Printed from https://fiscalreceipts.com/program/0606942A/ — data as of July 28, 2026. Every figure is citation-backed; see the page online for per-number provenance.
Assessments and Evaluations Cyber Vulnerabilities
Budget Figures
FY2026 award data is a partial year — USASpending awards are reported on a rolling basis and the fiscal year does not close until September 30. why partial FY2026 data? →
- FY24
- $6.03M
- FY25
- $10.1M
- FY26
- $6.35M
● actuals (line) · ○ enacted · ◇ request — gaps are editions the program is absent from, never interpolated.
| Series | FY17 | FY18 | FY19 | FY20 | FY21 | FY22 | FY23 | FY24 | FY25 | FY26 |
|---|---|---|---|---|---|---|---|---|---|---|
| Actuals | $0 | $0 | $88.3M | $4.50M | $6.50M | $5.47M | $5.82M | $6.03M | ||
| Enacted | – | $0 | $88.3M | $4.50M | $6.50M | $5.47M | $5.82M | $6.03M | $10.1M | |
| Request | – | – | $88.3M | $4.50M | $4.50M | $5.47M | $5.82M | $6.03M | $10.1M | $6.35M |
blank = series not published for this year; – = absent from that edition.
Asked vs spent: the PB2021 book requested $4.50M for FY2021; the PB2023 book reports $6.50M actually spent — $2.00M above the request.
Program Lineage
No predecessor/successor lineage was recorded for this program element — no FY-to-FY transfer into or out of this line was stated in the ingested J-books, and none was inferred from the program structure.
Description
Mission — Assessments and Evaluations Cyber Vulnerabilities
This funding line reduces the Army's risk to adversarial cyber intrusions or attacks that could compromise critical weapon/business systems and kill chains. Cyberspace Operational-Resilience Assessment - Platform (CORA-P) is the Army program to improve survivability across Army modernization efforts and maintain readiness of operational capabilities. CORA-P addresses Congressional requirements beginning with FY16 NDAA Section-1647, and through FY24 NDAA Section-1502, which directs the Services to identify and mitigate cyberspace vulnerabilities in critical weapon systems. Under CORA-P, the Army identifies and prioritizes capabilities most-relevant to National Defense Strategy priorities based on input from mission planning, JROC guidance, and sensitive threat intelligence. The Army then reviews the security posture of these critical components, develops remediation strategies, and facilitates delivery of fixes at mission-relevant speed. CORA-P is helping move the DoD from system-oriented compliance to system-of-systems resilience that addresses defensive gaps between individual components; this is necessary to prevent adversaries from denying critical kill chains. CORA-P ensures Army cyberspace remediation investments address areas of highest operational risk.
Mission — Cyber Vulnerabilities Assessments and Evaluations
This funding line reduces the Army's risk to adversarial cyber intrusions or attacks that could compromise critical weapon systems and kill chains. Cyberspace Operational-Resilience Assessment - Platform (CORA-P) is the Army program to improve survivability across Army modernization efforts and maintain readiness of operational capabilities. CORA-P addresses the requirements of Section 1502 of the FY24 NDAA, which directed the Services to harmonize the identification and mitigation cyberspace vulnerabilities in critical weapon systems. Headquarters, Department of the Army initially established CORA-P to continue Section 1647 assessments, while expanding to include supply chain risk analysis and electromagnetic spectrum vulnerabilities. CORA-P has since shifted from executing new assessments to harmonizing defensive efforts across existing Army and DoD assessment programs (including the Strategic Cybersecurity Program). CORA-P now focuses on developing and delivering vulnerability remediations that result from these assessments as well as from sensitive threat intelligence and other potential indicators of compromise. Activities include improving the structure and visibility of vulnerability data to improve portfolio risk management, initiating remediation efforts for high-priority, crosscutting issues, and avoiding future risks by driving improvements earlier in materiel development for modernization programs. As part of CORA-P, the Army identifies and prioritizes capabilities most-relevant to National Defense Strategy priorities based on input from mission planning, JROC guidance, and sensitive threat intelligence. This also includes coordinating Army Cyber Command lead Crisis Action Teams, where specific vulnerabilities affect the Army weapon/business systems. A key aspect is integrating efforts across both HQDA and Army Commands to understand total risk exposure while avoiding duplication. The Army then reviews the security posture of these critical components, develops remediation strategies, and facilitates delivery of fixes at mission-relevant speed. This includes working with program offices, capability managers, and resource managers to develop realistic plans of action for manage risk across outyears, and then gaining Army Senior Leader approval as needed. CORA-P ensures Army cyberspace remediation investments address areas of highest operational risk. When applicable, this PE also provides for Red Team enhancement to support Combatant Command mission-level cyber vulnerability assessments.
