The Business of Cyber Security

The Federal Cyber Budget & Appropriations

In April 2026 the administration released its FY2027 President's Budget Request, and for the cyber-services world the result was bifurcated: a $1.5 trillion defense topline that raised military cyber investment, paired with a civilian-side proposal that cut CISA's gross appropriation request to ~$2.49B and eliminated roughly 867 positions — bringing the lead civilian cyber agency down to about 2,865 employees (per the DHS FY2027 budget-in-brief and CRS analysis). That split — defense up, civilian flat-to-down — is a central macro variable for a government-exposed cyber asset. The federal budget is the demand floor beneath the integrators (14a), the certified product vendors (16d), and a large slice of the threat-intelligence and zero-trust markets.

Appropriation is a multi-stage pipeline

The federal cyber budget is not a single number. It moves through four distinct gates, and an asset's exposure to each gate determines how cyclical its government revenue is. (1) The President's Budget Request (PBR) — released each spring, it is a proposal, not money; the FY2027 PBR landed ~Apr 2026. (2) Congressional appropriations — the twelve appropriations bills (or, increasingly, a continuing resolution) that actually enact funding; in recent years cyber has more often been funded under CRs at prior-year levels than under fresh full-year bills, which freezes new-start programs. (3) Obligation — an agency putting the money on a contract vehicle (14c). (4) Outlay — cash actually paid. The lag from PBR to outlay can run 12–36 months, which is why government cyber revenue is counter-cyclical to commercial demand but lagging and lumpy, and why a CR or a shutdown threat delays catalysts for a government-heavy target.

Defense up, civilian flat-to-down: the FY2027 cyber request, ~$26.7B FY2027 President's Budget Request (released ~Apr 2026) — proposed, not yet appropriated ($B) 0 $3B $6B $9B $12B $15B DoD cyber (total) $14.5B · military cyber $7.4B · cyberspace ops $6.4B · cyber R&D $0.63B Civilian cyber (total) $12.2B · down from ~$12.5B (FY26) — of which CISA $2.49B −$386M / −867 positions vs FY25 CR The swing variable is timing, not the topline CRs & shutdown threats freeze new starts; defense grows while civilian/CISA is cut — the 2025–26 split. Source: FY2027 PBR / DHS FY2027 budget-in-brief; CRS DHS FY2027 analysis; FDD & CSO Online budget reads (Apr–May 2026). Figures are requested, not enacted. Exhibit: The Business of Cyber Security.
The federal cyber request totals roughly **$26.7B** (civilian $12.2B + DoD $14.5B; one outlet headlined ~$27.5B on a broader accounting). Defense rises; civilian falls; **CISA is cut**. For a government-exposed asset, the question is not the topline — it is *which side of the split* its revenue sits on, and *whether the money is appropriated or stuck under a CR*. See [Federal Integrators](14a-federal-integrators.md).

Where the money actually lands — the four pools

DoD / military cyber (~$14.5B request). The defense cyber budget is the largest and most resilient pool, split across military cyber operations (~$7.4B), cyberspace operations and related activities (~$6.4B), and cyber R&D (~$0.63B) in the FY2027 request. It funds U.S. Cyber Command and the service cyber components, the Cyber Mission Force build-out, zero-trust architecture across DoD networks (the department's zero-trust target architecture is a multi-year procurement driver), and weapons-system cyber hardening. This is where the offensive and mission dollars sit, and where cleared integrators (14a) and defense-tech crossover names (Palantir, Anduril) compete. It is the most insulated from the civilian-side cuts.

Civilian agency cyber (~$12.2B request, down from ~$12.5B in FY2026). This pool funds cybersecurity inside every civilian department (Treasury, HHS, State, Energy, Justice, etc.) — endpoint, identity, cloud, and SOC modernization sold through FedRAMP-authorized products (16d). It is the pool most exposed to the FY2027 squeeze and to CR-driven freezes.

CISA (~$2.49B request). The lead civilian agency runs the .gov defense (CDM — Continuous Diagnostics and Mitigation), EINSTEIN/NCPS network defense, the JCDC public-private coordination body, vulnerability scanning, and critical-infrastructure support. The FY2027 request is +$109M (4.6%) above the FY2026 request but −$386M (13.4%) below the FY2025 CR level, cutting roughly 867 positions and zeroing out programs including ~$45M of Cyber Defense Education & Training (CDET) grants and the election-security function. CDM is the single most M&A-relevant CISA line: it is a multi-billion-dollar, multi-year program that pulls commercial endpoint/identity/asset-management products into civilian agencies through integrator primes.

