DHS announces new funding for the State and Local Cybersecurity Grant Program

Author

Picture of Seamus Dowdall smiling in a suit jacket and button down with orange background

Seamus Dowdall

Legislative Director, Telecommunications & Technology | Veterans and Military Services
Image of Rita-Reynolds-2.png

Rita Reynolds

Director of Public Sector, CAI
Emma Conover

Emma Conover

Associate Legislative Director

Upcoming Events

Related News

County News

PDFs are DOA as new web standards approach

Image of Levers-Technology_1.jpg

Key Takeaways

On September 23, the Department of Homeland Security announced a new funding round for the State and Local Cybersecurity Grant Program (SLCGP). The SLGCP provides $1 billion over four years to state, local, and tribal governments to implement cybersecurity plans and build resilience against emerging threats as a part of the Bipartisan Infrastructure Law (BIL).  

This year’s allocation is $279.9 million, notably less than the fiscal year 23 (FY23) allocation of $375 million. Applications for funds must be submitted by December 2, 2024. Eligible entities for this program are state governments, and the program structure design allows for local governments to receive 80 percent of the funding via either pass-through funding or in-kind services. Counties should be advised that eligible entities may request counties to contribute to the non-federal cost-share element of a state’s application, which for this grant year is 3 percent for a single-entity applicant or 20 percent for a multi-entity applicant.  

Slight changes have come to the SLCGP for FY2024, including broadening the criteria for applications. In FY22 and FY23, state and local governments were limited to specific objectives of the program, where now applications can focus on any of these four objectives:  

  1. Develop and establish appropriate governance structures, including developing, implementing, or revising cybersecurity plans, to improve capabilities to respond to cybersecurity incidents and ensure continuity of operations 
  2. Understand their current cybersecurity posture and areas for improvement based on continuous testing, evaluation, and structured assessments 
  3. Implement security protections commensurate with risk 
  4. Ensure organization personnel are appropriately trained in cybersecurity, commensurate with responsibility 

The SLCGP requires that 25 percent of state allocations must benefit rural areas. Local and state governments have 48 months to complete projects and expend allocated funds. The BIL provided funding for four years, with FY 25 being the last year of the program.  

NACo encourages counties to coordinate with statewide cyber planning committees to prepare a proposal for the program. NACo will continue to monitor the program and update counties with any developments.  

Related News

ADA
County News

PDFs are DOA as new web standards approach

Counties with 50,000 residents or more have until April 24 to meet accessibility guidelines for their websites and social media accounts, while smaller counties have another year.

Shannon Smith, director, Public Sector, CAI, speaks Feb. 22 to members of the Mid-Size County Caucus. Photo by Denny Henry
County News

Expert warns Mid-Size County Caucus of rising cybersecurity risks as AI expands

Counties must prepare for increasingly sophisticated cyber threats, particularly if they still rely on aging technology systems, some decades old, which can make them vulnerable to attacks.

GettyImages-1300444386
Advocacy

White House sends legislative recommendations on national AI policy framework to Congress

The proposals prioritize children’s online safety, intellectual property rights, establishing risk mitigation and duty of care for AI , and enshrining protections for ratepayers.