The federal government still has cybersecurity grants on the books, but the money behind them tells two very different stories depending on which year you look at. The flagship program for local governments, the State and Local Cybersecurity Grant Program (SLCGP), handed out more than $400 million in its first cycle. For fiscal year 2025, the same program made $91.75 million available nationwide, and it asked applicants to bring a 40 percent match to the table. The program is technically alive, recently extended through September 2026. The funding behind it is not keeping pace.
The short version:
- The main federal cybersecurity grant for towns and counties is the SLCGP. Its FY2025 pot fell to $91.75 million, down from $279.9 million the year before.
- Local governments cannot apply directly. Only a state’s designated agency applies; cities and counties receive sub-awards through the state.
- The required cash match rose to 40 percent in FY2025, making the money more expensive to use.
- Congress extended the program’s authorization through September 2026 but attached no new appropriation. A long-term reauthorization (the PILLAR Act) passed the House but stalled in the Senate.
- CISA is openly telling states to plan for a future without the grant. The smart move now is reprioritization, not waiting on a new check.
Why the headline number dropped to $91.75 million
The SLCGP was never an open-ended program. It was created by the 2021 Infrastructure Investment and Jobs Act as a one-time, four-year commitment: roughly $1 billion spread across fiscal years 2022 through 2025. Because the total was fixed at the start, each year’s allocation was always going to taper as the pot drained. That tapering turned into a cliff. According to CISA’s own program-change summary, the total dropped from $279.9 million in FY2024 to $91.7 million in FY2025 — a roughly 67 percent cut in a single year.
That math matters more than any best-practice checklist, because it changes what a state can realistically do with its slice. A state that built a multi-year endpoint-detection rollout or a shared phishing-resistant authentication program around FY2023 and FY2024 dollars now has to sustain those services on a fraction of the funding. The Department of Homeland Security runs the program jointly: CISA handles the cybersecurity expertise, while FEMA administers the money. The FY2025 Notice of Funding Opportunity was released on August 8, 2025, and unlike earlier years, DHS said it would not grant extensions to the four-year performance period. If you are tracking where the dollars actually live, that combination of a smaller pot and a harder deadline is the real story behind this year’s federal grant cycle.
The structural trap: your city cannot apply for this grant
Here is the detail that trips up the most local officials, and it has nothing to do with the dollar amount. The SLCGP is a pass-through program. The only entities that can submit an application are the State Administrative Agencies (SAAs) for each state and territory. A town, county, school district, or water authority does not apply to the federal government at all — it receives a sub-award from its state, and only if the state’s cybersecurity planning committee approves the project.
The statute forces money downhill on purpose. States must pass at least 80 percent of their allocation to local governments, and at least 25 percent of the total must reach rural areas. That design was meant to close the gap between well-funded cities and the small jurisdictions that cannot staff a security team. In practice it means your real “application” is to your state’s planning committee, on the state’s timeline, for the categories your state has already chosen to fund. If you are a smaller organization used to hunting for opportunities in a grant database, the SLCGP behaves nothing like a competitive open call. It behaves like a budget negotiation with your state government.
What the money can buy
States have used SLCGP funds for a consistent menu: endpoint detection and response, phishing-resistant multifactor authentication tokens, security operations, incident-response planning, training, and “.gov” domain migration. Tennessee’s CIO told a House subcommittee that the state’s roughly $21 million in grant funding had secured almost 90,000 endpoints across local governments and trained more than 21,000 local employees. Those are the kinds of shared services that vanish first when a subscription-funded program loses its funding stream.
The 40 percent match changed the calculus
The second quiet change in FY2025 was the cost share. In FY2024, applicants had to cover 30 percent of an award with non-federal funds. In FY2025 that minimum climbed to 40 percent for single-entity projects (multi-entity group projects sit at 30 percent). On a shrinking pot, a rising match is a double squeeze: there is less federal money to claim, and you must put up more of your own to claim it.
For a cash-strapped county, a 40 percent match can be the difference between using a grant and skipping it. State officials testifying this spring flagged exactly this. They asked Congress not only to fund the program but to reduce or eliminate the match, arguing the requirement priced out the rural jurisdictions the grant was designed to help. Treat the match the way you would treat any matching requirement: as a real liability that has to come out of a budget you already have, not as free money. If you want the broader mechanics of how match obligations work across federal programs, that logic carries over to nearly every grant your organization will touch.
