M&A activity snapshot
Services firms now make up most cybersecurity deals. Capstone Partners reports that general cybersecurity service providers and MSSPs accounted for 59.5% of dealmaking in YTD 2026. Overall volume has cooled from its 2024 peak: Capstone counted 79 cybersecurity transactions in YTD 2026, a 9.2% decrease year over year, against 466 for full-year 2024.
Dollar value is a different story, driven by software megadeals. Momentum Cyber tracked $96B deployed across 400 cybersecurity transactions in 2025, the largest M&A year on record, with strategic acquirers capturing 92% of disclosed value. Most of that value was software, not services.
Spending behind the services market keeps rising. Gartner's July 2025 forecast puts worldwide security services spending at $83,812 million in 2025 and $92,780 million in 2026.
Who is buying
MDR and MSSP platforms building scale. Sophos acquired Secureworks in an all-cash transaction valued at approximately $859 million and now describes itself as the largest pure-play MDR provider. LevelBlue agreed to acquire Trustwave, creating the largest pure-play MSSP in the industry, then completed its purchase of Aon's cybersecurity consulting groups, including Stroz Friedberg, to pair incident response with its MDR service.
IT services majors. Accenture called CyberCX its largest cybersecurity acquisition to date and noted it has completed 20 security acquisitions since 2015. Terms were not disclosed.
Defense and government contractors. Parsons acquired national-security IT and cybersecurity provider Altamira Technologies for an enterprise value of $375 million, about 12.8x NTM EBITDA.
Private equity. Capstone reports the strategic share of cyber deals fell to 58.6% in YTD 2025, below 60% for the first time since 2018. PE-backed platforms are active below the large-cap tier: Capstone advised on Alchemy Technology Group's acquisition of Massachusetts provider IOvations, which closed in April 2026.
What buyers look for
Recurring managed revenue. Capstone says PE groups are drawn to the sector's continued expansion and strong recurring revenues. A firm whose revenue is mostly 24/7 monitoring and MDR contracts is valued differently from one that sells one-off penetration tests.
Government authorizations. LevelBlue's Trustwave announcement headlined adding FedRAMP and StateRAMP certifications. Authorizations like these, and CMMC assessor status, take years to earn.
A position in regulation-driven demand. Under the CMMC rule, Phase 2 adds third-party Level 2 certification as a condition of contract award one year after Phase 1 begins. The DFARS rule that starts Phase 1 was effective November 10, 2025. For public companies, the SEC requires a Form 8-K generally due four business days after a registrant determines that a cybersecurity incident is material, which drives incident response retainers and governance work.
Analyst retention. Talent is the constraint. ISC2 reports a global workforce gap of 4.8 million, up 19% year over year, and BLS reports a median annual wage of $129,180 for information security analysts in May 2025. Buyers check analyst turnover and how much of the SOC depends on a few senior people.
What makes a strong company
- A majority of revenue from multi-year managed services (MDR, SOC monitoring, managed compliance) rather than projects.
- Audited credentials such as SOC 2 Type II and ISO 27001, plus FedRAMP, StateRAMP, or CMMC assessor status where the client base needs them.
- Owned processes and tooling, so margin does not depend entirely on reselling a vendor's product.
- Low analyst turnover against a market where information security analyst employment is projected to grow 21 percent from 2025 to 2035.
- A client base that insurers view favorably. The NAIC notes that companies investing in security controls are looked upon favorably by underwriters, which gives clients a reason to keep paying for managed security.
Valuation and deal structure
Capstone's sector multiples blend software and services. Cyber deals averaged 4.3x EV/revenue and 11.7x EV/EBITDA from 2025 through YTD 2026, close to the eight-year sector average of 4.6x and 11.6x. Its September 2025 report adds that services businesses typically draw lower revenue multiples, while software providers averaged 6.3x in YTD 2025.
That makes EBITDA the more useful yardstick for a services firm. Disclosed services deals show the range at scale: Parsons paid about 12.8x NTM EBITDA for Altamira, and Secureworks shareholders received $8.50 per share, a 28% premium to the 90-day average price. No public source publishes a services-only multiple for lower-middle-market MSSPs, so smaller firms should treat these as upper reference points.
Earnouts and seller rollover are common in PE platform deals generally. The sources above do not quantify their use in cyber services. To see where a specific business might land, use the valuation tool.
Outlook
Demand drivers are dated and specific. CMMC Phase 2, requiring Level 2 third-party certification at contract award, begins November 10, 2026, and the DFARS rule applies CMMC across covered contracts on or after November 10, 2028. Gartner expects security services spending to keep growing through 2026.
Expect continued consolidation into MDR and MSSP platforms, with PE taking a larger share of smaller deals. Capstone expects competition for AI security developers and service providers to push bids up. The insurance market is a counterweight: the NAIC reported U.S. cyber insurance premiums fell 7% to about $9.14 billion in 2024, its first ever premium decline, while the number of claims rose almost 40%.
MSPs that add security are a frequent target too; see the MSP page, the Technology & IT Services overview, and what buyers look for in MSP and IT services firms.