What the New CDC Cybersecurity Contract Funded, and What It Only Authorized
If you sell risk management framework support, cloud security operations or continuous monitoring labor into HHS agencies, the new CDC cybersecurity contract is not your capture target. CDC awarded delivery order 75D30126F21441 to RELI Group on Sept. 1, 2026 and obligated $421,261.02 against it. The five-year figure is $2,192,192.16, a ceiling if every option year is exercised, not obligated spend. Thirty offers came in.
Your target sits one order over. Information Innovators’ consolidated cybersecurity services order has obligated its entire ceiling, against a period of performance ending July 29, 2027. CDC cannot add growth to it without a ceiling modification. That is a discrete action you would see.
| Field | Answer |
|---|---|
| Signal | Five-year CDC cloud security and RMF order, Sept. 1, 2026: $421,261.02 obligated, $2,192,192.16 ceiling, 30 offers |
| BD implication | Its ceiling averages roughly one-eleventh of the consolidated order’s annual funded rate, and that order has obligated its full ceiling |
| Customer | CDC’s Office of the Chief Information Officer, which owns the system authorizations |
| Buyer | CDC Office of Acquisition Services, on every order named here |
| Funding | Recorded order by order, not against a single appropriation line |
| Vehicle / path | GSA Multiple Award Schedule GS35F385CA for the new order; NIH CIO-SP3 HHSN316201200015W for the cyber services order |
| Incumbents / ecosystem | Two current holders: Information Innovators, RELI Group. Booz Allen Hamilton and Credence held predecessors, both ended Sept. 30, 2024 |
| Access strategy | Prime on a GSA Schedule seat, or subcontract to a current holder |
| Timing | CIO-SP3 ordering currently ends Oct. 29, 2026; cyber services performance ends July 29, 2027 |
| Confidence | The fully obligated ceiling creates a visible planning point for future CDC cybersecurity requirements. |
| Pursuit posture | SHAPE with a seat, TEAM without one, DEFEND for Information Innovators |
| Upgrade triggers | A CDC sources-sought notice, draft solicitation or forecast entry for the follow-on |
| Downgrade triggers | A ceiling increase, period extension, or bridge order on 75D30124F20274 |
Three facts from the award record set the frame:
- Firm fixed price, recorded as full and open competition under multiple-award fair opportunity procedures, no set-aside.
- It runs on RELI Group’s own GSA Multiple Award Schedule contract, GS35F385CA, not a health-agency vehicle.
- The base period ends Aug. 30, 2027. The four option years holding the rest of the ceiling are unexercised and unfunded.
Ceiling and Obligation Are Different Numbers on Order 75D30126F21441
The five-year headline buys nothing by itself. The obligated amount and the base-and-exercised-options value are the same number, $421,261.02, which tells you only the base year is funded.
- $421,261.02 obligated, covering Sept. 1, 2026 through Aug. 30, 2027.
- $2,192,192.16 ceiling, reached only if CDC exercises all four option years through Aug. 30, 2031.
- $1,770,931.14 between them: four annual option decisions CDC has not made.
A ceiling is also not fixed. Each modification can raise or cut it, as a change against the prior figure rather than a new running total. An order’s live ceiling is the award figure plus every later adjustment, which matters twice below.
Averaged across five years, the RELI ceiling works out to roughly $438,000 a year. The consolidated cybersecurity services order is funded to roughly $4.9M a year across its period of performance, eleven times that rate. The smaller RELI order should be viewed as a targeted entry opportunity rather than the primary CDC cybersecurity growth opportunity. For a capture lead, treating it as the CDC cyber opportunity misreads the account by an order of magnitude.
The $14M CDC Cyber Order With No Ceiling Left
CDC’s main cybersecurity services work sits on task order 75D30124F20274, held by Information Innovators, awarded Sept. 27, 2024 and now obligated to its live ceiling of $13,839,031.18. Five recorded actions sit on it:
- $4,051,864.62 obligated at award on Sept. 27, 2024.
- $4,934,106.93 obligated on July 2, 2025.
