Articles
DLA Contractor Acquisitions:
A Regulatory Diligence Guide for PE Buyers
September 1, 2026
Authors:

DLA contractors can be attractive acquisition targets, but they operate in a regulatory environment that creates diligence and structuring issues specific to government contracting. PE deal and legal teams should focus on the following:

  • Revenue durability: Understand the contract vehicles, product mix, and customer concentration driving the target’s DLA business, and distinguish between contractual ceilings and actual order history.
  • Transaction structure consequences: Even stock acquisitions that do not require novation can trigger size rerepresentation, cybersecurity reassessment, FOCI reporting, organizational conflict-of-interest issues, and other government contract consequences requiring agency engagement and pre-signing planning.
  • Successor liability exposure: Acquirers inherit False Claims Act risk for pre-closing conduct, and recent DOJ settlements confirm that both successor entities and PE sponsors with hands-on involvement face direct enforcement.
  • Compliance-dependent value: Small-business status, cybersecurity posture (including CMMC readiness), domestic-preference compliance, and product qualification status can each be central to the investment thesis and vulnerable to disruption by the transaction itself.
  • Integration planning: Post-closing decisions on IT consolidation, facility moves, name changes, and organizational restructuring carry government-contract consequences that should be mapped before signing.

The Defense Logistics Agency ("DLA") is one of the largest purchasing organizations in the federal government, obligating tens of billions of dollars each year for goods and services in support of the U.S. military and other federal agencies. For many defense contractors, DLA represents an attractive customer: demand can be recurring, customer relationships often extend for decades, and approved suppliers of critical components may benefit from meaningful barriers to entry.

Those same characteristics can make a DLA contractor an appealing acquisition target.

But a DLA business presents diligence issues that a conventional M&A process can miss. A target may show strong margins, a substantial backlog, and years of successful DLA performance yet carry historical compliance liabilities or face post-closing changes that impair its ability to compete for the same work.

For private equity buyers, DLA diligence should answer two questions:

  • First, what liabilities may be hiding in the business the buyer is acquiring?
  • Second, what changes because the buyer acquires it?

The sections below highlight issues that PE deal and legal teams should consider when evaluating a target with material DLA revenue.

1. Understand What Is Actually Driving the DLA Revenue

Start by looking behind the revenue numbers.

DLA purchases millions of different items, frequently identified by National Stock Numbers ("NSNs"), through a variety of contract vehicles, including indefinite-delivery/indefinite-quantity ("IDIQ") contracts, blanket purchase agreements ("BPAs"), prime vendor arrangements, spot buys, and automated acquisition procedures. Two businesses with identical amounts of DLA revenue can have very different risk profiles depending on how that revenue is generated.

Buyers should understand which DLA organizations are purchasing from the target (DLA Land and Maritime, DLA Aviation, DLA Troop Support, and others each have distinct product lines and procurement approaches), the contract vehicles through which those purchases occur, and which products and NSNs generate the target's revenue and margin.

Concentration deserves particular attention. A target whose DLA revenue is spread across hundreds of competitively sourced products presents a different investment profile from one whose EBITDA depends heavily on a handful of sole-source or source-controlled components. Sole-source items can be highly profitable, but they may also attract greater regulatory scrutiny and pricing pressure over time.

Deal teams should also distinguish between contractual ceilings and actual order history. The maximum value of an IDIQ contract does not represent a guaranteed revenue stream. DLA is obligated only to order the contract minimum (often a nominal amount), and future task orders depend on continued demand, satisfactory performance, and competitive pricing.

The goal is to pinpoint the sources of the target's DLA value and test whether they will endure after closing.

2. Determine What Changes Because of the Transaction

One of the most important diligence questions is also one of the simplest: What changes on Day 1 because the buyer now owns the company?

Start with the Anti-Assignment Act (41 U.S.C. 6305), which prohibits the transfer of government contracts from one party to another. Novation under FAR Subpart 42.12 is the statutory exception: the government may, when it is in its interest, recognize a successor in interest to a contract, but the contracting officer is not obligated to do so.

A stock acquisition generally does not require the government to novate the target's contracts, because the contracting entity remains legally unchanged. Under FAR 42.1204(b), a change of ownership through stock purchase, where there is no legal change in the contracting party and the original entity retains control of the assets, does not trigger the novation process. That said, FAR 42.1203(e) contemplates that even in a stock purchase, there may be ownership-related issues that the contracting officer will expect to address through a formal agreement between the contractor and the government. Buyers should not assume that a stock deal means no government engagement is required.

