Cybersecurity Grants for Churches: Funding to Protect Your Data

Key Takeaways

  • No single federal program funds cybersecurity alone — it's a line item inside broader security grants like NSGP and several state programs.
  • NSGP now treats cybersecurity as an eligible expense category, covering firewalls, endpoint protection, MFA rollout, secure backups, and staff training.
  • New York's SCAHC program names cybersecurity explicitly as an eligible use, and other state security grants are following the same pattern.
  • CISA's free Houses of Worship Security Self-Assessment covers cyber risk and can double as documentation for a grant application.
  • TechSoup offers discounted, not grant-funded, cybersecurity software for eligible churches that need protection faster than a competitive grant cycle allows.

There is no dedicated federal or state grant that exists purely to fund church cybersecurity. Instead, cybersecurity has become an eligible expense category inside the same security grant programs churches already use for cameras and access control — most notably the federal Nonprofit Security Grant Program (NSGP) and a growing number of state programs. If your church has a security grant strategy already, cybersecurity should be a line item inside it, not a separate hunt for a nonexistent program.

This guide covers what's actually fundable, what free resources exist outside the grant system entirely, and how to write a cybersecurity request that a reviewer will take seriously.

Building a Full Security Grant Strategy?

Answer a few questions about your congregation and we'll map which federal and state security programs — cybersecurity included — are worth applying to.

Check Your Grant Eligibility →

The Reality: There's No Standalone Cybersecurity Grant

Churches searching for "cybersecurity grants" often expect to find a program parallel to NSGP but dedicated entirely to digital security. That program doesn't exist at the federal level. What exists instead is a shift inside existing physical security grants: FEMA and a number of state security grant administrators now recognize that a data breach or ransomware attack can be as disruptive to a congregation as a break-in, and have opened up eligible-expense categories accordingly.

Practically, this means your cybersecurity funding request rides inside the same application, the same Investment Justification, and the same review process as your camera and access-control request — not a separate submission.

Why This Matters for Churches Specifically

Congregations tend to hold more sensitive data than their size suggests: donor financial information, background-check results on staff and volunteers who work with children, counseling and pastoral care records, and membership rolls that can include immigration status or other sensitive personal details for vulnerable members. Many churches run this on volunteer-administered systems with no dedicated IT staff, minimal patching discipline, and no formal incident response plan — a combination that makes a phishing email or an unpatched server a real operational risk, not a theoretical one.

Faith-affiliated organizations are also frequently targeted specifically because of their visibility and their donor base, which is the same underlying risk factor — elevated risk due to ideology, beliefs, or mission — that already qualifies churches for NSGP and state security grants in the first place. That overlap is exactly why cybersecurity sits inside the same funding programs rather than a separate one.

What NSGP Funds Under Cybersecurity

FEMA added cybersecurity as an eligible NSGP expense category in recent program years. Based on our own breakdown in the NSGP eligible expenses guide, the categories that qualify include:

ExpenseEligible Under NSGP?Notes
Network firewall hardware/software✅ YesMust protect organizational systems specifically
Endpoint protection / antivirus for org devices✅ YesChurch-owned devices, not personal staff devices
Email security and anti-phishing tools✅ YesCommon entry point for church breaches
Cybersecurity vulnerability assessment✅ YesStrengthens your Investment Justification narrative
Multi-factor authentication rollout✅ YesCovers licensing and implementation labor
Secure backup systems for organizational data✅ YesDirectly relevant to ransomware resilience
Staff cybersecurity awareness training✅ YesAddresses the human factor in phishing incidents
General office productivity software❌ NoNot a security expense regardless of vendor
New computers/laptops for general use❌ NoHardware refresh isn't a cybersecurity expense on its own

The distinction FEMA draws is consistent: a firewall protecting your donor database and camera network is eligible; a new printer or a general software upgrade is not, even if it happens to run more securely than the system it replaces. Frame every line item around the specific system or data it protects, not around general technology modernization.

State Security Grants and Cybersecurity

Cybersecurity eligibility isn't unique to the federal program. New York's Securing Communities Against Hate Crimes (SCAHC) program names "measures to strengthen cybersecurity" as an explicit eligible use alongside physical upgrades like lighting, locks, and fencing — see our New York SCAHC grant guide for the full program breakdown. California's CSNSGP and other state programs are moving in the same direction as digital threats against nonprofits and houses of worship increase.

If your church is weighing NSGP against a state program, or trying to decide which to apply to first, our state-by-state security grant guide covers which states run independent programs and how they compare to the federal baseline.

