Last updated: September 4, 2026
Quick Answer
There is no NAICS code called cybersecurity. 541512, Computer Systems Design Services, is the closest and the one most vendors register under. It is also not enough on its own, because agencies file security work under several codes depending on who is buying.
- 541512 covers design and integration work, which captures assessment and architecture engagements.
- 541519 catches managed and monitoring services, 541690 catches advisory work, 561621 catches security systems.
- Most state and local security engagements in 2026 records ran $12,500 to $48,000.
- Many buyers never apply a code at all, so a registration-only strategy is thin.
If you sell security services to state and local government, you will eventually be asked for a NAICS code by a registration portal. The question sounds administrative. It quietly decides which alerts you receive for the next year, so it is worth getting right.
Why there is no cybersecurity code
NAICS classifies industries by what a business produces, and it predates the point at which security became its own product category. Security work therefore gets distributed across the codes that describe the underlying activity: designing a system, running a system, advising on a system, or installing security equipment.
The practical consequence is that two agencies buying the same penetration test can classify it two different ways, and a vendor registered under one code never sees the other.
| Code | Official title | Security work it typically carries |
|---|---|---|
| 541512 | Computer Systems Design Services | Security architecture, assessments, integration, most consulting engagements |
| 541519 | Other Computer Related Services | Managed detection, monitoring, ongoing security operations |
| 541511 | Custom Computer Programming Services | Application security work delivered as custom development |
| 541690 | Other Scientific and Technical Consulting Services | Risk assessments and advisory work bought by a finance or audit committee |
| 561621 | Security Systems Services | Access control, cameras and monitoring, often bought by facilities |
Register under 541512 as your primary, then add the others that genuinely describe work you deliver. Padding the list with codes you cannot serve produces noise, not pipeline. For the basics of the system itself, see our explainer on what a NAICS code is.
Who is actually buying, and for how much
The buyer profile is broader than most vendors assume. In 2026 meeting records, security assessments were approved by school districts, cities, water districts, a public hospital and a career and technology education board, frequently in the same month.

Two things stand out. The deal sizes are small enough that many fall below competitive bidding thresholds, which means they are awarded from a quote rather than a solicitation. And the same engagement recurs, often annually, which makes an incumbent hard to dislodge once installed.
Grants are quietly funding a share of it
A Connecticut town approved $40,000 of penetration testing in June 2026 under a state cybersecurity grant, with a separate $50,000 state grant item recorded the same month. Grant funded work runs on the grant’s calendar, not the agency’s budget cycle, which is why it appears at odd times of year.
Where a code-only strategy breaks down
Registration gets you onto lists. It does not get you into the conversation, and in this category the conversation is usually short.
| Agency | Type | What was approved or discussed | Value / date |
|---|---|---|---|
| City of Long Beach | City | Council item on a cybersecurity engagement | $48,000, Jul 8 2026 |
| Mcwa Kendall Water District | Utility District | Planned cybersecurity assessment and penetration test, no vendor named | Jun 11 2026 |
| Lowell School District | School District | School security assessment RFP | Aug 11 2026 |
| Oswego Unified School District 504 | School District | External penetration testing engagement | $12,500, Jul 1 2026 |
| Career And Technology Education Centers | Higher Ed | Cybersecurity penetration testing engagement with a named provider | $19,117, Aug 25 2026 |
| Metro Nashville General Hospital | Public Hospital | Upcoming independent cybersecurity penetration test | Jun 10 2026 |
| City of Mountain Home | City | Budget meeting item covering penetration testing | Jun 25 2026 |
| Michigan community health authority | Public Authority | Three-year penetration testing contract | $34,848, Jul 16 2026 |
Source: state and local meeting records indexed by Civic IQ, pulled September 1, 2026. Values are as stated in each body’s own records.
Read the Mcwa Kendall and Metro Nashville rows again. Both describe a planned or upcoming assessment with no vendor named. Those are the two rows in the table where a new supplier could still win the work, and neither carried a NAICS code when it appeared.
What to do with this
- Register 541512 as primary, then add 541519, 541690 and 561621 only where you genuinely deliver.
- Register with the individual agencies in your territory as well. Codes route alerts, but many buyers keep their own vendor list.
- Watch for the words assessment, penetration test and vulnerability in board and council agendas, which is how the work is named before it is classified.
- Note the renewal month on any recurring engagement you lose. Annual programs come back around, and the incumbent gets complacent.
- Follow state cybersecurity grant programs in your states, since they create funded demand outside the normal budget cycle.
Security buying is one of the fastest moving categories in the SLED sector. Our guide to finding government cybersecurity projects before the RFP covers the monitoring side, and selling cybersecurity to local government covers the pitch itself.
Open RFPs related to this topic
Live opportunities surfaced by Civic IQ as of 2026-09-01. Status changes daily.
- Community TeamWork IT Support & Cybersecurity Services RFQ-2026-091, Community TeamWork, Inc., MA (due 2026-09-01)
- Community TeamWork IT Services Managed IT Support & Cybersecurity RFQ-2026-091, Community TeamWork, Inc., MA (due 2026-09-01)
- Gray County Airport Hardware, Network Diagnostics, and Cybersecurity Services 2026, Gray County, TX (due 2026-09-03)
- Mesa Consolidated Water Dist IT Managed Services RFP 2026-1007, Mesa Consolidated Water Dist, CA (due 2026-09-03)
- Haralson County Outsourced Managed IT and Phone Services RFP 2026, Haralson County, GA (due 2026-09-08)
- City of Weston IT Infrastructure Managed Services RFQ No. 2026-12, City of Weston, FL (due 2026-09-01)
Frequently asked questions
What is the NAICS code for cybersecurity?
There is no code named cybersecurity. 541512, Computer Systems Design Services, is the closest and most commonly used. Agencies also file security work under 541511, 541519, 541690 and 561621 depending on how they think about the purchase.
Is 541512 the right code for a security services vendor?
It is the right primary code for most of them, because 541512 covers designing and integrating computer systems, which is how assessment, architecture and implementation work is classified. It is rarely sufficient on its own.
What other codes should a cybersecurity vendor register under?
541519 for other computer related services, which catches managed and monitoring work. 541690 for other scientific and technical consulting, which catches assessment and advisory engagements. 561621 for security systems services, which is where physical and electronic security is filed. 541511 if you deliver custom software.
Do state and local agencies actually use NAICS codes?
Inconsistently. Many state portals and cooperative programs use NAICS for vendor registration and category alerts. Plenty of counties, districts and small towns use their own commodity codes or no classification at all, which is why code registration alone is a weak sourcing strategy.
What does a typical state or local penetration test cost?
In 2026 meeting records most sat between $12,500 and $48,000 for a single engagement. A Michigan authority signed a three-year testing contract at $34,848 and one New York district budgeted $120,000 a year for a broader program.
How do you find security work that is not classified at all?
Read the meeting records rather than the code. Assessments and testing are usually approved by name in a board or council item, often months before any purchase order carries a classification code.



