Overview
Our nation faces unprecedented cybersecurity risks, including increasingly sophisticated adversaries, widespread vulnerabilities in commonly used hardware and software, and broad dependencies on networked technologies for the day-to-day operation of critical infrastructure. Cyber risk management is further complicated by the ability of malicious actors to operate remotely, linkages between cyber and physical systems, and the difficulty of reducing vulnerabilities.
The State and Local Cybersecurity Grant Program (SLCGP) is administered by the Department of Homeland Security (DHS) and funded by the Infrastructure Investment and Jobs Act (IIJA). The SLCGP is a reimbursable pass-through grant program with an overall goal to improve the cybersecurity posture of state, local and territorial (SLT) government organizations by providing assistance for managing and reducing systemic cyber risk through the following objectives:
Objective 1: Develop and establish appropriate governance structures, including developing, implementing, or revising cybersecurity plans, to improve capabilities to respond to cybersecurity incidents and ensure continuity of operations.
Objective 2: Understand their current cybersecurity posture and areas for improvement based on continuous testing, evaluation, and structured assessments.
Objective 3: Implement security protections commensurate with risk.
Objective 4: Ensure organization personnel are appropriately trained in cybersecurity, commensurate with responsibility.
In Michigan, the SLCGP is administered by the Department of Technology, Management & Budget Cybersecurity and Infrastructure Protection division and the Michigan State and Local Cybersecurity Grant Program Advisory Board established Oct. 19, 2022.
State and Local Cybersecurity Grant Program (SLCGP) Funding Information
The State of Michigan was awarded the following for federal fiscal years (FFY):
- $4,777,219 initial allocation for FY 2022.
- Required 10% cost share match.
- Notification of subrecipient awards has been completed.
- $9,609,530 initial allocation for FY 2023.
- Required 20% cost share match.
- Notification of subrecipient awards has been completed.
- $7,178,365 initial allocation for FY 2024.
- Required 30% cost share match.
- Notification of subrecipient awards has been completed.
- $2,346,859 initial allocation for FY 2025.
- Required 40% cost share match.
- Open application period to award funds to be determined.
The SLCGP grant award application process is detailed below:
- FY 2022: Closed
- FY 2023: Closed
- FY 2024: N/A
- FY 2024 grant funds were awarded to subrecipient projects submitted through the FY 2023 application process.
- FY 2025: Application available date and application submission deadline to be determined.
Entities interested in participating in future grant funding opportunities are encouraged to subscribe using the form at the end of this page to learn more about the SLCGP program and receive automatic bulletin updates, which includes information about open application periods and announcements of funding awards.
State and Local Cybersecurity Grant Program (SLCGP) FY 2022 Projects
The following projects were approved by the State and Local Cybersecurity Grant Program Advisory Board. Subrecipients were awarded funding to implement and complete projects by the end of FY 2022 period of performance in August 2026 and November 2026 respectively. Funding for FY 2022 is closed, and no additional applications will be accepted.
Please contact DTMB-CIP-SLCGP@michigan.gov if you have questions regarding FY 2022 grant funds.
-
Procure, implement, and distribute advanced detection and response licensing and services, including endpoint detection and response (EDR), managed detection and response (MDR), extended detection and response (XDR), network detection and response (NDR), identity threat detection and response (ITDR), data detection and response (DDR), machine learning detection and response (MLDR), or other specialized detection and response monitoring areas.
-
Structured, grant-funded evaluations designed to help state, local, and territorial (SLT) governments identify, assess, and mitigate cyber risks to their information systems.
Procure and implement cybersecurity services up to but not limited to vulnerability scanning, penetration testing, maturity assessments, industrial control systems (ICS/OT) assessments, compliance assessments, incident response readiness assessments, human and specific threat assessments, specialized services designed to identify, evaluate, and mitigate risks within an organization's IT infrastructure.
State and Local Cybersecurity Grant Program (SLCGP) FY 2023 Projects
The following projects were approved by the State and Local Cybersecurity Grant Program Advisory Board. Subrecipients were awarded funding to implement and complete projects by the end of the FY 2023 period of performance in August 2027. Funding for FY 2023 is closed, and no additional applications will be accepted.
