Booz Allen Hamilton Secures $3.5M Defense Department Contract for IT and Cloud Services
Booz Allen Hamilton received a $3,501,690 DISA contract to provide Enterprise Mission Assurance Support Service cybersecurity capabilities for the Department of Veterans Affairs
Defense Contracts
The Contract
The Defense Information Systems Agency (DISA) has awarded Booz Allen Hamilton Inc. a contract valued at $3,501,690 to provide Enterprise Mission Assurance Support Service (eMASS) capabilities in direct support of the Department of Veterans Affairs (VA). The award, performed out of Maryland, underscores the growing convergence between Department of Defense cybersecurity frameworks and the federal civilian agencies that serve millions of American veterans and their families.
While the full contract type has not been publicly detailed in the initial announcement, contracts of this nature supporting DISA's eMASS platform are typically structured as firm-fixed-price or time-and-materials task orders issued under larger indefinite-delivery/indefinite-quantity (IDIQ) vehicles. DISA frequently leverages its own ENCORE III, SETI, or Defense Information Technology Contracting Organization (DITCO) contract vehicles to procure these types of cybersecurity and IT governance services. The period of performance for task orders supporting eMASS generally spans a base year with one or more option years, meaning the total ceiling value could ultimately exceed the initial $3.5 million figure if options are exercised and additional scope is added.
The place of performance is Maryland, which is consistent with both Booz Allen Hamilton's extensive presence in the National Capital Region and DISA's headquarters at Fort Meade, Maryland. Deliverables under this contract are expected to include the deployment, configuration, sustainment, and enhancement of eMASS instances tailored to the VA's specific risk management and cybersecurity compliance requirements. This encompasses system security plan management, continuous monitoring support, authorization to operate (ATO) workflow management, and integration with broader federal cybersecurity reporting frameworks such as the Risk Management Framework (RMF) mandated by the National Institute of Standards and Technology (NIST).
The contract also likely encompasses training, technical documentation, help desk support, and system administration services to ensure VA personnel can effectively leverage the eMASS platform across the department's sprawling and complex IT enterprise — one of the largest in the federal government.
Company Background
Booz Allen Hamilton Inc. is one of the most storied and deeply embedded management and technology consulting firms in the history of American national security. Founded in 1914, the firm has been a trusted advisor to the U.S. government for more than a century, with its defense and intelligence work stretching back to World War II, when it first began providing strategic counsel to the Department of the Navy. Today, the McLean, Virginia-headquartered company is a publicly traded firm (NYSE: BAH) and stands as one of the largest and most diversified government services contractors in the world.
Booz Allen Hamilton's defense and intelligence portfolio is vast. The company generates approximately $9 billion to $10 billion in annual revenue, with the overwhelming majority — roughly 97 percent — derived from contracts with the U.S. government. Of that, defense and intelligence clients represent the lion's share, with major programs spanning virtually every corner of the Pentagon, the Intelligence Community, and adjacent federal agencies. The firm employs approximately 33,000 professionals, many of whom hold top-secret and sensitive compartmented information (SCI) security clearances, making Booz Allen one of the largest cleared workforces in the private sector.
In the cybersecurity and IT governance domain specifically, Booz Allen Hamilton has established itself as a market leader. The company serves as a prime contractor on numerous high-profile cybersecurity programs across the DoD, including work for U.S. Cyber Command, the National Security Agency, DISA, and the military services. Its cybersecurity practice encompasses threat intelligence, vulnerability assessment, security operations center (SOC) management, zero-trust architecture implementation, and — critically for this contract — risk management framework compliance and authorization support.
Booz Allen has a particularly deep relationship with DISA, having supported the agency across multiple contract vehicles and mission areas for decades. The firm's expertise in eMASS — the very platform at the center of this contract — is well established, with Booz Allen personnel having supported the system's development, deployment, and sustainment across multiple federal and defense organizations. The company has also been a significant player in supporting the VA's IT modernization efforts, including cybersecurity, data analytics, and electronic health record (EHR) transformation programs.
