Manufacturing And Small Business Cybersecurity Resilience Program 2026
This grant provides funding to state entities or universities in Indiana, Ohio, or Virginia to enhance cybersecurity training and resilience for small businesses, particularly manufacturers, through collaborative technical assistance programs.
The U.S. Small Business Administration, through its Office of Small Business Development Centers, is offering the Cybersecurity Resilience Program as a federal cooperative agreement opportunity focused on technical assistance for small businesses. SBA has supported small businesses since 1953 through financial assistance as well as counseling, training, and other technical assistance. Under this program, SBA seeks to increase small business cybersecurity resilience, with an emphasis on small manufacturers when possible. The objective is to increase the number of small manufacturers and other small businesses that understand cybersecurity risks and take meaningful action to protect their businesses. SBA is particularly interested in collaborative approaches that can serve as models or best practices for cybersecurity assistance. SBA expects to make up to two awards from total available funding of $2,500,000. The maximum single award is $2,500,000, and the notice does not establish a minimum award amount. The period of performance is two years, with a program start date of October 1, 2026. There is no matching requirement. Program income may be generated under the award. Award funds must be used solely for purposes stipulated in the funding opportunity and Notice of Award and may not be commingled with other monies. Proposed costs must satisfy the allowability, allocability, and reasonableness requirements of 2 CFR Part 200. Applicants may request indirect costs using an applicable negotiated indirect cost rate agreement or the 15 percent de minimis rate of modified total direct costs, or may waive indirect costs. Eligibility is geographically and organizationally restricted. An applicant must be a state entity or university, or a designee of the state, in Indiana, Ohio, or Virginia. These states previously received SBA Cybersecurity Pilot Program funding and have demonstrated experience providing Cybersecurity Maturity Model Certification tier 1 training. Applicants must document specific eligible experience providing cybersecurity training relevant to the proposed program. A state entity or university may submit one proposal. The program expects awardees to leverage SBA funding through collaboration with SBA District Offices, government programs, SBA resource partners, Manufacturing Extension Partnerships, APEX Accelerators, educational institutions, trade schools, and appropriate private organizations. The technical proposal may not exceed 10 pages and must demonstrate the applicant's ability to increase cybersecurity training and awareness among manufacturing and other small businesses, encourage meaningful cybersecurity resilience actions, and manage curriculum development, course delivery, assessment, improvement, and overall program administration. The required model of operation covers curriculum development, course delivery, assessment, and program management. At minimum, curriculum development is expected to address cybersecurity awareness and fundamentals, threat identification and mitigation, data security and privacy, and cybersecurity best practices. Applicants must explain delivery methods, anticipated outcomes, evaluation methods, staffing, contractors and consultants, organizational structure, and quarterly performance milestones for the 24-month period. Applications must include a cover page, table of contents, technical proposal in MS Word format, budget information, certifications, forms and assurances, and applicable attachments and exhibits. Budget materials include SF-424, SF-424A, a Cost Price Analysis and Budget Justifications workbook, applicable separate budget justification information, and documentation supporting indirect costs when claimed. Applicable attachments may include resumes, position descriptions, letters of support, a conflict of interest policy, and other supporting documentation. Applications must be submitted electronically through Grants.gov. The opportunity opened August 13, 2026, and applications must be received by Grants.gov no later than 11:59 PM Eastern Daylight Time on September 4, 2026. Late applications will be rejected without evaluation except where an applicant demonstrates that submission failure resulted solely from Grants.gov system issues. Eligible, timely, and materially complete applications will be evaluated for organizational experience and capacity, program design, program management, collaboration and leveraging of resources, and operational controls. SBA will consider demonstrated cybersecurity assistance experience, statewide, regional, or national delivery capability, staff and instructor expertise, measurable outcomes, monitoring and continuous improvement, cost efficiency, financial controls, partnerships, and the ability to create an adaptable model for future programs. SBA states a preference, all else being equal, for organizations with lower indirect costs. Applications meeting the minimum requirements and presenting a comprehensive approach will also undergo a risk evaluation under 2 CFR 200.205. Selected applicants will receive written notification; unsuccessful applicants will not receive notification or a debriefing. Recipients must provide required financial and performance reporting, including quarterly reports due 30 days after each quarter and a final report no later than 120 days after the award period ends. Program questions may be directed to Traci Giddens at Traci.Giddens@sba.gov, budget questions to Teresa.Clouser@sba.gov, and GrantSolutions technical support to help@GrantSolutions.gov or 1-866-577-0771.
Award Range
Not specified - $2,500,000
Total Program Funding
$2,500,000
Number of Awards
2
Matching Requirement
No
Additional Details
Up to two awards totaling no more than $2,500,000; maximum single award is $2,500,000; 24-month period of performance beginning October 1, 2026; program income is allowed; indirect costs may use an applicable NICRA or the 15 percent de minimis MTDC rate; funds must be used solely for authorized program purposes and may not be commingled with other monies.
Eligible Applicants
Additional Requirements
Applicants must be a state entity or university, or a designee of the state, in Indiana, Ohio, or Virginia. The eligible states previously received SBA Cybersecurity Pilot Program funding and have demonstrated experience providing Cybersecurity Maturity Model Certification tier 1 training. Applicants must provide documentation of specific eligible history providing cybersecurity training relevant to the proposed program. A state entity or university may submit one proposal.
Geographic Eligibility
All
Address every evaluation criterion directly and provide concrete evidence of cybersecurity assistance experience and successful past performance. Demonstrate capability to deliver specialized cybersecurity programming on a statewide, regional, or national scale. Build the proposal around curriculum development, course delivery, assessment, and program management. Define measurable outcomes, participant metrics, quarterly milestones, monitoring, mid-course correction, and continuous improvement. Document strong staffing, financial controls, digital platform support, and collaboration with SBA and other cybersecurity and small-business partners. Demonstrate efficient use of funds because SBA will evaluate cost effectiveness and, all else being equal, prefers organizations with lower indirect costs.
Application Opens
August 13, 2026
Application Closes
September 4, 2026
Grantor
Traci Giddens
Subscribe to view contact details
Subscribe to access grant documents

