October 5, 2026 | Policy Brief
Federal Grant Program’s Third Lapse Endangers State Cybersecurity
October 5, 2026 | Policy Brief
Federal Grant Program’s Third Lapse Endangers State Cybersecurity
U.S. states are once again being left with limited access to cybersecurity resources as funding for the federal government’s State and Local Cybersecurity Grant Program (SLCGP) lapsed on September 30. This is the program’s third funding lapse since September 2025. The SLCGP plays an essential role in states’ ability to develop and maintain cyber resilience amid increasing attacks.
A Program With Proven Value
Congress created the SLCGP in 2021 to provide cyber-specific funding for under-resourced entities. In its first four years, it helped fund 839 state and local cybersecurity projects. In Tennessee alone, program grant funding has secured almost 90,000 endpoints and provided cyber training for more than 21,000 employees across local governments, building cyber resilience from the ground up.
The impact extends beyond equipment and training. In Utah, for example, SLCGP-funded security tools helped detect and interrupt a cyberattack on a local airport days before Christmas, allowing the state’s Cyber Center to stop the intrusion before operations were disrupted and without paying a ransom.
Recent Attacks Raise the Stakes for States
U.S. infrastructure continues to fall victim to cyberattackers, underscoring the need for the SLCGP. In late July, alleged Iranian state-sponsored actors accessed water-management systems in at least 12 states. Federal resources are vital to preparing infrastructure entities for these types of attacks — especially for the many small communities that lack staff with cyber expertise, rely on aging equipment, and manage complex operational technology with limited security controls.
Despite the program’s demonstrated success, Congress failed to effectively renew it after the original four-year timeframe that ended last October. Congress temporarily extended the program through the end of January, resulting in a second lapse and reauthorization last spring. That extension has now expired, leaving the future of the program and the projects it funds uncertain.
Policy Steps To Secure Predictable Cyber Funding
This stop-and-go pattern risks undermining the effectiveness of the program: states and localities cannot plan multiyear projects around a program that may expire at any moment. Entities weighing whether to build a multiyear security program around SLCGP dollars have little reason to commit when the program’s future is renewed in increments of months. Amid cuts to other government-funded entities supporting small cyber operators, the SLCGP provides much-needed support for cyber preparedness and infrastructure-hardening efforts, and uncertainty as to its future leaves states wanting.
Congress should abandon the short-term patches for the program in favor of long-term reauthorization. The 2025 Protecting Information by Local Leaders for Agency Resilience (PILLAR) Act, which passed the House last November before stalling in the Senate, is one piece of legislation that would extend the SLCGP to 2035. However, reauthorization only provides the legal authority for the program to operate; it does not fund it. Congress must also pair any extension with dedicated appropriations, since an authorized program without funding cannot deliver grants to the states and localities that depend on it.
Sophie McDowall is a research associate for the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies (FDD), where Elisa Montgomery is an intern. For more analysis from the authors and FDD, subscribe HERE. Follow Sophie on X @SophieMcDowall_. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.