GrantExec, a Euna Solutions® company

State and Local Cybersecurity Grant Program

This funding opportunity provides financial support to Wisconsin's state, local, and tribal governments, as well as K-12 entities, to enhance their cybersecurity capabilities and protect critical information systems and public services.

$100,000
Active
WI
Recurring
Grant Description

The State and Local Cybersecurity Grant Program Cycle 3 Funding opportunity is administered in Wisconsin by Wisconsin Emergency Management and the Division of Enterprise Technology using federal funding established through the Infrastructure Investment and Jobs Act. The federal program is administered through the U.S. Department of Homeland Security, including the Cybersecurity and Infrastructure Security Agency and the Federal Emergency Management Agency. The program is intended to help state, local, and tribal governments address cybersecurity risks and threats to information systems, improve cybersecurity capabilities, protect networks, systems, and data, and increase the resilience of public services. This solicitation represents the third round of Wisconsin funding available from the Cycle 3 FY2024 allocation and supports the Wisconsin Cybersecurity Plan objective of improving cybersecurity capability and capacity among K-12 entities, local governments, and publicly owned critical infrastructure. A total of USD 4,712,514.40 is available under this funding opportunity. Wisconsin Emergency Management anticipates approximately 100 awards and identifies an anticipated grant award amount of USD 100,000, with a maximum allowable award of USD 100,000 per entity. There is no local cost share requirement because the 30 percent match requirement associated with this cycle has been waived by FEMA. Awarded entities are responsible for costs exceeding the eligible award amount and for all ongoing sustainment costs. The anticipated performance and budget period is March 1, 2027 through August 31, 2028. Subscription and licensing costs included in an application must be prorated to the anticipated 18-month grant period. Funding is limited to specified cybersecurity activities. Eligible uses include internet edge security such as next-generation firewalls, firewall as a service, secure web gateways, DNS security, web filtering, email security, distributed denial-of-service protection, cloud-based edge security, and intrusion prevention systems. Funding may also support implementation assistance for migration to the .gov domain; vulnerability management involving scanning, assessment, remediation or mitigation, and rescanning; immutable cloud backups; security awareness and training programs; penetration testing; multifactor authentication; managed detection and response; endpoint detection and response; and extended detection and response. Allowable direct cost categories include supplies and operating costs, equipment, and consultant or contractual services when tied to eligible activities. Equipment over USD 10,000 must comply with procurement and asset management requirements and approved equipment must be on applicable FEMA Authorized Equipment List categories. There are no conditionally allowable costs. Supplanting, duplication of benefits, pre-award costs, and activities occurring outside the approved performance period are prohibited. Eligible applicants include Wisconsin counties, tribes, municipalities, school districts, utilities, councils of governments, and other public entities. The person submitting the application must have authority to obligate the applicant to the requirements of the notice. Applicants must have a valid Unique Entity Identifier in the System for Award Management before applying unless a regulatory exemption or approved exception applies. Entities that are debarred, suspended, excluded, or otherwise ineligible to participate in federal assistance programs are not eligible. Applicants must identify their entity type and provide community profile information, including whether they serve a rural community where applicable. Multi-entity applications are permitted, but applicants must identify participating entities and indicate which participating entities are rural. No pre-application or letter of intent is required. Applications must be submitted through the Wisconsin Emergency Management Egrants system at https://wem.egrants.us on or before Friday, October 30, 2026. Applicants must obtain Egrants access and must include their UEI in the application. Required Egrants content includes the Main Summary, Budget Detail, Budget Narrative, Agency Profile, Community Profile, Project Narrative, Program Sustainability, Organizational Structure and Resources, Evidence of Need, and an Implementation Schedule. Required budget support includes quotes, estimates, or calculations. Applicants must also provide multi-entity application information when applicable, an implementation schedule, and cybersecurity vulnerability scan results when available, without disclosing specific vulnerabilities. The Project Narrative asks for the number of staff employed and the estimated number and types of computing devices covered by requested endpoint security services. Applicants must also explain project objectives, sustainability after federal funding ends, urgency and potential consequences if the project does not proceed, and whether the project will mitigate circumstances associated with an impactful cybersecurity breach or incident. Applications submitted by the deadline are first screened by Wisconsin Emergency Management for completeness, eligibility, compliance, and responsiveness. Applications that pass that review are evaluated and ranked for merit. Projects that provide scalable and low-cost cybersecurity protections across multiple users, systems, or participating entities, including shared service models, may receive favorable consideration consistent with program goals and scoring methodology. Applicants are also subject to a risk assessment that may consider Single Audit findings and prior suspension or debarment information. During responsiveness review, the Grant Manager may return an application for corrections or request additional information, and applicants must respond and resubmit promptly to avoid delays in approval and the grant start date. The anticipated notice of award date is February 15, 2027, subject to final approval of subgrants by FEMA and CISA. Approved applicants will receive a grant agreement setting forth their obligations, and signed grant agreements should be returned as soon as possible and no later than 60 days after receipt. Post-award program and fiscal reports are due semi-annually, with final program and fiscal reports due within 30 days after the grant period ends. Inventory reporting is required at closeout when applicable. Reimbursements are submitted through Egrants and are paid on a reimbursement basis after Wisconsin Emergency Management verifies compliance, completed activities, and eligible expenses. The program contact is Marc Couturier, SLCGP Grant Manager, at marc.couturier@widma.gov or 608-590-9112.

Funding Details

Award Range

Not specified - $100,000

Total Program Funding

$4,712,514

Number of Awards

100

Matching Requirement

No

Additional Details

Anticipated grant award amount is USD 100,000 and the maximum allowable award is USD 100,000 per entity. Anticipated performance and budget period is 03/01/2027 through 08/31/2028. Subscription and licensing costs must be prorated for the anticipated 18-month period. Recipients are responsible for sustainment costs and costs above the eligible award amount. Payments are reimbursement-based.

Eligibility

Eligible Applicants

County governments
City or township governments
Independent school districts
Native American tribal organizations

Additional Requirements

Eligible applicants are Wisconsin counties, tribes, municipalities, school districts, utilities, councils of governments, and other public entities. The applicant representative submitting the application must have authority to obligate the entity to the NOFO requirements. A valid Unique Entity Identifier in the System for Award Management is required before applying unless an exemption under 2 CFR 25.110(b) or (c), or an exception approved under 2 CFR 25.110(d), applies. Entities that are debarred, suspended, excluded, or otherwise ineligible for federal assistance are ineligible. Multi-entity applicants must identify participating entities and applicable rural status. No pre-application is required.

Geographic Eligibility

All

Expert Tips

Prioritize low-cost, scalable, cloud-delivered or shared cybersecurity protections where appropriate. Smaller entities are encouraged to use free CISA cyber hygiene services. Break out separate activities and costs clearly in the budget, including separate contractual implementation and licensing line items. Prorate subscription and licensing expenses to the anticipated 18-month grant period. Use quotes, estimates, and calculations to substantiate requested costs. Clearly document project urgency, unmet needs, prior cyber impacts, mandates, audit findings, or unsupported systems. Projects protecting multiple users, systems, or entities may receive favorable consideration. Respond promptly to WEM requests and returned-application corrections to avoid delaying the grant start date.

Key Dates

Application Opens

Not specified

Application Closes

October 30, 2026

Contact Information

Grantor

Marc Couturier

Subscribe to view contact details

Newsletter Required
Categories
Safety
Science and Technology
Infrastructure
Capacity Building
Education

Subscribe to access grant documents