Federal Cybersecurity Spending: $35B Across 10 Agencies
Federal cybersecurity spending is concentrated in fewer agencies than most people expect. Across 51,000+ contracts we analyzed (description keywords "cyber" or "security" plus NAICS 541512), 10 agencies account for virtually all of it.
Where the $35B Is Going
| Agency | Contracts | Total Value |
|---|---|---|
| Department of Defense | 27,033 | $15.5B |
| Department of Homeland Security | 3,627 | $6.1B |
| Department of Health and Human Services | 2,031 | $3.9B |
| Department of Veterans Affairs | 1,591 | $3.0B |
| General Services Administration | 9,892 | $1.9B |
| Department of the Treasury | 969 | $1.4B |
| Department of Commerce | 788 | $982M |
| Department of Transportation | 2,426 | $915M |
| Department of State | 1,460 | $781M |
| Department of Justice | 2,020 | $731M |
DoD Dominates But Has Long Tail
DoD alone is 44% of federal cyber spending. 27,033 contracts averaging $573K each. The dollar concentration is real but the per-contract size is small — most are task orders on existing vehicles, not standalone megacontracts.
DHS is the high-growth sleeper. Only 3,627 contracts but $6.1B in value. Per-contract average of $1.7M — three times DoD's. When DHS buys cyber, they buy big: CISA operations, CBP infrastructure security, FEMA incident response tooling.
HHS has quietly become the third-largest cyber buyer. $3.9B across 2,031 contracts. Healthcare data security, CMS payment integrity, and NIH research IT security are the big drivers.
Who's Not on This List Should Surprise You
Notable absences from the top 10: Department of Energy (nuclear security should push them higher), Social Security Administration (massive PII target), and the intelligence community (IC contracts are classified and not in USAspending data, so this list undercounts actual cyber spending by an estimated 20-30%).
If you are selling into cyber, the "fishing where the fish are" hierarchy is clear: DoD for volume, DHS for big deals, HHS for healthcare-specific past performance, VA for compliance-heavy work.
Positioning Advice
DoD and DHS require specialized cleared personnel. Most of this spend requires Secret or TS/SCI clearance. If you do not have a cleared workforce, you are bidding against firms that do. Partner or sub.
Past performance is the moat. Cyber contracts are rarely awarded to firms without direct prior performance in the agency. The easiest path in is subcontracting on an existing cyber task order, then bidding as prime on the re-compete.
FedRAMP matters more than CMMC right now. For software and services, FedRAMP authorization unlocks the most spend. CMMC is required but not yet differentiating.
Find cyber re-competes in your target agencies
Pursight tracks every cyber contract with vulnerability scores and keyword search across descriptions. Save searches, get alerts on new opportunities.
Start Free