Free Resources That Aren't Grants

Not every improvement needs a grant cycle behind it. Two resources are worth using regardless of where your church is in the grant application process:

CISA's Houses of Worship Security Self-Assessment

The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the DHS Center for Faith-Based and Neighborhood Partnerships, publishes a free Houses of Worship Security Self-Assessment covering both physical and cyber risk. It's available as a web tool or a downloadable paper version, and it's designed explicitly to help organizations prioritize security measures and build the kind of documented vulnerability narrative that strengthens an NSGP or state grant Investment Justification. Running this assessment costs nothing and can happen well before any grant window opens.

TechSoup's Discounted Cybersecurity Software

TechSoup isn't a grant — it's a discount marketplace for eligible nonprofits — but it gets churches protection faster than any competitive grant cycle can. Eligible churches can access steeply discounted cybersecurity and IT security software through TechSoup's catalog, which is often the fastest way to close an urgent gap (an unpatched firewall, missing endpoint protection) while a grant application for a larger project is still pending. See our TechSoup for churches guide for the eligibility requirements and how the discount program works.

Not Sure Where to Start?

We'll help you sequence free resources, discounted software, and grant applications so your church closes urgent gaps now and funds bigger upgrades through the right grant cycle.

Start the Free Eligibility Review →

Writing a Cybersecurity Investment Justification

Grant reviewers score cybersecurity requests the same way they score a camera system or a fence: on specificity. A vague line like "we need better cybersecurity" is weak. A specific gap tied to a specific fix is strong. Structure your justification around three things:

  1. The specific vulnerability. No multi-factor authentication on the donor database login. Volunteer-managed email accounts with no phishing filter. No tested backup of membership and financial records.
  2. The specific fix and its cost. A named MFA product with per-user licensing costs, or a named backup service with a vendor quote — not a placeholder budget line.
  3. Why it matters for your organization specifically. Reference any prior incident (a phishing attempt reported by staff, a vendor breach affecting your church's data), the sensitivity of the records you hold, and your current lack of dedicated IT staff to manage risk without automated protection.
⚠️ Common mistake: Copying generic national cybersecurity statistics into an Investment Justification without connecting them to your organization's specific systems. Reviewers score the same way on cyber requests as on physical security requests — local, documented, specific beats generic every time.

What's Still Not Covered

Being realistic about the limits saves wasted application effort. NSGP and state security grants generally will not fund:

If your actual need is a broader technology upgrade rather than a security-specific fix, look at TechSoup's discount catalog or Google's nonprofit programs instead of trying to fit a general IT need into a security grant application.

Getting Started: A Practical Sequence

  1. Run CISA's free self-assessment to document your specific gaps — this costs nothing and builds the evidence base for everything after it.
  2. Close the cheapest, most urgent gaps immediately through TechSoup's discounted software rather than waiting on a grant cycle for basics like antivirus or a password manager.
  3. Fold larger cybersecurity line items into your next NSGP or state security grant application — firewalls, MFA rollout, secure backup systems, and staff training belong in the same Investment Justification as your physical security requests.
  4. Document everything. Keep records of any phishing attempts, vendor breaches affecting your data, or near-misses — this is the same kind of specific evidence that strengthens a physical security application.

Frequently Asked Questions

Is there a grant specifically for church cybersecurity?
No standalone federal grant funds only cybersecurity for churches. It's funded as an eligible expense category inside broader physical security grants — NSGP and several state programs, including New York's SCAHC, explicitly allow cybersecurity spending.
What cybersecurity expenses does NSGP actually cover?
Network firewalls, endpoint protection and antivirus software, email security and anti-phishing tools, cybersecurity vulnerability assessments, multi-factor authentication rollout, secure backup systems, and staff cybersecurity awareness training — all tied to protecting organizational systems specifically, not general IT purchases.
Does CISA offer free cybersecurity help for churches?
Yes. CISA's free Houses of Worship Security Self-Assessment, developed with the DHS Center for Faith-Based and Neighborhood Partnerships, covers physical and cyber risk. It requires no grant application, and its output can support an NSGP or state grant Investment Justification.
Can TechSoup help with church cybersecurity instead of a grant?
TechSoup isn't a grant, but eligible churches can access discounted cybersecurity and IT security software through its nonprofit marketplace — often faster than waiting on a competitive grant cycle for urgent protection needs.
Will a cybersecurity grant application be judged the same way as a physical security one?
Yes. Reviewers expect your Investment Justification to tie each cybersecurity item to a documented, specific vulnerability — no MFA on donor logins, unpatched software, no backup system — the same standard applied to physical security requests like unlit entrances or missing cameras.
⚠️ Disclaimer: FaithGrants is an independent grant assistance service and is not affiliated with FEMA, CISA, DHS, or any government agency. Program eligibility, expense categories, and award amounts change frequently — always verify current requirements directly with the administering agency before applying. Funding is not guaranteed.
Website by Rank Easy Digital — websites, SEO & AI search visibility for your business. Get a free consult →