An asset acquisition, by contrast, may require government consent and a formal novation under FAR 42.1204(a), since the government's contracting relationship is being transferred to a new legal entity. Novation is not automatic; the contracting officer must agree that recognizing the successor is in the government's interest.

The absence of a novation requirement, however, does not mean a stock acquisition has no government-contract consequences. Even a straightforward stock deal may trigger:

  • Size or socioeconomic status rerepresentation obligations under FAR 19.301-2;
  • Changes to SAM.gov registration data, including ownership and CAGE code updates;
  • Revised representations and certifications;
  • Cybersecurity reassessment and notification obligations;
  • Potential FOCI (Foreign Ownership, Control, or Influence) reporting, depending on the buyer's ownership structure;
  • Organizational conflicts of interest under FAR Subpart 9.5, particularly where the buyer's other portfolio companies provide advisory, technical, or consulting services to DLA or other DoD components while the target competes for supply contracts.

The buyer should identify those consequences before signing rather than discovering them during integration. Each of these issues carries its own timeline and procedural requirements, and several can affect the target's eligibility for future awards if not handled correctly.

The organizational conflict of interest point deserves particular emphasis for PE buyers. A sponsor with multiple defense portfolio companies may find that one company's existing relationships create an OCI that affects the target's ability to compete for or perform on specific contracts. Common ownership alone does not necessarily establish an OCI, but it may make the relationships among the portfolio companies relevant to the agency’s analysis. FAR 42.1204(d) also requires the contracting officer to evaluate OCI when considering any novation request. Identifying potential conflicts early allows the buyer to structure the deal, or plan post-closing firewalls, in a way that preserves the target's competitive position.

3. Understand How Much of the Investment Case Depends on Small-Business Status

Small-business status can be particularly important in DLA contracting, where a meaningful share of procurement activity is set aside for small businesses or flows through small-business subcontracting plans.

A target may hold current contracts or qualify for future competitions because it is a small business, a service-disabled veteran-owned small business, a HUBZone firm, or another socioeconomic category. A private equity acquisition can upend that analysis. Under SBA's affiliation rules at 13 CFR 121.103, the target may be required to aggregate its employees or annual receipts with those of the sponsor, the sponsor's other portfolio companies, and potentially entities further up the fund's ownership chain. Affiliation is not limited to majority ownership. It can arise from the power to control the target's board, veto rights over ordinary business decisions, common management across portfolio companies, or identity of interest between related parties.

An acquisition can also trigger mandatory size rerepresentation requirements under existing federal contracts. A rerepresentation as other than small generally changes how the agency reports future contract dollars and may affect eligibility for future orders, options, or competitions depending on the contract vehicle and applicable rules.

The diligence question is not simply, "Is the target currently a small business?" Buyers should also determine:

  • Whether the target will remain small after the acquisition, once SBA affiliation rules are applied and the sponsor's broader portfolio is taken into account.
  • How much of the target's current revenue and pipeline depends on small-business status, including set-aside awards, sole-source 8(a) contracts, and mentor-protégé arrangements.
  • What the competitive landscape looks like without small-business preferences. A target that competes successfully in set-aside procurements may face a very different competitive environment in full-and-open competitions.

Losing small-business status is not necessarily disqualifying, but it can meaningfully change the investment thesis. Buyers should model the revenue impact before the deal closes, not after.

4. Evaluate Historical and Successor False Claims Act Exposure

The False Claims Act (“FCA”) is among the most significant liability risks in a government contractor acquisition. For DLA contractors, the risk can arise from product quality, pricing, cybersecurity, and domestic-preference issues.

FCA exposure can arise from a range of conduct, including: knowingly delivering nonconforming products; misrepresenting country of origin, product testing, or material certifications; submitting inflated pricing data; and falsely certifying compliance with contract terms, cybersecurity requirements, or domestic-preference rules. DLA's high volume of individual purchase transactions, often involving technical product specifications and testing requirements, creates a broad surface area for potential violations.

An acquisition does not eliminate historical FCA risk. In a stock acquisition, the target entity generally retains its pre-closing liabilities, leaving the buyer economically exposed through its ownership of the target. In other transaction structures, including certain business transfers and asset acquisitions, the government may also pursue acquiring entities under successor-liability theories. As a result, buyers should not assume that transaction structure alone insulates them from pre-acquisition misconduct.

Recent DOJ enforcement actions underscore this risk. In May 2025, DOJ announced an $8.4 million settlement with Raytheon Company, RTX Corporation, and Nightwing Group, resolving allegations that Raytheon and its then-subsidiary failed to implement required cybersecurity controls on an internal system used for DoD work between 2015 and 2021. Nightwing, which acquired Raytheon's cybersecurity business in March 2024, was named as a "successor in liability" even though the misconduct predated the acquisition by several years. Both the original entities and the acquiring entity were jointly responsible for the settlement amount.

