The Last Cybersecurity Grant: $91.7M, a 40 Percent Match, and State Deadlines Closing in October 2026

October 6, 2026 · 6 min read

Granted Research Team · Editorial policy

The State and Local Cybersecurity Grant Program was never designed to last. It was written into the 2021 Infrastructure Investment and Jobs Act as a one-time, four-year commitment — roughly $1 billion spread across fiscal years 2022 through 2025, on a declining schedule, with a rising local match. That design is now fully expressed, and the final year looks like this: $91.7 million nationally, down from $279.9 million in FY2024, a 67 percent cut in a single year, paired with a 40 percent non-federal match for single-entity projects where FY2024 required 30.

State pass-through windows for that last tranche are closing right now. Michigan's closed on October 11, 2026. Wisconsin's runs to October 30, 2026. Colorado's application deadline passed September 30 with award recommendations due October 30. We covered the structural end of the program and the stalled reauthorization in our analysis of the exhausted IIJA pool. This piece is about the money that is still on the table and the mechanics that determine whether your jurisdiction can actually take it.

Why your neighbor's terms are better than yours

Here is the detail that should reframe how local governments read this program: the federal match requirement does not land on the applicant the same way in every state.

Compare two midwestern states in the same cycle. Michigan's initial FY2025 allocation was $2,346,859, and its guidance passes a 40 percent cost-share match through to local applicants. Wisconsin made $4,712,514.40 available with no local cost share requirement at all.

Both states are administering the same federal program under the same NOFO. The difference is a state-level policy choice about who absorbs the non-federal share. The 40 percent is owed to the federal government by the recipient — the State Administrative Agency — and a state may satisfy it with state funds, with in-kind contributions, or by requiring sub-recipients to bring it. Wisconsin chose to eat it. Michigan passed it down.

This is the single most important thing a city manager or county IT director can know before writing: read your own state's guidance for the match treatment before you size the project. A $250,000 project in Wisconsin needs $250,000. The same project in a pass-through state needs roughly $167,000 in federal share plus about $100,000 your council has not budgeted. Teams routinely scope to the federal number and discover the gap in the award-acceptance phase, which is the worst possible moment.

One federal lever exists on this: the cost share drops from 40 percent to 30 percent for multi-entity group projects. Cost-share waivers are otherwise prohibited in FY2025, except for American Samoa, Guam, the U.S. Virgin Islands, and the Northern Mariana Islands. In a pass-through state, finding two or three neighboring jurisdictions and submitting jointly is not a collaboration nicety — it is a 10-point reduction in the money you have to find locally, and it is the only discount available.

The pass-through arithmetic, and the rural bonus

Two allocation rules govern how state-held money has to move:

Cities and counties cannot apply to DHS directly. Only State Administrative Agencies submit; locals receive sub-awards. That is why the operative deadline is always a state deadline and why national coverage of SLCGP is close to useless for an individual jurisdiction.

The rural set-aside is where the most under-exploited leverage sits. Michigan's FY2025 guidance stacks three advantages for small applicants: at least 25 percent of funds must support rural applicants, jurisdictions in counties with populations under 50,000 receive bonus review points, and first-time applicants receive priority consideration. A township that has never applied, sits in a county below 50,000, and submits a modest, well-specified project is competing in a protected lane — and in most states that lane is undersubscribed, because the jurisdictions with the least grant-writing capacity are exactly the ones the set-aside was built for.

If you are a small jurisdiction reading this after your state's window closed, the thing to do is still call the SAA. Rural set-asides that go unclaimed create reallocation problems for states, and administrators are often looking for eligible rural projects late in a cycle.

What to actually propose

The four program objectives are unchanged from prior years: implement cyber governance and planning, assess and evaluate systems and capabilities, mitigate prioritized issues, and build a cybersecurity workforce.

What has changed is sector emphasis. State guidance in this cycle has pushed hard toward critical infrastructure, with publicly owned water and wastewater systems named as the highest-priority sector, followed by energy and transportation. Note the provenance honestly: this prioritization appears prominently in state-level FY2025 guidance rather than in CISA's own published list of key federal changes, which does not mention the water sector. The practical effect is the same — in states that adopted it, a water-utility SCADA project scores above a generic endpoint-software refresh — but confirm the framing in your state's guidance document rather than assuming it is a federal mandate.

The reason the water sector rose to the top is not mysterious. Municipal water and wastewater utilities run operational technology that predates the modern threat environment, frequently with remote access added opportunistically, under utility boards with no cybersecurity staff. New York has already run state-level water cybersecurity grant awards specifically because the sector could not compete for general-purpose IT money.

Projects that fit this cycle well: network segmentation between business IT and utility OT, multifactor authentication on remote access to control systems, asset inventory and vulnerability assessment for water and wastewater SCADA, incident response planning that names the utility as an in-scope entity, and shared services where a county provides monitoring to small municipal utilities that will never hire an analyst.

The deadline behind the deadline

Two FY2025-specific administrative changes deserve more attention than they have gotten.

First, DHS will not consider requests to extend the FY2025 period of performance. The POP remains four years from the award date, but unlike FY2022, FY2023, and FY2024 — all of which saw extension requests entertained — this one is firm. For a program whose chronic failure mode is slow procurement, this is the binding constraint. A project that depends on a 2027 bond issue, an unhired position, or a vendor contract that has not been scoped will not finish, and there is no relief valve. Scope to what you can execute, not to what you can justify.

Second, the FY2025 NOFO does not require sub-entities receiving subawards to complete the National Cybersecurity Review. That removes a real administrative barrier for small jurisdictions, for whom the NCSR self-assessment was often the single largest paperwork burden in the application. If an NCSR requirement was the reason your jurisdiction skipped a prior cycle, that reason is gone. Cybersecurity Plan resubmission for states carried a January 30, 2026 deadline, and FEMA has implemented enhanced payment review procedures — expect drawdowns to be scrutinized more closely than in earlier cycles.

Planning for the cliff

Program authorization extends through September 30, 2026 but carries no new appropriation. The PILLAR Act, which would reauthorize the program through 2033, passed the House and remains stalled in the Senate. A senior CISA official has advised states to pursue "reprioritization" rather than wait on future grant cycles — which is as close to an official statement that the money is not coming back as an agency makes.

So the right posture for the FY2025 tranche is not "fund the next increment of our roadmap." It is fund the thing that becomes self-sustaining, because the follow-on cycle that would have paid year two may not exist.

That argues for a specific kind of project. One-time capital with low recurring cost — segmentation hardware, an assessment that produces a durable asset inventory, a plan that satisfies a state requirement for years — survives the cliff. Multi-year software subscriptions and new staff positions create a general-fund obligation that outlives the federal share, and in a pass-through state you will have already spent 40 cents of local money on every federal dollar to create it.

A reasonable test before submitting: if this grant is the last federal cybersecurity dollar your jurisdiction ever receives, does the project still make sense in year five? Projects that pass that test are the ones worth the match. Projects that fail it are how jurisdictions end up with an expired license and a line item nobody approved.

Check your State Administrative Agency's page this week. In several states the window is already shut; in others it closes in the next three weeks; and in a few, rural set-aside capacity is still looking for a taker.

Get AI Grants Delivered Weekly

New funding opportunities, deadline alerts, and grant writing tips every Tuesday.

More Tips Articles

Not sure which grants to apply for?

Use our free grant finder to search active federal funding opportunities by agency, eligibility, and deadline.

Find Grants

Ready to write your next grant?

Draft your proposal with Granted AI. Professional members win a grant in 12 months or get a full refund.

Backed by the Granted Guarantee