Telos wins $13.7m HHS contract to automate federal cyber GRC
Telos Corporation has secured a $13.7 million task order from the U.S. Department of Health and Human Services to overhaul the department's cyber governance, risk and compliance (GRC) and Authority to Operate (ATO) workflows. The 18-month contract, awarded to the Ashburn, Virginia-listed firm (NASDAQ: TLS), covers the full Xacta platform alongside cybersecurity services, enterprise integration, staff training and data migration.
The deployment centres on three products from the Xacta suite. Xacta 360 will handle security authorisation workflows, control assessments and continuous monitoring. Xacta.io aggregates data from security tooling across the HHS enterprise to improve visibility into posture and risk. Xacta.ai layers AI-powered analysis on top to reduce manual compliance effort and surface actionable risk insights. All three components are authorised at FedRAMP Class D (High), the programme's most demanding security baseline, which covers environments handling sensitive unclassified government information.
John B. Wood, chairman and chief executive of Telos, said the award "demonstrates the scale and breadth of what our cyber GRC platform can deliver for large, complex federal organisations," adding that it "reflects the need for an integrated approach to cyber risk management that brings automation, enterprise security data and AI together in a secure cloud environment."
Federal GRC market context
The federal GRC and ATO market has grown steadily as agencies contend with rising volumes of systems requiring authorisation under the Federal Information Security Management Act (FISMA) and the Office of Management and Budget's evolving zero-trust mandate. The sheer size of HHS, which operates dozens of agencies including the FDA, CDC and CMS, makes continuous ATO a significant operational challenge: the department manages a large and heterogeneous IT estate, and manual compliance processes create backlogs that delay mission-critical system deployments.
Telos competes in this space against ServiceNow's Integrated Risk Management module, Archer (a Symphony Technology Group product), and a number of specialist federal IT contractors. The AI-augmented automation angle differentiates Xacta.ai at a time when agencies are under pressure from the Office of Management and Budget to accelerate compliance timelines without proportionally increasing headcount. FedRAMP High authorisation is a meaningful barrier to entry: achieving and maintaining it is costly and time-consuming, which tends to consolidate federal SaaS procurement around a smaller pool of pre-authorised vendors.
Regulatory and standards read-across
HHS is subject to HIPAA as well as FISMA, and the department's information security office must demonstrate compliance with NIST SP 800-53 controls across systems that hold protected health information. The broader federal push toward continuous authorisation (cATO), endorsed by the Cybersecurity and Infrastructure Security Agency (CISA) and codified in OMB memoranda, favours platforms that automate evidence collection and reduce reliance on point-in-time assessment cycles. Telos's Xacta.io integration layer is directly positioned to support this model by pulling real-time signals from existing security tools rather than requiring manual data entry.
The contract runs for 18 months, suggesting an initial delivery window extending into early 2028. Telos did not disclose whether the task order includes options for extension or additional agencies within the HHS enterprise. With federal IT budgets under ongoing scrutiny on Capitol Hill, the company's ability to demonstrate measurable reductions in compliance cycle time at HHS will likely influence whether the programme is expanded or replicated across other cabinet-level departments.