Cybersecurity Grants for Churches: Funding to Protect Your Data
Key Takeaways
- No single federal program funds cybersecurity alone — it's a line item inside broader security grants like NSGP and several state programs.
- NSGP now treats cybersecurity as an eligible expense category, covering firewalls, endpoint protection, MFA rollout, secure backups, and staff training.
- New York's SCAHC program names cybersecurity explicitly as an eligible use, and other state security grants are following the same pattern.
- CISA's free Houses of Worship Security Self-Assessment covers cyber risk and can double as documentation for a grant application.
- TechSoup offers discounted, not grant-funded, cybersecurity software for eligible churches that need protection faster than a competitive grant cycle allows.
In This Article
- The Reality: There's No Standalone Cybersecurity Grant
- Why This Matters for Churches Specifically
- What NSGP Funds Under Cybersecurity
- State Security Grants and Cybersecurity
- Free Resources That Aren't Grants
- Writing a Cybersecurity Investment Justification
- What's Still Not Covered
- Getting Started: A Practical Sequence
- Frequently Asked Questions
There is no dedicated federal or state grant that exists purely to fund church cybersecurity. Instead, cybersecurity has become an eligible expense category inside the same security grant programs churches already use for cameras and access control — most notably the federal Nonprofit Security Grant Program (NSGP) and a growing number of state programs. If your church has a security grant strategy already, cybersecurity should be a line item inside it, not a separate hunt for a nonexistent program.
This guide covers what's actually fundable, what free resources exist outside the grant system entirely, and how to write a cybersecurity request that a reviewer will take seriously.
Building a Full Security Grant Strategy?
Answer a few questions about your congregation and we'll map which federal and state security programs — cybersecurity included — are worth applying to.
Check Your Grant Eligibility →The Reality: There's No Standalone Cybersecurity Grant
Churches searching for "cybersecurity grants" often expect to find a program parallel to NSGP but dedicated entirely to digital security. That program doesn't exist at the federal level. What exists instead is a shift inside existing physical security grants: FEMA and a number of state security grant administrators now recognize that a data breach or ransomware attack can be as disruptive to a congregation as a break-in, and have opened up eligible-expense categories accordingly.
Practically, this means your cybersecurity funding request rides inside the same application, the same Investment Justification, and the same review process as your camera and access-control request — not a separate submission.
Why This Matters for Churches Specifically
Congregations tend to hold more sensitive data than their size suggests: donor financial information, background-check results on staff and volunteers who work with children, counseling and pastoral care records, and membership rolls that can include immigration status or other sensitive personal details for vulnerable members. Many churches run this on volunteer-administered systems with no dedicated IT staff, minimal patching discipline, and no formal incident response plan — a combination that makes a phishing email or an unpatched server a real operational risk, not a theoretical one.
Faith-affiliated organizations are also frequently targeted specifically because of their visibility and their donor base, which is the same underlying risk factor — elevated risk due to ideology, beliefs, or mission — that already qualifies churches for NSGP and state security grants in the first place. That overlap is exactly why cybersecurity sits inside the same funding programs rather than a separate one.
What NSGP Funds Under Cybersecurity
FEMA added cybersecurity as an eligible NSGP expense category in recent program years. Based on our own breakdown in the NSGP eligible expenses guide, the categories that qualify include:
| Expense | Eligible Under NSGP? | Notes |
|---|---|---|
| Network firewall hardware/software | ✅ Yes | Must protect organizational systems specifically |
| Endpoint protection / antivirus for org devices | ✅ Yes | Church-owned devices, not personal staff devices |
| Email security and anti-phishing tools | ✅ Yes | Common entry point for church breaches |
| Cybersecurity vulnerability assessment | ✅ Yes | Strengthens your Investment Justification narrative |
| Multi-factor authentication rollout | ✅ Yes | Covers licensing and implementation labor |
| Secure backup systems for organizational data | ✅ Yes | Directly relevant to ransomware resilience |
| Staff cybersecurity awareness training | ✅ Yes | Addresses the human factor in phishing incidents |
| General office productivity software | ❌ No | Not a security expense regardless of vendor |
| New computers/laptops for general use | ❌ No | Hardware refresh isn't a cybersecurity expense on its own |
The distinction FEMA draws is consistent: a firewall protecting your donor database and camera network is eligible; a new printer or a general software upgrade is not, even if it happens to run more securely than the system it replaces. Frame every line item around the specific system or data it protects, not around general technology modernization.
