The Business of Cyber Security

The Procurement Rails

A FedRAMP authorization (16d) gets a cyber product allowed into the government; it does not get the product bought. Between an appropriation (14b) and a paid invoice sits a layer largely invisible from the commercial side: the contract vehicles and aggregators the government transacts through. A vendor without a position on the right vehicle — GSA Schedule, a GWAC, NASA SEWP, or a master aggregator like Carahsoft — is, for practical purposes, un-buyable by most agencies regardless of how good or how authorized its product is. Distribution into the government is therefore a moat in its own right, is frequently the actual asset acquired in a federal-cyber deal, and means a sub-scale product company's "government-ready" status is best assessed at the vehicle layer, not just the certification layer.

The rails: a parallel, gated distribution system

Commercial software is sold through a familiar stack — direct sales, VARs, cloud marketplaces (05a). The government runs a parallel stack with its own gatekeepers, designed to make purchasing fast, competed, and compliant with federal acquisition rules. The practical effect is that a contracting officer who wants a cyber product will reach for a pre-competed vehicle rather than run a fresh full-and-open procurement, because the vehicle has already done the price and compliance work. So whether an agency can buy a product easily reduces to whether the product is on a vehicle that agency uses. Three layers matter: (1) GSA Schedules / MAS (the broad catalog), (2) GWACs (large, pre-competed governmentwide IT contracts with ceilings in the tens of billions), and (3) aggregators/resellers (Carahsoft and peers) who carry hundreds of cyber vendors onto those vehicles so the vendor doesn't have to hold each contract itself.

The rails: appropriated money reaches a cyber vendor through pre-competed vehicles A FedRAMP authorization permits entry; a vehicle position enables the sale Appropriation FY budget → agency obligation authority THE VEHICLE LAYER (pre-competed) GSA Schedules / MAS broad catalog · OneGov govt-wide deals GWACs Alliant 3 ($82.5B) · Polaris ($28B SB) · CIO-SP NASA SEWP products GWAC · SEWP VI ceiling ~$60B Aggregators / resellers Carahsoft (master aggregator), carry 100s of cyber vendors onto the vehicles Cyber vendor paid invoice (direct or via prime) Integrators ride the same rails as primes — the vendor often sells through them No vehicle position ⇒ effectively un-buyable, however good or authorized the product is Source: GSA (Alliant 3, Polaris, MAS/OneGov); NASA SEWP; Carahsoft contract-vehicle disclosures (2026). Ceilings are program maximums, not spend. Exhibit: The Business of Cyber Security.
The rails are a *parallel distribution system*. A cyber vendor reaches an agency by holding a GSA Schedule, riding a GWAC, sitting on NASA SEWP, or — most commonly for product companies — being carried by a **master aggregator** like Carahsoft. Vehicle access is a moat that is frequently the real asset in a federal-cyber acquisition. See [Certifications as Moats](16d-certifications-moats.md).

The rails, by name

GSA Multiple Award Schedule (MAS / "Schedule 70" legacy). The broad, long-term catalog from which any agency can buy commercial products and services at pre-negotiated terms. Most cyber product companies' first federal beachhead is a GSA Schedule listing (often held through a reseller). GSA has layered on OneGov — governmentwide, pre-negotiated deals with single vendors — which in 2025–26 produced headline AI/cloud agreements (e.g., Google "Gemini for Government" at $0.47 per agency through Sep 30 2026, and a Microsoft OneGov package GSA framed as >$1B in first-year savings). OneGov is structurally important because it concentrates buying power and can commoditize a category's federal pricing overnight — a risk for incumbents and an opening for challengers.

GWACs (Governmentwide Acquisition Contracts). Large, pre-competed IT contracts that any agency can order against, stewarded by three hosts: GSA (Alliant, Polaris), NIH/NITAAC (CIO-SP), and NASA (SEWP). They carry enormous ceilings (program maximums, not guaranteed spend): Alliant 3 at ~$82.5B (the ceiling was raised in Dec 2024 as GSA moved to replace Alliant 2), and Polaris at ~$28B, set aside for small businesses (including HUBZone, SDVOSB, and WOSB pools). A position on a GWAC is a multi-year right to compete for task orders — valuable, durable, and not quickly replicable, which is exactly what makes it acquisition-relevant.

NASA SEWP (Solutions for Enterprise-Wide Procurement). The government's premier products GWAC — hardware and software, including a large share of cyber product spend — known for low fees and fast ordering. SEWP VI carries a program ceiling of ~$60B (NASA named 2,100+ awardees in June 2026; ten-year ordering period running into 2036; $20B per-awardee max), with GSA slated to assume management of the vehicle. (An earlier pre-award estimate cited ~$90B; the awarded program ceiling is ~$60B per NASA / awardee disclosures, Jun 2026.) SEWP's prime base is broad and small-business-heavy (the prior generation ran ~146 primes, ~120 of them small businesses), which is why so many cyber vendors reach agencies through a SEWP prime rather than holding their own.

