State, Local, Tribal and Territorial Security Operations Center/Information Sharing and Analysis Center
Program Funding
Annual program obligations reported to SAM.gov.
Funded Projects
Examples of what this program has supported.
CISA award a single SLTT SOC | ISAC Program cooperative agreement in FY 2023 with a 2-year period of performance from September 30, 2023, to September 29, 2025. As the period of performance did not begin until the very end of the FY 2023, the recipient did not have any significant accomplishments in FY 2023.
CISA projects that it will issue continuation funding for the FY 2023 cooperative agreement award for a second 1-year budget period from September 30, 2024, to September 29, 2025.
CISA anticipates that it will compete and award a new cooperative agreement award in FY 2025 with a period of performance from September 30, 2025, to September 29, 2027.
Program Objective
The mission of CISA is to lead the national effort to understand and manage cyber and physical risk to our critical infrastructure. In carrying out this mission, Section 2209 of the Homeland Security Act of 2002 assigns the CISA Director the responsibilities to, among other things, provide operational technical assistance, risk management support, and incident response capabilities to non-federal entities with respect to cyber threat indicators, defensive measures, cybersecurity risks, and incidents; provide information and recommendations on security and resilience measures to non-federal entities; and, through an entity that has entered an agreement with CISA, collaborate with state and local governments on cybersecurity risks and incidents. Section 102 of the Homeland Security Act of 2002 authorizes the Secretary to make cooperative agreements in carrying out these responsibilities. Pursuant to these authorities, CISA carries out the SLTT SOC | ISAC Program to provide cybersecurity services to SLTT governments and their election infrastructure to assist them in improving their overall cybersecurity resilience and readiness.
Under the SLTT SOC | ISAC Program, CISA provides financial assistance through a cooperative agreement to for-profit and/or non-profit organizations to operate a security operations center | information sharing and analysis center to collaborate with SLTT governments and their election infrastructure on cybersecurity threats and incidents with the goal of strengthening the SLTT governments’ cybersecurity readiness and resilience. The objectives of financial assistance under the SLTT SOC | ISAC Program are to: (1) build and improve the capacity for cyber threat information sharing among SLTTs and their elections infrastructure and the federal government; (2) support SLTTs and their elections infrastructure to build and improved the capability to respond to that cyber threat information; and (3) provide no-cost cyber managed services to SLTTs and their elections infrastructure. The SLTT SOC | ISAC Program supports Goal 3: Secure Cyberspace and Critical Infrastructure under the 2020-2024 Department of Homeland Security Strategic Plan and Goal 1 – Cyber Defense, Goal 2 – Risk Reduction and Resilience, and Goal 3 – Operational Collaboration of the CISA Strategic Plan 2023-2025.
Eligibility
Eligible Applicants
- Public nonprofits
- For-profit organizations
The entities eligible for financial assistance under the SLTT SOC | ISAC Program include for-profit and non-profit organizations.
Beneficiaries
- 4
- 9
- 10
- 5
SLTT government organizations and their elections infrastructure are the beneficiaries of the SLTT SOC | ISAC Program. The recipient may not provide services under the cooperative agreement award to any other type of non-federal entity.
How to Apply
Application Procedure
The Notice of Funding Opportunity will provide the application procedures for the SLTT SOC | ISAC Program. The following summarizes the typical application procedures for this competitive program. An applicant must apply online via www.grants.gov. The documents required to be submitted in the application include various standard forms, such as the Standard Forms (SF) 424 (Application for Financial Assistance), SF 424A (Budget Information for Non-Construction Programs), SF 424B (Assurances for Non-Construction Programs), and SF LLL (Disclosure of Lobbying Activities). They will also include a program abstract, program narrative, program approach, program management plan, budget narrative, letters of commitment confirming support to the program, and a service operational plan.
CISA will initially screen applications to determine whether an applicant is eligible, whether an applicant submitted its application on time, and whether the application conforms to the administrative requirements for application content. Any application not meeting these requirements will not be considered and will not move forward to the evaluation phase. Following this initial screening, an objective review panel will evaluate and score applications using the criteria detailed in the Notice of Funding Opportunity. CISA, during the objective review process, may communicate with applicants about their applications. For the higher scoring applications, CISA will review the proposed budget for allowability, allocability, and financial reasonableness and conduct a financial integrity and supplemental financial integrity review. The objective review panel will use the results of the review process to make funding recommendations to the DHS awarding official. Final funding decisions are made by the DHS awarding official. Following any necessary pre-award communications and clarifications, CISA will issue via email a federal award notice to each successful recipient.