State Security Grants and Cybersecurity
Cybersecurity eligibility isn't unique to the federal program. New York's Securing Communities Against Hate Crimes (SCAHC) program names "measures to strengthen cybersecurity" as an explicit eligible use alongside physical upgrades like lighting, locks, and fencing — see our New York SCAHC grant guide for the full program breakdown. California's CSNSGP and other state programs are moving in the same direction as digital threats against nonprofits and houses of worship increase.
If your church is weighing NSGP against a state program, or trying to decide which to apply to first, our state-by-state security grant guide covers which states run independent programs and how they compare to the federal baseline.
Free Resources That Aren't Grants
Not every improvement needs a grant cycle behind it. Two resources are worth using regardless of where your church is in the grant application process:
CISA's Houses of Worship Security Self-Assessment
The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the DHS Center for Faith-Based and Neighborhood Partnerships, publishes a free Houses of Worship Security Self-Assessment covering both physical and cyber risk. It's available as a web tool or a downloadable paper version, and it's designed explicitly to help organizations prioritize security measures and build the kind of documented vulnerability narrative that strengthens an NSGP or state grant Investment Justification. Running this assessment costs nothing and can happen well before any grant window opens.
TechSoup's Discounted Cybersecurity Software
TechSoup isn't a grant — it's a discount marketplace for eligible nonprofits — but it gets churches protection faster than any competitive grant cycle can. Eligible churches can access steeply discounted cybersecurity and IT security software through TechSoup's catalog, which is often the fastest way to close an urgent gap (an unpatched firewall, missing endpoint protection) while a grant application for a larger project is still pending. See our TechSoup for churches guide for the eligibility requirements and how the discount program works.
Not Sure Where to Start?
We'll help you sequence free resources, discounted software, and grant applications so your church closes urgent gaps now and funds bigger upgrades through the right grant cycle.
Start the Free Eligibility Review →Writing a Cybersecurity Investment Justification
Grant reviewers score cybersecurity requests the same way they score a camera system or a fence: on specificity. A vague line like "we need better cybersecurity" is weak. A specific gap tied to a specific fix is strong. Structure your justification around three things:
- The specific vulnerability. No multi-factor authentication on the donor database login. Volunteer-managed email accounts with no phishing filter. No tested backup of membership and financial records.
- The specific fix and its cost. A named MFA product with per-user licensing costs, or a named backup service with a vendor quote — not a placeholder budget line.
- Why it matters for your organization specifically. Reference any prior incident (a phishing attempt reported by staff, a vendor breach affecting your church's data), the sensitivity of the records you hold, and your current lack of dedicated IT staff to manage risk without automated protection.
What's Still Not Covered
Being realistic about the limits saves wasted application effort. NSGP and state security grants generally will not fund:
- General website development or redesign unrelated to security
- Routine software subscriptions with no security function (accounting software, streaming/livestreaming platforms, church management systems used for general administration)
- Hardware refreshes framed as "more secure" without a specific vulnerability driving the purchase
- Ongoing IT staff salaries — grants fund one-time capital and assessment costs, not recurring payroll, in the same way physical security grants don't fund an ongoing guard salary beyond the personnel cap
If your actual need is a broader technology upgrade rather than a security-specific fix, look at TechSoup's discount catalog or Google's nonprofit programs instead of trying to fit a general IT need into a security grant application.
Getting Started: A Practical Sequence
- Run CISA's free self-assessment to document your specific gaps — this costs nothing and builds the evidence base for everything after it.
- Close the cheapest, most urgent gaps immediately through TechSoup's discounted software rather than waiting on a grant cycle for basics like antivirus or a password manager.
- Fold larger cybersecurity line items into your next NSGP or state security grant application — firewalls, MFA rollout, secure backup systems, and staff training belong in the same Investment Justification as your physical security requests.
- Document everything. Keep records of any phishing attempts, vendor breaches affecting your data, or near-misses — this is the same kind of specific evidence that strengthens a physical security application.