapon systems and kill chains. Cyberspace Operational-Resilience Assessment - Platform (CORA-P) is the Army program to improve survivability across Army modernization efforts and maintain readiness of operational capabilities. CORA-P addresses the requirements of Section 1502 of the FY24 NDAA, which directed the Services to harmonize the identification and mitigation cyberspace vulnerabilities in critical weapon systems. Headquarters, Department of the Army initially established CORA-P to continue Section 1647 assessments, while expanding to include supply chain risk analysis and electromagnetic spectrum vulnerabilities. CORA-P has since shifted from executing new assessments to harmonizing defensive efforts across existing Army and DoD assessment programs (including the Strategic Cybersecurity Program). CORA-P now focuses on developing and delivering vulnerability remediations that result from these assessments as well as from sensitive threat intelligence and other potential indicators of compromise. Activities include improving the structure and visibility of vulnerability data to improve portfolio risk management, initiating remediation efforts for high-priority, crosscutting issues, and avoiding future risks by driving improvements earlier in materiel development for modernization programs. As part of CORA-P, the Army identifies and prioritizes capabilities most-relevant to National Defense Strategy priorities based on input from mission planning, JROC guidance, and sensitive threat intelligence. This also includes coordinating Army Cyber Command lead Crisis Action Teams, where specific vulnerabilities affect the Army weapon/business systems. A key aspect is integrating efforts across both HQDA and Army Commands to understand total risk exposure while avoiding duplication. The Army then reviews the security posture of these critical components, develops remediation strategies, and facilitates delivery of fixes at mission-relevant speed. This includes working with program offices, capability managers, and resource managers to develop realistic plans of action for manage risk across outyears, and then gaining Army Senior Leader approval as needed. CORA-P ensures Army cyberspace remediation investments address areas of highest operational risk.

Budget Line Items(workbook-cited)

Exhibit R-1

AccountOrgTypeAmount
Research, Development, Test and Evaluation, ArmyAFY24 Actuals$6.03M
Research, Development, Test and Evaluation, ArmyAFY25 Enacted$10.1M
Research, Development, Test and Evaluation, ArmyAFY25 Total$10.1M
Research, Development, Test and Evaluation, ArmyAFY26 Disc. Request$6.35M
Research, Development, Test and Evaluation, ArmyAFY26 Total$6.35M

Budget Details(R-2/P-40 facts)

ProjectFY24 ActualsFY25 TotalFY26 BaseFY26 Request
FL2: Cyber Vulnerabilities Assessments and Evaluations$6.03M$10.1M$6.35M$6.35M
Program Element$6.03M$10.1M$6.35M$6.35M

No follow-the-dollar view — this program's awards haven't been crosswalked at high confidence (flows cover 17 of 1741 programs). why coverage is partial? →

Awards

No awards are linked to this program element at high confidence — the budget→award crosswalk only asserts links it can defend, and this line has none yet.

Lobbying Mentions

No Senate LDA lobbying filing in the tracked data mentions this program element by code or alias.

No research dossier for this program — dossiers cover 50 of 1741 programs, the largest fully J-book-detailed lines by FY2026 requested dollars. why no dossier here? →