Please contact DTMB-CIP-SLCGP@michigan.gov if you have any questions regarding FY 2023 grant funds.
-
Where jurisdictions can receive funding to purchase backup software, cloud services, backup servers, storage devices, or other services that support the recovery and reconstitution of entity backup data.
-
Where jurisdictions can receive funding to purchase an independent cybersecurity assessment or penetration testing for the organization using existing MiDEAL negotiated contractors or another contracted vendor following the organization's established procurement policies and within grant performance and spend time frames.
-
Where jurisdictions can receive funding to purchase subscriptions for cybersecurity awareness training for employees to better understand cyber threats, best practices, incident response, compliance, and policies.
-
Where jurisdictions can receive funding to purchase professional cybersecurity training for those responsible for mitigation risk and maintaining resiliency in the organization's environment.
-
Where jurisdictions can receive funding to purchase subscriptions for EDR/MDR/XDR licensing vendor selected utilizing entities established procurement policies and grant performance and spend period time frames.
-
Where jurisdictions can receive funding to pay managed service providers for cybersecurity services that mitigate risk, improve cyber resiliency, and perform cybersecurity work where an organization does not have onsite staff to support.
-
Where jurisdictions can receive funding to pay for services that support the migration of the organization's domain to a .gov domain. Managed service provider (MSP) services to pay support vendors to perform migration tasks to a .gov domain.
-
Where jurisdictions can receive funding to purchase authentication devices, MFA software, or other systems/hardware supporting MFA, such as identity and access management (IAM) systems.
State and Local Cybersecurity Grant Program (SLCGP) FY 2024 Projects
The following projects were approved by the State and Local Cybersecurity Grant Program Advisory Board. Subrecipients were awarded funding to implement and complete projects by the end of the FY 2024 period of performance in August 2028. Applications submitted in the FY 2023 process were used to award subrecipients funding from FY 2024 funds. FY 2024 funding opportunity is closed.
Please contact DTMB-CIP-SLCGP@michigan.gov if you have questions regarding FY 2024 grant funds.
-
Where jurisdictions can receive funding to purchase backup software, cloud services, backup servers, storage devices, or other services that support the recovery and reconstitution of entity backup data.
-
Where jurisdictions can receive funding to purchase an independent cybersecurity assessment or penetration testing for the organization using existing MiDEAL negotiated contractors or another contracted vendor following the organization's established procurement policies and within grant performance and spend time frames.
-
Where jurisdictions can receive funding to purchase subscriptions for cybersecurity awareness training for employees to better understand cyber threats, best practices, incident response, compliance, and policies.
-
Where jurisdictions can receive funding to purchase professional cybersecurity training for those responsible for mitigation risk and maintaining resiliency in the organization's environment.
-
Where jurisdictions can receive funding to purchase subscriptions for EDR/MDR/XDR licensing vendor selected utilizing entities established procurement policies and grant performance and spend period time frames.
-
Where jurisdictions can receive funding to pay managed service providers for cybersecurity services that mitigate risk, improve cyber resiliency, and perform cybersecurity work where an organization does not have onsite staff to support.
-
Where jurisdictions can receive funding to pay for services that support the migration of the organization's domain to a .gov domain. Managed service provider (MSP) services to pay support vendors to perform migration tasks to a .gov domain.
-
Where jurisdictions can receive funding to purchase authentication devices, MFA software, or other systems/hardware supporting MFA, such as identity and access management (IAM) systems.
State and Local Cybersecurity Grant Program (SLCGP) FY 2025 Projects
The =State and Local Cybersecurity Grant Program FY 2025 application period is open Sept. 14, 2026, and will end Oct. 11, 2026, at 11:49 p.m. EST.
Michigan FY 2025 SLCGP funding priorities
Priority sectors: Critical infrastructure organizations will be prioritized, with the highest focus on publicly owned Water and Wastewater Systems, followed by Energy and Transportation Systems.
Rural prioritization: The grant requires that 25% of funding be passed through to rural organizations. Entities located in rural counties with populations under 50,000 applications will receive additional points for consideration to strengthen cybersecurity resilience in underserved areas.
Funding prioritization: Entities that have not previously received SLCGP funding will receive priority consideration for this cycle. All eligible entities are encouraged to apply for funding.
