Other Computer Related Services (U.S.) — NAICS 541519
An investor's primer for both public-market and private investors. NAICS = North American Industry Classification System, the standard code set U.S. statistical agencies use to group businesses. IT = information technology.
1. Overview
NAICS 541519 is the "everything else" bucket for computer services — the catch-all inside the IT-services family for firms that don't fit the more specific codes for custom programming (541511), systems-design (541512), or facilities management (541513). In practice it covers a grab-bag of labor-based technology work: computer disaster-recovery and business-continuity services, software installation and rollout, IT consulting and technical advice, IT security advisory, and specialized infrastructure and operational services that don't fit another computer-services code.[1]
It is important to read 541519 as a statistical activity bucket, not a clean stock-market sector. No large company files its financials as "a 541519 company," and the code's boundaries are fuzzy by design. It matters to investors for two practical reasons. First, it is one of the most-used codes in federal contracting — the U.S. government tags a large share of its IT-services purchases to 541519, making it a window into a multi-billion-dollar defense-and-civilian IT market.[7] Second, the same activities power a much larger commercial IT-services economy. The economics are easy to understand: skilled people's time, sold by the hour or by the project.
Public vs. private ways in. Public investors get exposure through diversified IT-services firms, federal contractors, distributors (value-added resellers, or VARs), and managed-service providers (MSPs) — none of them pure plays. Private investors can own MSPs, VARs, cybersecurity specialists, government IT contractors, and buy-and-build consolidation platforms directly. Ownership is dominated by private equity (several of the biggest players were taken private) and by thousands of small, owner-operated IT shops — a fragmented, deal-heavy industry. The investment case is strongest where a provider has recurring contracts, specialized expertise, high switching costs, or proprietary tools; weakest where revenue is mostly low-margin hardware resale, labor-arbitrage staffing, or one-off projects.
2. What it is and how it's structured
Scope. Establishments primarily engaged in providing computer-related services except custom programming, systems-integration design, and facilities management. The Census definition specifically names computer disaster-recovery services and software-installation services; the code has also become the default label for IT consulting, IT security consulting (advice, not build), specialized infrastructure/operations work, and some IT staffing.[1]
What it explicitly excludes — and where that work is counted instead:
- 541511 Custom Computer Programming Services — writing or modifying code to a client's spec.[1]
- 541512 Computer Systems Design Services — integrating hardware, software and communications into a working system (where most large "systems integrators" actually classify).[1]
- 541513 Computer Facilities Management Services — running a client's data center or IT operation on-site.[1]
- 513210 Software Publishers and 518210 Data Processing, Hosting & Related Services — packaged-software publishing and cloud/hosting/data-processing.[1]
- 611420 Computer Training and 811210 Electronic & Precision Equipment Repair — training on, and physically repairing, computers.[1]
Because 541519 is a residual "other" code, the boundary with 541512 in particular is blurry and firms self-select; that matters for reading the statistics below.
Ownership mix. The population skews tiny: roughly 13,300 establishments employing about 169,000 people — an average of ~13 workers per site.[2] At the top sit a handful of large federal contractors, most either publicly traded or private-equity owned. In the middle and long tail are boutique IT consultancies, disaster-recovery specialists, MSPs and staffing shops — many S-corps or LLCs — plus a large uncounted layer of sole proprietors (see §3). The industry also blends in public-company subsidiaries and government in-house IT teams. Our federal statistics do not provide a public-versus-private ownership split, so none is stated.