- An administrative action on June 9, 2026 moving no money.
- $5,008,188.50 obligated on July 15, 2026.
- A July 27, 2026 modification cutting $155,128.87 from the obligated amount and the same $155,128.87 from the order’s total potential value.
That last action moved both sides of the ledger.
The reduction in the order’s total value may indicate either a reduced requirement or preparation for a future transition. A cut to an order’s total value fits a shrinking requirement as well as it fits clearing the decks for a replacement, and the obligation rates below lean that way. Against it, the period of performance was left intact, and a shrinking requirement would more usually show up as a shortened period than a $155,128.87 haircut. Available contract actions do not confirm whether the adjustment reflects reduced demand or a transition strategy.
Either way, CDC has ten months left and no room to grow the order inside it. CDC has ten months of performance remaining with no ceiling headroom. A ceiling increase, bridge, or new competed order would define the next acquisition path, making mid-2027 the key planning window for prospective contractors.
CDC’s Cyber Labor Went From Two Orders to One in September 2024
CDC’s cyber account is not fragmented today. Two cybersecurity labor orders ran in parallel from March 30, 2021, and both were extended in three-month steps through 2024 before ending on the same day:
| Holder | Order | Awarded | Ceiling at award | Obligated at award | Ends |
|---|---|---|---|---|---|
| Credence Management Solutions | 75D30121F10681 | Mar. 30, 2021, 10 offers | $8,685,290.00 | $2,852,258.41 | Sept. 30, 2024 |
| Booz Allen Hamilton | 75D30121F10682 | Mar. 30, 2021, 3 offers | $7,859,244.31 | $2,568,056.65 | Sept. 30, 2024 |
| Information Innovators | 75D30124F20274 | Sept. 27, 2024, 3 offers | $13,994,160.05 | $4,051,864.62 | July 29, 2027 |
| RELI Group | 75D30126F21441 | Sept. 1, 2026, 30 offers | $2,192,192.16 | $421,261.02 | Aug. 30, 2031 |
Later modifications raised both predecessor ceilings to match their lifetime obligations, $11,597,035.46 for Credence and $9,192,880.31 for Booz Allen. The Information Innovators award landed three days before both expired. The timing suggests CDC consolidated cybersecurity labor requirements, although the exact scope relationship between the contracts is not publicly defined.
The obligation rates complicate it. Those two orders together were funded to about $5.9M a year across their periods of performance. The consolidated order sits closer to $4.9M on the same basis, roughly 18% lower. The RELI order’s ceiling does not close the gap. CDC may have consolidated a shrinking requirement rather than a stable one.
Dell Federal Systems holds a different position: order 75D30126F20922 for Microsoft Azure cloud consumption, obligated at $24,999,040.00 against a $62,997,496.00 ceiling. That is capacity, not security labor, bought under a different product code and acquisition vehicle. The two are not comparable as a ratio.
The opening for a challenger is not fragmentation. It is that one anchor holder has no headroom and a fixed end date. CDC then went outside that anchor on Sept. 1, 2026 for a scope it could arguably have ordered inside it. An MSSP or systems integrator competes for the services scope Information Innovators holds. A GRC vendor goes after the authorization and assessment scope RELI Group now holds.
The Vehicle CDC Did Not Use on Sept. 1
CDC did not place its newest cyber order on the vehicle carrying its largest one. The cybersecurity services order runs on NIH’s CIO-SP3 governmentwide acquisition contract, HHSN316201200015W. The Sept. 1, 2026 order went to the GSA Multiple Award Schedule instead, eight weeks before the CIO-SP3 ordering window closes Oct. 29, 2026.
That window has been extended and restored more than once, and not on a tidy schedule: an extension signed Sept. 23, 2024 carried ordering only to April 29, 2025, and the next was not signed until Feb. 25, 2026. A single award does not establish a long-term acquisition pattern, but it demonstrates CDC’s flexibility in using multiple contracting paths for cybersecurity requirements. The pairing points to vehicle drift rather than a decision, and drift is still worth positioning against:
- A CIO-SP3 seat alone does not guarantee access to CDC’s next cyber order, because the ordering window is a shorter clock than the requirement it carries.
