Federal · Title 6 — Domestic Security

6 U.S.C. § 665g: State and Local Cybersecurity Grant Program

Read the full statutory text
The term “Cybersecurity Plan” means a plan submitted by an eligible entity under subsection (e)(1). State; or Tribal government. The term “multi-entity group” means a group of 2 or more eligible entities desiring a grant under this section. The term “online service” means any internet-facing service, including a website, email, virtual private network, or custom application. The term “rural area” has the meaning given the term in section 5302 of title 49 . The term “State and Local Cybersecurity Grant Program” means the program established under subsection (b). The term “Tribal government” means the recognized governing body of any Indian or Alaska Native Tribe, band, nation, pueblo, village, community, component band, or component reservation, that is individually identified (including parenthetically) in the most recent list published pursuant to section 5131 of title 25 . There is established within the Department a program to award grants to eligible entities to address cybersecurity risks and cybersecurity threats to information systems owned or operated by, or on behalf of, State, local, or Tribal governments. An eligible entity desiring a grant under the State and Local Cybersecurity Grant Program shall submit to the Secretary an application at such time, in such manner, and containing such information as the Secretary may require. The State and Local Cybersecurity Grant Program shall be administered in the same office of the Department that administers grants made under sections 604 and 605 of this title. implement the Cybersecurity Plan of the eligible entity; develop or revise the Cybersecurity Plan of the eligible entity; pay expenses directly relating to the administration of the grant, which shall not exceed 5 percent of the amount of the grant; assist with activities that address imminent cybersecurity threats, as confirmed by the Secretary, acting through the Director, to the information systems owned or operated by, or on behalf of, the eligible entity or a local government within the jurisdiction of the eligible entity; or fund any other appropriate activity determined by the Secretary, acting through the Director. An eligible entity applying for a grant under this section shall submit to the Secretary a Cybersecurity Plan for review in accordance with subsection (i). any existing plans of the eligible entity to protect against cybersecurity risks and cybersecurity threats to information systems owned or operated by, or on behalf of, State, local, or Tribal governments; and if the eligible entity is a State, consultation and feedback from local governments and associations of local governments within the jurisdiction of the eligible entity; manage, monitor, and track information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, and the information technology deployed on those information systems, including legacy information systems and information technology that are no longer supported by the manufacturer of the systems or technology; monitor, audit, and, 1 track network traffic and activity transiting or traveling to or from information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity; 1 So in original. The comma probably should not appear. enhance the preparation, response, and resiliency of information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, against cybersecurity risks and cybersecurity threats; implement a process of continuous cybersecurity vulnerability assessments and threat mitigation practices prioritized by degree of risk to address cybersecurity risks and cybersecurity threats on information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity; the practices set forth in the cybersecurity framework developed by the National Institute of Standards and Technology; cyber chain supply chain risk management best practices identified by the National Institute of Standards and Technology; and knowledge bases of adversary tools and tactics; promote the delivery of safe, recognizable, and trustworthy online services by the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, including through the use of the .gov internet domain; ensure continuity of operations of the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, in the event of a cybersecurity incident, including by conducting exercises to practice responding to a cybersecurity incident; use the National Initiative for Cybersecurity Education Workforce Framework for Cybersecurity developed by the National Institute of Standards and Technology to identify and mitigate any gaps in the cybersecurity workforces of the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, enhance recruitment and retention efforts for those workforces, and bolster the knowledge, skills, and abilities of personnel of the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, to address cybersecurity risks and cybersecurity threats, such as through cybersecurity hygiene training; if the eligible entity is a State, ensure continuity of communications and data networks within the jurisdiction of the eligible entity between the eligible entity and local governments within the jurisdiction of the eligible entity in the event of an incident involving those communications or data networks; assess and mitigate, to the greatest degree possible, cybersecurity risks and cybersecurity threats relating to critical infrastructure and key resources, the degradation of which may impact the performance of information systems within the jurisdiction of the eligible entity; if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, including by expanding information sharing agreements with the Department; and the Department; leverage