Start With the Applicant and the Work, Not the Word Cybersecurity
Cybersecurity funding is not one market. A university team securing scientific computing, a researcher studying privacy, a college building a public-service talent pipeline, and a county replacing vulnerable systems may all search for a cybersecurity grant. They do not belong in the same application queue. A useful first step is to identify who will submit, what the funded work produces, and who benefits after the award. Use four routing questions. First, is the applicant an accredited U.S. institution of higher education, a research-linked U.S. nonprofit, a state administrative agency, a local government seeking a state subaward, or an individual student? Second, is the core work applied security for scientific cyberinfrastructure, fundamental security and privacy research, cybersecurity or AI education, scholarships tied to government service, or implementation of a government cybersecurity plan? Third, does the opportunity fund the organization or an individual? Fourth, is the date a hard deadline, a target date, a state pass-through window, or a closed prior cycle? Those answers separate the routes in this guide. NSF Cybersecurity Innovation for Cyberinfrastructure is for security and privacy work that benefits scientific cyberinfrastructure and its users. NSF Security, Privacy, and Trust in Cyberspace 2.0 supports research and education that advance security, privacy, and trust. NSF CyberAICorps Scholarship for Service funds eligible organizations to build education or scholarship programs, not students applying directly to NSF. The State and Local Cybersecurity Grant Program sends federal assistance through state and territorial administrative agencies, with local governments participating as subapplicants or beneficiaries under state processes. This route-first approach prevents three expensive mistakes: drafting for a program whose eligible prime does not match the organization, treating an expired date as current, and forcing an implementation purchase into a research solicitation. It also makes monitoring more useful. Instead of one broad cyber alert, a team can watch the official route that matches its work and use a broader search to catch state programs, amended dates, and new companion opportunities.
Use CICI for Security That Advances Scientific Cyberinfrastructure
Choose CICI when the project improves the security, privacy, resilience, usability, integrity, or reproducibility of cyberinfrastructure used for scientific discovery. The current CICI program page lists a January 20, 2027 full-proposal deadline at 5 p.m. in the submitting organization's local time. NSF estimates $8 million to $12 million in total program funding and 12 to 20 awards, subject to available funds. Those figures are the program pot and estimated award count, not the amount every applicant can request. The four program areas set different ceilings. Usable and Collaborative Security for Science and Reference Scientific Security Datasets each allow up to $600,000 for as long as three years. Transition to Cyberinfrastructure Resilience allows up to $1.2 million for as long as three years. Integrity, Provenance, and Authenticity for Artificial Intelligence Ready Data allows up to $900,000 for as long as three years. The distinction matters because a proposal should be routed by the work and beneficiary, not by the largest ceiling. A team hardening a scientific platform and transitioning a tested security capability may fit TCR. A team creating a rigorously collected, reusable security dataset from scientific workflows may fit RSSD. A team focused on trustworthy scientific datasets used by AI may fit IPAAI. The current CICI solicitation, NSF 25-531 permits accredited U.S. two-year and four-year institutions of higher education and U.S. nonprofit, nonacademic organizations directly associated with education or research. It does not list a commercial cybersecurity vendor as an eligible prime. A vendor may have a documented project role where the rules permit it, but collaboration does not convert the vendor into an eligible submitting organization. Voluntary committed cost sharing is prohibited. An individual may participate as principal investigator, co-principal investigator, or senior or key personnel on no more than two CICI proposals. Before choosing CICI, write a one-sentence beneficiary test: what scientific cyberinfrastructure, science workflow, data resource, or research community becomes more secure and usable because of the project? NSF states that CICI is not the route for non-cybersecurity infrastructure work and is not intended for fundamental cybersecurity or privacy research. That boundary is a practical handoff to SaTC. Review the current Funding Landscape CICI record, then confirm every date and requirement against NSF before submission.
