The $1 Billion Cybersecurity Lifeline for Local Government Is Running Dry: Inside the SLCGP, the PILLAR Act, and What Every CISO Should Do Before Reauthorization Lands
August 5, 2026 · 6 min read
Granted Research Team · Editorial policy
For four years, one federal program did something the cybersecurity world had been asking for since ransomware first started shutting down county courthouses and small-city water utilities: it sent money directly toward the least-defended layer of American government. Not the Pentagon, not the Fortune 500 — the 90,000 counties, municipalities, school districts, and special districts that run elections, treat drinking water, dispatch ambulances, and store the personal data of nearly every resident, usually with an IT staff of one or two people and no dedicated security budget at all.
That program is the State and Local Cybersecurity Grant Program (SLCGP), jointly administered by the Cybersecurity and Infrastructure Security Agency (CISA) and FEMA. It was created by the 2021 Infrastructure Investment and Jobs Act (IIJA) with a fixed appropriation of $1 billion spread across four fiscal years. As of August 2026, that money is essentially spent — the FY2025 round was the final IIJA-funded cycle — and whether the program continues at all now depends on a reauthorization fight in Congress. If you run technology for a state agency, a county, a city, or a K-12 district, this is the funding cliff that should be on your radar right now.
How the SLCGP was built
The design of the SLCGP is worth understanding in detail, because the next version of the program — if it survives — will almost certainly inherit its bones.
The money flowed to states, territories, and tribal governments, but it was never meant to stay there. The statute required each state to pass through at least 80% of its allocation to local governments, and within that, to direct a minimum of 25% to rural areas. This was a deliberate anti-hoarding provision: Congress had watched other homeland-security dollars pool at the state capital, and it wrote the SLCGP to force the money outward to the small jurisdictions that need it most and have the least capacity to chase it.
The funding was substantial early and tapered sharply. The four annual appropriations landed at roughly $185 million, $375 million, $280 million, and $91.75 million across FY2022 through FY2025 — front-loaded by design, on the theory that states would need the biggest infusion to stand up their programs and could sustain them on smaller sums later. That assumption is now being tested, because "later" has arrived and the federal spigot is closing.
The cost share moved in the opposite direction. In the first year, the federal government covered 90% of project costs and the local match was just 10%. That match climbed each year — 20%, then 30%, then 40% in FY2025. The escalating match was another intentional lever: ease jurisdictions in cheaply, then push them to build cybersecurity into their permanent budgets so the capability outlives the grant. For a cash-strapped county, though, a 40% match on a security project is a real barrier, and many of the smallest eligible entities have struggled to put up their share.
The strings that made it more than a check
Two requirements distinguished the SLCGP from a simple grant and turned it into a governance program.
First, every state had to stand up a Cybersecurity Planning Committee — a body with representation from state and local governments, and specifically from rural jurisdictions — and use it to write a statewide Cybersecurity Plan approved by CISA. You could not simply spend the money on whatever the CIO wanted; expenditures had to trace back to an approved plan aligned to CISA's required elements, which included multi-factor authentication, migrating away from unsupported systems, adopting .gov domains, and improving incident response.
Second, the eligible uses were bounded to genuine capability-building: closing known vulnerabilities, deploying MFA and endpoint detection, cyber training and exercises, and hiring or contracting for security expertise. It was not a slush fund for routine IT refresh, and CISA leaned on the planning process to keep it that way.
The result, for all its friction, was that thousands of jurisdictions that had never conducted a risk assessment or written an incident-response plan now had both — plus, in many cases, their first MFA rollout and their first tabletop exercise. That is the capability now at risk.
The cliff, and the bill that might bridge it
Here is the uncomfortable arithmetic. The IIJA authorized and funded the SLCGP for four years only. The FY2025 Notice of Funding Opportunity — published in August 2025 at $91.75 million — drew down the last of that appropriation. There is no fifth year built into current law. A continuing resolution briefly extended the program's authorization window into early 2026, but authorization is not appropriation; without new money and new authority, the SLCGP does not automatically roll forward.
The legislative vehicle to watch is the Protecting Information by Local Leaders for Agency Resilience (PILLAR) Act (H.R. 5078), which cleared the House Homeland Security Committee and would extend the SLCGP through 2033 — a full decade of runway rather than the original four years. County and municipal associations, led by the National Association of Counties, have made reauthorization a top federal priority, and the case they make is straightforward: cyberattacks on local government did not stop when the money ran out, and letting the only dedicated federal funding stream lapse would strand the very planning committees and security programs the first $1 billion just finished building.
But reauthorization is not guaranteed, and even if the PILLAR Act passes, the funding levels, the cost-share schedule, and the timing of a new NOFO all remain open questions. The broader FY2026 appropriations environment has been turbulent — including a DHS funding lapse earlier in 2026 — which makes the trajectory of any new homeland-security grant dollar genuinely uncertain.
What state and local technology leaders should do now
Waiting for a NOFO to appear is the wrong posture. The jurisdictions that won SLCGP dollars fastest were the ones that had done the unglamorous groundwork before the money existed. Do the same for whatever comes next:
- Keep your Cybersecurity Planning Committee alive and your plan current. If a reauthorized program launches, an approved, up-to-date statewide plan will again be the gate to spending. Committees that went dormant when the money stopped will be a step behind.
- Maintain a ranked project backlog with cost estimates. MFA gaps, unsupported systems, network segmentation, incident-response retainers — have a prioritized, costed list ready so you can move within a compressed application window rather than starting your needs assessment from scratch.
- Solve the match problem in advance. If the escalating cost share returns, the 40% local match is the reason good projects die. Line up the non-federal share now — general fund, capital budget, or interlocal agreements that let small jurisdictions pool their contributions.
- Do not treat the SLCGP as your only option. The Homeland Security Grant Program and, for eligible nonprofits, the Nonprofit Security Grant Program allow certain cybersecurity uses, and states run their own cyber grants. A resilient funding strategy layers these rather than betting everything on one lapsing program.
- Document your outcomes from prior rounds. Reauthorization debates turn on evidence. Jurisdictions that can show what their SLCGP dollars bought — vulnerabilities closed, MFA coverage, incidents contained — strengthen both the national case for the program and their own competitiveness in the next cycle.
The SLCGP proved a thesis that many had doubted: that a federal grant, structured with pass-through mandates and a planning requirement, could measurably raise the cyber floor under thousands of small governments in just a few years. The open question is whether Washington will fund the second act. The organizations that stay ready — plan current, backlog costed, match secured — will be the ones positioned to move the day a new NOFO drops. For a running view of how this and adjacent homeland-security programs are evolving, see our ongoing coverage in Granted News.