3. How big it is
U.S. federal statistics (our ground-truth figures). County Business Patterns (CBP) figures are for 2023; receipts, firm counts, and concentration figures are from the 2022 Economic Census — so they are not same-year measures.
| Metric | Value | Source (year) |
|---|---|---|
| Receipts (revenue) | ~$54.97 billion | 2022 Economic Census[3] |
| Firms | 11,570 | 2022 Economic Census[3] |
| Establishments | 13,275 | County Business Patterns 2023[2] |
| Paid employees | 168,654 | County Business Patterns 2023[2] |
| Annual payroll | ~$20.86 billion | County Business Patterns 2023[2] |
| First-quarter payroll | ~$5.32 billion | County Business Patterns 2023[2] |
| Avg. pay per employee | ~$123,700 | derived from CBP 2023[2] |
| Avg. revenue per firm | ~$4.8 million | derived from 2022 Census[3] |
| SBA small-business ceiling | $34 million avg. annual receipts (150 employees for IT value-added resellers) | SBA size standards 2023[6] |
CBP = County Business Patterns; SBA = U.S. Small Business Administration. The ~$124k average wage confirms this is skilled, well-paid labor, not a low-cost service. The average firm books under $5 million of revenue — small businesses dominate the count even though a few giants dominate the dollars. The SBA ceiling is a contracting-eligibility threshold, not an estimate of typical firm size; note the special 150-employee standard that applies to IT value-added resellers.[6]
The undercount caveat (important here). Treat the $54.97 billion as a floor, for three reasons:
- It's a residual code. The largest IT-services firms classify primarily under 541512, so a big slice of "other computer-related" activity is booked in sibling codes rather than here. Meanwhile the federal government tags far more contract dollars to 541519 than the Census counts in firm receipts — roughly $7–8 billion of federal obligations were tagged to the code in a recent year, and it ranks among the single most-used NAICS codes in procurement.[7]
- Nonemployer firms are largely excluded. CBP and the Economic Census primarily cover employer establishments with paid staff; the many one-person IT-setup, software-install and freelance-consulting operations sit in the Census Bureau's separate Nonemployer Statistics program, which is not in our figures.[4][5]
- Government in-house IT isn't counted as private-sector 541519 revenue.
Concentration can also be far higher inside narrow niches (federal cybersecurity, specialized defense work, national IT distribution) than the six-digit figures suggest. For context, the whole computer-systems-design family (NAICS 5415, of which 541519 is one of four sub-codes) generates on the order of $470 billion in U.S. revenue.[8] 541519 is the smallest and fuzziest slice of that.
4. The investable universe
There is no pure-play public "541519" stock. The code does not map onto public-company reporting; the names below are representative proxies chosen by service mix and federal-contracting relevance, not pure plays. Revenue is the most recent fiscal year and rounded.
| Company | Ticker | ~Revenue | Relevance / lens |
|---|---|---|---|
| Kyndryl | KD | ~$16B[9] | Managed IT, cloud, infrastructure, security & network services — closest large public proxy by disclosed service mix |
| Accenture | ACN | ~$69B[10] | Global consulting + managed services (incl. infra, cloud, security); Accenture Federal Services is a major U.S. gov player |
| IBM | IBM | ~$63B (Consulting seg. ~$20B)[11] | Consulting, infrastructure support, hybrid cloud & AI — services bundled with software/hardware |
| Leidos Holdings | LDOS | ~$17.2B (FY25)[13] | Largest federal IT-services prime; defense, health, civil, intel |
| Booz Allen Hamilton | BAH | ~$12.0B (FY25)[14] | Federal technology, AI, cyber & digital modernization; heavily defense & intel |
| CACI International | CACI | ~$8.6B (FY25)[16] | National-security IT, cyber, C4ISR (command, control, communications, computers, intelligence, surveillance & reconnaissance), enterprise IT |
| SAIC | SAIC | ~$7.5B (FY25)[15] | Government IT modernization, enterprise IT integration, mission support |
| General Dynamics (GDIT unit) | GD | GDIT ~$9B of GD's ~$50B[17] | GDIT is one of the biggest federal IT integrators; GD parent is aerospace & defense |