π Search related opportunities now
Use SaTC 2.0 for Security, Privacy, and Trust Research or Education
Choose SaTC 2.0 when the central contribution is research or education in cybersecurity, privacy, or trust rather than deployment for scientific cyberinfrastructure. The SaTC 2.0 program page shows September 28, 2026 and January 25, 2027 target dates. NSF accepts proposals at any time, but explains that a proposal submitted after a target date may miss the associated review panel. A target date is therefore different from CICI's hard deadline. It offers scheduling flexibility, not assurance that a late proposal will be reviewed in the intended cycle. SaTC has three routes. Research proposals may request up to $1.2 million for as long as four years, with additional requirements above $600,000. Education proposals may request up to $500,000 for as long as three years, and the solicitation allows an additional $100,000 for a qualifying education-research component with the required collaboration. Seed proposals may request up to $300,000 for as long as two years, but they are available only through an accompanying Dear Colleague Letter. NSF estimates about 75 awards and $60 million per year, subject to funds and proposal quality. Again, $60 million is estimated annual program funding, not an individual award. The current SaTC solicitation, NSF 25-515 allows accredited U.S. two-year and four-year institutions of higher education and U.S. nonprofit, nonacademic research or education organizations such as independent museums, observatories, laboratories, and professional societies. For-profit organizations are not eligible submitting organizations under the listed categories. An individual may participate on no more than four SaTC proposals in a rolling 12-month period, with no more than two Research, one Education, and one Seed proposal. Route by the intended contribution. Use Research for new knowledge, methods, systems, or evidence in security, privacy, and trust. Use Education for a learning intervention whose design and evaluation meet the solicitation. Use Seed only when a current Dear Colleague Letter expressly opens the route and the project meets it. Do not assume that a workforce course belongs in Education or that a prototype belongs in Research without matching the program description. The data management and sharing plan also needs to address the privacy and security of project data, access protections, and access to software or hardware when relevant. Start from the current Funding Landscape SaTC record, then use NSF's live solicitation as the controlling source.
Use CyberAI SFS for Institutional Education and Scholarship Programs
CyberAI SFS is an institutional funding route with two tracks. It is not a direct NSF scholarship application for an individual student. The Scholarship Track funds eligible institutions to operate scholarship-for-service programs that combine cybersecurity and artificial intelligence preparation. The Innovation Track funds education projects that expand curricula, pathways, methods, experiential learning, professional development, or partnerships in AI, cybersecurity, or their intersection. The CyberAI SFS program page now shows an April 5, 2027 Innovation Track target date and a July 20, 2027 Scholarship Track deadline at 5 p.m. in the submitting organization's local time. The July 21, 2026 Scholarship Track deadline has passed. NSF says the Innovation Track accepts proposals around its annual target date, while a Scholarship Track proposal after its hard deadline is not accepted for that competition. The maximum award is $500,000 for Innovation and $2.5 million for Scholarship. NSF anticipates up to 25 projects per fiscal year, subject to funding and proposal quality. Eligibility differs by track. Under the current CyberAI SFS solicitation, NSF 26-503, the Scholarship Track is limited to accredited U.S. institutions of higher education, and community colleges may participate only as subawardees of a partnering four-year Scholarship for Service institution. The Innovation Track also permits eligible U.S. nonprofit, nonacademic education or research organizations. Scholarship recipients must be U.S. citizens or lawful permanent residents and must work after graduation in an AI or cybersecurity mission of a government organization for at least the length of the scholarship. Institutional teams should select the track before assembling the project. A college creating widely adoptable CyberAI curriculum may belong in Innovation. A four-year institution proposing a formal scholarship program, student support, placement, and service obligations may belong in Scholarship. The Scholarship Track limits each performing organization to one proposal for the same competition date and restricts active awardees from applying again until they are within 14 months of the current award's expected end. The Innovation Track has no organization-level proposal limit, while an individual may participate on no more than two Innovation proposals within a rolling 12 months. NSF's CyberAI SFS FAQ is a useful companion for interpretation, but the solicitation controls. Review the current Funding Landscape CyberAI SFS record and verify the selected track, date, and organizational limits before investing in a draft.
