1,000+ Opportunities
Find the right grant
Search federal, foundation, and corporate grants with AI — or browse by agency, topic, and state.
Continuous Autonomous Penetration Testing (CAPT) is sponsored by National Security Agency (NSA). The NSA's Continuous Autonomous Penetration Testing (CAPT) program leverages an AI-powered platform to provide small businesses with a way to conduct internal network penetration tests at no cost. This program can lead to firm fixed price contracts for proposed solutions.
Get a weekly digest of new grants like this
A free weekly digest of new foundation and federal funding opportunities as they're added to Granted. Unsubscribe anytime.
Or search similar grants →Extracted from the official opportunity page/RFP to help you evaluate fit faster.
NSA CAPT Program for DIB Suppliers | Horizon3. ai Fortifying the Defense Industrial Base (DIB): NodeZero® for Supply Chain Security NSA Cybersecurity Collaboration Center and Horizon3. ai are working together to elevate the security posture of the Defense Industrial Base (DIB) suppliers.
What is the CAPT program? The NSA’s Continuous Autonomous Penetration Testing (CAPT) program, powered by Horizon3. ai’s NodeZero®, identifies exploitable vulnerabilities across DIB suppliers’ IT infrastructures.
With ongoing, intelligence-driven cyber risk assessments, NodeZero reinforces critical infrastructures, bolstering national supply chain security. How does the program work? Horizon3.
ai manages enrollment, onboarding, and activation onto the NodeZero platform, enabling DIB suppliers to quickly launch self-service pentests. These tests help meet compliance, strengthen security, and eliminate costly consulting engagements. This benefits the taxpayer, DoD, and DIB suppliers alike.
Before the NSA launched CAPT, the DIB was dangerously exposed, with many critical vulnerabilities unchecked. Now, program participants have closed 71% of critical findings within 30 days, moving from 1-2 pentests a year to several each month. This isn’t just compliance; it’s ownership of national security.
The DIB is now proactively defending the nation’s safety. – Snehal Antani, CEO and Co-Founder Horizon3. ai How does this benefit my business?
Free, world-class pentesting to help you uncover your most vulnerable areas User-friendly interface with simplified remediation guidance and reporting Continuous and safe risk assessments that complete in hours, not days Prioritized pentest findings so you know what to fix first Proof that risks have been remediated with one-click verification Demonstrates your ability to reduce vulnerabilities and ensure continuity Aligns with CMMC, SOC2, and other key cybersecurity standards NodeZero simplifies the process of pinpointing and addressing vulnerabilities that expose suppliers to cyber threats.
Its ease of use, accurate vulnerability prioritization, and clear remediation guidance significantly enhance security for DIB suppliers enrolled in this no-cost program. Positive outcomes with real risk reduction One DIB firm completed 70+ bi-weekly pentests with NodeZero in the last four months with limited effort other than to set up and launch the tests.
Another DIB firm conducted its first pentests two days after onboarding and NodeZero proved it could exploit a known vulnerable software product in use. Another DIB firm discovered that NodeZero was able to gain access to testing data, manuals, and other sensitive information stored in the supplier’s network.
Latest NodeZero + DIB Supplier Statistics Number of Participants: 713 Number of Pentests: 22,751 Number of Endpoints: 2,586,400 Number of Critical and High Weaknesses Mitigated: 23,454 Duration of Operations: 286,889 hours Number of Exploitable Weaknesses and Vulnerabilities Detected: What do DIB suppliers have to say about the program? A huge thank you to the team! NodeZero is a total game-changer for us.
With a small team, every second counts and this tool is saving us serious time. It’s a no-brainer to have NodeZero in our toolbelt. We’re beyond grateful for the opportunity!"
– Alexandru Stratila, Information Technology Manager at KVG Horizon3. ai’s NodeZero has been a game-changer for our cybersecurity. Its autonomous pentesting provides deep insights into vulnerabilities, while clear, actionable reports help us prioritize and resolve critical risks efficiently.
It has strengthened our defenses, saved valuable time, and enhanced our security posture. We highly recommend it for any organization looking to stay ahead of threats." – Cybersecurity Analyst, Manufacturer of Machined Components for the Defense Industry We pride ourselves on maintaining a strong security posture, which is why we partner with NodeZero for pentesting.
Within hours of running NodeZero internal pentesting, our MSP was able to quickly review the findings and remediate the weaknesses. As a member of the DIB, it's my personal responsibility to help protect our nation's secrets. With Horizon3.
ai and NodeZero verifying our system security at a regular cadence, I'm confident we're well-positioned to handle the critical data ultimately supporting our troops." – Rick MacKirdy, CEO Modus Advanced, Inc. The NSA does not endorse any commercial product or service provided by Horizon3. ai.
Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by NSA.
According to the current listing, eligibility includes: Small businesses with an active DoD contract (sub or prime) or access to non-public DoD information. Small business set-aside contracts may also be considered. Confirm the full requirements in the official notice before applying.
Continuous Autonomous Penetration Testing (CAPT) is funded by National Security Agency (NSA). Verify program details on the funder's official page before applying.
Start from the official opportunity page linked in this listing — it carries the sponsor's submission instructions.
The FY 2026 Daniel Anderl Judicial Security and Privacy Program carries $6,526,269 across 22 awards, closing October 15 in Grants.gov and October 22 in JustGrants. A single statutory clause disqualifies most applicants before the narrative is written.
Read articleThe Hewlett Foundation's Emerging Technology and Security Initiative commits $20 million a year through 2031 across AI, biotechnology, and quantum computing security. Its 2026 exploratory grants went to thirteen named institutions with no open call. For organizations outside that list, the path in runs through a specific set of moves — and the five-year term starting in 2027 is the window.
Read articleThe Department of War's Office of Strategic Capital opened its National Security Fund Finance program with facilities of $500 million to $1 billion. It is not a grant, the applicant is not a company, and the eligibility bar filters out almost everyone reading this. Here is who it is actually for — and what the rest of the critical-minerals ecosystem should do about it.
Read article