Justification
Accomplishments & Planned Programs (2)
Red Team
The Army Acquisition Red Team will provide Red Team capability to test emerging and evolving DoD/Army capabilities against operationally relevant and realistic threats. Red Teaming of emerging technologies is critical to testing Army modernization efforts and evaluation of how it will conduct Multi-Domain Operations. The Army Acquisition Red Team provides Persistent Cyber Operations (PCO) at the COCOM mission level, develops adversary techniques, tactics, and procedures (TTPs), conducts broad assessments of Science and Technology (S&T) and acquisition office environments and industrial base assets, as well as provide PCO, Close Access Assessments, and Adversarial Assessments in support of Section 1647 of the 2016 National Defense Authorization Act.
Cyberspace Operational Resiliency Assessment - Platform (CORA-P)
This funding line reduces the Army's risk to adversarial cyber intrusions or attacks that could compromise critical weapon systems and kill chains. Cyberspace Operational-Resilience Assessment - Platform (CORA-P) is the Army program to improve survivability across Army modernization efforts and maintain readiness of operational capabilities. CORA-P addresses the requirements of Section 1502 of the FY24 NDAA, which directed the Services to harmonize the identification and mitigation cyberspace vulnerabilities in critical weapon systems. Headquarters, Department of the Army initially established CORA-P to continue Section 1647 assessments, while expanding to include supply chain risk analysis and electromagnetic spectrum vulnerabilities. CORA-P has since shifted from executing new assessments to harmonizing defensive efforts across existing Army and DoD assessment programs (including the Strategic Cybersecurity Program). CORA-P now focuses on developing and delivering vulnerability remediations that result from these assessments as well as from sensitive threat intelligence and other potential indicators of compromise. Activities include improving the structure and visibility of vulnerability data to improve portfolio risk management, initiating remediation efforts for high-priority, crosscutting issues, and avoiding future risks by driving improvements earlier in materiel development for modernization programs. As part of CORA-P, the Army identifies and prioritizes capabilities most-relevant to National Defense Strategy priorities based on input from mission planning, JROC guidance, and sensitive threat intelligence. This also includes coordinating Army Cyber Command lead Crisis Action Teams, where specific vulnerabilities affect the Army weapon/business systems. A key aspect is integrating efforts across both HQDA and Army Commands to understand total risk exposure while avoiding duplication. The Army then reviews the security posture of these critical components, develops remediation strategies, and facilitates delivery of fixes at mission-relevant speed. This includes working with program offices, capability managers, and resource managers to develop realistic plans of action for manage risk across outyears, and then gaining Army Senior Leader approval as needed. CORA-P ensures Army cyberspace remediation investments address areas of highest operational risk.
Budget Line Items(workbook-cited)
Exhibit R-1
| Account | Org | Type | Amount |
|---|---|---|---|
| Research, Development, Test and Evaluation, Army | A | FY24 Actuals | $6.03M |
| Research, Development, Test and Evaluation, Army | A | FY25 Enacted | $10.1M |
| Research, Development, Test and Evaluation, Army | A | FY25 Total | $10.1M |
| Research, Development, Test and Evaluation, Army | A | FY26 Disc. Request | $6.35M |
| Research, Development, Test and Evaluation, Army | A | FY26 Total | $6.35M |
Budget Details(R-2/P-40 facts)
| Project | FY24 Actuals | FY25 Total | FY26 Base | FY26 Request |
|---|---|---|---|---|
| FL2: Cyber Vulnerabilities Assessments and Evaluations | $6.03M | $10.1M | $6.35M | $6.35M |
| Program Element | $6.03M | $10.1M | $6.35M | $6.35M |
No follow-the-dollar view — this program's awards haven't been crosswalked at high confidence (flows cover 17 of 1741 programs). why coverage is partial? →
Awards
No awards are linked to this program element at high confidence — the budget→award crosswalk only asserts links it can defend, and this line has none yet.
Lobbying Mentions
No Senate LDA lobbying filing in the tracked data mentions this program element by code or alias.
No research dossier for this program — dossiers cover 50 of 1741 programs, the largest fully J-book-detailed lines by FY2026 requested dollars. why no dossier here? →