Independent desk

The Deep State Times

Institutional power. Public record. Official contradiction.

Procurement

CISA’s JCDC charter roster overlaps with DHS cybersecurity vendors

Public membership lists for the Joint Cyber Defense Collaborative sit beside federal award records that name many of the same firms. Officials have described the partnership as voluntary information-sharing; the contracting trail is a separate, documented channel.

The Times desk · September 27, 2026

CISA’s JCDC charter roster overlaps with DHS cybersecurity vendors

The Cybersecurity and Infrastructure Security Agency announced the Joint Cyber Defense Collaborative in 2021 as a forum for government and industry to exchange operational cyber threat information. CISA’s public materials listed charter participants that included large cloud providers, endpoint vendors, telecommunications carriers, and sector coordinators. Those names appear again, according to USAspending.gov extracts and DHS contract announcements, among recipients of agency awards for software, cloud hosting, incident response retainers, and related services.

The two channels are not the same legal instrument. JCDC membership, as described on CISA’s website, is a collaborative arrangement rather than a procurement vehicle. Award records, by contrast, flow through the Federal Acquisition Regulation, interagency agreements, and other-transaction authorities that DHS and CISA have used for years. The record shows the same corporate entities can occupy both roles without a statutory bar, provided conflict-of-interest rules and source-selection procedures are followed as written.

Charter-era lists published by CISA named firms such as Amazon Web Services, Microsoft, Google, CrowdStrike, Palo Alto Networks, Cisco, and others that also appear as prime or subcontractors on DHS cybersecurity line items. USAspending data for the Department of Homeland Security and CISA, filtered to information-technology and cybersecurity product-service codes, show multi-year obligations to several of those companies for cloud, identity, threat-intelligence platforms, and professional services. Dollar amounts fluctuate by fiscal year; the pattern of overlap is visible in the public ledgers rather than in any single classified annex.

Inspector General reports on DHS acquisition have repeatedly flagged competition, small-business set-aside compliance, and contractor past-performance documentation as recurring audit themes. Those reports do not, on their face, allege that JCDC membership caused an award. They do document that cybersecurity buying at DHS is concentrated among a relatively small set of large vendors—the same market that supplies both commercial tools and the personnel who sit on industry working groups.

CISA officials have, in public testimony and fact sheets, described JCDC as a means to speed defensive information from private operators to government and back. Industry associations have echoed that framing in congressional statements of record. Neither side, in those public positions, has claimed that collaborative status substitutes for a competitive bid. Contracting officers remain bound, according to DHS acquisition manuals posted online, to evaluate proposals against stated criteria, including price, technical approach, and organizational conflicts of interest.

Organizational conflict rules are the hinge. Federal Acquisition Regulation Subpart 9.5 requires agencies to identify situations in which a contractor’s other relationships could bias advice or give an unfair advantage. JCDC participation involves access to threat indicators and, in some workstreams, draft operational playbooks. Whether that access creates a conflict for a subsequent bid is a fact-specific determination that contracting files, not press releases, would record. Those files are not routinely published in full; GAO bid-protest decisions and IG audits occasionally surface excerpts when a protest is filed.

GAO’s public docket on DHS and CISA information-technology protests shows a mix of sustained and denied challenges over the past several years, including disputes over evaluation of technical solutions and past performance. None of the published decisions reviewed for this dispatch rest the outcome solely on JCDC membership. They do illustrate that competitors watch the same vendor set and will protest when they believe evaluation was uneven.

Budget justifications submitted to Congress list CISA’s Continuous Diagnostics and Mitigation program, the National Cybersecurity Protection System, and related efforts as major spend categories. Those justifications name commercial products and cloud environments without always naming every prime. Cross-walking those program names to USAspending awards again surfaces many of the JCDC-era firms. The alignment is consistent with a concentrated commercial cybersecurity market rather than proof of a secret preference.

Revolving-door statistics compiled by watchdog groups from lobbying disclosures and Office of Government Ethics filings show former DHS and CISA officials later employed by large cyber vendors, and vendor executives later appointed to advisory bodies. Those movements are lawful when cooling-off periods and recusal rules are observed. They add a personnel overlay to the institutional overlap already visible in membership lists and award tables.

State, local, tribal, and territorial partners that receive CISA technical assistance often inherit the same commercial stack through federal grant conditions or shared-services offerings. Grant guidance posted by DHS does not require JCDC membership; it does frequently reference tools already on federal contract vehicles. The practical effect, according to the published guidance, is that a vendor successful in Washington can appear again in a city’s security operations center via a different funding stream.

Transparency mechanisms exist in incomplete form. USAspending, SAM.gov, and CISA’s own JCDC pages are public. Detailed source-selection statements, conflict-of-interest analyses, and the full text of other-transaction agreements are not. FOIA logs published by DHS show repeated requests for CISA partnership and contracting records; production is often delayed or redacted for proprietary and deliberative exemptions.

The institutional picture that public documents support is therefore modest: a voluntary cyber-defense collaborative whose charter members include firms that also win DHS cybersecurity dollars, under rules that treat collaboration and procurement as separate processes, audited after the fact rather than walled off in advance. Whether that arrangement concentrates risk, improves defense, or both is a policy argument Congress has taken up in hearings; the ledgers themselves show the names recurring.

Further awards will continue to post. Further membership expansions will continue to be announced on CISA’s site. The comparison between those two public lists remains available to anyone willing to read both.