Authorized, but not appropriated: where the law actually stands
The legislative status is the part most summaries get wrong, because “reauthorized” and “funded” are not the same thing. The program’s authority lapsed at the end of September 2025. A continuing resolution revived it temporarily, and a February 2026 funding law extended the authorization through September 30, 2026 — but attached no new money. As Nextgov/FCW reported, the House voted in November 2025 to pass the Protecting Information by Local Leaders for Agency Resilience (PILLAR) Act, which would reauthorize the program through fiscal 2033. The Senate’s companion offered only a one-year extension, and a separate Senate proposal to put $300 million toward the program this year has not advanced.
So the honest status is: the legal framework exists through September 2026, the long-term fix passed one chamber, and no guaranteed new appropriation is attached to any of it. As StateScoop noted, even the House-passed PILLAR Act is an authorization measure, not a check — future dollar amounts would still depend on annual spending bills. For anyone budgeting a multi-year cyber project, that distinction is the whole ballgame.
The reprioritization playbook CISA is already recommending
The most useful signal this year did not come from a statute. It came from CISA itself. At a state and local cybersecurity summit in March 2026, a senior CISA official told the room that the grant funding “is not going to be reupped” and that states needed to start “reprioritization” of their own cyber budgets and lean on free federal resources. As Route Fifty reported, that is a notable thing for the granting agency to say out loud. It is, in effect, a recommendation to stop building plans around a check that may not arrive.
For a local government or the nonprofit and special-district partners that depend on one, that translates into a few concrete moves. First, ask your state SAA where it stands in spending its existing FY2023 and FY2024 awards — states still have up to three years to spend, so there may be sub-award capacity left in the current cycle. Second, build any new cyber initiative so its recurring costs survive the grant; one-time grant money should buy durable capability, not a subscription you cannot renew. Third, fold cybersecurity into broader infrastructure and resilience funding streams where it qualifies, rather than treating it as a standalone line that lives or dies with one program. The agencies that weather this gap best will be the ones that treated the SLCGP as a catalyst, exactly as the state CIO associations have urged, rather than a permanent subsidy.
Frequently Asked Questions
Can a small town apply for the State and Local Cybersecurity Grant Program directly?
No. Only a state or territory’s designated State Administrative Agency can submit an application. Local governments receive sub-awards through the state, and the state must pass at least 80 percent of its allocation down to local entities, with 25 percent reaching rural areas. Your point of contact is your state’s cybersecurity planning committee, not FEMA or CISA.
How much SLCGP money is available now?
The FY2025 round made $91.75 million available nationally through the SLCGP, plus a separate $12.1 million for the Tribal Cybersecurity Grant Program. That is down sharply from $279.9 million in FY2024. No new appropriation has been guaranteed beyond the FY2025 cycle, even though the program’s authorization runs through September 2026.
What is the cost-share requirement for cybersecurity grants?
For FY2025, single-entity SLCGP projects required a 40 percent non-federal match, up from 30 percent in FY2024. Multi-entity group projects required 30 percent. Cost-share waivers were available only for the insular-area territories, so most applicants must budget real non-federal dollars to use the award.
Is the SLCGP being renewed?
Partly. The program’s authorization was extended through September 30, 2026, and the House passed the PILLAR Act to reauthorize it through 2033. But those are authorization actions, not funding. As of mid-2026, no new multi-year appropriation has cleared both chambers, and CISA has advised states to plan for a future without the grant.
Where do I find the official application materials?
The FY2025 Notice of Funding Opportunity is posted on Grants.gov, and eligible state agencies apply through the FEMA Grant Outcomes (FEMA GO) system. Program details and the cybersecurity-plan requirements live on CISA’s cyber grants pages. Local entities should route questions through their state SAA rather than applying themselves.
Bottom line: plan for the gap, not the grant
Cybersecurity grants for state and local governments have not disappeared, but they have quietly become smaller, more expensive to access, and structurally indirect. The SLCGP is still authorized through September 2026, yet its FY2025 pot is a third of what it was a year earlier, the match has climbed to 40 percent, and the granting agency itself is telling states to reprioritize. The organizations that come out ahead will not be the ones refreshing an application portal — they will be the ones working their state’s sub-award pipeline now and building cyber capability that does not collapse the moment the federal money pauses.
If you are trying to map which federal and state programs your organization actually qualifies for in a year this volatile, that is exactly the kind of search worth doing systematically. Start with OpenGrants’ grant discovery database to see what is open across agencies, and keep an eye on our industry news coverage for the next move on SLCGP reauthorization. The program’s near-term fate runs through the Senate — and your cyber budget should be built to survive whichever way that vote goes.

