FEMA's June 16, 2026, Information Bulletin No. 565 has opened a door many procurement teams have been waiting for. You can now use State and Local Cybersecurity Grant Program (SLCGP) and Tribal Cybersecurity Grant Program (TCGP) funds to purchase individual CIS Services, as long as you comply with federal procurement standards under 2 C.F.R. §§ 200.317-200.327.
The immediate change? Eligible services now include network monitoring and management, managed detection and response, vulnerability scanning, penetration testing, malicious code analysis, and hardened system images. If you've been self-funding these capabilities while sitting on grant allocations, your strategy just shifted.
What Changed
FEMA removed two significant barriers. First, individual CIS Services are now confirmed as allowable grant expenditures. Second, the Nationwide Cybersecurity Review (NCSR) requirement for SLCGP, TCGP, HSGP, and THSGP recipients has been dropped. While the NCSR is no longer required, FEMA may introduce a replacement assessment later.
However, membership fees for bundled services remain ineligible. FEMA cited its "inability to determine if these costs are reasonable and allocable to these grants programs." This creates a procurement challenge for organizations relying on bundled membership models but clarifies the path for itemized service purchases.
Key Findings
Individual services are eligible; bundled memberships are not. You can use grant funds for specific technical services but not for membership fees that bundle multiple services. This distinction requires you to itemize your security spending to meet federal cost-allocation rules.
Federal procurement standards apply to every purchase. The 2 C.F.R. §§ 200.317-200.327 requirements remain unchanged. You still need competitive procurement processes, documented price reasonableness, and clear allocation justifications. The bulletin confirms that CIS Services can meet these standards when purchased individually.
The NCSR requirement is gone, but assessments are still necessary. Dropping the NCSR removes one compliance checkpoint, but you still need to assess your security program maturity. Your organization needs a baseline understanding of current capabilities to justify grant-funded improvements. FEMA may introduce a replacement framework, so maintain assessment documentation regardless.
Different grant programs have different rules. The membership-fee restriction applies specifically to SLCGP and TCGP. If you're funded through HSGP or THSGP, confirm with your grant administrator before assuming the same limitations apply. This is program-specific guidance, not a universal FEMA policy.
What This Means for Your Team
Your procurement office now has a compliance-approved pathway to fund managed security services that previously lived in your operational budget. This is significant if you've been deferring MDR deployments or vulnerability management programs due to budget constraints.
Your procurement and security teams need to align on service itemization. You can't submit a bundled membership invoice and expect grant approval. Instead, vendors must break out individual service costs to satisfy federal cost-allocation requirements. This requires more documentation upfront but creates clearer audit trails later.
The NCSR removal simplifies one compliance requirement but doesn't eliminate your need for baseline assessments. If you're building a grant application, you still need to demonstrate your current security posture and justify how funded services address specific gaps. Consider using NIST Cybersecurity Framework categories or NIST SP 800-53 control families to structure your justification, even if FEMA doesn't mandate a specific assessment tool.
Action Items by Priority
Immediate: Confirm your funding program and restrictions. Don't assume SLCGP rules apply to HSGP funding or vice versa. Contact your grant administrator to verify which program funds your organization and what specific restrictions apply. This prevents wasted effort on proposals that don't fit your actual funding constraints.
Week one: Inventory current security service contracts. List every managed service, scanning tool, or technical capability you're currently purchasing. Identify which services align with grant-eligible categories (MDR, vulnerability scanning, penetration testing, malicious code analysis). Calculate the annual cost of each service separately; bundled pricing won't work for grant applications.
Week two: Engage procurement on federal standards compliance. Schedule a working session with your procurement office to review 2 C.F.R. §§ 200.317-200.327 requirements. Specifically address competitive procurement thresholds, price reasonableness documentation, and cost allocation methods. Your procurement team needs to understand what "itemized and transparent pricing" means in practice before you approach vendors.
Week three: Request itemized pricing from current vendors. Contact vendors providing bundled services and request separate pricing for individual capabilities. Explain that you need line-item costs that satisfy federal grant cost-allocation rules. If vendors can't or won't provide itemized pricing, you may need to source individual services from different providers.
Month one: Document your security baseline. Even without the NCSR requirement, you need a defensible assessment of current security program maturity. Map your existing controls to NIST CSF 2.0 or ISO/IEC 27001:2022 to establish a baseline. Document specific gaps that grant-funded services will address. This documentation supports your grant application and provides evidence of reasonable cost allocation.
Ongoing: Monitor for NCSR replacement guidance. FEMA may introduce a new assessment requirement. Track Information Bulletins and grant program updates to catch any new baseline assessment mandates early. If you maintain current documentation, adapting to a new framework becomes an update exercise rather than a ground-up effort.
For bundled membership questions: Contact [email protected] If your organization currently relies on MS-ISAC membership, reach out directly to discuss which services your funding can cover and how the membership-fee restriction affects your specific situation.
The path to grant-funded security services is clearer than it was last month. The work now is in documentation, itemization, and procurement alignment. Start with your funding program confirmation and build from there.



