HomeProcurementThe CDC Cybersecurity Contract Worth Chasing Is the $14M One That Just...

The CDC Cybersecurity Contract Worth Chasing Is the $14M One That Just Ran Out of Ceiling

A five-year award drew 30 offers against a ceiling averaging roughly $438,000 a year. One order over, CDC has obligated every dollar of its consolidated cybersecurity services ceiling with ten months of performance still to run.

What the New CDC Cybersecurity Contract Funded, and What It Only Authorized

If you sell risk management framework support, cloud security operations or continuous monitoring labor into HHS agencies, the new CDC cybersecurity contract is not your capture target. CDC awarded delivery order 75D30126F21441 to RELI Group on Sept. 1, 2026 and obligated $421,261.02 against it. The five-year figure is $2,192,192.16, a ceiling if every option year is exercised, not obligated spend. Thirty offers came in.

Your target sits one order over. Information Innovators’ consolidated cybersecurity services order has obligated its entire ceiling, against a period of performance ending July 29, 2027. CDC cannot add growth to it without a ceiling modification. That is a discrete action you would see.

Field Answer
Signal Five-year CDC cloud security and RMF order, Sept. 1, 2026: $421,261.02 obligated, $2,192,192.16 ceiling, 30 offers
BD implication Its ceiling averages roughly one-eleventh of the consolidated order’s annual funded rate, and that order has obligated its full ceiling
Customer CDC’s Office of the Chief Information Officer, which owns the system authorizations
Buyer CDC Office of Acquisition Services, on every order named here
Funding Recorded order by order, not against a single appropriation line
Vehicle / path GSA Multiple Award Schedule GS35F385CA for the new order; NIH CIO-SP3 HHSN316201200015W for the cyber services order
Incumbents / ecosystem Two current holders: Information Innovators, RELI Group. Booz Allen Hamilton and Credence held predecessors, both ended Sept. 30, 2024
Access strategy Prime on a GSA Schedule seat, or subcontract to a current holder
Timing CIO-SP3 ordering currently ends Oct. 29, 2026; cyber services performance ends July 29, 2027
Confidence The fully obligated ceiling creates a visible planning point for future CDC cybersecurity requirements.
Pursuit posture SHAPE with a seat, TEAM without one, DEFEND for Information Innovators
Upgrade triggers A CDC sources-sought notice, draft solicitation or forecast entry for the follow-on
Downgrade triggers A ceiling increase, period extension, or bridge order on 75D30124F20274

Three facts from the award record set the frame:

  • Firm fixed price, recorded as full and open competition under multiple-award fair opportunity procedures, no set-aside.
  • It runs on RELI Group’s own GSA Multiple Award Schedule contract, GS35F385CA, not a health-agency vehicle.
  • The base period ends Aug. 30, 2027. The four option years holding the rest of the ceiling are unexercised and unfunded.

Ceiling and Obligation Are Different Numbers on Order 75D30126F21441

The five-year headline buys nothing by itself. The obligated amount and the base-and-exercised-options value are the same number, $421,261.02, which tells you only the base year is funded.

  • $421,261.02 obligated, covering Sept. 1, 2026 through Aug. 30, 2027.
  • $2,192,192.16 ceiling, reached only if CDC exercises all four option years through Aug. 30, 2031.
  • $1,770,931.14 between them: four annual option decisions CDC has not made.

A ceiling is also not fixed. Each modification can raise or cut it, as a change against the prior figure rather than a new running total. An order’s live ceiling is the award figure plus every later adjustment, which matters twice below.

Averaged across five years, the RELI ceiling works out to roughly $438,000 a year. The consolidated cybersecurity services order is funded to roughly $4.9M a year across its period of performance, eleven times that rate. The smaller RELI order should be viewed as a targeted entry opportunity rather than the primary CDC cybersecurity growth opportunity. For a capture lead, treating it as the CDC cyber opportunity misreads the account by an order of magnitude.

The $14M CDC Cyber Order With No Ceiling Left

CDC’s main cybersecurity services work sits on task order 75D30124F20274, held by Information Innovators, awarded Sept. 27, 2024 and now obligated to its live ceiling of $13,839,031.18. Five recorded actions sit on it:

  1. $4,051,864.62 obligated at award on Sept. 27, 2024.
  2. $4,934,106.93 obligated on July 2, 2025.
  3. An administrative action on June 9, 2026 moving no money.
  4. $5,008,188.50 obligated on July 15, 2026.
  5. A July 27, 2026 modification cutting $155,128.87 from the obligated amount and the same $155,128.87 from the order’s total potential value.

That last action moved both sides of the ledger.

CDC has obligated $13,839,031.18 against a cybersecurity services ceiling of $13,839,031.18. Zero headroom remains. Performance runs to July 29, 2027.

