Secure $200K for Your House of Worship: The Pastor’s Guide to the FY 2026 NSGP Grant
Summary
- The FY 2026 Nonprofit Security Grant Program (NSGP) offers up to $200,000 per location for houses of worship to fund security upgrades.
- A successful application requires an integrated approach, combining physical security hardware with a secure network and cybersecurity controls.
- The entire grant proposal must be based on a formal Threat, Vulnerability, and Risk Assessment (TVRA) that identifies specific weaknesses.
- The NSGP is a reimbursement grant, meaning organizations must plan to cover project costs upfront before receiving funds from FEMA.
As a pastor, the safety of your congregation and the sanctity of your mission are your highest priorities. In an increasingly complex world, ensuring your facility is a true sanctuary requires a plan. The FY 2026 Nonprofit Security Grant Program (NSGP) offers up to $200,000 per location to fund these critical security enhancements, but winning this competitive grant demands a strategic, integrated blueprint.
This guide demystifies the process for ministry leaders. We’ll walk you through the essential steps, from confirming your eligibility to building an application that integrates best-in-class technology, positioning your house of worship for maximum funding success.
Key Takeaways
- Significant Funding Available: The NSGP provides up to $200,000 per location for 501(c)(3) nonprofits, including houses of worship, to implement physical security and target hardening measures.
- Integration is Non-Negotiable: A winning application must demonstrate how physical security (like cameras) is protected by a secure network backbone and robust cybersecurity controls. Standalone projects are less competitive.
- Risk Assessment is the Foundation: Your entire project proposal must be based on a formal Threat, Vulnerability, and Risk Assessment (TVRA) that identifies specific weaknesses your project will solve.
- It’s a Reimbursement Grant: You must have the funds to pay for the project upfront before seeking reimbursement from FEMA, a critical financial planning consideration.
Table of Contents
- Why the NSGP is Your Essential Security Partner
- Are You Eligible? A Pre-Application Checklist
- The Cornerstone of Your Application: The Risk Assessment
- Actionable Project Ideas for Advanced Physical Security
- The Foundational Layer: Network, Cabling, and Infrastructure
- Securing Your People and Digital Assets
- How to Prepare Your NSGP Application: A Step-by-Step Guide
- Glossary of Terms
- Frequently Asked Questions
Why the NSGP is Your Essential Security Partner
Administered by FEMA and the Department of Homeland Security (DHS), the NSGP is the vital funding mechanism for protecting your community through target hardening and physical security enhancements. Given the persistent threats facing nonprofits and houses of worship, this program is fiercely competitive.
For the FY 2026 cycle, successful applications must prove they are building an integrated defense. Modern security breaches don’t just happen at the front door; they often exploit the computer network that controls your cameras and access systems. Your project must secure this underlying technology to maintain the confidentiality, integrity, and availability of your security systems, adhering to frameworks like NIST.
Crucial Financial Constraint: The NSGP is a reimbursement grant. This means you must pay your contractors and purchase the equipment before seeking payment from FEMA. This requires rigorous, audit-ready documentation and sufficient cash reserves or financing to cover upfront costs.
Are You Eligible? A Pre-Application Checklist
Before you invest time in writing, confirm you meet these foundational criteria.
- Confirm Your 501(c)(3) Status: Your organization must be a registered 501(c)(3) entity and tax-exempt under 501(a). Houses of worship are explicitly eligible.
- Identify Your Grant Stream (UA vs. S): Your physical location determines whether you apply under the Urban Area (NSGP-UA) or State (NSGP-S) stream. Do not guess. You must contact your State Administrative Agency (SAA) to confirm your designation. Applying to the wrong stream can lead to disqualification.
- Leverage the First-Timer Advantage: If your organization has never received NSGP funding before, you automatically receive 15 bonus points. This is a massive competitive advantage. Maximize it by submitting a professionally scoped, airtight project plan.
The Cornerstone of Your Application: The Risk Assessment
Your project proposal, known as the Investment Justification (IJ), is a treatment plan. It must be based on a formal diagnosis: the mandatory Threat, Vulnerability, and Risk Assessment (TVRA).