Treat SLCGP as a State Pass-Through Route, Not a Direct Local Application
A county, city, town, school district, special district, or other eligible local government does not submit the federal State and Local Cybersecurity Grant Program application directly to FEMA. The CISA SLCGP FAQ says local governments apply as subapplicants through their state or territory's State Administrative Agency and work with the Cybersecurity Planning Committee. The state decides which local projects receive funds or state-procured services and how they align with the approved Cybersecurity Plan. This structure changes the research job. A local government should identify its State Administrative Agency, current Cybersecurity Plan, planning committee process, local notice page, subaward calendar, and whether the state passes cash, shared services, centrally procured tools, or a mix. CISA says at least 80 percent of a state allocation generally must pass through to local governments and at least 25 percent of the total must pass through to rural communities, with stated exceptions. The pass-through may consist of items, services, capabilities, or activities when the benefiting local government consents. Those percentages describe allocation requirements. They do not promise an award to a specific local applicant. The latest completed federal competition should be used as historical operating context, not advertised as open. FEMA reported $91.75 million for FY 2025, compared with $279.9 million in FY 2024. The FY 2025 minimum nonfederal cost share was 40 percent, or 30 percent for a multi-entity group project, with specified territorial waivers. The FY 2025 period of performance was four years without extensions. The FY 2025 key-changes page also retained four program objectives: governance and Cybersecurity Plans, posture assessment, risk-based protections, and workforce training. The federal FY 2025 application deadline has passed, so those figures should not be projected onto an unannounced later cycle. A useful local readiness file is still possible before the next state window. Record the system owner, risk or threat, affected public service, current control, proposed improvement, project objective, Cybersecurity Plan alignment, rural or multi-entity status, procurement route, implementation capacity, maintenance cost, cost-share source if required, measurable outcome, and authorizing officials. Ask the state whether it expects a project worksheet, local consent for centrally provided services, a match commitment, or other evidence. Monitor both federal guidance and the state subaward page because the federal notice and the practical local window are separate events.
Build a Route-Specific Readiness File and Monitor the Exact Scope
A strong monitoring system follows routes, not just keywords. For CICI, watch NSF's annual deadline, program-area language, scientific cyberinfrastructure beneficiary, budget ceiling, personnel participation limit, and any revised solicitation. For SaTC, watch the September and January target cycles, applicable Dear Colleague Letters, proposal class, participation limits, and review timing. For CyberAI SFS, watch Innovation and Scholarship separately because they have different applicants, limits, award ceilings, and date semantics. For SLCGP, watch CISA and FEMA for federal guidance, then watch the State Administrative Agency for the local process. Create one compact evidence row for every candidate. Include the Funding Landscape opportunity ID, official source URL, eligible prime, eligible partner or subrecipient roles, project route, deadline type, exact date and time zone, total program funding, maximum individual award, project duration, cost share, application system, required institutional approvals, open questions, and last verified date. Never place total program funding in an award-ceiling field. Never treat a target date as a deadline. Never treat a student beneficiary as the federal applicant. Preserve the source language for any ambiguous condition and ask the program contact rather than inferring eligibility. Use the current Funding Landscape cybersecurity grant search as a broad discovery intake, not as a verified three-route list. On August 22, the public search also surfaced Maryland's Small Business Cybersecurity Resilience in Maryland program, but SCRIM is closed: the Maryland Commerce page says applications are no longer accepted. It surfaced the Department of War Cyber Service Academy student route, although the official DoW CSA page says the 2026 cycle is closed for new applicants. It also contained a duplicate Grants.gov representation of the direct NSF CyberAI record. Those rows make a raw count larger without creating distinct current routes. Funding Landscape therefore withholds the automatic live-results panel on this guide. The public Browse all and saved-alert contract does not preserve record-level exclusions, so a panel that displayed three curated cards would reopen the closed and duplicate rows in its continuation. Readers can still inspect the three source-linked current NSF records in the route sections above, use the broad search as an intake queue, and reject any row whose official status or identity fails review. Save a cybersecurity search only if that broader intake is useful and the team will re-check official sources. Export or MCP access can support the same review discipline, but neither turns an unfiltered result into a verified route. This is a deliberate honesty boundary, not an empty-state claim.