Coact
COACT is an SDVOSB cybersecurity and compliance services firm serving U.S. federal agencies, the Department of Defense, DIB contractors, and regulated organizations with accredited FedRAMP and GovRAMP 3PAO assessments, penetration testing, operational support, and mission-focused software development.
- Company typePrivate
- Founded1990
- HeadquartersColumbia, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Coact does
COACT, Inc. is a Columbia, Maryland-based Service-Disabled Veteran-Owned Small Business (SDVOSB) founded in 1990 that delivers cybersecurity and compliance professional services. Its core offerings cover compliance advisory and assessment for FISMA, FedRAMP, GovRAMP, LADMF, NIST SP 800-171, and CMMC; offensive security testing (Red Team operations, vulnerability assessments, social engineering); operational support including 24/7 system administration for classified Department of Defense environments; and mission-focused software development for missile defense modeling, simulation, and analysis built primarily in C++ and Java. The firm operates on a professional-services model: revenue is generated through custom-quoted consulting engagements, independent assessment fees charged to organizations seeking authority to operate, and task orders issued under federal IDIQ vehicles including SeaPort-NxG in support of the Department of the Navy (awarded January 2025) and the Missile Defense Agency SHIELD IDIQ (awarded December 2025, $151B ceiling, performance through December 2035).
COACT's competitive position is anchored by four hard-to-replicate regulatory credentials: FedRAMP Third-Party Assessment Organization (3PAO) accreditation (granted May 2012 as one of the first commercial recipients), GovRAMP 3PAO status, Accredited Conformity Assessment Body (ACAB) designation for the Limited Access Death Master File under NTIS, and ISO 17020 plus ISO 9001:2015 quality accreditations. Customer concentration is overwhelmingly federal: the Department of Defense (including missile defense modeling-and-simulation centers), Defense Industrial Base contractors needing CMMC certification, federal civilian agencies requiring FISMA/FedRAMP work, and State, Local, and Education buyers under GovRAMP. SDVOSB status enables sole-source and set-aside awards, which materially lowers the cost of federal-customer acquisition. The company has 11–50 employees per its self-classified headcount band, does not raise disclosed funding, has no parent company, and sells via direct consultations and contract-vehicle presence rather than volume marketing.
Coact firmographics
Firmographics- Name
- Coact
- Legal name
- COACT, Inc.
- Website
- https://coact.com
- Company type
- Private
- Founded year
- 1990
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- COACT is an SDVOSB cybersecurity and compliance services firm serving U.S. federal agencies, the Department of Defense, DIB contractors, and regulated organizations with accredited FedRAMP and GovRAMP 3PAO assessments, penetration testing, operational support, and mission-focused software development.
- Ownership category
- akta.pro rank
Where Coact is headquartered
LocationHeadquarters
- HQ city
- Columbia
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Coact business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Government Cybersecurity & Compliance Consulting: COACT generates revenue through professional services engagements providing cybersecurity compliance consulting (FISMA, FedRAMP, GovRAMP, LADMF, NIST 800-171, CMMC), penetration testing, operational support, and software development to federal agencies and contractors. Revenue is earned through contract awards, IDIQ task orders, and direct consulting engagements, primarily with government clients.
- Third-Party Assessment Services (3PAO/ACAB): As an accredited FedRAMP and GovRAMP Third-Party Assessment Organization and ACAB for LADMF, COACT performs independent security assessments of cloud service providers and other organizations. These assessment services generate revenue from assessment fees charged to organizations seeking authorization or certification.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting and assessment engagements priced per project |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels4 records
Coact product offering
Product offeringCore offering
Coact is a Service-Disabled Veteran-Owned Small Business providing independent cybersecurity and compliance services to federal agencies, the Department of Defense, the intelligence community, defense contractors, and commercial organizations. The company delivers accredited third-party assessments (FedRAMP 3PAO, GovRAMP 3PAO, LADMF ACAB), penetration testing, vulnerability assessments, incident response, classified operational support for DoD systems, and mission-focused software development for missile defense and modeling/simulation applications.
Product overview
COACT is a cybersecurity and compliance services company that offers a comprehensive suite of professional services rather than a unified software product. The core offerings include: Compliance Services (covering FISMA, FedRAMP, GovRAMP, LADMF, NIST SP 800-171, and CMMC frameworks); Penetration Testing & Adversary Emulation; Operational Support for DoD systems; and Software Development for modeling, simulation, and missile defense applications. These services are delivered through accredited 3PAO assessments, consulting engagements, and mission-focused engineering. COACT operates as a Service Disabled Veteran Owned Small Business (SDVOSB) founded in 1990.
Differentiator
Problem solved
Functional benefit
Products and services
- FedRAMP Third-Party Assessment (3PAO) Services Accredited independent security assessments for cloud service providers pursuing FedRAMP authorization, including readiness assessments, full security assessments, and continuous monitoring reviews, delivered to federal agencies and cloud providers.
- GovRAMP Third-Party Assessment (3PAO) Services Independent security assessments under the GovRAMP program for state, local, and education (SLED) cloud service providers seeking GovRAMP authorization.
