How to Write a Security Risk Assessment for Your Church Grant Application (2026)

⚡ TL;DR — Key Takeaways

A Security Vulnerability Assessment (SVA) is the #1 document that determines whether your NSGP application gets funded. It documents your specific threats, existing gaps, and serves as the factual foundation for your Investment Justification. This guide gives you a complete framework, a fill-in template, and a checklist to complete your SVA — whether you hire a consultant or do it yourself.

The number one reason NSGP applications get denied is not a missing form or an ineligible expense — it is a weak or generic threat narrative. Grant reviewers score applications on the specificity and credibility of the documented threat. Organizations that walk in with a real security vulnerability assessment — documenting their specific threat environment, their existing gaps, and the precise upgrades needed — consistently outperform those that rely on national statistics.

This guide gives you a complete, practical framework for conducting or commissioning a church security vulnerability assessment that will strengthen your 2026 grant application — whether for NSGP, a state program, or both.

⚠️ Disclaimer: FaithGrants is an independent grant assistance service and is not affiliated with FEMA, DHS, or any government agency. Always verify current assessment requirements with your SAA.

1. What Is a Security Vulnerability Assessment?

Definition: Security Vulnerability Assessment (SVA) A systematic evaluation of an organization's physical location, operations, and threat environment to identify security weaknesses and prioritize protective measures. For grant purposes, an SVA documents the specific risks facing an organization and provides the evidence base for requesting security funding. Also referred to as a Security Risk Assessment (SRA) or Threat and Vulnerability Assessment (TVA).

In the context of the NSGP and state security grant programs, an SVA serves two purposes: it is both a planning tool (it tells you what to fix) and an application document (it proves to reviewers that you know what to fix and why). A well-executed SVA transforms your application from an abstract request into a documented security plan with a clear threat rationale.

The federal NSGP does not mandate a specific SVA format — but it strongly recommends using the DHS Houses of Worship Security Guide, published by CISA (Cybersecurity and Infrastructure Security Agency), as a framework. This guide is free, comprehensive, and specifically designed for faith communities.

2. Why the SVA Makes or Breaks Your Grant Application

NSGP applications are scored competitively. Your SAA assigns scores based on defined criteria, and the organizations with the highest scores receive funding. The Investment Justification — which is built on your SVA — is the primary scored document.

Application ElementWhat Reviewers Look ForImpact of Weak SVA
Threat narrativeSpecific, documented, local threats — not just national statisticsGeneric national data without local specificity = low score
Vulnerability documentationNamed gaps: specific entry points, blind spots, coverage percentagesVague references to "inadequate security" = low score
Project justificationEach budget item tied to a specific named vulnerabilityItems without documented rationale = defunded or denied
FeasibilityEvidence the organization can execute the projectUnsupported claims = credibility questions

The SVA is the evidence layer under everything. Without it, your IJ is assertions. With it, your IJ is documented findings — which scores dramatically higher.

3. DIY vs. Professional Assessment: Which Should You Choose?

ApproachCostCredibilityBest For
Self-assessment (using CISA framework)$0Moderate — acceptable for most SAAsSmall congregations; organizations with security-savvy leadership
Law enforcement assessment (FBI, local PD)Usually freeHigh — law enforcement documentation carries significant weightOrganizations with existing relationships with local PD or FBI field office
Professional consultant (certified security assessor)$3,000–$10,000+Highest — professional credentials and formal report formatLarger organizations; competitive applications; organizations in high-demand states
💡 Pro Tip: A professional security assessment is itself an eligible NSGP expense — you can fund it through the grant. Many organizations use a prior-year award to fund a professional assessment, then use that assessment to strengthen a subsequent application. If you are applying for the first time, budget $3,000–$5,000 for a consultant assessment as a line item in your grant budget.

The FBI's Faith-Based Community Partnership program offers free security assessments for houses of worship through local field offices. This is an excellent, zero-cost option that produces law enforcement-credentialed documentation — one of the most powerful forms of threat evidence you can include in a grant application.