| CDW | CDW | ~$21B[12] | IT VAR (value-added reseller): distribution + advisory, implementation & managed services (meaningful product pass-through) |
| Insight Enterprises | NSIT | ~$9B | IT VAR; software install & deployment plus growing services |
| ePlus | PLUS | ~$2B[18] | Cloud, security & data-center solutions with a growing services component |
| Telos | TLS | ~$0.1B[19] | Cybersecurity, cloud, identity & secure networks — narrow, higher company-specific risk |
| ASGN / Kforce | ASGN / KFRC | ~$4B / ~$1.4B | Commercial + government IT staffing (staff-augmentation) |
| ICF International / V2X / Maximus | ICFI / VVX / MMS | ~$2B / ~$4B / ~$5B | Government IT + advisory, engineering/logistics IT, and business-process/IT services |
Major private platforms and owners. Much of the top tier is not public:
- Peraton — ~$7–8 billion revenue; owned by Veritas Capital (built from a 2021 roll-up of Perspecta and Northrop Grumman's IT unit).[20]
- ManTech International — taken private by The Carlyle Group in 2022 for about $4.2 billion (was NASDAQ: MANT).[22]
- Guidehouse — acquired by Bain Capital Private Equity for ~$5.3 billion in 2023; public-sector and commercial consulting + managed services.[21]
- Presidio — cloud/digital-infrastructure/security provider; ~$2.1 billion take-private, now majority-owned by Clayton, Dubilier & Rice (with BC Partners minority).[23]
- World Wide Technology (WWT) and SHI International — large, privately held, founder-led VARs/solutions integrators; WWT bought Softchoice for ~$1.3 billion in 2025.[24]
- Accenture Federal Services (subsidiary of Accenture) and Deloitte are large federal consulting/IT players; and a very long tail of small, founder-owned IT consultancies and disaster-recovery shops — the natural hunting ground for search funds and lower-middle-market buyout firms.
Private-company financial disclosure is limited, so private underwriting requires direct access to customer, contract, margin, retention and debt data.
Takeaway: public exposure means buying federal IT primes, broad IT-services firms, or resellers/staffers; the "purest" 541519 businesses (small IT shops, DR specialists, MSPs) are almost entirely private.
5. How the money works
This is a labor-based professional-services industry. Owners make money by selling skilled people's time for more than it costs to employ them.
The core equation. Revenue is billable hours × bill rate (time-and-materials work), a fixed price per project, cost-plus-fee (common on government contracts), or recurring managed-service/support fees. Some firms also resell software and hardware bundled with implementation. Profit comes from the spread between the bill rate charged and the fully-loaded pay of the worker (salary + payroll taxes + benefits + overhead), multiplied by how much of the workforce is actually billing. Kyndryl, IBM and Accenture all disclose a mix of time-and-materials, fixed-price and recurring arrangements.[9][10][11]
The metrics that matter:
- Billable utilization — the share of staff hours billed to clients. Healthy IT-services and consulting firms run ~70–80%; a few points of utilization separates a good quarter from a bad one.[29]
- Bill rate / markup and revenue per employee — staffing markups run ~20–75% over pay; consulting can be 1.5–3× pay.[29] Higher-skill, cleared, or scarce specialties (cyber, cloud, AI) command premium rates. Revenue per employee is a rough gauge of productivity and pricing power.
- Gross margin by offering — resale revenue carries far lower margins than advisory or specialized services.
- Recurring revenue and renewal rates — managed-service and support agreements give visibility; project work is more cyclical because clients can defer it.
- Backlog and book-to-bill — for the federal primes, backlog (contracted future work) and the book-to-bill ratio (new awards ÷ current revenue) are the key leading indicators; above 1.0 means the pipeline is growing.
- Contract mix — cost-plus is low-risk/low-margin; fixed-price carries execution risk but more upside. The blend drives margins.
- Headcount, attrition and clearances — the "inventory" is people; losing cleared or specialized staff directly shrinks capacity. Distributors/resellers also carry meaningful receivables and working capital.