Beyond cybersecurity, Booz Allen Hamilton holds prime contractor positions on landmark programs including the Army's digital transformation initiatives, the Air Force's Kessel Run software factory support, intelligence community data analytics platforms, and numerous classified programs that remain outside public disclosure. The company's fiscal year 2024 results showed continued strong growth in its defense portfolio, with particular strength in digital transformation, artificial intelligence, and cybersecurity — all areas directly relevant to the eMASS VA contract.
Technology Deep-Dive
The Enterprise Mission Assurance Support Service, or eMASS, is a web-based application developed and maintained by DISA that serves as the authoritative system of record for cybersecurity risk management and compliance across the Department of Defense and an expanding universe of federal agencies. At its core, eMASS automates and manages the complex, document-intensive process of assessing, authorizing, and continuously monitoring the security posture of information systems — a process that, if done manually, would be staggeringly labor-intensive given the scale of modern government IT environments.
To understand why eMASS matters, one must first understand the Risk Management Framework (RMF), which replaced the older DoD Information Assurance Certification and Accreditation Process (DIACAP) in 2014. RMF, defined by NIST Special Publication 800-37, establishes a structured, repeatable process for managing cybersecurity risk. Every information system that processes, stores, or transmits government data must go through the RMF lifecycle: categorize the system, select security controls, implement those controls, assess their effectiveness, authorize the system to operate, and then continuously monitor for ongoing compliance. eMASS is the digital backbone that manages this entire lifecycle.
Within eMASS, system owners and information system security officers (ISSOs) register their systems, document which of the hundreds of NIST security controls apply, record how each control is implemented, upload evidence of compliance, track Plans of Action and Milestones (POA&Ms) for any deficiencies, and route authorization packages through the chain of approval up to the Authorizing Official (AO) who ultimately grants or denies the Authority to Operate. The system also supports continuous monitoring by ingesting automated security data feeds, tracking control assessment schedules, and flagging systems that fall out of compliance.
For the Department of Veterans Affairs, eMASS is not merely a bureaucratic convenience — it is a mission-critical capability. The VA operates one of the largest and most complex IT environments in the federal government, encompassing electronic health records for more than nine million enrolled veterans, benefits processing systems handling tens of billions of dollars in annual disbursements, the National Cemetery Administration's scheduling and records systems, and a vast network of medical devices and internet-of-things (IoT) endpoints across 1,298 health care facilities nationwide. Each of these systems must be assessed, authorized, and monitored for cybersecurity compliance. A failure in any one of them could expose sensitive veteran health data, disrupt benefits payments, or — in the worst case — compromise patient safety.
The contract's focus on eMASS for the VA reflects a broader trend in federal cybersecurity: the adoption of DoD-grade security frameworks and tools by civilian agencies. While the VA is technically a civilian department, its deep interoperability with DoD systems — particularly in the health care domain, where VA and DoD share patient data through initiatives like the Federal Electronic Health Record Modernization (FEHRM) program — necessitates alignment with DoD cybersecurity standards. DISA's provision of eMASS to the VA, supported by contractors like Booz Allen Hamilton, enables this alignment.
The technical work under this contract would involve configuring eMASS workflows to match the VA's organizational structure and approval hierarchies, integrating eMASS with the VA's existing cybersecurity tools and continuous monitoring infrastructure, migrating legacy system security documentation into the platform, training VA cybersecurity personnel on RMF processes within eMASS, and providing ongoing sustainment to ensure the system remains operational and current with evolving NIST and DISA security requirements.
Strategic Significance
This contract, while modest in dollar terms relative to the largest Pentagon procurements, carries strategic significance that far exceeds its price tag. It sits at the intersection of several critical national security priorities: federal cybersecurity hardening, DoD-VA interoperability, and the broader push toward a unified federal approach to cyber risk management in an era of escalating nation-state threats.
The cybersecurity of the Department of Veterans Affairs has been a recurring concern at the highest levels of government. The VA's systems are attractive targets for adversaries ranging from nation-state actors to ransomware gangs, owing to the vast troves of personally identifiable information (PII) and protected health information (PHI) they contain. A major breach of VA systems would not only compromise the privacy of millions of veterans but could also erode trust in the institutions that serve them — a strategic objective for foreign adversaries seeking to undermine American social cohesion and institutional credibility.