Grant reviewers look for a clear, logical link:
- Threat/Risk: An external factor (e.g., documented extremist activity in your region).
- Vulnerability: An internal weakness (e.g., an unlocked side door, an unmonitored parking lot, or an outdated camera system).
Your proposed project must mitigate a specific vulnerability identified in your TVRA. If your TVRA identifies “Vulnerability A,” your IJ must propose “Project B” that explicitly solves it.
For a great starting point, use the CISA Houses of Worship Security Self-Assessment. This tool helps you identify weaknesses and can inform your formal grant application.
Actionable Project Ideas for Advanced Physical Security
The NSGP funds “target hardening.” Today, that means integrated, network-enabled solutions that work together. Frame your project around the four principles of layered defense: Deter, Detect, Deny, and Delay.
- Electronic Access Control (Deny & Deter): Poorly managed access is a critical vulnerability. Implementing a system like Verkada Access Control at primary and secondary entries allows you to manage access via badges or mobile credentials. Justify this by explaining how it removes the risk of human error by automating door schedules and creating a verifiable log of every entry.
- AI-Powered Surveillance (Detect & Delay): Modern grants demand more than just cameras. Propose AI-powered systems like Verkada that use computer vision for rapid threat detection and instant alerts, minimizing false alarms. Your narrative should emphasize how this technology reduces the time between an incident and your response, giving first responders critical situational awareness.
The Foundational Layer: Network, Cabling, and Infrastructure
Your advanced security hardware is useless without a secure, reliable network foundation. NSGP funds can cover these essential infrastructure costs.
- Standards-Compliant Cabling: Modern security cameras and access control readers run on Power over Ethernet (PoE), which combines power and data into a single cable for simplicity and reliability. Your grant scope must specify standards-compliant wiring, like CAT6 cabling in protective conduit, to ensure durability and guarantee the cost is allowable.
- Resilient Network Backbone: Your security systems require a secure network to ensure they are always available. Justify network modernization with solutions from a partner like HPE Aruba Networking. Explain that a scalable network is critical to maintaining the confidentiality, integrity, and availability of your sensitive video and access data.
Securing Your People and Digital Assets
While the NSGP focuses on physical security, it recognizes that human error and cyber threats can undermine your investment. You can use up to 5% of your total award for Management and Administration (M&A) to fund critical training and software.
- Security Awareness Training (KnowBe4): Your staff and volunteers are your first line of defense. Propose security awareness training from a provider like KnowBe4 to mitigate risks like phishing and social engineering. Justify this by explaining how the training prevents an attacker from gaining digital access to your NSGP-funded camera system via a stolen password.
- Identity Management (Okta): Securely manage who has access to your systems. Implementing an Identity and Access Management (IAM) platform like Okta ensures that only verified, current personnel can use digital credentials to unlock doors or view security footage.
- Endpoint Protection (SentinelOne/ArmorPoint): The computers that manage your security systems are prime targets for ransomware. Justify cybersecurity solutions like SentinelOne by arguing that the availability of your entire security system depends on protecting these critical endpoints from attack.
How to Prepare Your NSGP Application: A Step-by-Step Guide
- Confirm Eligibility & SAA Contact: Verify your 501(c)(3) status and immediately contact your State Administrative Agency (SAA) to confirm your funding stream (NSGP-UA or NSGP-S) and learn their specific deadlines and requirements.
- Conduct a Threat, Vulnerability, and Risk Assessment (TVRA): Start with the CISA self-assessment tool. For a competitive application, engage a professional to conduct a formal TVRA that will serve as the foundation for your project.
- Develop an Integrated Project Scope: Work with a technology partner like CIT to design a holistic solution. Select specific hardware (cameras, access control), network infrastructure, and cybersecurity tools that directly address the vulnerabilities identified in your TVRA.