Margins are thin. Federal IT-services operating/EBITDA margins (EBITDA = earnings before interest, taxes, depreciation and amortization) typically sit in the high-single to low-double digits; commercial staffing and resale are slimmer still. There is little capital intensity — the balance sheet is mostly receivables and goodwill from acquisitions, not factories — so returns hinge on utilization, rate discipline, and winning recompetes. (This is an interpretation of the business models, not a reported industry statistic.)
6. What drives demand
- Cloud and hybrid-cloud modernization. Moving legacy systems, applications and data into hybrid environments is a durable workstream.[9][11][12]
- Cybersecurity and resilience. Threat detection, identity management, disaster recovery and compliance create recurring demand — and ransomware and outages keep DR (disaster-recovery) planning a defensive, recurring line within the code.[1][10][19]
- Artificial intelligence (AI) deployment. AI creates demand for data preparation, infrastructure, integration, governance and security — but it also threatens to automate portions of help-desk, testing, migration and routine implementation work. A genuine two-sided force.[9][11][15]
- Government IT and defense budgets. Federal, state and local agencies keep outsourcing specialized technology, cyber, cloud and mission-support work; government spending is the single biggest demand engine for the top tier.[13][14][15][17]
- Technology complexity and IT labor shortages. Clients increasingly buy an integrated outcome rather than separate hardware, software and labor — and rent talent through staffing/consulting firms when they can't hire fast enough.[12][29]
Cyclicality. Commercial demand tracks the corporate IT-capex cycle. Federal demand is politically cyclical rather than economically cyclical — it swings on budget appropriations, continuing resolutions (stopgap funding that freezes new starts), government shutdowns, debt-ceiling fights, and administration priorities.
7. Regulation
There is no single industry regulator. Requirements depend on the customer, the data handled, and the contract — heavy on the government side, lighter on the commercial side.
Federal contractors operate under the FAR/DFARS (Federal Acquisition Regulation and its Defense supplement), sell through vehicles like GSA (General Services Administration) schedules, and must comply with:
- CMMC (Cybersecurity Maturity Model Certification) — the Department of Defense framework assessing how contractors protect Federal Contract Information and controlled unclassified information; defense-acquisition rules (DFARS 204.75) prescribe how it enters contracts.[25]
- FedRAMP (Federal Risk and Authorization Management Program) — standardized security assessment and authorization for cloud services used by federal agencies.[26]
- NIST CSF 2.0 — the National Institute of Standards and Technology Cybersecurity Framework, a widely used risk-management framework organized around governing, identifying, protecting, detecting, responding and recovering.[27]
- Security clearances, organizational-conflict-of-interest and cost-accounting rules.
The SBA size standard ($34 million average receipts, or 150 employees for IT VARs) determines who qualifies for small-business set-asides — a major competitive lever, since a large share of federal dollars is reserved for small and disadvantaged businesses.[6]
Purely commercial firms face less industry-specific regulation but still hit data rules: the HIPAA (Health Insurance Portability and Accountability Act) Security Rule when handling electronic protected health information for a healthcare client,[28] plus state privacy and breach laws (which increasingly flow through customer contracts, security questionnaires, insurance and indemnities) and general labor/worker-classification law (W-2 employee vs. 1099 contractor). Compliance can be a competitive advantage, but it raises hiring, audit, certification, insurance and infrastructure costs.
8. Competitive dynamics and consolidation
The industry is extremely fragmented at the code level. The top four firms account for just 23.2% of receipts (CR4), the top eight 28.9% (CR8), the top twenty 36.9% (CR20), and the top fifty only 45.8% (CR50); the Herfindahl-Hirschman Index (HHI, a standard concentration measure where below 1,500 is "unconcentrated") is a very low 186.6.[3] In plain terms: thousands of firms, no dominant player, low barriers for basic consulting. Barriers rise sharply for classified government work, regulated data, large contract vehicles, security certifications, vendor partnerships and complex migrations — where customer relationships and institutional knowledge create real switching costs.
