municipaltrade-pressNewsThe Broadside2 min read

State-local cyber grant faces Sept. 30 lapse with no Senate path

The House passed reauthorization. The continuing resolution skipped it. Now the Senate has three weeks and no visible markup.


TL;DR

The State and Local Cybersecurity Grant Program's authorization expires Sept. 30, and the recent continuing resolution that extended CISA 2015 left it out. House Homeland Security Chairman Andrew Garbarino (R-NY) is pressing the Senate to take up the PILLAR Act, which the House passed in November. CISA and FEMA can still administer remaining FY2025 funds, $103.8 million announced in August, but a GOP committee aide told Inside Cybersecurity that reauthorization is "the only way to ensure stability." The Senate Homeland Security Committee has not indicated whether it will take up either the House bill or Sen. Maggie Hassan's narrower extension before the deadline.

State-local cyber grant faces Sept. 30 lapse with no Senate path
Editorial illustration · drawn by The Broadside

The State and Local Cybersecurity Grant Program runs out of authorization on Sept. 30, and the Senate has not marked up or scheduled either reauthorization bill, the House-passed PILLAR Act or Sen. Maggie Hassan's shorter extension to fiscal 2026. The continuing resolution that kept the government open and extended CISA 2015 didn't include the grant program. Garbarino's statement to Inside Cybersecurity frames the lapse against recent Iran-linked attacks: "The suspected Iran-linked cyberattacks targeting municipal water systems across several states underscore the importance of ensuring state and local governments have access to the support they need."

The program was created by the 2021 Infrastructure Investment and Jobs Act with $1 billion distributed over four years through CISA and FEMA. Authorization initially lapsed during the 2025 government shutdown; lawmakers passed short-term extensions, the last of which lands on Sept. 30. CISA can continue administering funds already allocated. But a House Homeland Security GOP staffer told Inside Cybersecurity that reauthorization "is the only way to ensure stability for this program and that it continually receives the funding it requires."

House appropriators have included $50 million in the FY2027 DHS appropriations bill, a signal that funding appetite exists, though an appropriation without an authorization is inherently contingent.

Who's pushing

The Operational Technology Cybersecurity Coalition called the July water utility attacks a "wake up call" and pressed for reauthorization. NASCIO included "long-term and appropriately funded reauthorization" in its August legislative priorities letter to House and Senate leaders. NASCIO deputy executive director Meredith Ward said states have used grant funds to deploy multi-factor authentication, endpoint detection and response, and training to local governments, the kind of ground-level security work that stops when the money stops.

What the Senate faces

Hassan's bill, introduced last December, extends the program only to fiscal 2026 and has seen little movement. The PILLAR Act, sponsored by House Homeland Security cyber subcommittee Chairman Andy Ogles (R-TN), runs through fiscal 2033 and passed the House by voice vote in November. The Senate Homeland Security Committee has given no public indication it will take up either one before Sept. 30. House Homeland Security ranking member Bennie Thompson (D-MS) accused Senate Republicans and the administration of letting the program lapse "while cyber threats are on the rise."

If the Senate does nothing, the program doesn't vanish overnight, CISA and FEMA still have $103.8 million in FY2025 funds to push out, and the FY2027 appropriation suggests continued congressional interest. But the sequence of short-term extensions ending in a CR that deliberately excluded the grant program while preserving CISA 2015 gives states and localities a clear signal about which cybersecurity program got the lifeboat.


Published ·Deep Fathom