- A GSA Schedule seat with cybersecurity and cloud services offerings carried CDC’s most recent cyber labor buy.
- For a firm holding neither, a subcontract to one of the two current holders beats chasing a new vehicle award.
Check which of your own vehicle seats can still take an order in mid-2027, not just which ones you hold today.
A 30-Offer Field Prices Out a Standalone CDC Bid
Thirty offers competed for a CDC order whose ceiling averages roughly $438,000 a year. With 30 offers competing for an order averaging roughly $438,000 annually, the smaller opportunity is strategically stronger as an entry point into broader CDC cybersecurity work than as a standalone pursuit.
- Check whether your GSA Schedule seat carries cybersecurity or cloud services offerings, and what adding them would take.
- Count how many of your health-agency awards over the last three years were competed rather than set aside.
- Identify which current CDC cyber holder overlaps least with your delivery history, and open a teaming conversation there.
For a BD lead at a mid-market firm with an HHS cyber practice, the move is customer shaping at CDC’s OCIO in the next two quarters. The next CDC cybersecurity contract of consequence gets scoped in that window, not announced in it.
Small businesses should size their entry to the RELI order. CDC’s anchor cyber labor orders have each obligated between $9.2M and $13.8M, a different competition. Whether that smaller scope is worth a proposal cycle turns on whether it buys you CDC past performance.
Firms holding no seat on either vehicle should open a teaming conversation with a current holder now, while the follow-on scope is still being written. For Information Innovators, the posture is protective. July 29, 2027 represents the key planning milestone for companies positioning around CDC’s cybersecurity services requirement.
Nothing here is a live solicitation yet, which is why this is shaping work rather than a pursuit. A CDC sources-sought notice, draft solicitation or forecast entry for follow-on cybersecurity services turns it into one. A ceiling increase or period extension pushes it back a year. Future CDC announcements will determine whether the requirement moves toward recompete, bridge, or contract modification activity.
FAQ
Who owns the budget for CDC’s cybersecurity work?
CDC’s Office of the Chief Information Officer owns the requirement and sets the scope. The CDC Office of Acquisition Services is the contracting and funding office on every CDC cyber order named here. Its contracting officer decides the vehicle and timing. CDC records these obligations order by order rather than against a single appropriation line.
Which contract vehicles should I monitor for CDC cyber work?
Monitor two vehicles. The GSA Multiple Award Schedule carried the Sept. 1, 2026 award. NIH’s CIO-SP3, contract HHSN316201200015W, carries the cybersecurity services order. Its ordering period currently runs to Oct. 29, 2026.
Is this FedRAMP work?
No. FedRAMP authorizes a cloud service offering for governmentwide use. This order covers the agency-side risk management framework labor CDC needs to authorize and monitor its own systems running on those services. A provider’s FedRAMP authorization does not discharge CDC’s own obligation. CDC buys the two separately.
When is CDC’s cybersecurity services order likely to be recompeted?
Its period of performance ends July 29, 2027. Its ceiling is fully obligated. A follow-on competition, bridge or ceiling modification would normally surface several months ahead of that date.
Can a small business realistically win one of these orders?
On the smaller scopes, yes. The Sept. 1, 2026 award carried no set-aside and funded $421,261.02 in its base year. The consolidated order is a different proposition at a $13,994,160.05 award ceiling. The first constraint is holding a schedule contract with the right offerings; after that, bid cost against award size.
What is the subcontract route onto CDC cyber work?
Two prime holders are performing: Information Innovators on cybersecurity services through July 29, 2027, and RELI Group on RMF and cloud security operations through at least Aug. 30, 2027. A teaming approach to either is the near-term route for a firm holding neither vehicle seat. Make the approach before the follow-on scope is written.
Is the new RELI Group order a recompete of existing CDC work?
It is recorded as a new delivery order with its own base period and four option years, competed on its own terms. No predecessor CDC order is referenced against it. The 2024 award that replaced two ending orders covered a different scope.