- LADMF ACAB Assessment Services Independent cloud security assessments under the DoD Launch Authorization Designated Maturity Framework (LADMF) as an Authorized Cybersecurity Assessor Body (ACAB).
- FISMA and NIST RMF Compliance Services Federal Information Security Modernization Act (FISMA) and NIST Risk Management Framework (RMF) compliance support for federal information systems, including documentation, assessment, and authorization support.
- NIST 800-171 and CMMC Compliance Services Cybersecurity compliance services for defense contractors and federal suppliers needing to meet NIST 800-171 and Cybersecurity Maturity Model Certification (CMMC) requirements for protecting Controlled Unclassified Information (CUI).
- Penetration Testing and Vulnerability Assessment Adversary-style penetration testing and vulnerability assessments of networks, applications, and systems for federal agencies, defense contractors, and commercial organizations.
- Classified DoD Operational Support Cleared personnel providing operational, technical, and cybersecurity support for classified Department of Defense systems, networks, and missions.
- Mission-Focused Defense Software Development Custom software development for DoD and intelligence community mission applications, including missile defense systems and modeling/simulation platforms.
Quantifiable outcome
- FedRAMP 3PAO authorization enabling COACT to perform security assessments for Cloud Service Providers seeking ATO
- +2 more outcomes
Companies that use Coact
Customer profileNamed customers6 records
Segments6 records
Ideal customer profiles4 records
Coact technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature9 records
Coact partnerships and signals
Strategic signalScale indicators7 records
Recent moves6 records
Expansion highlights6 records
Coact competitors and assessment
Company assessmentDirect peers
- CGI Federal: CGI Federal is an accredited FedRAMP 3PAO delivering federal cloud, cybersecurity, and compliance services — a near-direct peer to COACT in FedRAMP/GovRAMP advisory and assessment work.
- Coalfire Federal: Coalfire Federal is one of the original FedRAMP 3PAOs and provides FedRAMP/GovRAMP advisory, CMMC readiness, and federal cybersecurity assessments — directly overlapping COACT's 3PAO and compliance service line for federal and commercial clients.
- Linford & Company: Linford & Co. is an accredited FedRAMP 3PAO focused on federal and commercial compliance assessments — directly competing for the same assessment and advisory engagements COACT targets.
- A-LIGN: A-LIGN is an accredited FedRAMP 3PAO providing FedRAMP, CMMC, SOC 2 and ISO assessments with strong federal/SLED exposure — competing head-to-head with COACT on compliance assessment and advisory work.
- Schellman & Co. Schellman is an accredited FedRAMP 3PAO delivering FedRAMP, CMMC, SOC, ISO and other compliance assessments to CSPs and federal contractors — directly competing for the same 3PAO engagements that COACT pursues.
Broad incumbents
- SAIC: SAIC is a large federal IT and cybersecurity integrator holding MDA and Navy IDIQ vehicles — a broader incumbent that will compete against COACT for higher-dollar task orders under SeaPort-NxG and SHIELD.
- Kratos Defense & Security Solutions: Kratos is a publicly traded federal contractor with a sizable cybersecurity and missile defense practice, sharing the MDA SHIELD IDIQ program — overlapping with COACT on DoD cyber, compliance, and MDA mission work.
- Booz Allen Hamilton: Booz Allen is a top-tier federal cyber consulting prime with deep penetration of FedRAMP, CMMC, and DoD cybersecurity work — establishing the upper-bound benchmark for pricing and delivery scale that COACT must match.
- Leidos: Leidos is a federal systems integrator with substantial cybersecurity, compliance, and classified IT work — competing for the same DoD and federal civilian task orders as COACT at the prime level.
- RSM US Federal: RSM US has a growing federal cybersecurity and compliance practice offering FedRAMP, CMMC, and FISMA advisory — comparable to COACT's mid-market compliance consulting scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
Coact social profiles
Digital presenceCoact compliance and trust
Trust signalCompliance5 records
Coact financial estimates
Financial estimateRevenue estimate
Valuation estimate
Coact leadership team
Management profileNumber of profiles
Coact funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Coact M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Coact
What does Coact do?
Coact is a Service-Disabled Veteran-Owned Small Business providing independent cybersecurity and compliance services to federal agencies, the Department of Defense, the intelligence community, defense contractors, and commercial organizations. The company delivers accredited third-party assessments (FedRAMP 3PAO, GovRAMP 3PAO, LADMF ACAB), penetration testing, vulnerability assessments, incident response, classified operational support for DoD systems, and mission-focused software development for missile defense and modeling/simulation applications.
Is Coact a public or private company?
Coact is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Coact founded?
Coact was founded in 1990. It employs 11 to 50 people.
Where is Coact based?
Coact is headquartered in Columbia, United States, in the North America region.
How does Coact make money?
Two revenue lines are on record. Government Cybersecurity & Compliance Consulting is the primary driver. The others are third-Party Assessment Services (3PAO/ACAB).
Who are Coact's main competitors?
Direct peers on record are CGI Federal, Coalfire Federal, Linford & Company, A-LIGN and Schellman & Co.. Broad incumbents are SAIC, Kratos Defense & Security Solutions, Booz Allen Hamilton, Leidos and RSM US Federal.
Does Coact have an API?
No public API is recorded for Coact.