Competition comes from global IT integrators and consultancies, cloud and software vendors, distributors, offshore/nearshore providers (India-based TCS, Infosys, Wipro, Cognizant, plus Accenture) that undercut commercial bill rates, specialist cybersecurity firms, and clients' own internal IT departments.[12][17] Increasingly, automation and AI threaten the billable-hours model at the commodity end of the work.
Against that fragmented backdrop, the federal and reseller tiers have been consolidating hard through M&A (mergers and acquisitions), because scale wins large contract vehicles and carries the compliance overhead:
- Carlyle's take-private of ManTech for ~$4.2 billion (2022).[22]
- Bain Capital's ~$5.3 billion acquisition of Guidehouse (2023).[21]
- Presidio's ~$2.1 billion take-private, later majority-sold to Clayton, Dubilier & Rice.[23]
- World Wide Technology's ~$1.3 billion acquisition of Softchoice (2025).[24]
- The Peraton/Perspecta/Northrop-IT roll-up under Veritas Capital, plus serial acquisitions by Leidos, SAIC and CACI.[20]
Buy-and-build can improve vendor purchasing, geographic coverage, contract access and service breadth — but also creates leverage, integration problems, customer churn, and pressure to keep acquiring.
9. Risks
- Government budget and political risk. In 2025–26 the Department of Government Efficiency (DOGE) drove recommended cuts of tens of billions in federal contracts, concentrated in consulting and IT services; several large primes saw contracts terminated or descoped and civilian-agency revenue flatten after years of double-digit growth. This is the dominant near-term risk for the public federal names.[29] Appropriations, procurement delays, protests, continuing resolutions and shutdowns all stall awards and delay payments.
- Contract concentration and recompete risk. A single large recompete lost can dent revenue; a cost-plus-heavy mix caps upside; for smaller firms one lost contract or account can be material.
- Execution risk. Fixed-price projects can lose money when scope, staffing or integration complexity is underestimated.
- Commoditization / AI disruption. Cloud vendors, software publishers, automation and AI can erode the value of routine services and the labor-hours model — a genuine threat to volume even as AI-modernization creates new demand (two-sided).
- Margin compression from competitive bidding, offshore rates, wage inflation and client vendor-consolidation; VARs also depend on vendor authorization, rebates and product availability.
- Talent and clearance scarcity. Cleared and specialized staff are hard to hire and easy to lose — the whole asset base walks out the door each night.
- Acquisition and leverage risk. Sponsor-backed platforms may lean on debt and repeated deals to hit growth targets.
- Cyber and measurement risk. These firms hold sensitive client and government systems (a breach means remediation, contract loss, regulatory action and reputational damage); and NAICS data do not cleanly separate pure-play services from adjacent activity or capture nonemployer/government work.
10. How to invest and the outlook
Public investors
Use the NAICS code as a research starting point, not a stock screen. The liquid exposure is the federal IT-services primes — Leidos (LDOS), Booz Allen (BAH), CACI (CACI), SAIC (SAIC) and diversified General Dynamics (GD) via GDIT — plus broad IT-services proxies (Kyndryl (KD), Accenture (ACN), IBM (IBM)), VARs (CDW, Insight (NSIT), ePlus (PLUS)) for install/deployment exposure, cyber specialists (Telos (TLS)), and IT staffing (ASGN, Kforce (KFRC)).[9][10][11][12][13][14][15][16][17] Compare them by actual exposure to managed services, government IT, cyber, cloud implementation, resale and proprietary software, and weigh:
- Organic (not acquisition-led) revenue growth; utilization, productivity and gross-margin trends.
- Recurring managed-service revenue and renewals; backlog quality, contract duration and recompete risk.
- Customer/government concentration; free cash flow after acquisitions; net debt and acquisition discipline.
- Valuation relative to service mix, growth, margins and balance-sheet risk. The federal primes trade like defensive government-services names — modest dividends, valuations often in the low-teens on an EV/EBITDA (enterprise value to EBITDA) basis — and share prices move with the federal-budget narrative, which turned negative on DOGE cuts in 2025, compressing multiples.[29] (Tickers, yields and multiples belong to this section only — the underlying industry is mostly private.)