The adoption of eMASS by the VA, facilitated by this contract, directly addresses the capability gap between the VA's historical cybersecurity posture and the more rigorous, standardized approach mandated by contemporary federal policy. Executive Order 14028, signed in May 2021, directed federal agencies to modernize their cybersecurity practices, adopt zero-trust architectures, and improve their ability to detect, respond to, and recover from cyber incidents. The Office of Management and Budget's subsequent implementation memoranda have further emphasized the need for continuous monitoring, automated security assessments, and standardized risk management — all of which eMASS is designed to support.
At the geopolitical level, this contract reflects the recognition that modern warfare and great power competition extend well beyond the traditional battlefield. Chinese, Russian, Iranian, and North Korean cyber actors have all demonstrated the capability and intent to target U.S. federal networks, including health care systems. The SolarWinds supply chain compromise of 2020 and the subsequent cascade of federal network intrusions underscored the urgency of strengthening cybersecurity governance across all federal agencies, not just those within the DoD. By extending DISA's eMASS capability to the VA through a contractor with Booz Allen Hamilton's depth of expertise, the government is effectively hardening a critical node in the broader federal cyber ecosystem.
Furthermore, this contract supports the DoD-VA continuum of care that is central to the nation's commitment to its service members. As active-duty personnel transition to veteran status, their health records, benefits data, and personal information must flow seamlessly and securely between DoD and VA systems. Any misalignment in cybersecurity frameworks between the two departments creates seams that adversaries can exploit. The use of a common eMASS platform, governed by the same RMF processes, helps close those seams and ensures that the data underpinning veteran care remains protected throughout its lifecycle.
Competitive Landscape
The market for federal cybersecurity compliance, risk management, and eMASS support services is competitive but concentrated among a relatively small number of firms with the requisite expertise, cleared personnel, and institutional knowledge. Booz Allen Hamilton's primary competitors in this space include Leidos Holdings, General Dynamics Information Technology (GDIT), ManTech International (now a subsidiary of Carlyle Group), Science Applications International Corporation (SAIC), Perspecta (now part of Peraton, a Veritas Capital portfolio company), and Deloitte's federal practice.
Whether this specific award was competed or issued as a sole-source action has not been explicitly detailed in the initial contract announcement. However, several factors suggest that Booz Allen Hamilton may have been positioned as the incumbent or preferred provider. The firm's longstanding relationship with DISA, its deep bench of eMASS-qualified personnel, and its existing footprint within VA cybersecurity programs all create significant barriers to entry for competitors. In the world of cybersecurity compliance support, institutional knowledge is paramount — understanding not just the eMASS platform itself but the specific organizational structures, approval workflows, legacy system inventories, and cultural dynamics of the supported agency. Transitioning such work to a new contractor carries risk, which often favors incumbents during recompetition or option-year evaluations.
That said, the competitive dynamics in this segment are intensifying. Leidos, which inherited significant DISA-related work through its acquisition of Lockheed Martin's Information Systems & Global Solutions division, is a formidable competitor with deep roots in defense IT and cybersecurity. GDIT, backed by General Dynamics' substantial balance sheet and its own legacy of DISA support, competes aggressively for similar work. SAIC has also invested heavily in its cybersecurity practice, while Peraton, bolstered by successive acquisitions, has rapidly built scale in the defense and intelligence IT market.
Booz Allen Hamilton's competitive advantage in this particular domain rests on three pillars: the depth and breadth of its cleared cybersecurity workforce, its intimate familiarity with both DISA and VA mission environments, and its reputation for technical excellence in RMF and continuous monitoring implementation. Winning and maintaining this contract reinforces Booz Allen's position as the go-to integrator for cross-agency cybersecurity governance — a niche that is likely to grow in importance and value as federal cyber mandates continue to expand.
Financial & Economic Impact
At $3,501,690, this contract represents a relatively small fraction of Booz Allen Hamilton's annual revenue, which exceeded $9.3 billion in fiscal year 2024. However, its significance should not be measured solely in top-line dollar terms. Contracts of this nature serve as critical footholds that generate follow-on work, establish institutional incumbency, and provide the operational experience that positions the company for larger, more lucrative awards in the future.
From a revenue recognition standpoint, the contract value will be recognized over the period of performance, likely on a proportional basis as services are delivered. If the contract includes option years — as is typical for DISA task orders — the total potential value could grow substantially, potentially doubling or tripling the base award over a multi-year period. Each option year exercised extends Booz Allen's incumbency and deepens its integration into the VA's cybersecurity infrastructure, making displacement by a competitor increasingly difficult.
