The nonprofit security grant program is deciding who gets a share of $300 million right now, and the deciding factor is not how compelling your threat narrative sounds. It is arithmetic. FEMA published the FY26 Nonprofit Security Grant Program funding opportunity (DHS-26-GPD-008-00-99) on June 24, 2026, with a federal closing date of July 24, 2026 – a 30-day window, one of the shortest in the program’s history. Behind that window sits a scoring formula most applicants never read: your state’s score, multiplied by a factor FEMA assigns based on what kind of organization you are, plus a flat bonus if you have never won before. Understand the formula and you can position for it. Ignore it and you are competing blind.

  • FEMA’s FY26 NSGP makes $300 million available for physical security and target hardening at nonprofits facing terrorist or extremist threats; the federal window closes July 24, 2026.
  • Awards run on score math: your State Administrative Agency scores your application, then FEMA multiplies that score – x3 for religious and ideology-based organizations, x2 for secular educational and medical institutions, x1 for everyone else – and adds 15 points if you have never received an NSGP award.
  • Caps: $200,000 per site, up to three sites, $600,000 maximum per organization per state. No cash match, but funding is reimbursement-based.
  • Most state windows have already closed (New York and Virginia on July 10, North Carolina on July 17). Fifty-eight members of Congress have asked DHS to extend the cycle.
  • If you missed this cycle, the same math makes a first-time FY27 application unusually strong – preparation starts now.

How the Nonprofit Security Grant Program Multiplies Your Score

Every application enters a two-stage evaluation. First, your State Administrative Agency (SAA) reviews and scores your Investment Justification – the fillable form that serves as the application – using the scoring tool DHS provides in the NOFO’s appendices. That state score is only the input. FEMA then applies a multiplier keyed to organization type. According to North Carolina’s SAA guidance for the FY26 cycle, religious and ideology-based organizations – houses of worship, faith-affiliated schools, community centers – have their scores multiplied by three. Secular educational and medical institutions are multiplied by two. Every other nonprofit gets a factor of one. On top of that, sub-applicants that have never received an NSGP award get 15 points added at the FEMA stage.

The strategic consequences are concrete. A synagogue, mosque, or church school starts with triple leverage on every point its SAA awards, which is why faith-based institutions have historically taken a large share of awards. A secular food bank or arts nonprofit with an identical vulnerability profile needs a substantially stronger state score to land at the same rank. That is not a reason to skip applying – it is a reason to maximize the parts of the score you control: a professional vulnerability assessment tied point-by-point to the investments you request, a documented threat history, and a clean, complete Investment Justification on the current year’s form. Incomplete forms, prior-year forms, and scanned copies are deemed incomplete and never reach scoring at all.

The multiplier system also explains a pattern that frustrates many applicants: well-written applications from x1 organizations that go unfunded cycle after cycle. Demand has exceeded supply in every recent cycle, and when the ranked list runs past the available dollars, the multiplied scores at the top absorb the money first.

The State Window Is the Real Window – and This Cycle It Slammed Shut

Nonprofits never apply directly to FEMA. The NSGP is a pass-through program: each state’s SAA collects subapplications, scores them, ranks them, and forwards a bundled state submission before the federal deadline. That structure means the deadline that governs you is your state’s, and state windows this cycle were compressed to a degree that drew formal congressional protest. New York’s Division of Homeland Security and Emergency Services closed its FY26 window on July 10. Virginia closed July 10 and explicitly warned it could not accept resubmissions or corrections because of the abbreviated timeline FEMA set. North Carolina’s Salesforce portal closed July 17 at 11:59 p.m. with a no-extensions policy.

For readers tracking how federal money flows through state agencies, this is the same pattern we map across state-administered grant programs: the federal NOFO sets the ceiling, but the state pass-through sets the calendar, the portal, and the paperwork. The FY26 cycle turned that structural quirk into the whole ballgame – roughly two weeks between many state portals opening and closing, inside a 30-day federal window.

The Extension Fight in Congress

The compression did not go unnoticed. A bipartisan letter signed by 58 members of Congress, organized by the Jewish Federations of North America, formally asked DHS to extend the application window, arguing the timeline “leaves states and eligible nonprofit organizations insufficient time to complete the application process.” As of this writing DHS has not extended the July 24 federal close. If an extension lands, some SAAs may reopen portals – which is exactly why the single most valuable action for any nonprofit still hoping for this cycle is subscribing to its SAA’s grant notification list today.

The FY25 Overlap Trap That Can Void an Application

A quieter risk sits underneath the FY26 cycle: FEMA has not yet announced FY25 sub-awardees. Organizations that applied last year and reapplied this year for the same project are exposed to an automatic-denial rule. North Carolina’s SAA spelled it out: if FEMA later funds your FY25 application for a given project, an identical FY26 application for that project is automatically denied, because the program cannot fund the same project twice. SAAs are telling applicants to propose a different project for FY26 than they did for FY25.