Federal IT modernization (the ~$75.7B FY2027 IT topline). Cyber rides inside the broader federal IT budget — the FY2027 IT topline is roughly $75.7B — because "modernization" (cloud migration, legacy-system replacement, zero-trust) is where much security spend is actually embedded rather than line-itemed as "cyber."

Budget pool FY2027 request (approx.) What it funds M&A relevance
DoD / military cyber ~$14.5B CYBERCOM, CMF, DoD zero-trust, weapons-system cyber, offense Most resilient; integrator + defense-tech demand
Civilian agency cyber ~$12.2B (↓ from ~$12.5B) Cyber inside every civilian dept; FedRAMP products Most CR/cut-exposed; product pull-through
CISA ~$2.49B (↓ vs FY25 CR) CDM, EINSTEIN/NCPS, JCDC, .gov defense CDM = endpoint/identity/asset pull-through
Federal IT topline ~$75.7B Cloud, modernization, zero-trust (cyber embedded) Where most security spend actually rides

How budget timing re-prices government cyber assets

The 2025–26 cycle illustrates the mechanism. A combination of continuing resolutions, the DOGE consulting-cut campaign (which named Leidos, Booz Allen, SAIC, CACI and targeted ~$65B of consulting spend — 14a), and the CISA reductions compressed federal-services valuations from their late-2024 highs, shelved Peraton's IPO, and triggered analyst downgrades across the integrator group. None of that was a demand collapse — defense cyber grew — it was a timing-and-allocation shock. The transmission is mechanical: a CR freezes new-start obligations, integrators' book-to-bill softens, public comps de-rate, PE exit math (and IPO windows) tighten, and bolt-on pricing for sub-scale certified targets falls. The reverse is the upside: a passed full-year defense appropriation with cyber growth un-freezes the pipeline, and the certified-asset bolt-on market re-rates with it. Budget timing functions as the catalyst calendar for the sovereign cyber complex — the government analog of the regulatory-deadline calendar on 16c.

Falsifiable bear case

(1) The civilian squeeze is structural, not a one-year dip. If CISA and civilian-agency cyber are cut or CR-frozen for multiple cycles, the FedRAMP product pull-through that underwrites a whole class of "we sell to the federal government" cyber theses weakens — and the demand floor sags everywhere except defense. (2) Appropriations dysfunction is the base case, not the tail. Full-year cyber appropriations have become the exception; if CRs and shutdown brinkmanship persist, announced budget growth never becomes obligated spend, and the lag lengthens. (3) Efficiency cuts can hit the buyers, not just the sellers. The DOGE-style campaigns target the integrators that are the natural acquirers of certified cyber product — so a budget shock can freeze the acquisition market, not only end-customer demand. The bull case — a rising defense topline, a durable zero-trust mandate, and certification-gated demand that can't be cut to zero — is intact, but it lives or dies on appropriation actually flowing, and 2025–26 showed how violently that variable can move.

→ / angle

Score government-cyber targets by which budget pool they sit in, not just "has federal revenue." A target whose revenue rides DoD/military cyber or the DoD zero-trust mandate is materially more defensible than one dependent on CISA grants or civilian-agency discretionary cyber under CR pressure. The single most useful diligence question on a government-exposed asset in 2026 is "which appropriation line funds this, and is that line growing, flat, or cut in the FY2027 request?"


Sources: DHS FY2027 Budget-in-Brief / CISA OCFO budget (PDF) · CRS — DHS Budget Request Analysis FY2027 (R48979) · Cybersecurity Dive — CISA in the FY2027 budget · CSO Online — cyber winners and losers in the 2027 budget · FDD — America's Cyber Strategy Has a Budget Problem (civilian $12.2B / DoD $14.5B) · FedScoop — $75.7B FY2027 IT topline · GovInfoSecurity — US federal budget proposes $27.5B for cybersecurity · AFCEA — proposed $707M cut in CISA programs


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.