Private investors
Ownership here is unusually private-equity-heavy: Carlyle (ManTech), Veritas Capital (Peraton), Bain (Guidehouse) and CD&R (Presidio) have concentrated the top tier off the public market.[20][21][22][23] The most attractive targets are specialized MSPs, cybersecurity firms, regulated-industry specialists, and government contractors with diversified customers and repeatable delivery — most of the long tail is sub-$5-million-revenue, light on capital, with recurring service relationships, making classic search-fund and lower-middle-market buyout targets. PE creates value through professionalization, cross-selling, vendor purchasing, geographic expansion and selective acquisitions. Private-credit investors should focus on recurring contract cash flow, retention, working-capital needs, contract assignability, cyber controls and downside recovery value — labor-led businesses carry less hard collateral than infrastructure owners, so cash-flow quality and leverage discipline matter more.
Outlook (forward-looking judgment, not settled fact)
The base case is secularly positive but cyclical and margin-dispersed. Expect a two-speed market: continued pressure on federal civilian and consulting work as budget discipline persists, partly offset by defense, intelligence and AI-modernization spending that plays to the primes' strengths; on the commercial side, IT-staffing revenue is expected to stabilize after several down years, led by cyber, cloud and AI skills.[29] Cloud modernization, cybersecurity, AI implementation and government technology needs should support demand, while automation, direct vendor selling, offshore competition, wage inflation and fixed-price execution will limit pricing power. The strongest businesses combine recurring services with specialized expertise, defensible relationships and disciplined capital allocation; the weakest stay exposed to commodity labor, hardware pass-through, single contracts, or acquisition-driven leverage. The wildcard both ways is AI. Position sizing should respect the political and technological uncertainty baked into the setup.
Sources
- U.S. Census Bureau, "541519 Other Computer Related Services" (definition, inclusions, exclusions), 2022. https://www.census.gov/naics/?details=541519&input=541519&year=2022
- U.S. Census Bureau, County Business Patterns 2023 — NAICS 541519: establishments, employees, annual and Q1 payroll (Histometrics ingested federal statistics). https://data.census.gov/profile/541519_-_Other_computer_related_services?n=541519
- U.S. Census Bureau, 2022 Economic Census — NAICS 541519: receipts, firm count and concentration (CR4/CR8/CR20/CR50, HHI), table EC2200SIZECONCEN (Histometrics ingested federal statistics). https://data.census.gov/table/ECNSIZE2022.EC2200SIZECONCEN?q=EC2200SIZECONCEN
- U.S. Census Bureau, "County Business Patterns Methodology" (employer-only coverage), 2026. https://www.census.gov/programs-surveys/cbp/technical-documentation/methodology.html
- U.S. Census Bureau, "Nonemployer Statistics," 2025. https://www.census.gov/econ/overview/mu0500.html
- U.S. Small Business Administration, "Table of Size Standards" (NAICS 541519 = $34.0M avg. annual receipts; 150-employee standard for IT value-added resellers), 2023. https://www.sba.gov/document/support-table-size-standards
- Outrider / HigherGov, "NAICS 541519 — Other Computer-Related Services: Federal Contracting Profile," 2024. https://outrider.app/naics-codes/541519-other-computer-related-services
- EBSCO Research Starters, "Computer systems industry" (NAICS 5415 U.S. revenue context), 2024. https://www.ebsco.com/research-starters/information-technology/computer-systems-industry