This is worth internalizing as a portfolio rule, not a one-year quirk. Security needs at a single facility are rarely one project deep – access control, cameras, shatter-resistant film, lighting, bollards, contracted security (allowable up to 50 percent of the award this cycle), planning, and training are all separable investments. Splitting your facility’s needs into distinct, independently justified projects across cycles keeps every application viable no matter when a prior year’s awards land. It also matches how the program’s money actually behaves: awards are announced months after submission, and the FEMA program page shows funding climbing from $274.5 million in FY25 to $300 million in FY26 precisely because oversubscription keeps the political pressure on.

Missed the Window? The Math Says Build Your FY27 File Now

If your state’s portal is closed, the honest answer is that FY26 is probably over for you – and the scoring formula is the reason next cycle can go differently. Remember the 15-point first-timer bonus: if you have never held an NSGP award, FEMA adds those points on top of your multiplied score. For a first-time faith-based applicant, that bonus rides on a x3 multiplier’s output. The organizations that win in FY27 will mostly be the ones whose files are ready before the NOFO drops, because the last two cycles prove the window can be a month or less.

The FY27 preparation sequence costs little and starts immediately. Get registered in SAM.gov and obtain your Unique Entity Identifier – registration can take weeks, and our guide to getting a UEI without getting stuck covers the validation traps. Request a no-cost vulnerability assessment from your local law enforcement agency or a DHS Protective Security Advisor; assessor availability is the binding constraint every summer. Start a dated threat and incident log for your facility. Draft your Investment Justification against the most recent year’s form so you are editing, not writing, when the window opens. And plan your cash: NSGP is reimbursement-based, meaning you spend first and get paid back, the same working-capital reality we broke down in our guide to cost reimbursement grants. A $200,000 award your organization cannot float is a $200,000 problem.

Meanwhile, the nonprofit security grant program is not the only source of security money. State-level hardening programs, private foundation safety grants, and community-safety funds run on their own calendars – many are searchable alongside federal programs in our nonprofit grants hub.

Frequently Asked Questions

Who is eligible for the nonprofit security grant program?

Q: Which organizations can apply?

A: Eligible sub-applicants are 501(c)(3) nonprofits – including houses of worship, religious schools, museums, community centers, day camps, and social-service agencies – that can demonstrate high risk of terrorist or other extremist attack. Applications go through your State Administrative Agency, not FEMA. Location determines your stream: NSGP-UA covers organizations inside FEMA-designated high-risk urban areas; NSGP-S covers everywhere else.

How much money can one organization get?

Q: What are the award caps?

A: Up to $200,000 per physical site, for up to three sites per funding stream, with a hard maximum of $600,000 per organization per state. Each site needs its own vulnerability assessment and its own Investment Justification, and each is scored separately. Contracted security personnel are allowable up to 50 percent of the award, and up to 5 percent can go to management and administration.

Is there a matching requirement?

Q: Do we have to put up our own money?

A: There is no cash match – one reason the program is heavily oversubscribed. But the grant is reimbursement-based: you pay vendors first, then submit for reimbursement as approved project phases complete. Budget for that float before you accept an award, especially on six-figure construction-adjacent work where vendor deposits come due long before FEMA money arrives.

What happens if our FY25 application is still pending?

Q: Can we reapply for the same project?

A: Risky. FEMA has not announced FY25 sub-awardees, and if your FY25 project is eventually funded, an identical FY26 application is automatically denied – the program cannot fund the same project twice. SAAs are advising applicants to propose a different project each cycle so that no pending decision can void a live application.

Bottom Line: Score Yourself Before the Next Window Opens

Run your own numbers the way FEMA will. Identify your multiplier – x3 if you are a religious or ideology-based organization, x2 if you are a secular school or medical institution, x1 otherwise. Add the 15-point bonus if you have never won. Then be honest about what that means: a x1 organization needs a near-perfect state score, which means a professional vulnerability assessment and a surgically specific Investment Justification, not a general plea for safety funding. A x3 first-timer, by contrast, may be closer to an award than it realizes, and the biggest risk is simply missing a two-week state window.

Either way, the winning move is the same: have the file built before the NOFO drops. Track your SAA, hold a current vulnerability assessment, keep your SAM.gov registration active, and stage your project pipeline so no overlap rule can void it. If you want the deadline-watching handled for you, OpenGrants’ grant database tracks security funding across federal and state sources – and if the Investment Justification itself is the bottleneck, our grant writing services team can have your FY27 application drafted while this year’s awards are still being scored.