Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Companies publicly announced more than $3.1 billion in potential U.S. government cybersecurity-related contract value during 2022. The figure combines maximum contract values, task-order ceilings and multi-year amounts reported by companies and trade coverage—not cash already paid, one year of federal spending or a complete government-wide procurement total.
The largest announcements included Booz Allen Hamilton’s potential $622.5 million NASA CyPrESS contract, a Peraton subsidiary’s potential $562.9 million Department of Defense Cyber Crime Center task order, and ECS’s five-year, $430 million Army endpoint-security recompete. Several other awards covered broader IT infrastructure, forensics or mission support in addition to cybersecurity.
What the $3.1 billion figure actually represents
This article uses cybersecurity-related contracts because the announcements did not all describe exclusively cybersecurity work. The aggregate is an editorial calculation from publicly announced 2022 awards and selections with stated values. It is not an official federal total.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match- Potential value: The maximum amount available if all options, task orders or other contract capacity are used.
- Base-period value: The initial period of performance, which may be the only portion guaranteed at award.
- Obligated value: Money the government has actually committed. This can be much lower than a contract ceiling.
- IDIQ ceiling: A maximum under an indefinite-delivery, indefinite-quantity vehicle; it does not mean the contractor immediately receives that amount.
- Option years: Additional periods the government may exercise, but is not required to purchase.
For example, NASA’s CyPrESS award had a total potential value of $622.5 million. Booz Allen described it as a hybrid, single-award IDIQ contract, with work beginning in 2022 and option periods extending through September 2030. The ceiling should not be interpreted as $622.5 million in 2022 revenue. Booz Allen’s announcement
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
The source roundup was published by SecurityWeek on December 22, 2022, although a SecurityWeek category page displayed a different date. The calculation below follows the article page and search-result date. SecurityWeek’s roundup · SecurityWeek category page
Largest publicly announced awards
| Company | Customer | Program or work | Publicly stated value | Contract form and scope |
|---|---|---|---|---|
| Booz Allen Hamilton | NASA | Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) | $622.5 million | Hybrid single-award IDIQ; enterprise cybersecurity, privacy, architecture, vulnerability discovery, cyber defense and incident response. |
| Peraton subsidiary Perspecta Enterprise Services LLC | DoD Cyber Crime Center | Technical, Analytical and Business Operations Services | Up to $562.9 million | Task order with a one-year base and four one-year options; digital forensics, cyber analytics, vulnerability sharing and technical solutions. |
| ECS | U.S. Army | Army Endpoint Security Solution recompete | $430 million over five years | Endpoint detection and response and unified asset management for as many as 800,000 classified and unclassified endpoints. |
| General Dynamics Information Technology | Army National Guard | Guard Enterprise Cyber Operations Support | $267 million | Cyber and security operations combined with infrastructure, network operations, hosting and related IT services. |
| Five Stones Research, or 5SRC | Missile Defense Agency | Weapon-system cybersecurity support | $266 million | Cyber-risk identification and mitigation for missile-defense systems. |
| Peraton | State Department Diplomatic Security Service | Diplomatic Security Cyber Mission Support Services | $254 million over five years | Incident management, threat analysis, penetration testing and cyber operations. |
| Sealing Technologies | U.S. Marine Corps | Defensive Cyber Weapons System task order | $168 million over five years | Vulnerability analysis, cybersecurity assessments and incident response. |
| Echelon Services | Defense Counterintelligence and Security Agency | Enterprise and transformational cybersecurity support | $153 million over five years | Enterprise cybersecurity and modernization support. |
The Peraton entry is for Perspecta Enterprise Services LLC, a Peraton subsidiary. It should not be counted again as a separate Perspecta award. Peraton said the DC3 task order was issued through GSA’s Federal Systems Integration and Management Center under the Alliant 2 governmentwide acquisition contract. Peraton’s DC3 announcement
Other priced 2022 cybersecurity-related announcements
| Company | Customer | Work | Publicly stated value |
|---|---|---|---|
| Booz Allen Hamilton | Two U.S. Navy organizations | Cybersecurity support | $99 million |
| Oasis | Nuclear Regulatory Commission | Cybersecurity Program Support Services, including FISMA compliance, supply-chain security, training and situational awareness | $92 million over five years |
| Rite-Solutions | Naval Surface Warfare Center Dahlgren Division | Cybersecurity engineering, cyber command and control, mission assurance and situational awareness | $77 million over five years |
| Sealing Technologies | U.S. Cyber Command/Cyber National Mission Force | Selection supporting hunt-forward cyber operations | Nearly $60 million |
| WWC Global | Cybersecurity and Infrastructure Security Agency | Critical-infrastructure protection, analysis, planning and compliance tracking | $37 million over three years |
| CounterCraft | DoD and the federal government | Deception technology for active cyber defense | $26 million |
| CGI Federal | Nuclear Regulatory Commission | GLINDA agreement addressing emerging cyber threats | $17 million |
Adding the listed values produces approximately $3.131 billion. That calculation includes the $99 million Navy award and Sealing Technologies’ separate “nearly $60 million” hunt-forward selection. Because some source figures are rounded and the announcements use different contract structures, the result is best described as more than $3.1 billion in announced potential or stated value, not a precise spending figure.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteRank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
What the biggest contracts covered
NASA: enterprise protection across IT, operational technology and missions
CyPrESS was the clearest enterprise-wide cybersecurity award in the group. The scope covered NASA’s Office of the Chief Information Officer and included IT systems, operational technology and mission systems. It also addressed cybersecurity standards and architecture, security engineering, program management, cyber defense, vulnerability discovery, incident response, automation and privacy services.