Award Procedure
CISA communicates a Notice of Award to a recipient for which CISA has made a federal award. Payments to a recipient under the cooperative agreement award are made via an electronic system as detailed above in the Length and Time Phasing of Assistance section. A recipient may not contract out or subaward any work under the federal award unless described in the application and funded in the approved cooperative agreement award or approved by CISA after the cooperative agreement award. There is no negotiation of any terms and conditions or any other parts of the federal award communicated to the recipient in the Notice of Award.
The range of time required for CISA to process applications for a federal award is approximately 30-60 days. CISA will communicate all Notices of Awards on or before September 30.
Program details & compliance
Use of Funds
Allowed Uses
The SLTT SOC | ISAC Program provides financial assistance for a for-profit or non-profit entity to operate a SOC ISAC that will provide various cybersecurity services to SLTT governments and their election infrastructure to share cyber threat information and enable response to that cyber threat information. The Notice of Funding Opportunity will typically identify a detailed scope of work across four functional program areas, which are: program management; cybersecurity operations center services; cybersecurity operations center architecture, engineering, operations, and maintenance; and cybersecurity communications and coordination.
The eligible activities under these four areas will include, among other things, sharing cyber situational awareness with SLTT governments concerning threats, incidents, vulnerabilities, best practices, and mitigation strategies; providing cyber managed services to SLTT governments (such as EDR, threat monitoring and analysis, and incident assessment and management); providing technical assistance to SLTT governments; and performing other activities to support SLTT governments prevent, protect against, respond to, recover from, and mitigate against cybersecurity threats and incidents. The allowable direct costs under a federal award may include salaries and fringe benefits of recipient employees, travel costs of recipient employees, purchase costs of necessary equipment and supplies, pre-award costs, contracts, subawards, and management and administration costs. Indirect costs are allowable.
Unallowable costs include those incurred for mis- or dis-information activities, construction and renovation of buildings or other physical facilities, and acquisition of land or physical facilities. The Notice of Funding Opportunity will detail the eligible work, allowable costs, and restrictions on the use of federal funds.
Required Documentation
An applicant for a SLTT SOC | ISAC Program cooperative agreement award must provide documentation that it meets the various eligibility criteria set forth in the Notice of Funding Opportunity. These include that the applicant: (1) currently performs the functions of a cyber information sharing and analysis center; (2) possesses the capability to mature to a functioning 24x7 security operations center; (3) can grow and unite stakeholder communities; (4) can retain cybersecurity analytic staff with appropriate security clearances; (5) can provide access to cybersecurity information, tools, and best practices; (6) can analyze large amounts of information in real-time to identify trends and prioritize cyber information sharing for actionable insights; (7) can sustain a communications model that allows critical cybersecurity information to be quickly disseminated among SLTTs; and (8) can manage cyber threat intelligence.
An applicant must also include letters of commitment from key collaborating organizations and agencies confirming support to the applicant’s project under a future cooperative agreement award and letters of commitment from entities that will be responsible for generating reports based on transactional data (e.g., internet service providers, technology, vendors, or others).
The Cost Principles at 2 C.F.R. pt. 200, subpart E apply to the SLTT SOC | ISAC Program, including awards to both nonprofit and for-profit entities.
Matching Requirements
The SLTT SOC | ISAC Program is a discretionary financial assistance program and there is no statutory or regulatory formula for allocating funds. CISA will provide federal funding of up to 70 percent of total project costs in the approved budget for a federal award. A recipient must contribute the remaining 30 percent of total project costs and can meet this non-federal cost share requirement through cash and/or in-kind contributions. CISA administers the cost-sharing requirements in accordance with 2 C.F.R. § 200.306. There are no maintenance of effort requirements and no non-supplanting requirements.
Reporting & Compliance
Applicable 2 CFR 200 Subparts
- Subpart B — General Provisions
- Subpart C — Pre-Federal Award Requirements
- Subpart D — Post-Federal Award Requirements
- Subpart E — Cost Principles
- Subpart F — Audit Requirements