- Kyndryl, "Form 10-K for Fiscal 2025" (service mix, contract types), 2025. https://www.sec.gov/Archives/edgar/data/1867072/000155837025008282/kd-20250331x10k.htm
- Accenture, "Form 10-K for Fiscal 2025," 2025. https://www.sec.gov/Archives/edgar/data/1467373/000146737325000217/acn-20250831.htm
- International Business Machines, "Form 10-K for 2025," 2026. https://www.sec.gov/Archives/edgar/data/51143/000005114326000010/ibm-20251231.htm
- CDW Corporation, "Form 10-K," 2026. https://www.sec.gov/Archives/edgar/data/1402057/000140205726000011/cdw-20251231.htm
- GovConWire / Leidos, "Leidos Closes FY25 With $17.2B Revenue," 2025. https://www.govconwire.com/articles/leidos-fy2025-17-2b-revenue-financial-report
- Booz Allen Hamilton, "Fourth Quarter and Full Year Fiscal 2025 Results" (revenue ~$12.0B, FY ended March 31, 2025), 2025. https://investors.boozallen.com/static-files/4882d4af-72c8-4576-ad98-4418db0c8251
- GovConWire / SAIC, "SAIC Announces Full Fiscal Year 2025 Results" (revenue ~$7.5B), 2025. https://www.govconwire.com/articles/saic-q4-full-fy25-revenue-growth
- CACI International, "Results for Its Fiscal 2025 Fourth Quarter and Full Year" (revenue ~$8.6B, FY ended June 30, 2025), 2025. https://investor.caci.com/news/news-details/2025/CACI-Reports-Results-for-Its-Fiscal-2025-Fourth-Quarter-and-Full-Year-and-Issues-Fiscal-Year-2026-Guidance/
- General Dynamics, "Form 10-K for 2025" (GDIT segment), 2026. https://www.sec.gov/Archives/edgar/data/40533/000004053326000006/gd-20251231.htm
- ePlus, "Form 10-K for Fiscal 2025," 2025. https://www.sec.gov/Archives/edgar/data/1022408/000114036125020204/ef20047615_10k.htm
- Telos Corporation, "Form 10-K for 2025," 2026. https://www.sec.gov/Archives/edgar/data/320121/000032012126000010/tls-20251231.htm
- Peraton (Veritas Capital) — formation and enterprise IT/national-security profile, 2024. https://www.peraton.com/news/peraton-appoints-steve-schorer-as-chief-executive-officer
- Guidehouse, "Guidehouse Completes Transaction with Bain Capital" (~$5.3B, 2023), 2023. https://guidehouse.com/news/corporate-news/2023/guidehouse-completes-transaction-with-bain-capital
- ManTech, "ManTech Announces Completion of Acquisition by Carlyle" (~$4.2B, 2022), 2022. https://www.globenewswire.com/news-release/2022/09/14/2516381/0/en/ManTech-Announces-Completion-of-Acquisition-by-Carlyle.html
- BC Partners, "CD&R to Acquire Presidio from BC Partners" (~$2.1B take-private lineage), 2024. https://www.bcpartners.com/news/cdr-to-acquire-presidio-from-bc-partners/
- World Wide Technology, "Completion of Softchoice Acquisition" (~$1.3B, 2025); WWT and SHI are privately held VARs. https://www.wwt.com/press-release/world-wide-technology-announces-completion-of-softchoice-acquisition-expanding-software-cloud-cybersecurity-and-ai-capabilities
- U.S. Department of Defense, "Subpart 204.75 — Cybersecurity Maturity Model Certification (CMMC)," 2025. https://www.acq.osd.mil/dpap/dars/dfars/html/current/204_75.htm
- FedRAMP, "Is FedRAMP Right for You?," 2026. https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/getting-started/
- National Institute of Standards and Technology, "NIST Releases Version 2.0 of Landmark Cybersecurity Framework," 2024. https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
- U.S. Department of Health and Human Services, "The HIPAA Security Rule," 2025. https://www.hhs.gov/hipaa/for-professionals/security/index.html
- Washington Technology / Mordor Intelligence / Stafiz, "DOGE federal contract cuts, IT-staffing market size, and billable-utilization benchmarks," 2025–2026. https://www.washingtontechnology.com/opinion/2025/12/doge-was-government-contractings-biggest-story-2025-and-its-not-close/410372/; https://www.mordorintelligence.com/industry-reports/it-staffing-market