cybersecurity services offered by the Department; implement an information technology and operational technology modernization cybersecurity review process that ensures alignment between information technology and operational technology cybersecurity objectives; if the eligible entity is a State, local governments and associations of local governments within the jurisdiction of the eligible entity; and eligible entities that neighbor the jurisdiction of the eligible entity or, as appropriate, members of an Information Sharing and Analysis Organization; and countries that neighbor the jurisdiction of the eligible entity; ensure adequate access to, and participation in, the services and programs described in this subparagraph by rural areas within the jurisdiction of the eligible entity; and distribute funds, items, services, capabilities, or activities to local governments under subsection (n)(2)(A), including the fraction of that distribution the eligible entity plans to distribute to rural areas under subsection (n)(2)(B); assess the capabilities of the eligible entity relating to the actions described in subparagraph (B); describe, as appropriate and to the extent practicable, the individual responsibilities of the eligible entity and local governments within the jurisdiction of the eligible entity in implementing the plan; outline, to the extent practicable, the necessary resources and a timeline for implementing the plan; and implementing the plan; and reducing cybersecurity risks to, and identifying, responding to, and recovering from cybersecurity threats to, information systems owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity. consult with the Multi-State Information Sharing and Analysis Center; include a description of cooperative programs developed by groups of local governments within the jurisdiction of the eligible entity to address cybersecurity risks and cybersecurity threats; and include a description of programs provided by the eligible entity to support local governments and owners and operators of critical infrastructure to address cybersecurity risks and cybersecurity threats. The Secretary may award grants under this section to a multi-entity group to support multi-entity efforts to address cybersecurity risks and cybersecurity threats to information systems within the jurisdictions of the eligible entities that comprise the multi-entity group. a Cybersecurity Plan that has been reviewed by the Secretary in accordance with subsection (i); and a cybersecurity planning committee established in accordance with subsection (g). A multi-entity group applying for a multi-entity grant under paragraph (1) shall submit to the Secretary an application at such time, in such manner, and containing such information as the Secretary may require. the division of responsibilities among the eligible entities that comprise the multi-entity group; the distribution of funding from the grant among the eligible entities that comprise the multi-entity group; and how the eligible entities that comprise the multi-entity group will work together to implement the Cybersecurity Plan of each of those eligible entities. assist with the development, implementation, and revision of the Cybersecurity Plan of the eligible entity; approve the Cybersecurity Plan of the eligible entity; and assist with the determination of effective funding priorities for a grant under this section in accordance with subsections (d) and (j). the eligible entity; if the eligible entity is a State, counties, cities, and towns within the jurisdiction of the eligible entity; and institutions of public education and health within the jurisdiction of the eligible entity; and include, as appropriate, representatives of rural, suburban, and high-population jurisdictions. Not less than one-half of the representatives of a committee established under paragraph (1) shall have professional experience relating to cybersecurity or information technology. meets the requirements of this subsection; or may be expanded or leveraged to meet the requirements of this subsection, including through the formation of a cybersecurity planning subcommittee. Nothing in this subsection shall be construed to permit a cybersecurity planning committee of an eligible entity that meets the requirements of this subsection to make decisions relating to information systems owned or operated by, or on behalf of, the eligible entity. With respect to any requirement under subsection (e) or (g), the Secretary, in consultation with the Secretary of the Interior and Tribal governments, may prescribe an alternative substantively similar requirement for Tribal governments if the Secretary finds that the alternative requirement is necessary for the effective delivery and administration of grants to Tribal governments under this section. review the Cybersecurity Plan of the eligible entity, including any revised Cybersecurity Plans of the eligible entity; and determine that the Cybersecurity Plan reviewed under clause (i) satisfies the requirements under paragraph (2). In the case of a determination under subparagraph (A)(ii) that a Cybersecurity Plan satisfies the requirements under paragraph (2), the determination shall be effective for the 2-year period beginning on the date of the determination. determine whether the Cybersecurity Plan and any revisions continue to meet the criteria described in paragraph (2); and renew the determination if the Secretary, acting through the Director, makes a positive determination under clause (i). satisfies the requirements of subsection (e)(2); and the cybersecurity planning committee of the eligible entity established under subsection (g); and the Chief Information Officer, the Chief Information Security Officer, or an equivalent official of the eligible