Entities are encouraged to review the application guidance documentation in preparation to submit your application. Apply during the official application window by visiting FY 2025 SLCGP Application Submission.
The projects below have been approved by the advisory board to award funds to eligible subrecipients.
The end of performance for FY 2025 projects is June 30, 2029.
Please contact DTMB-CIP-SLCGP@michigan.gov if you have questions regarding FY 2025 grant funds.
-
Funding for cybersecurity hardening projects focused on and essential to systems such as but not limited to SCADA (Supervisory Control and Data Acquisition), Industrial Control Systems (ICS), Distributed Control Systems (DCS), Programmable Logic Controller (PLC), Operational Technology (OT) and associated IT Infrastructure. Strengthening cybersecurity posture of critical infrastructure by integrating enhanced physical security measures with modern protection for operational technologies (OT).
- Objective 1: Establish a governance framework for physical security and integrating it into the overall cybersecurity plan. Objective 1 focuses on developing or revising cybersecurity plans and governance to improve incident response and operational continuity.
- Objective 2: Focus on conducting assessments and evaluations to understand the current cybersecurity posture, including cyber-physical vulnerabilities and identify areas for improvement.
- Objective 3: Implement targeted security upgrades that reduce identified cyber risks to critical government facilities, network infrastructure, and operational technology (OT) systems.
- Objective 4: Ensure personnel are trained at levels appropriate to their cybersecurity responsibilities, including those responsible for physical access, facility management, and equipment security. Physical access control is a foundational part of cyber hygiene.
-
Where jurisdictions can receive funding to purchase backup software, cloud services, backup servers, storage devices, or other services that support the recovery and reconstitution of entity backup data.
-
Where jurisdictions can receive funding to purchase an independent cybersecurity assessment or penetration testing for the organization using existing MiDEAL negotiated contractors or another contracted vendor following the organization's established procurement policies and within grant performance and spend time frames.
-
Where jurisdictions can receive funding to purchase subscriptions for cybersecurity awareness training for employees to better understand cyber threats, best practices, incident response, compliance, and policies.
-
Where jurisdictions can receive funding to purchase professional cybersecurity training for those responsible for mitigation risk and maintaining resiliency in the organization's environment.
-
Where jurisdictions can receive funding to purchase subscriptions for EDR/MDR/XDR licensing vendor selected utilizing entities established procurement policies and grant performance and spend period time frames.
-
Where jurisdictions can receive funding to pay managed service providers for cybersecurity services that mitigate risk, improve cyber resiliency, and perform cybersecurity work where an organization does not have onsite staff to support.
-
Where jurisdictions can receive funding to pay for services that support the migration of the organization's domain to a .gov domain. Managed service provider (MSP) services to pay support vendors to perform migration tasks to a .gov domain.
-
Where jurisdictions can receive funding to purchase authentication devices, MFA software, or other systems/hardware supporting MFA, such as identity and access management (IAM) systems.
Additional Resources
SLCGP is a reimbursement grant with a 30% match requirement for FY 2024 and a 40% match requirement for FY 2025.
Eligibility Requirements
Local government is defined in 6 U.S.C. § 101(13) as:
A.) A county, municipality, city, town, township, local public authority, school district, special district, intrastate district, council of governments, regional or interstate government entity, or an agency or instrumentality of a local government.
B.) An Indian tribe or authorized tribal organization, or in Alaska a Native village or Alaska Regional Native Corporation: and
C.) A rural community, unincorporated town or village, or other public entity.
Please visit the SLCGP background page for more information on eligibility and grant requirements.
SLCGP Reimbursements
The following Michigan State Police grant forms are required to submit a reimbursement package: EMD-056, EMD-057, and EMD-054.
To submit a reimbursement package, use the specific link for each grant year.
Cybersecurity & Infrastructure Security Agency's (CISA) cyber hygiene services are required services for grant compliance. Learn more about CISA's cyber hygiene services and enrollment instructions.
To learn more about the State and Local Cybersecurity Grant Program, visit our SLCGP Background page.
For questions or input, please contact DTMB-CIP-SLCGP@michigan.gov.
For updates, please sign up for the distribution list below.