The contract will directly support a team of cybersecurity professionals, system administrators, and program managers based in Maryland — likely in the corridor between the National Capital Region and Fort Meade. Given the specialized nature of eMASS support and RMF compliance work, these positions typically command competitive salaries and require active security clearances, contributing to the high-skill, high-wage employment base that characterizes the Maryland defense technology corridor. The regional economic impact, while modest in isolation, contributes to the broader ecosystem of defense IT employment that sustains communities in Anne Arundel, Howard, and Prince George's counties.
For Booz Allen Hamilton's broader financial narrative, this contract reinforces the company's strategy of pursuing high-margin, repeatable cybersecurity services work that generates steady, predictable revenue. The company's management has consistently emphasized cybersecurity as a growth vector in its investor communications, and awards like this one — even at a relatively modest scale — validate that thesis and contribute to the firm's overall backlog, which stood at approximately $30 billion as of the most recent quarterly report.
The contract also has downstream economic implications for Booz Allen's subcontractor ecosystem. The firm frequently partners with small and mid-sized cybersecurity firms, many of which are minority-owned, veteran-owned, or HUBZone-certified businesses, to fulfill subcontracting requirements on federal contracts. This award may generate subcontracting opportunities for specialized firms in areas such as automated security testing, documentation development, or training delivery.
What to Watch
Defense industry analysts and investors should track several developments related to this contract and the broader eMASS ecosystem in the coming months and years.
First, option year exercises will be a key indicator of program health and Booz Allen Hamilton's performance. If DISA and the VA exercise all available options, the total contract value will increase significantly, and each extension will further cement Booz Allen's incumbency. Analysts should monitor federal procurement databases for modification notices that signal option exercises or scope expansions.
Second, the broader trajectory of DISA's eMASS program is worth watching closely. DISA has been investing in modernizing eMASS to support evolving cybersecurity requirements, including integration with automated security scanning tools, enhanced continuous monitoring dashboards, and alignment with zero-trust architecture principles. Any major eMASS modernization effort could generate substantial follow-on contract opportunities, and Booz Allen Hamilton's position as a current eMASS support provider gives it a significant advantage in competing for that work.
Third, the expansion of eMASS to additional federal civilian agencies beyond the VA and DoD is a trend that could multiply the addressable market for firms like Booz Allen Hamilton. The Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Management and Budget have been pushing for greater standardization of cybersecurity risk management across the federal enterprise, and eMASS — or a successor platform — could play a central role in that standardization. Any policy directive mandating broader eMASS adoption would represent a significant growth opportunity.
Fourth, the Federal Electronic Health Record Modernization (FEHRM) program, which is deploying the Oracle Health (formerly Cerner) electronic health record system across both DoD and VA, creates a growing requirement for cybersecurity governance of shared health IT infrastructure. The eMASS platform will be essential for managing the ATO process for FEHRM-related systems, and contractors with expertise in both eMASS and health IT cybersecurity — a profile that fits Booz Allen Hamilton precisely — will be well-positioned for follow-on work.
Fifth, congressional oversight of VA cybersecurity remains active, with multiple committees having expressed concern about the department's vulnerability to cyber threats. Any adverse cybersecurity incident at the VA — or any positive audit finding attributable to improved eMASS-driven governance — could influence future funding levels and contract scope. The fiscal year 2025 and 2026 budget cycles will be particularly important, as they will reflect the administration's priorities for federal cybersecurity investment in the context of an increasingly contested budget environment.
Finally, investors and analysts should watch for Booz Allen Hamilton's quarterly earnings calls, where management typically provides color on contract wins, pipeline developments, and strategic priorities. While a $3.5 million award is unlikely to be called out individually, the firm's commentary on its cybersecurity portfolio growth and its DISA and VA client relationships will provide broader context for how this contract fits into the company's long-term growth strategy. In a market where cybersecurity spending is one of the few budget lines enjoying bipartisan support and consistent growth, Booz Allen Hamilton's continued penetration of the eMASS and federal risk management market positions it well for sustained relevance in one of the most critical domains of national security.