Tribal Cybersecurity Grant Program
Program Funding
Annual program obligations reported to SAM.gov.
Program Objective
The goal of the Tribal Cybersecurity Grant Program (TCGP) is to assist tribal governments with managing and reducing systemic cyber risk. This goal can be achieved over the course of the Period of Performance (POP) as applicants focus on their Cybersecurity Plans, priorities, projects, and implementation toward addressing the program objectives. Program Objectives for TCGP include:
1. Develop and establish appropriate governance structures, as well as plans, to improve capabilities to respond to cybersecurity incidents and ensure continuity of operations;
2. Tribal governments understand their current cybersecurity posture and areas for improvement based on continuous testing, evaluation, and structured assessments;
3. Implement security protections commensurate with risk (outcomes of Objectives 1 & 2); and
4. Ensure organization personnel are appropriately trained in cybersecurity, commensurate with responsibility
Performance Measures:
• Percentage of tribes with CISA approved tribal Cybersecurity Plans
• Percentage of tribes with Tribal Cybersecurity Planning Committees that meet the Homeland Security Act of 2002 and TCGP funding notice requirements
• Percentage of tribes conducting annual table-top and full-scope exercises to test Cybersecurity Plans
• Percent of the tribes’ TCGP budget allocated to exercises
• Average dollar amount expended on exercise planning for Tribes
• Percentage of tribes conducting an annual cyber risk assessment to identify cyber risk management gaps and areas for improvement
• Percentage of tribes performing phishing training
• Percentage of entities conducting awareness campaigns
• Percent of tribes providing role-based cybersecurity awareness training to employees
• Percentage of tribes adopting the Workforce Framework for Cybersecurity (NICE Framework) as evidenced by established workforce development and training plans
• Percentage of tribes with capabilities to analyze network traffic and activities related to potential threats
• Percentage of tribes implementing multi-factor authentication (MFA) for all remote access and privileged accounts
• Percentage of tribes with programs to anticipate and discontinue use of end-of-life software and hardware
• Percentage of tribes prohibiting the use of known/fixed/default passwords and credentials
• Percentage of tribes operating under the “.gov” internet domain
• Number of cybersecurity gaps or issues addressed annually by tribes
Eligibility
Eligible Applicants
- Federally recognized tribes
Federally Recognized Tribal Governments may apply directly through the Tribal Cybersecurity Grant Program or may receive funds as subrecipients of the State and Local Cybersecurity Grant Program.
Eligible entities are “Tribal government” under Section 2220A(a)(7) of the Homeland Security Act of 2002 (codified as amended at 6 U.S.C. § 665g(a)(7). This statute defines “Tribal government” as the recognized governing body of any Indian or Alaska Native Tribe, band, nation, pueblo, village, community, component band, or component reservation, that is individually identified (including parenthetically) in the most recent list published pursuant to Section 104 of the Federally Recognized Indian Tribe List of 1994 (25 U.S.C. § 5131).
Tribal governments that apply must submit a Cybersecurity Plan, Cybersecurity Planning Committee List, Charter, TCGP Investment Justification (IJ) form, and a Project Worksheet form. These requirements must be fulfilled before a Tribal government may receive TCGP award funding.
Two or more Tribal governments may apply together as a Tribal consortium and submit one application for the consortium.
How to Apply
Application Procedure
Notice of Funding Opportunities (NOFO) for this listing will be posted on FEMA GO.
Applying for an award under the TCGP is a multi-step process. In order to apply for a grant award, an applicant must have a Unique Entity Identifier (UEI), Employer Identification Number (EIN), an active System for Award Management (SAM) registration, a Login.gov, and a FEMA GO account. Applicants are encouraged to register early for SAM and UEI because the registration process can take four weeks or more to complete. Registration should be done in sufficient time to ensure it does not impact an applicant’s ability to meet the required submission deadline.
Eligible applicants should submit their initial application at least one week before the final application submission deadline through the FEMA GO System. Applicants needing FEMA GO support may contact the For general questions, email the FEMA GO Help Desk, or call 1-877-585-3242 on Monday - Friday, 9 a.m. - 6 p.m. ET.
Award Procedure
Once both reviews are complete, awards are dispersed to recipients.
Program details & compliance
Description
The Tribal Cybersecurity Grant Program provides funding to eligible entities to address cybersecurity risks and threats to information systems owned or operated by, or on behalf of tribal governments.
Use of Funds
Allowed Uses
Tribal governments shall use the grant funds to: (1) implement the Cybersecurity Plan of the eligible entity; (2) revise the Cybersecurity Plan of the eligible entity; (3) pay expenses directly relating to the management and administration of the grant, up to 5 percent of the grant amount; (4) assist with activities that address imminent cybersecurity threats to the information systems owned or operated by, or on behalf of, the tribal government; (5) fund any other appropriate activity determined by the Department of Homeland Security. An eligible entity applying for a grant shall agree to consult the Chief Information Officer (or equivalent), the Chief Information Security Officer, or an equivalent official of the eligible entity, in allocating grant funds under this program.
Each eligible tribal government is required to meet the following criteria for FY 2024:
• Submit a Cybersecurity Plan, Cybersecurity Planning Committee List, and a Cybersecurity Charter that aligns with the criteria detailed in this funding notice.
• Cybersecurity projects funded by the Tribal Homeland Security Grant Program (THSGP) may be considered for TCGP funding if not duplicative of the THSGP project(s).
FEMA will not release funds to a recipient until CISA approves the entity’s Cybersecurity Plan. Details on the requirements for the Cybersecurity Plan, Committee Membership List, and Charter can be found in Appendices A - C in this funding notice.
Required Documentation
Eligible entities applying for a grant under this Assistance Listing must have an approved Cybersecurity Plan, Project Worksheet, and Investment Justification to have funds released. Eligible entities should also refer to the Notices of Funding Opportunity, once published, for additional documents required to apply for a grant. 2 CFR 200, Subpart E - Cost Principles applies to this program.
Reporting & Compliance
Applicable 2 CFR 200 Subparts
- Subpart B — General Provisions
- Subpart C — Pre-Federal Award Requirements
- Subpart D — Post-Federal Award Requirements
- Subpart E — Cost Principles
- Subpart F — Audit Requirements