CISA Cyber Security Awareness Campaign

Cybersecurity Awareness Campaign
CFDA 97.128 Active Cooperative Agreement
No open Grants.gov opportunities under this program right now. Browse all Department of Homeland Security programs →

Program Funding

Annual program obligations reported to SAM.gov.

Latest annual funding (estimated)
$550K FY2026
$550K
FY24
$437K
FY25
$550K
FY26*
* estimated

Funded Projects

Examples of what this program has supported.

FY2025 The recipient is projected to accomplish the following in the second year of the period of performance of the FY 2023 Cybersecurity Awareness Campaign Program cooperative agreement: (1) assessing current and future cybersecurity awareness needs for the general public as well as for targeted segments based on susceptibility to cyber threats and receptivity to adopting cybersecurity practices; (2) based on the research from years one and two, determine successful elements of the awareness campaign to date and target FY 25 strategy to those elements to ensure program message is resonating with audiences’ interests during execution of Cybersecurity Awareness Month to address cybersecurity risk most effectively; (3)developing an executing the annual Cybersecurity Awareness Campaign; (4) measuring, analyzing, and reporting on the effectiveness of awareness efforts and associated outcomes fo year 3; (5) conducting research to measure behavior changes due to Cybersecurity Awareness Month exposure/saturation to determine program effectiveness and measurement of project, group and/or individual activities that encourage cybersecurity risk reduction actions by the targeted audiences so they might be used throughout the year; and (6);Analyzing and identifying activities that encourage cyber risk reduction by targeted audiences. (7) develop partnerships with stakeholders who will amplify the cybersecurity messages of the program.

CISA projects that it will award continuation funding for a third budget period for the cooperative agreement award that will begin on September 30, 2025, and end on February 28, 2026. In addition, CISA projects that it will competitively award a new Cybersecurity Awareness Campaign cooperative agreement in FY 2025 with a period of performance from March 1, 2026, to February 28, 2029.

Program Objective

CISA’s mission is to lead the national effort to understand, manage, and reduce risk to our cyber and physical infrastructure. In carrying out this mission, Section 2202 of the Homeland Security Act of 2002 assigns CISA with the responsibilities to coordinate a national effort to secure and protect against critical infrastructure risks, carry out cybersecurity and critical infrastructure stakeholder outreach and engagement, and encourage and build cybersecurity awareness and competency across the United States. In carrying out its mission and pursuant to these authorities, CISA provides financial assistance under the CAC Program to non-federal entities to perform cybersecurity awareness activities to reduce cybersecurity risks through messaging, tools, and resources to encourage individuals and organizations to reduce their exposure to malicious cyber activity. Through strategies implemented year-round with a focal point of the Cybersecurity Awareness Month in October, a recipient under this federal award engaged in efforts to improve the public’s understanding of cyber threats, amplify opportunities that individuals and non-federal entities can leverage to strengthen their own cybersecurity posture, and encourage discussion, engagement, and actions that can be taken to reduce cyber risk.
For the CAC program, CISA established the following six goal:
1. Strengthen the security and resilience of critical infrastructure;
2. Assess and counter evolving cybersecurity risks through actions that promote threat risk reduction;
3. Build a national culture of preparedness for all Americans, ensuring equity and accessibility in our efforts to increase online and digital safety;
4. Build stakeholder relationships that encourage and support data-driven actions by governments, the private sector, tribes, non-profits, and the public that reduce cybersecurity risk;
5. Reinforce the importance of secure by default and secure by design industry practices that do not place the first line of cyber threat risk reduction on those with the least capabilities and resources; and
6. Encourage activities supported by data which result in key behavior change that reduce cyber risk.

CISA established the following six objectives for the CAC Program:
1. Educate the public, small businesses, and industry about the dangers of cyber threats and key actions that can be taken to mitigate risks;
2. Promote sustainable cybersecurity and encourage the technology industry to provide secure-by-default technology products with strong security features right out of the box, without added costs; and technology that is secure-by-design, purposefully developed, built, and tested to significantly reduce the number of exploitable flaws before they are introduced into the market for broad use;
3. Identify effective approaches to increase cybersecurity awareness among the general public and target audiences, including vulnerable populations and those with disabilities that may make it challenging to take actions that reduce risk;
4. Build relationships and coalitions across cybersecurity stakeholders to support Cybersecurity Awareness Month;
5. Develop a baseline from which to measure the impact Cybersecurity Awareness Month campaign strategies and messaging has on changing behavior and increasing public awareness of cybersecurity risk; and
6. Contribute to the agency’s efforts to build a culture of preparedness, by informing and empowering communities and individuals to obtain the skills and take the preparatory actions necessary to become more resilient against threats and hazards Americans face.