entity. integral to the development of the Cybersecurity Plan of the eligible entity; or necessary to assist with activities described in subsection (d)(4), as confirmed by the Director; and the eligible entity will submit to the Secretary a Cybersecurity Plan for review under this subsection by September 30, 2023 . regulate the manner by which an eligible entity or local government improves the cybersecurity of the information systems owned or operated by, or on behalf of, the eligible entity or local government; or participation in a particular Federal program; or the use of a specific product or technology. to supplant State or local funds; for any recipient cost-sharing contribution; to pay a ransom; for recreational or social purposes; or for any purpose that does not address cybersecurity risks or cybersecurity threats on information systems owned or operated by, or on behalf of, the eligible entity that receives the grant or a local government within the jurisdiction of the eligible entity. In addition to any other remedy available, the Secretary may take such actions as are necessary to ensure that a recipient of a grant under this section uses the grant for the purposes for which the grant is awarded. Nothing in paragraph (1)(A) shall be construed to prohibit the use of funds from a grant under this section awarded to a State, local, or Tribal government for otherwise permissible uses under this section on the basis that the State, local, or Tribal government has previously used State, local, or Tribal funds to support the same or similar uses. In considering applications for grants under this section, the Secretary shall provide applicants with a reasonable opportunity to correct any defects in those applications before making final awards, including by allowing applicants to revise a submitted Cybersecurity Plan. 0.25 percent of such amounts to each of American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, and the United States Virgin Islands; 1 percent of such amounts to each of the remaining States; and 3 percent of such amounts to Tribal governments. 50 percent of such remainder in the ratio that the population of each State, bears to the population of all States; and 50 percent of such remainder in the ratio that the population of each State that resides in rural areas, bears to the population of all States that resides in rural areas. In determining how to apportion amounts to Tribal governments under paragraph (1)(C), the Secretary shall consult with the Secretary of the Interior and Tribal governments. An amount received from a multi-entity grant awarded under subsection (f)(1) by a State or Tribal government that is a member of the multi-entity group shall qualify as an apportionment for the purpose of this subsection. for fiscal year 2022, 90 percent; for fiscal year 2023, 80 percent; for fiscal year 2024, 70 percent; and for fiscal year 2025, 60 percent; and for fiscal year 2022, 100 percent; for fiscal year 2023, 90 percent; for fiscal year 2024, 80 percent; and for fiscal year 2025, 70 percent. The Secretary may waive or modify the requirements of paragraph (1) if an eligible entity or multi-entity group demonstrates economic hardship. The Secretary shall establish and publish guidelines for determining what constitutes economic hardship for the purposes of this subsection. changes in rates of unemployment in the jurisdiction from previous years; changes in the percentage of individuals who are eligible to receive benefits under the supplemental nutrition assistance program established under the Food and Nutrition Act of 2008 ( 7 U.S.C. 2011 et seq.) from previous years; and any other factors the Secretary considers appropriate. Notwithstanding paragraph (2), the Secretary, in consultation with the Secretary of the Interior and Tribal governments, may waive or modify the requirements of paragraph (1) for 1 or more Tribal governments if the Secretary determines that the waiver is in the public interest. for the purpose for which the grant is awarded; and in compliance with subsections (d) and (j). not less than 80 percent of funds available under the grant; with the consent of the local governments, items, services, capabilities, or activities having a value of not less than 80 percent of the amount of the grant; or with the consent of the local governments, grant funds combined with other items, services, capabilities, or activities having the total value of not less than 80 percent of the amount of the grant. 25 percent of the amount of the grant awarded to the eligible entity; items, services, capabilities, or activities having a value of not less than 25 percent of the amount of the grant awarded to the eligible entity; or grant funds combined with other items, services, capabilities, or activities having the total value of not less than 25 percent of the grant awarded to the eligible entity. any grant awarded under this section that solely supports activities that are integral to the development or revision of the Cybersecurity Plan of the eligible entity; or the District of Columbia, the Commonwealth of Puerto Rico, American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, the United States Virgin Islands, or a Tribal government. An eligible entity or multi-entity group shall certify to the Secretary that the eligible entity or multi-entity group has made the distribution to local governments required under paragraph (2). An eligible entity or multi-entity group may request in writing that the Secretary extend the period of time specified in paragraph (2) for an additional period of time. The Secretary may approve a request for an extension under subparagraph (A) if the Secretary determines the extension is necessary to ensure that the obligation and expenditure of grant funds