cisatrade-pressNewsThe Broadside1 min read

CISA grant program stares down Sept. 30 lapse, states told to triage

Former state cyber officials are telling states to act like the money's already gone, because Congress hasn't moved, and the authorization clock doesn't care about bipartisan agreement.


TL;DR

The State and Local Cybersecurity Grant Program's authorization expires Sept. 30, 2026, and former state cyber officials are advising governments to adopt risk-based prioritization now rather than wait for reauthorization. The program, funded at $1 billion over four years by the 2021 infrastructure law, saw a short-term extension in January but faces an uncertain path forward in the Senate despite bipartisan House support. Former North Carolina CIO James Weaver called the sentiment among states "anxiety, the fact is there is no extension of it."

The SLCGP has a House champion, Rep. Andy Ogles (R-TN) put forward a reauthorization bill with cost-share adjustments and new MFA language, and House appropriators penciled in $50 million for FY 2027. But Ogles himself has acknowledged the Senate is the bottleneck. "I just need my Senate friends to do their part," he said in April. So far, they haven't.

The practical advice coming from the former officials is straightforward and grim: run vulnerability assessments now, build the evidence base, and use it to sharpen budget requests whether or not Washington comes through. Russell Ollis, formerly of Mecklenburg County, NC, put it plainly: "You have to ruthlessly prioritize what you want to spend on."

That framing is a departure from the program's original posture, which assumed sustained federal partnership. The GAO flagged the sustainability problem in an April report, noting that states "were concerned about sustaining funding for cybersecurity projects once the program ends." The webinar made clear that "once the program ends" is now the planning baseline.

Venable's Zack Martin told participants the funding landscape is shifting and urged states to exhaust remaining grant dollars "before these opportunities shift." The anxiety Weaver described isn't about whether the program is popular (it is) but about whether popularity translates to floor time in a Congress preoccupied elsewhere.

For municipal CISOs, the message amounts to: treat the grant as sunsetting. If reauthorization materializes, it's upside. If it doesn't, the vulnerability assessments you run now are the justification for whatever you can scrape together at budget season.


Published ·Deep Fathom

CISA grant program stares down Sept. 30 lapse, states told to triage — The Broadside