Eligibility

Eligible Applicants

  • Nonprofit Organization

Nonprofit organizations, other than institutions of higher education, with an effective ruling letter from the U.S. Internal Revenue Service granting tax exemption under Section 501(c)(3) of the Internal Revenue Code of 1986

A recipient under the Cybersecurity Awareness Campaign Program must be a nonprofit organization with an effective ruling letter from the U.S. Internal Revenue Service granting tax exemption under Section 501(c)(3) of the Internal Revenue Code of 1986. A “nonprofit organization” means any organization that: (1) is operated primarily for scientific, educational, service, charitable, or similar purposes in the public interest; (2) is not organized primarily for profit; (3) uses net proceeds to maintain, improve, or expand the organization’s operations; and (4) is not an institution of higher education as defined at 20 U.S.C. § 1001.

How to Apply

Award Procedure

CISA/DHS communicates the Notices of Award to recipients for which CISA/DHS has made a cooperative agreement award. Payments to a recipient under the cooperative agreement award are made via an electronic system as detailed above in the Length and Time Phasing of Assistance section. A recipient may not contract out or subaward any work under the federal award unless described in the application and funded in the approved cooperative agreement award or approved by CISA after the cooperative agreement award. There is no negotiation of any terms and conditions or any other parts of the cooperative agreement award communicated to the recipient in the Notice of Award.

The range of time required for CISA to process applications for a federal award is approximately 30-60 days. CISA will communicate all Notices of Awards on or before September 30.

Program details & compliance

Description

In carrying out its mission and pursuant to its authorities, CISA provides financial assistance under the CAC Program to non-federal entities to perform cybersecurity awareness activities to reduce cybersecurity risks through messaging, tools, and resources to encourage individuals and organizations to reduce their exposure to malicious cyber activity. Through strategies implemented year-round with a focal point of Cybersecurity Awareness Month in October, a recipient under a federal cooperative agreement award will engage in efforts to improve the public’s understanding of cyber threats, amplify opportunities that individuals and non-federal entities can leverage to strengthen their own cybersecurity posture, and encourage discussion, engagement, and actions that can be taken to reduce cyber risk.

Mission Categories

Primary: STEM Education

Use of Funds

Allowed Uses

The CAC Program provides financial assistance for a nonprofit organization to carry out public awareness activities concerning cybersecurity risks and messaging, tools, and resources to encourage individuals and non-federal entities to reduce their exposure to malicious cyber activity.

Restrictions

Please refer to the NOFO.

Required Documentation

An applicant for a Cybersecurity Awareness Campaign cooperative agreement award must provide documentation that it meets various eligibility criteria as further detailed in the Notice of Funding Opportunity. This will include documentation that the applicant’s mission includes promoting cybersecurity-related awareness and safe behavior online and that the applicant is a nonprofit organization with an effective ruling letter from the U.S. Internal Revenue Service granting tax exemption under Section 501(c)(3) of the Internal Revenue Code of 1986. The Cost Principles at 2 C.F.R. pt. 200, subpart E apply to all recipients under the Cybersecurity Awareness Campaign Program.

Reporting & Compliance

Audit Required
Yes — Annual
Records Retention
3 years

Applicable 2 CFR 200 Subparts

  • Subpart B — General Provisions
  • Subpart C — Pre-Federal Award Requirements
  • Subpart D — Post-Federal Award Requirements
  • Subpart E — Cost Principles
  • Subpart F — Audit Requirements

Contacts

Nic Harris, Program Analyst — DHS, National Protection and Programs Directorate (NPPD)
202-436-2107
4200 Wilson Avenue, Arlington, VA 20598
Jeanie Moore, Program Officer
202-794-0412
4200 Wilson Avenue, Arlington, VA 20598
Data from SAM.gov Federal Assistance Listings. Source published: 2026-05-11. Spec v2.0. Last synced: 2026-05-28 07:23:07.