Cybersecurity

Federal Cybersecurity Spending: $35B Across 10 Agencies

Federal cybersecurity spending is concentrated in fewer agencies than most people expect. Across 51,000+ contracts we analyzed (description keywords "cyber" or "security" plus NAICS 541512), 10 agencies account for virtually all of it.

Where the $35B Is Going

AgencyContractsTotal Value
Department of Defense27,033$15.5B
Department of Homeland Security3,627$6.1B
Department of Health and Human Services2,031$3.9B
Department of Veterans Affairs1,591$3.0B
General Services Administration9,892$1.9B
Department of the Treasury969$1.4B
Department of Commerce788$982M
Department of Transportation2,426$915M
Department of State1,460$781M
Department of Justice2,020$731M

DoD Dominates But Has Long Tail

DoD alone is 44% of federal cyber spending. 27,033 contracts averaging $573K each. The dollar concentration is real but the per-contract size is small — most are task orders on existing vehicles, not standalone megacontracts.

DHS is the high-growth sleeper. Only 3,627 contracts but $6.1B in value. Per-contract average of $1.7M — three times DoD's. When DHS buys cyber, they buy big: CISA operations, CBP infrastructure security, FEMA incident response tooling.

HHS has quietly become the third-largest cyber buyer. $3.9B across 2,031 contracts. Healthcare data security, CMS payment integrity, and NIH research IT security are the big drivers.

Who's Not on This List Should Surprise You

Notable absences from the top 10: Department of Energy (nuclear security should push them higher), Social Security Administration (massive PII target), and the intelligence community (IC contracts are classified and not in USAspending data, so this list undercounts actual cyber spending by an estimated 20-30%).

If you are selling into cyber, the "fishing where the fish are" hierarchy is clear: DoD for volume, DHS for big deals, HHS for healthcare-specific past performance, VA for compliance-heavy work.

Positioning Advice

DoD and DHS require specialized cleared personnel. Most of this spend requires Secret or TS/SCI clearance. If you do not have a cleared workforce, you are bidding against firms that do. Partner or sub.

Past performance is the moat. Cyber contracts are rarely awarded to firms without direct prior performance in the agency. The easiest path in is subcontracting on an existing cyber task order, then bidding as prime on the re-compete.

FedRAMP matters more than CMMC right now. For software and services, FedRAMP authorization unlocks the most spend. CMMC is required but not yet differentiating.

Find cyber re-competes in your target agencies

Pursight tracks every cyber contract with vulnerability scores and keyword search across descriptions. Save searches, get alerts on new opportunities.

Start Free