Its importance is therefore broader than a conventional software purchase. The contract was designed to support the policies, engineering, operations and response functions needed to protect a complex civilian space agency.
DC3: forensics and cyber investigations
The DC3 task order shows that “cybersecurity” procurement also includes investigative and analytical capabilities. The work covered digital and multimedia forensics, cyber-threat analytics, vulnerability sharing and technical-solutions development. It supported law-enforcement, counterintelligence, counterterrorism, cybersecurity and critical-infrastructure missions.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
That makes the $562.9 million ceiling relevant to cyber defense, but not directly comparable to an endpoint-security license or a network-monitoring contract.
Army endpoint security: protection at enormous scale
ECS’s Army recompete focused on endpoint detection and response and unified asset management for up to 800,000 endpoints across classified and unclassified networks. The scale matters: the challenge is not only detecting malicious activity, but also maintaining an accurate view of devices and applying consistent security controls across different environments.
Army National Guard: cyber operations bundled with IT
GDIT’s Guard Enterprise Cyber Operations Support award combined network and security operations with infrastructure, application hosting and other enterprise IT services. It belongs in a cybersecurity-related roundup, but the full $267 million should not be characterized as spending solely on a cybersecurity product or service.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Defense and diplomatic missions
Five Stones Research’s Missile Defense Agency work focused on identifying and mitigating cyber risk in weapon systems. Peraton’s Diplomatic Security award covered incident management, threat analysis, penetration testing and cyber operations. Sealing Technologies’ Marine Corps task order emphasized vulnerability analysis, assessments and incident response.
Together, these awards illustrate how federal cyber work is tied to mission assurance: protecting weapons platforms, diplomatic operations and military networks rather than only securing office computers.
Capabilities federal agencies were buying
- Endpoint detection and response: Monitoring and responding to threats on large fleets of classified and unclassified devices.
- Security and network operations: Continuous monitoring, infrastructure defense, hosting and enterprise-network protection.
- Threat analytics and vulnerability management: Finding weaknesses, analyzing adversary activity and sharing vulnerability information.
- Incident response and penetration testing: Preparing for, identifying and containing compromises.
- Digital and multimedia forensics: Supporting cyber investigations and broader law-enforcement and national-security missions.
- Mission-system security: Applying cyber-risk controls to space, missile-defense, military and diplomatic systems.
- Compliance and training: FISMA support, supply-chain security, program management and workforce preparation.
- Critical-infrastructure protection: Planning, analysis and expertise for physical and electronic threats.
- Active defense and emerging technologies: Deception capabilities and work involving quantum-resistant cryptography.
Other cyber announcements without comparable public dollar figures
The 2022 roundup also identified announcements involving Lockheed Martin, SandboxAQ, QuSecure and Netskope. They are relevant to the year’s federal cybersecurity activity, but the available coverage did not provide a comparable public dollar figure for inclusion in the $3.1 billion calculation.
Leaving them outside the total is more transparent than assigning an estimated value. An announcement can establish that work was selected, adopted or made available without establishing a contract ceiling, obligated amount or contractor revenue figure.
How to interpret the total
- Do not equate ceiling with spending. A $622.5 million IDIQ or “up to” $562.9 million task order describes purchasing capacity, not necessarily money already obligated.
- Check the time period. A five-year value and a one-year fiscal-year amount answer different questions.
- Separate cyber from adjacent IT work. Infrastructure, hosting, forensics and mission support can be cyber-relevant without being pure cybersecurity.
- Identify the award type. IDIQs, task orders, agreements, selections and service contracts are not interchangeable.
- Watch for duplicate reporting. A subsidiary, parent company, contract vehicle and task order can all appear in coverage of the same procurement.
- Distinguish announcement from government records. Company releases and trade-publication roundups are useful evidence, but they are not the same as a complete federal procurement-data extraction.
A narrow methodology would exclude some bundled IT and mission-support awards and produce a more conservative cyber-only total. A broader methodology better reflects how agencies actually buy integrated cyber capabilities, but it creates a greater risk of overstating the amount attributable to cybersecurity alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