DOJ also has shown a willingness to scrutinize the role of private equity sponsors themselves.

In July 2025, Aero Turbine Inc. and its controlling private equity investor, Gallant Capital Partners LLC, agreed to pay $1.75 million to resolve allegations relating to cybersecurity compliance under an Air Force contract. DOJ alleged, among other things, that a Gallant employee directed the transfer of controlled unclassified information to an unauthorized software provider in Egypt.

The settlement demonstrates that sponsor-level involvement in a portfolio company’s compliance decisions can create enforcement risk beyond the portfolio company itself.

Effective FCA diligence for a DLA target should include, at minimum:

  • A review of the target's testing and inspection records, particularly for items subject to critical safety or specification requirements;
  • Examination of product origin documentation and country-of-origin certifications;
  • Assessment of the target's pricing practices, including compliance with the Truthful Cost or Pricing Data Act (formerly the Truth in Negotiations Act, and still commonly called “TINA”) for negotiated contracts above the applicable threshold, as well as price reduction clauses and economic price adjustment mechanisms on competitively awarded contracts;
  • Evaluation of whether the target has received any government audit findings, show-cause letters, cure notices, or inquiries from an Inspector General or the Department of Justice;
  • Review of the target's internal compliance program, including any voluntary disclosures or hotline complaints.

Whistleblower exposure warrants separate review. FCA qui tam actions are often filed under seal and may not appear on a target's litigation docket. Buyers should ask specifically about sealed or threatened qui tam matters and consider appropriate representations and indemnification protections in the acquisition agreement.

Deal teams should also review the target’s directors and officers (D&O) insurance, including whether it covers government investigation costs and whether exclusions or limits could leave a gap.

5. Assess Cybersecurity Obligations and CMMC Readiness

Cybersecurity is now a core diligence issue in defense contractor acquisitions, including for DLA suppliers.

Any DLA contractor that handles Controlled Unclassified Information (“CUI”) is subject to the safeguarding requirements of DFARS 252.204-7012, which incorporates the 110 security controls of NIST SP 800-171 Revision 2. Beyond baseline compliance, the Department of Defense has been rolling out the Cybersecurity Maturity Model Certification (“CMMC”) program, which replaces self-attestation with a tiered certification framework assessed by accredited third-party organizations. CMMC Level 1 (for contractors handling only Federal Contract Information) requires 15 practices corresponding to the 15 basic safeguarding requirements of FAR 52.204-21 and permits self-assessment. CMMC Level 2 (for contractors handling CUI) requires full implementation of the 110 NIST SP 800-171 controls, with third-party assessment for most contracts involving information critical to national security.

DoD began incorporating CMMC requirements into defense contracts in late 2025 through a phased rollout. In July 2026, DoD suspended the Phase II third-party certification requirement pending further review, although Phase I self-assessment obligations remain in effect and the underlying NIST SP 800-171 requirements have not changed. As a result, CUI contractors currently continue to operate under the self-assessment and Supplier Performance Risk System (“SPRS”) reporting model rather than mandatory third-party certification.

Buyers should not treat the suspension as a reason to defer cybersecurity diligence. A suspended assessment requirement is a deferred cost, not an eliminated one, and an inaccurate self-assessment carries independent False Claims Act risk. The regulatory direction toward verified compliance remains, and prime contractors are already screening their supply chains for CMMC readiness.

For PE buyers, cybersecurity diligence should focus on several questions:

  • What is the target's current NIST SP 800-171 assessment score, and does its System Security Plan reflect the actual state of its IT environment?
  • Has the target submitted its score to SPRS, and is that score accurate? (Overstating a SPRS score has been a basis for FCA enforcement.)
  • What CUI does the target handle, and has it properly scoped and segmented its CUI environment?
  • What would it cost to remediate identified gaps to achieve CMMC Level 2 readiness, and should that cost be reflected in the deal valuation?

A target’s IT environment may also need to be reassessed or reconfigured following the acquisition, particularly if the buyer plans to integrate the target's systems into a shared platform or migrate data to new infrastructure.

6. Identify FOCI Issues Early

Foreign Ownership, Control, or Influence (“FOCI”) is a concern primarily associated with classified contracts, but its reach is expanding. PE buyers should account for FOCI because fund structures and governance rights can affect transaction timing and post-closing control.