The aggregators — Carahsoft and peers. This is the layer most commercial dealmakers underestimate. Carahsoft Technology Corp. is the master government aggregator: it carries hundreds of best-of-breed technology vendors onto GSA, SEWP, 2GIT, ITES-SW2, and OneGov, so a cyber vendor can sell to the government without holding each contract itself. Its GSA Schedule (legacy GS-35F-0119Y) runs through Dec 19 2026, and essentially every major cyber product brand (Zscaler, Palo Alto, CrowdStrike-adjacent, and a long tail) lists through Carahsoft or a peer (Immix, DLT/TD SYNNEX Public Sector, Four Points, GuidePoint Federal). For a sub-scale product company, "we have a Carahsoft relationship and a SEWP/GSA listing" can be a larger part of the enterprise value than the headcount or the ARR — because it is the thing that converts authorization into orders.

Rail Steward Scale / ceiling What it carries Why it's acquisition-relevant
GSA MAS / OneGov GSA Catalog; OneGov = govt-wide deals Commercial products & services First beachhead; OneGov can re-price a category
Alliant 3 (GWAC) GSA ~$82.5B ceiling IT services incl. cyber Multi-year right to compete; durable
Polaris (GWAC) GSA ~$28B ceiling IT services (small-business set-asides) Small-biz access; M&A entry point
CIO-SP (GWAC) NIH / NITAAC Multi-billion IT/health IT services Agency-specific reach
NASA SEWP NASA (→ GSA) SEWP VI ~$60B ceiling IT products, incl. cyber Primary product rail; small-biz primes
Carahsoft (aggregator) Private Carries 100s of vendors Cyber/IT products onto all vehicles The distribution moat itself

Why the rails are the asset: the disintermediation tension

Two opposing forces bear on the value of vehicle access. The moat case: a vehicle position plus aggregator relationships is a slow-to-build, certification-gated distribution asset — frequently the reason a government-traction cyber company is worth a strategic premium, and why integrators (14a) and aggregators are themselves periodically acquisition targets. The disintermediation case: as commercial platforms achieve their own FedRAMP/IL authorizations (16d) and as OneGov concentrates governmentwide buying directly with single vendors, the reseller margin in the middle compresses, and the largest vendors can increasingly transact direct. On balance, vehicle access is most valuable to sub-scale, certified, category-leading product companies (whose federal distribution they could never build alone) and least durable as a standalone reseller-margin business as the platforms scale and OneGov spreads.

Falsifiable bear case

(1) OneGov and direct authorization erode the middle. If GSA's OneGov push and broader platform self-authorization continue, the aggregator/reseller margin — and the value of "we have a Carahsoft relationship" — compresses, and the rail becomes a thinner moat. (2) Ceilings are not spend. A $60B SEWP ceiling or an $82.5B Alliant figure is a maximum, not demand; if appropriations are CR-frozen (14b), task orders don't flow regardless of how many vehicles a vendor sits on. (3) Procurement reform / consolidation risk. Periodic pushes to consolidate or reform federal IT buying (including GSA absorbing SEWP) can reshuffle which vehicles matter, stranding a vendor whose entire access strategy was built on the wrong rail. The base case still favors vehicle access as a genuine moat — but it is a moat that rewards the certified product owner more than the pure reseller, and it is only as live as the appropriation behind it.

→ / angle

Diligence federal-cyber targets at the vehicle layer, not just the certification layer. The right questions: Which contract vehicles does the target hold or ride (GSA MAS, which GWACs, SEWP)? Through which aggregator (Carahsoft, Immix, DLT)? What is the task-order book against those vehicles, and how concentrated is it? A target with FedRAMP and strong vehicle/aggregator positions is materially more valuable to a strategic acquirer than one with the authorization alone — the rails are often the premium.


Sources: GSA — Alliant 2 / Alliant 3 GWAC · GSA — Polaris GWAC ($28B small-business ceiling) · GWAC guide — Alliant 3 ~$82.5B ceiling / Polaris (govdash, Feb 2026) · NASA SEWP — program home · WidePoint — $60B NASA SEWP VI prime awards (GlobeNewswire, Jun 23 2026) · FedScoop — NASA names 2,100 SEWP VI awardees (Jun 2026) · Carahsoft — government IT contract vehicles (GSA/SEWP/2GIT/ITES-SW2/OneGov) · Carahsoft — Google Gemini for Government OneGov ($0.47/agency through Sep 30 2026) · Carahsoft — Microsoft OneGov (>$1B first-year savings) · FedScoop — OneGov strategy review


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.