Twenty-five companies just picked up a shot at $1 billion in federal cybersecurity work, giving them a five-year runway to compete for task orders protecting one of Washington's largest civilian agencies. The U.S. Department of Agriculture named the winners of a new blanket purchase agreement built around USDA's Cybersecurity and Privacy Operations Center, the unit inside the Office of the Chief Information Officer that defends the department's networks and data.

Ordering periods for most of the awards began Monday, Sept. 21, 2026, and run through Sept. 20, 2031, according to federal spending data GovConWire cited and independently confirmed on ASSYST's own contract-vehicle page, which lists the identical five-year performance period under ASSYST's award, Contract Number 12314426A0031. "Federal spending data shows ordering periods for most of the awards began Monday, Sept. 21, and run through Sept. 20, 2031," GovConWire reported, citing the government's own contract-award records.

Inside the $1 Billion CPOC Cybersecurity BPA

A blanket purchase agreement is not a guaranteed payout. It is a pre-negotiated pool of qualified vendors that USDA program offices can draw from without running a fresh competition every time they need cybersecurity help, up to a combined ceiling of $1 billion over five years if the agency exercises every option and every awardee wins work. ASSYST's own description of the award frames the job in similar terms: the BPA exists "to rapidly procure enterprise-wide cybersecurity support services through call orders issued by warranted USDA contracting officers," delivering capabilities "across all eight USDA Mission Areas, 29 Staff Offices, and the Office of the Chief Information Officer's (OCIO) Cybersecurity and Privacy Operations Center (CPOC)," according to the company's own contract-vehicle page.

The specific dollar amount and structure at each call order will depend on which agency office is buying and what work it needs. Order types will be determined at the call-order level under the General Services Administration's Multiple Award Schedule special item number for Highly Adaptive Cybersecurity Services, according to ASSYST's own description of the vehicle, meaning the BPA rides on top of an existing GSA schedule rather than standing up a brand-new acquisition track from scratch. That structure is common for large-scale cyber support vehicles: it lets USDA lean on GSA's pre-vetted pricing and terms while still running its own competitions among the 25 awardees for each individual order, keeping the paperwork lighter than a standalone multiple-award contract would require.

Three Functional Areas of Work

USDA split the BPA's call orders into three buckets. The first covers mission-area-level cybersecurity work: Risk Management Framework activities, security engineering built directly into the software development lifecycle, and cyber defense and security operations. The second covers independent evaluations of security controls, running the full arc from assessment planning through findings and reporting -- the kind of work that produces the audit trail USDA needs to keep its systems authorized to operate under federal security rules. The third covers CPOC's departmentwide operations, spanning enterprise cybersecurity engineering, privacy operations, and identity, credential and access management across USDA's eight mission areas and 29 staff offices.

That third bucket lines up directly with work USDA has already been buying piecemeal through earlier, smaller contracts. Splitting the BPA this way lets USDA route narrow, specialized task orders -- an identity-management refresh here, a control assessment there -- to whichever of the 25 firms fits best, instead of forcing every requirement through a single prime contractor that may not have deep bench strength in every discipline the department needs.

Who Made the Cut

The winner list mixes the government's largest integrators with smaller, cyber-focused specialists. Accenture Federal Services, Deloitte & Touche, Guidehouse and Leidos made the cut alongside ASSYST, Alpha Omega, Easy Dynamics, Koniag Data Solutions and Vinsys Information Technology, among 16 other awardees. That spread gives USDA program managers a bench that spans full-scale systems integration down to boutique identity-management and assessment work, and it gives the smaller firms on the list a shot at task orders they might not win competing head-to-head against the primes on a single, undivided contract. It also reflects a pattern federal cyber buyers have leaned on increasingly in recent years: pairing a handful of large integrators with a longer tail of specialized small and mid-size firms on the same vehicle, so agencies are not locked into one size of contractor for every kind of cybersecurity need.

Building on Two Prior CPOC Contracts

The new BPA does not appear out of nowhere. USDA has been building CPOC's contractor bench in stages for several years. Alpha Omega and Dynamo Technologies won a five-year, $70 million contract in June 2023 for the center that eventually became CPOC. Easy Dynamics followed in June 2025 with a $50 million recompete win covering identity, credential and access management work for the same operation. Both firms appear again on the new $1 billion BPA, giving them continuity on a program they helped build while opening the door to two dozen additional competitors for the broader body of work the earlier, narrower contracts did not cover.

What It Means for Contractors

For the 25 companies on the BPA, the win itself is only the entry ticket. Because orders route through the GSA Highly Adaptive Cybersecurity Services schedule and get decided call order by call order, individual task-order competitions among the 25 awardees will determine who actually books revenue, and firms that already hold CPOC-adjacent past performance -- like Alpha Omega, Dynamo and Easy Dynamics -- start with a credibility edge on relevant orders. For firms outside the winner pool, the multiple-award structure closes off direct competition for USDA CPOC work for the next five years unless USDA opens a follow-on procurement, making this an award worth tracking even for companies that did not bid this time.

The three-part task structure also signals where USDA expects to spend. Departmentwide identity and access management work, in particular, has already drawn real dollars through the Easy Dynamics recompete, suggesting that bucket may see steadier order flow than the more episodic independent-assessment work tied to specific system authorizations. Companies chasing task orders under the new BPA will want to watch which of the three functional areas USDA activates first once the ordering period is fully underway, and how quickly the department starts issuing individual calls against a $1 billion ceiling that, for now, remains a five-year potential rather than a guarantee.

Sources