4. The 5 Core Components of a Church Security Vulnerability Assessment

A complete SVA for grant purposes covers five areas. Each feeds directly into a section of the Investment Justification.

  1. Organizational Threat Profile — Who you are and why that creates risk
  2. Geographic and Community Threat Environment — What threats exist in your location
  3. Physical Vulnerability Audit — Where your facility is exposed
  4. Current Security Measures — What you already have in place
  5. Prioritized Recommendations — What you need to add or improve

5. Component 1: Organizational Threat Profile

This section documents who your organization is and why that identity creates security risk. It answers the core NSGP eligibility question: does your organization face elevated risk due to its ideology, beliefs, or mission?

Include:

⚠️ Be Specific: "Our congregation is a faith-based organization" is not a threat profile. "Our mosque serves 600 members of the Muslim faith. Anti-Muslim hate crimes increased 47% nationally in 2025 (FBI UCR data). Our facility received two pieces of threatening correspondence in 2025, copies attached. Local law enforcement conducted a walkthrough in October 2025 and noted elevated concern" — that is a threat profile.

6. Component 2: Geographic and Community Threat Environment

This section documents the threat environment around your specific location — not just national trends. Sources to cite:

7. Component 3: Physical Vulnerability Audit

Walk your facility and document every security gap. Be systematic — use the checklist below and attach photos where possible. Photos of uncovered entry points, dark parking areas, and unmonitored zones are powerful application support documents.

✅ Physical Vulnerability Audit Checklist

  • Count and map all entry points (main doors, side doors, emergency exits, loading docks)
  • Note which entry points are monitored by camera — and which are not
  • Identify areas with inadequate lighting (parking lots, walkways, rear of building)
  • Note whether exterior doors have reinforced frames or are standard construction
  • Assess parking lot visibility and access control
  • Document camera coverage percentage for each exterior zone
  • Note interior blind spots not covered by current cameras
  • Assess whether access to children's areas, offices, and storage is controlled
  • Review intercom or visitor screening capabilities at main entrance
  • Assess whether staff can lockdown the facility quickly in an emergency
  • Note whether there is a designated safe room or hardened shelter area
  • Review whether emergency communication systems (PA, text alert) exist
  • Assess cyber exposure: unsecured networks, outdated systems, public WiFi

For each gap identified, write one sentence describing the risk it creates. Example: "The north parking lot (approximately 60 vehicles) has no camera coverage, creating an unmonitored zone during evening services attended by approximately 200 congregants."

8. Component 4: Current Security Measures

Document what you already have. This demonstrates to reviewers that your organization takes security seriously — and makes it clear exactly what gaps the grant would fill.

9. Component 5: Prioritized Recommendations

This section lists the specific security improvements needed, ranked by priority. Each recommendation must map to a specific vulnerability identified in Component 3. This is the section that becomes your grant budget.

PriorityRecommendationAddresses VulnerabilityEstimated Cost
1 (Critical)Install 8 cameras covering north parking lot and rear entranceNorth lot has zero coverage; rear entrance is unmonitored$12,000
2 (Critical)Install access control intercom on main entranceNo visitor screening at primary entry point$6,500
3 (High)Upgrade exterior lighting in north lot and east walkwayThree documented lighting gaps creating cover for approach$4,800
4 (High)Active shooter and run-hide-fight training for all staffNo current emergency response training on record$2,200
5 (Medium)Install vehicle bollards at main entranceNo vehicle barrier at primary pedestrian entrance$8,000

10. Fill-In SVA Template

Use this template as the structure for your assessment document. Replace all bracketed items with your organization's specific information.