align with the purpose of the State and Local Cybersecurity Grant Program. If an eligible entity does not make a distribution to a local government required under paragraph (2) in a timely fashion, the local government may petition the Secretary to request the Secretary to provide funds directly to the local government. A grant awarded under this section may not be used to acquire land or to construct, remodel, or perform alterations of buildings or other physical facilities. An eligible entity applying for a grant under this section shall agree to consult the Chief Information Officer, the Chief Information Security Officer, or an equivalent official of the eligible entity in allocating funds from a grant awarded under this section. terminate or reduce the amount of a grant awarded under this section to the eligible entity; or in the case of an eligible entity that is a State, directly to the appropriate local government as a replacement grant in an amount determined by the Secretary; or in the case of an eligible entity that is a Tribal government, to another Tribal government or Tribal governments as a replacement grant in an amount determined by the Secretary. guidance for applicants for grants under this section, including guidance for Cybersecurity Plans; the study of risk-based formulas required under subsection (q)(4); the development of guidelines required under subsection (m)(2)(B); and any modifications described in subsection (q)(2)(D). Not later than 3 business days before the date on which the Department announces the award of a grant to an eligible entity under this section, including an announcement to the eligible entity, the Secretary shall provide to the appropriate congressional committees notice of the announcement. implementing the Cybersecurity Plan of the eligible entity; and reducing cybersecurity risks to, and identifying, responding to, and recovering from cybersecurity threats to, information systems owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity. develop or revise a Cybersecurity Plan; or assist with the activities described in subsection (d)(4). the use of grants awarded under this section; the proportion of grants used to support cybersecurity in rural areas; the effectiveness of the State and Local Cybersecurity Grant Program; any necessary modifications to the State and Local Cybersecurity Grant Program; and developing, implementing, or revising Cybersecurity Plans; and reducing cybersecurity risks to, and identifying, responding to, and recovering from cybersecurity threats to, information systems owned or operated by, or on behalf of, State, local, or Tribal governments as a result of the award of grants under this section. The Secretary, acting through the Director, shall make each report submitted under paragraph (2) publicly available, including by making each report available on the website of the Agency. In making each report publicly available under subparagraph (A), the Director may make redactions that the Director, in consultation with each eligible entity, determines necessary to protect classified or other information exempt from disclosure under section 552 of title 5 (commonly referred to as the “Freedom of Information Act”). potential components that could be included in a risk-based formula, including the potential impact of those components on support for rural areas under this section; potential sources of data and information necessary for the implementation of a risk-based formula; any obstacles to implementing a risk-based formula, including obstacles that require a legislative solution; if a risk-based formula were to be implemented for fiscal year 2026, a recommended risk-based formula for the State and Local Cybersecurity Grant Program; and any other information that the Secretary, acting through the Director, determines necessary to help Congress understand the progress towards, and obstacles to, implementing a risk-based formula. The requirements of chapter 35 of title 44 (commonly referred to as the “Paperwork Reduction Act”), shall not apply to any action taken to carry out this paragraph. describes the cybersecurity needs of Tribal governments, which shall be determined in consultation with the Secretary of the Interior and Tribal governments; and includes any recommendations for addressing the cybersecurity needs of Tribal governments, including any necessary modifications to the State and Local Cybersecurity Grant Program to better serve Tribal governments. the grant selection process of the Secretary; and a sample of grants awarded under this section. for fiscal year 2022, $200,000,000; for fiscal year 2023, $400,000,000; for fiscal year 2024, $300,000,000; and for fiscal year 2025, $100,000,000. During a fiscal year, the Secretary or the head of any component of the Department that administers the State and Local Cybersecurity Grant Program may transfer not more than 5 percent of the amounts appropriated pursuant to paragraph (1) or other amounts appropriated to carry out the State and Local Cybersecurity Grant Program for that fiscal year to an account of the Department for salaries, expenses, and other administrative costs incurred for the management, administration, or evaluation of this section. Any funds transferred under subparagraph (A) shall be in addition to any funds appropriated to the Department or the components described in subparagraph (A) for salaries, expenses, and other administrative costs. Subject to paragraph (2), the requirements of this section shall terminate on September 30, 2026 . The reporting requirements under subsection (q) shall terminate on the date that is 1 year after the date on which the final funds from a grant under this section are expended or returned.

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.