Under the National Industrial Security Program, any company applying for or maintaining a facility security clearance (“FCL”) must disclose and, where necessary, mitigate foreign ownership, control, or influence. FOCI can arise through direct or indirect foreign ownership, foreign board members or officers, foreign debt or financial obligations, or other relationships that give a foreign entity the ability to direct or influence the company's operations. DCSA (the Defense Counterintelligence and Security Agency) evaluates FOCI through the SF-328 form. Depending on the nature and degree of foreign involvement, the agency may require mitigation instruments such as board resolutions, special security agreements (“SSAs”), proxy agreements, or voting trust agreements.

For PE buyers, FOCI analysis is not limited to foreign-domiciled sponsors. A domestic PE fund with foreign limited partners, a fund-of-funds structure that includes sovereign wealth investors, or a co-investment arrangement involving a foreign entity can all trigger FOCI considerations. The analysis also extends beyond classified contracts: in May 2026, DoD proposed a new DFARS rule that would require contractors and subcontractors with contracts over $5 million to disclose beneficial ownership and FOCI information even where no classified work is involved (a development we analyzed separately in a July 27, 2026 alert).

Buyers should assess whether the target holds or needs a facility security clearance, whether the buyer’s own ownership structure raises FOCI issues, and what mitigation measures (if any) would be required. FOCI mitigation can take months to negotiate and implement, and in some cases the required mitigation instruments may limit the buyer’s operational control in ways that affect the investment thesis.

Deal and legal teams should factor that timeline into the transaction’s outside date or long-stop date, particularly where closing depends on an approved mitigation arrangement.

Transactions with a foreign nexus may also trigger review by the Committee on Foreign Investment in the United States (“CFIUS”) under 31 CFR Part 800. CFIUS has jurisdiction over transactions that could result in foreign control of, or certain foreign involvement with, a U.S. business, and defense contractors are a frequent focus of CFIUS scrutiny. CFIUS review and FOCI mitigation are parallel but distinct processes with different agencies, different timelines, and different remedies. A transaction could require clearance from both, and buyers should assess each independently.

7. Do Not Overlook Domestic-Preference and Country-of-Origin Requirements

DLA procurement is subject to an overlapping set of domestic-preference regimes, each with its own rules, and noncompliance in this area has been a recurring source of enforcement activity.

The three principal statutes buyers should understand are:

  • The Berry Amendment (10 U.S.C. 4862) requires that certain items purchased by DoD be entirely of domestic origin. Covered categories include, among other items, food, clothing, fabrics, fibers, yarns, textiles, tents, tarpaulins, flags, hand and measuring tools, and stainless steel flatware and dinnerware (though the flatware and dinnerware provision, added effective January 1, 2026, is in effect until January 1, 2029). The Berry Amendment is more restrictive than the Buy American Act: it imposes a 100% domestic-origin requirement with no component-cost percentage test, generally requiring that covered items be grown, reprocessed, reused, or produced entirely in the United States. Exceptions are narrow and include purchases below the simplified acquisition threshold and items determined to be domestically unavailable.

Separately, specialty metals used in defense procurement are subject to restrictions under 10 U.S.C. 4863, implemented through DFARS 225.7003, which imposes its own distinct requirements and exception framework. Although sometimes conflated with the Berry Amendment, the specialty metals statute is a separate provision with different covered items, applicability rules, and exceptions, and buyers should evaluate the target’s compliance with each independently.

  • The Buy American Act (“BAA”) applies to direct government purchases of supplies and requires that end products be manufactured in the United States with domestic component costs exceeding a specified percentage of total component costs. Under the phased schedule established by Executive Order 14005 and implemented through a 2022 FAR final rule, the domestic content threshold is 65% for items delivered in calendar years 2024 through 2028, rising to 75% for items delivered starting in calendar year 2029. A separate, more restrictive rule applies to products consisting wholly or predominantly of iron or steel, which must contain less than 5% foreign iron and steel content by cost. Contractors with performance periods spanning multiple threshold dates must comply with the applicable threshold for each year of delivery, not simply the threshold in effect at the time of award.
  • The Trade Agreements Act (“TAA”) applies to acquisitions above certain dollar thresholds and requires that products be manufactured or substantially transformed in the United States or a designated country. Unlike the BAA, the TAA focuses on the country of substantial transformation rather than component-level domestic content, meaning a product made primarily from foreign components can be TAA-compliant if it is substantially transformed in a qualifying country.

For DLA contractors, these rules can interact in complex ways. A product sold to DLA may need to satisfy the Berry Amendment for one contract and the TAA for another, depending on the contract vehicle, the product category, and the applicable dollar threshold. Compliance depends heavily on the target's supply chain, manufacturing processes, and documentation practices.