SECURITY VULNERABILITY ASSESSMENT Organization: [Full legal name of organization] Address: [Street address, city, state, ZIP] Date of Assessment: [Month, Year] Assessed By: [Name, title, and credentials of assessor] --- SECTION 1: ORGANIZATIONAL THREAT PROFILE [Organization name] is a [faith tradition] congregation/organization serving approximately [number] members and [number] weekly visitors. We are a registered 501(c)(3) nonprofit (EIN: [number]). Our organization faces elevated risk due to [specific reasons — e.g., anti-[faith] incidents, hate group activity targeting our tradition, prior threats]. Documented incidents include: [list incidents with dates]. [Attach supporting documentation.] National context: [cite relevant statistics — e.g., FBI UCR data showing X% increase in hate crimes against your faith tradition in the most recent year]. --- SECTION 2: GEOGRAPHIC THREAT ENVIRONMENT Our facility is located in [city/county], [state]. Relevant local threat indicators include: - [Local crime/hate crime data with source] - [Recent regional incidents against similar organizations] - [Any law enforcement threat briefings or advisories] --- SECTION 3: PHYSICAL VULNERABILITY FINDINGS Site: [describe facility size, building type, lot size] Entry Points: [number] total — [X] monitored, [Y] unmonitored Camera Coverage: Approximately [X]% of exterior; [list uncovered areas] Lighting: Inadequate in [list specific areas] Access Control: [describe current state and gaps] Key Vulnerabilities Identified: 1. [Specific gap #1] 2. [Specific gap #2] 3. [Continue for all major findings] --- SECTION 4: CURRENT SECURITY MEASURES [List all existing cameras, alarms, personnel, procedures, training] --- SECTION 5: PRIORITIZED RECOMMENDATIONS [List recommendations ranked by priority, tied to each vulnerability above] --- PREPARER SIGNATURE: ___________________ Date: _______

11. How to Use Your SVA in the Grant Application

Once your SVA is complete, it becomes the source document for your entire application. Here is how each section maps to the NSGP Investment Justification:

SVA SectionIJ Section It Feeds
Organizational Threat ProfileIJ Part 1: Nature of the threat
Geographic Threat EnvironmentIJ Part 1: Local threat context
Physical Vulnerability FindingsIJ Part 2: Current vulnerabilities
Prioritized RecommendationsIJ Part 3: Proposed activities and budget
Vulnerability → Recommendation mappingIJ Part 4: How activities reduce risk

Attach the full SVA document to your grant application as a supporting document. In your IJ, reference specific SVA findings by section number. This creates a documented, cross-referenced record that reviewers can validate — and it scores significantly higher than an IJ that stands alone without evidentiary support.

Get Help With Your Security Assessment

Not sure where to start? Our team can help you structure a grant-ready security assessment and eligibility review for free.

Start Free Eligibility Review →

12. Frequently Asked Questions

Is a security risk assessment required for NSGP?
A formal SVA is not always mandatorily required as a separate document, but it forms the factual basis of the Investment Justification, which is required. Applications without documented threat assessments score significantly lower. Treating the SVA as optional is one of the most common strategic mistakes applicants make.
Do we need to hire a professional to do the assessment?
No — you can conduct a self-assessment using the CISA Houses of Worship Security Guide framework. However, a professional assessment from a certified security consultant carries more credibility with reviewers. The FBI also offers free assessments through its Faith-Based Community Partnership program at fbi.gov.
Can we use NSGP funds to pay for the security assessment?
Yes. Professional security vulnerability assessments are an explicitly eligible NSGP expense. Budget $3,000–$10,000 depending on facility size. For a first-time applicant, funding the assessment through the grant and using it to strengthen future applications is a valid strategy.
What if our church has never had an incident?
You can establish elevated risk without prior incidents. Document your faith identity, the national threat environment for your tradition, local hate crime data, and any concerning online activity. Organizations do not need to have been attacked to demonstrate they are at elevated risk of attack. See: Church Security Grants for Small Congregations.
How recent does the assessment need to be?
Most SAAs want an assessment conducted within the 12–24 months prior to the application. An assessment from several years ago may still be useful as background, but a current assessment reflecting present-day vulnerabilities is always stronger.

FaithGrants Editorial Team

Our editorial team researches grant programs and application best practices for faith-based organizations. We are not affiliated with FEMA, DHS, or any government agency. For official NSGP guidance, visit fema.gov and cisa.gov. Last updated: June 5, 2026.