The news
SAIC acquires Information Security Corporation (ISC), the Reston, Virginia-based government technology contractor said on October 5, 2026, adding a maker of encryption and digital identity software to its defense and intelligence business. SAIC, which trades on Nasdaq as SAIC, did not disclose financial terms.
ISC has spent more than 30 years building public key infrastructure (PKI), encryption and credential management software, according to SAIC's announcement. PKI is the system of digital certificates and keys that lets computers prove who they are and encrypt data between them, and it underpins secure email, VPNs and smart-card logins.
SAIC said ISC's CertAgent certificate software has been on the National Security Agency's Commercial Solutions for Classified (CSfC) Components List for more than a decade. That list names commercial products approved for use in layered systems that protect classified information.
The company said ISC's technology is deeply embedded across the U.S. intelligence community and the Department of War, supporting authentication and data protection. SAIC also said ISC's products are built to be crypto-agile, meaning encryption methods can be swapped without rebuilding systems, which helps customers transition to post-quantum cryptography.
SAIC Chief Executive Jim Reagan said in the release that the deal combines ISC's cryptographic technology with SAIC's work delivering and operating zero-trust architectures, a security model that verifies every user and device on every request. KPMG advised SAIC and TideLock Partners advised ISC, according to the announcement. SAIC describes itself as having about 23,000 employees and about $7.3 billion in annual revenue.
The numbers
- Deal value
- Not disclosed
- ISC years in business
- 30+
- CertAgent on NSA CSfC list
- 10+ years
- SAIC annual revenue (company figure)
- About $7.3 billion
- SAIC employees (company figure)
- About 23,000
Why CEOs should care
Post-quantum cryptography is encryption designed to withstand future quantum computers, which are expected to break much of today's public-key encryption. U.S. federal agencies are under pressure to inventory and replace vulnerable cryptography, and the work runs straight through PKI: every certificate authority, smart card and VPN that relies on older algorithms. Buying a PKI vendor gives SAIC its own product in that migration rather than reselling someone else's.
For executives at federal contractors and suppliers, this is a roadmap signal. Primes are moving to own cryptographic capability, so expect contract requirements that ask for crypto-agility and a plan for post-quantum algorithms. Questions to ask your teams: do we have a list of where we use public-key encryption, which certificate systems we depend on, and how long it would take to swap algorithms?
For CISOs in regulated private-sector industries, the same logic applies on a delay. Banks, healthcare groups and critical infrastructure firms that follow federal guidance will face similar migrations. Treat certificate management as a strategic system, not a back-office utility.
The bigger picture
Large government integrators have been adding specialized security software to differentiate in a crowded services market, and cryptography is one of the few areas where approved, long-certified products are hard to build quickly. A decade on an NSA components list is the kind of credential that takes years to earn.
The deal also fits a wider industry shift toward crypto-agility. Our coverage of Cloudflare's plan for a public certificate authority with post-quantum certificates in early 2027 points the same way: the plumbing of digital trust is being rebuilt.
What’s next
Watch for how SAIC packages ISC's products in upcoming defense and intelligence bids, and whether it discloses the deal's financial effect in its next earnings report. Contractors should also track federal guidance on post-quantum migration deadlines, which will decide how fast this market grows.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