Buyers should review:

  • Whether the target's products are subject to the Berry Amendment, and if so, whether its supply chain can support a fully domestic-origin certification;
  • The target's country-of-origin certifications and the documentation supporting them;
  • Whether the target has changed suppliers, manufacturing locations, or component sources in ways that could affect compliance;
  • Any history of Trade Agreements Act or Berry Amendment violations, government audits, or corrective action requests.

Country-of-origin fraud, including false certifications of domestic origin for products manufactured or partially sourced overseas, has been a significant area of FCA enforcement in the DLA space. Buyers should treat this as a high-priority diligence item.

8. Understand the Regulatory Landscape Around the Target's Products

Depending on the products involved, a DLA contractor may also be subject to regulatory requirements that go beyond standard procurement rules.

For example, items with military-critical applications may be subject to export controls under the International Traffic in Arms Regulations ("ITAR") or the Export Administration Regulations ("EAR"). If the target is a manufacturer, it may be subject to qualification or testing requirements specific to the product line, including Qualified Products Lists ("QPLs") or Qualified Manufacturers Lists ("QMLs") maintained by DLA or the military services. Loss of QPL or QML status can effectively shut down a product line, and re-qualification can be a lengthy process.

Buyers should also consider whether the target's products are subject to first-article testing requirements, shelf-life restrictions, hazardous material regulations, or other product-specific compliance obligations that could be disrupted by changes in ownership, management, or manufacturing processes.

9. Assess Suspension and Debarment Risk

Government contractors can be suspended or debarred from future contracting for a range of misconduct, including fraud, material misrepresentation, willful failure to perform, and violations of various statutes and regulations. DLA has been active in referring suppliers for suspension and debarment, and these actions can affect not only the target but also affiliated entities.

For a PE buyer, suspension or debarment of one portfolio company can, in certain circumstances, raise questions about the responsibility of other entities under common ownership or control.

Diligence should include a review of the target's responsibility record, any pending or past suspension or debarment proceedings, and compliance with the mandatory disclosure requirements of FAR 52.203-13 (Contractor Code of Business Ethics and Conduct). The clause applies to contracts over $7.5 million with performance periods of 120 days or more. It requires timely written disclosure to the agency's Office of Inspector General of credible evidence that a principal, employee, agent, or subcontractor has committed (A) a violation of federal criminal law involving fraud, conflict of interest, bribery, or gratuity violations found in Title 18 of the United States Code, or (B) a violation of the civil False Claims Act (31 U.S.C. 3729–3733). Separately, the FAR payment clauses (including FAR 52.212-4(i)(5), 52.232-25(d), 52.232-26(c), and 52.232-27(l)) impose a distinct obligation to remit significant overpayments, and knowing failure to disclose such overpayments is itself a basis for suspension or debarment.

Buyers should ask whether the target has made any mandatory disclosures, whether any are pending or under review, and whether its internal compliance program and reporting mechanisms satisfy the clause's requirements. Failure to disclose when disclosure was required is itself a basis for suspension or debarment.

10. Plan for Post-Closing Integration with Government-Contract Requirements in Mind

For PE buyers, integrating a DLA contractor after closing raises issues not present in a typical portfolio company acquisition.

Routine portfolio-company decisions, such as consolidating back-office functions, migrating IT systems, changing the company's legal name or organizational structure, replacing management, or moving manufacturing to a different facility, can have meaningful government-contract consequences. Consolidating the target's IT infrastructure into a shared services model, for example, may expand the CUI boundary and require a fresh CMMC assessment. Changing the target's name requires a formal change-of-name agreement under FAR 42.1205. Moving production to a new facility could affect QPL status, Berry Amendment compliance, or performance obligations under existing contracts.

The integration plan should be developed with government-contracts counsel involved from the outset, not brought in to clean up problems after the fact.

Conclusion

Acquiring a DLA contractor can be a sound investment, but only if the buyer understands the regulatory environment surrounding the target. The issues above are not exhaustive, and each transaction will turn on its own facts. Government-contract compliance is part of the investment thesis, not a back-office matter to address after closing, and it should shape the deal process from the outset.

Authors
William T. Gordon (Bill)
Partner
Corporate
Steve Cave
Partner
Special Matters & Government Investigations
Christina Wood
Associate
Special Matters & Government Investigations
Downloadable Documents
Explore King & Spalding
a blue and green background
Capabilities
Government Contracts
a blue and green background
Capabilities
Private Equity