The reduction in the order’s total value may indicate either a reduced requirement or preparation for a future transition. A cut to an order’s total value fits a shrinking requirement as well as it fits clearing the decks for a replacement, and the obligation rates below lean that way. Against it, the period of performance was left intact, and a shrinking requirement would more usually show up as a shortened period than a $155,128.87 haircut. Available contract actions do not confirm whether the adjustment reflects reduced demand or a transition strategy.

Either way, CDC has ten months left and no room to grow the order inside it. CDC has ten months of performance remaining with no ceiling headroom. A ceiling increase, bridge, or new competed order would define the next acquisition path, making mid-2027 the key planning window for prospective contractors.

CDC’s Cyber Labor Went From Two Orders to One in September 2024

CDC’s cyber account is not fragmented today. Two cybersecurity labor orders ran in parallel from March 30, 2021, and both were extended in three-month steps through 2024 before ending on the same day:

Holder Order Awarded Ceiling at award Obligated at award Ends
Credence Management Solutions 75D30121F10681 Mar. 30, 2021, 10 offers $8,685,290.00 $2,852,258.41 Sept. 30, 2024
Booz Allen Hamilton 75D30121F10682 Mar. 30, 2021, 3 offers $7,859,244.31 $2,568,056.65 Sept. 30, 2024
Information Innovators 75D30124F20274 Sept. 27, 2024, 3 offers $13,994,160.05 $4,051,864.62 July 29, 2027
RELI Group 75D30126F21441 Sept. 1, 2026, 30 offers $2,192,192.16 $421,261.02 Aug. 30, 2031

Later modifications raised both predecessor ceilings to match their lifetime obligations, $11,597,035.46 for Credence and $9,192,880.31 for Booz Allen. The Information Innovators award landed three days before both expired. The timing suggests CDC consolidated cybersecurity labor requirements, although the exact scope relationship between the contracts is not publicly defined.

The obligation rates complicate it. Those two orders together were funded to about $5.9M a year across their periods of performance. The consolidated order sits closer to $4.9M on the same basis, roughly 18% lower. The RELI order’s ceiling does not close the gap. CDC may have consolidated a shrinking requirement rather than a stable one.

Dell Federal Systems holds a different position: order 75D30126F20922 for Microsoft Azure cloud consumption, obligated at $24,999,040.00 against a $62,997,496.00 ceiling. That is capacity, not security labor, bought under a different product code and acquisition vehicle. The two are not comparable as a ratio.

The opening for a challenger is not fragmentation. It is that one anchor holder has no headroom and a fixed end date. CDC then went outside that anchor on Sept. 1, 2026 for a scope it could arguably have ordered inside it. An MSSP or systems integrator competes for the services scope Information Innovators holds. A GRC vendor goes after the authorization and assessment scope RELI Group now holds.

The Vehicle CDC Did Not Use on Sept. 1

CDC did not place its newest cyber order on the vehicle carrying its largest one. The cybersecurity services order runs on NIH’s CIO-SP3 governmentwide acquisition contract, HHSN316201200015W. The Sept. 1, 2026 order went to the GSA Multiple Award Schedule instead, eight weeks before the CIO-SP3 ordering window closes Oct. 29, 2026.

“Extend the ordering period of performance of the contract to 10/29/2026.” (Modification P00024 to contract HHSN316201200015W, April 30, 2026)

That window has been extended and restored more than once, and not on a tidy schedule: an extension signed Sept. 23, 2024 carried ordering only to April 29, 2025, and the next was not signed until Feb. 25, 2026. A single award does not establish a long-term acquisition pattern, but it demonstrates CDC’s flexibility in using multiple contracting paths for cybersecurity requirements. The pairing points to vehicle drift rather than a decision, and drift is still worth positioning against:

  • A CIO-SP3 seat alone does not guarantee access to CDC’s next cyber order, because the ordering window is a shorter clock than the requirement it carries.
  • A GSA Schedule seat with cybersecurity and cloud services offerings carried CDC’s most recent cyber labor buy.
  • For a firm holding neither, a subcontract to one of the two current holders beats chasing a new vehicle award.

Check which of your own vehicle seats can still take an order in mid-2027, not just which ones you hold today.

A 30-Offer Field Prices Out a Standalone CDC Bid

Thirty offers competed for a CDC order whose ceiling averages roughly $438,000 a year. With 30 offers competing for an order averaging roughly $438,000 annually, the smaller opportunity is strategically stronger as an entry point into broader CDC cybersecurity work than as a standalone pursuit.

