If your county has used federal money for a cybersecurity plan, an assessment, or new monitoring tools in the last few years, there's a good chance it came through the State and Local Cybersecurity Grant Program. It's been one of the only funding sources built specifically for jurisdictions too small to have their own dedicated security budget — and right now, its future is genuinely uncertain.
How we got here
The program was created under the 2021 federal infrastructure law with roughly a billion dollars to distribute over four years, split between states and passed through to local governments. That original window has already closed once and been pushed back by stopgap funding measures more than once since. Rather than a clean multi-year renewal, the program has been living deadline to deadline for the better part of a year.
There's real momentum behind fixing that. A House bill would extend the program's authorization for years longer, and a competing Senate proposal has been introduced as a simpler, shorter renewal. Neither has crossed the finish line as of this writing, and advocacy groups representing counties have continued pressing Congress on the issue through the summer.
The short version: the money that's already been awarded for open projects should still get spent. What's uncertain is whether there will be a next round to apply to once the current authorization runs out.
Why this matters more for small jurisdictions
Larger cities have security budgets that exist independent of any one grant. Smaller counties and towns often don't — for a lot of our government clients, this program (or a state-level equivalent it helped fund) has been the difference between having a written cybersecurity plan and not having one at all. That gap matters: smaller jurisdictions tend to be more exposed than big cities, not less, mostly because of older systems, thin security staffing, and budget cycles that move slower than the threats do.
What to do regardless of how this shakes out
- Don't build a multi-year plan that assumes the money definitely renews. Treat any current award as a bridge, not a foundation.
- Check your state's allocation status. Every state's Administrative Agency manages this differently, and some are further along than others in getting FY2024–2025 funds out the door.
- Do the groundwork anyway. A written cybersecurity plan and an honest inventory of what systems you actually have pay off no matter which program eventually funds the next step — and they're usually the cheapest part of the process.
- Ask before you assume you're ineligible. Eligibility and pass-through rules vary by state, and we've seen small jurisdictions skip applying because someone assumed a nearby city would take the whole allocation.
We'll post an update here if the reauthorization picture changes in a way that affects planning. In the meantime, if you want help figuring out where your jurisdiction actually stands, that's exactly the kind of question our grant and funding navigation work is built for.