  • Check whether your GSA Schedule seat carries cybersecurity or cloud services offerings, and what adding them would take.
  • Count how many of your health-agency awards over the last three years were competed rather than set aside.
  • Identify which current CDC cyber holder overlaps least with your delivery history, and open a teaming conversation there.
Companies should evaluate their own contract consumption trends to identify similar ceiling exhaustion risks. Where you are above 90% consumed with more than six months of performance left, you carry the same exposure Information Innovators carries at CDC right now. Your customer is already deciding where the follow-on goes. Bring a ceiling-increase request before that customer builds a competition around the gap.

For a BD lead at a mid-market firm with an HHS cyber practice, the move is customer shaping at CDC’s OCIO in the next two quarters. The next CDC cybersecurity contract of consequence gets scoped in that window, not announced in it.

Small businesses should size their entry to the RELI order. CDC’s anchor cyber labor orders have each obligated between $9.2M and $13.8M, a different competition. Whether that smaller scope is worth a proposal cycle turns on whether it buys you CDC past performance.

Firms holding no seat on either vehicle should open a teaming conversation with a current holder now, while the follow-on scope is still being written. For Information Innovators, the posture is protective. July 29, 2027 represents the key planning milestone for companies positioning around CDC’s cybersecurity services requirement.

Nothing here is a live solicitation yet, which is why this is shaping work rather than a pursuit. A CDC sources-sought notice, draft solicitation or forecast entry for follow-on cybersecurity services turns it into one. A ceiling increase or period extension pushes it back a year. Future CDC announcements will determine whether the requirement moves toward recompete, bridge, or contract modification activity.

FAQ

Who owns the budget for CDC’s cybersecurity work?

CDC’s Office of the Chief Information Officer owns the requirement and sets the scope. The CDC Office of Acquisition Services is the contracting and funding office on every CDC cyber order named here. Its contracting officer decides the vehicle and timing. CDC records these obligations order by order rather than against a single appropriation line.

Which contract vehicles should I monitor for CDC cyber work?

Monitor two vehicles. The GSA Multiple Award Schedule carried the Sept. 1, 2026 award. NIH’s CIO-SP3, contract HHSN316201200015W, carries the cybersecurity services order. Its ordering period currently runs to Oct. 29, 2026.

Is this FedRAMP work?

No. FedRAMP authorizes a cloud service offering for governmentwide use. This order covers the agency-side risk management framework labor CDC needs to authorize and monitor its own systems running on those services. A provider’s FedRAMP authorization does not discharge CDC’s own obligation. CDC buys the two separately.

When is CDC’s cybersecurity services order likely to be recompeted?

Its period of performance ends July 29, 2027. Its ceiling is fully obligated. A follow-on competition, bridge or ceiling modification would normally surface several months ahead of that date.

Can a small business realistically win one of these orders?

On the smaller scopes, yes. The Sept. 1, 2026 award carried no set-aside and funded $421,261.02 in its base year. The consolidated order is a different proposition at a $13,994,160.05 award ceiling. The first constraint is holding a schedule contract with the right offerings; after that, bid cost against award size.

What is the subcontract route onto CDC cyber work?

Two prime holders are performing: Information Innovators on cybersecurity services through July 29, 2027, and RELI Group on RMF and cloud security operations through at least Aug. 30, 2027. A teaming approach to either is the near-term route for a firm holding neither vehicle seat. Make the approach before the follow-on scope is written.

Is the new RELI Group order a recompete of existing CDC work?

It is recorded as a new delivery order with its own base period and four option years, competed on its own terms. No predecessor CDC order is referenced against it. The 2024 award that replaced two ending orders covered a different scope.

The Contract Opportunity Atlas

Two issues a week.. Free.

Two issues a week. Data-driven intelligence for small tech firms selling to the federal government. Free.

Subscribe to Contract Opportunity Atlas

Get federal technology, AI, procurement, and GovCon insights delivered to your inbox.

Shahid Shah
Shahid Shah
Shahid specializes in bringing world-class CTO, CISO, and EiR expertise to startups, business units and companies on a part-time (fractional) basis. With a rich background in regulated, safety-critical industries like Med Devices, Digital Health, and Gov 2.0, he possess a unique understanding of complex, high-demand products and services. He is a C-suite native that can easily blend in with technical and engineering teams that need to deliver revenue-generating solutions to the marketplace. He has served as an Entrepreneur in Residence when a market seems lucrative but it's unclear how to build and launch products and services for such opportunities. Shahid has years of leadership experience as a co-founding startup CTO for multiple venture-backed companies, business unit CTO and EiR, and public company CTO helping transform product teams from marginal to high performance. His software/hardware engineering and cybersecurity body of knowledge is up to date because he rolls up his sleeves to create code when appropriate & dive into system architecture and design when required. He also conduct technology due diligence exercises for corporate acquisition or product integration requirements.
RELATED ARTICLES

Most Popular

CATEGORIES