- Create a Detailed, Itemized Budget: Do not use lump sums. Your Investment Justification must provide a precise breakdown for every piece of equipment, software license, and hour of labor. Each cost must trace back to a specific vulnerability.
- Address Environmental & Historic Preservation (EHP): If your facility is a historic structure, begin the EHP review process with your SAA as early as possible. Delays here can jeopardize your ability to complete the project on time.
- Write a Compelling Investment Justification (IJ): Clearly and concisely explain the threat, the vulnerability, and how your proposed project will mitigate the risk. Tell the story of how this integrated solution will protect your people and your mission.
Glossary of Terms
- NSGP: Nonprofit Security Grant Program. A FEMA-administered grant providing funding for target hardening and physical security enhancements to nonprofit organizations at high risk of terrorist or extremist attack.
- SAA (State Administrative Agency): The state-level government agency responsible for managing and administering the NSGP grant process. All applications must be submitted through your designated SAA.
- TVRA (Threat, Vulnerability, and Risk Assessment): A mandatory assessment that formally documents the specific threats, internal vulnerabilities, and overall risks facing your organization. It is the basis for your grant proposal.
- PoE (Power over Ethernet): A technology that allows a single Ethernet cable to transmit both data and electrical power, simplifying the installation of devices like security cameras and access control readers.
- XDR (Extended Detection and Response): An advanced cybersecurity solution that provides autonomous prevention, detection, and response against threats across all endpoints (computers, servers) on your network.
Frequently Asked Questions
What is the maximum amount we can apply for?
You can request up to $200,000 per location. You can submit applications for up to three sites in the Urban Area (UA) stream and three in the State (S) stream, for a potential maximum of $600,000 per state or territory (https://www.fema.gov/fact-sheet/fy-2025-nonprofit-security-grant-program-key-changes).
Can the NSGP grant be used to pay for security guards?
No, the NSGP is intended for physical and cybersecurity hardware, software, training, and planning. It generally does not cover ongoing operational costs like hiring security personnel.
What is the first step we should take to get started?
Your very first step is to contact your State Administrative Agency (SAA). They are the gatekeeper for the entire process and can confirm your eligibility, funding stream, and state-specific deadlines.
Do we need professional help to write the grant?
While not required, working with an experienced partner can significantly increase your chances of success. Experts can help conduct a defensible TVRA, scope an integrated technology solution, create an audit-proof budget, and write a compelling justification that aligns with FEMA’s priorities.
Protect Your Mission with a Winning Strategy
The FY 2026 NSGP is a fiercely competitive, complex reimbursement grant. Don’t risk denial due to insufficient planning or non-compliant project scoping.
As a Verkada Platinum Plus Partner, CIT provides the precise, integrated expertise you need to win the grant and deploy your security solution flawlessly. Our team does more than guide you through paperwork; we help you:
- Secure Your Plan: We craft the mandatory Threat, Vulnerability, and Risk Assessment (TVRA) and develop a meticulous, compliant Investment Justification (IJ) and Scope of Work that reviewers trust.
- Guarantee Compliance: When your project is funded, our Verkada Certified Installers and Services teamensure your integrated cameras and access control systems are deployed perfectly, guaranteeing project effectiveness and maximizing your reimbursement success.
Schedule a consultation with a CIT specialist today to turn your vulnerability list into a fully funded, integrated defense solution.
Sources
FEMA | https://www.fema.gov/grants/preparedness/nonprofit-security | General information on the NSGP program.
U.S. Department of Energy | https://www.energy.gov/sites/default/files/2023-03/ICF%20DOE%20GRIP%20Training%20for%20Secured%20by%20Design%20Considerations%20022823_508.pdf | Details on securing technology with frameworks like NIST and ensuring confidentiality, integrity, and availability.
Texas Department of Public Safety | https://egrants.gov.texas.gov/fundingopp/nonprofit-security-grant-program-nsgp-federal-fiscal-year-2025 | Historical data on project Period of Performance (POP) timelines.
FEMA | https://www.fema.gov/fact-sheet/fy-2025-nonprofit-security-grant-program-frequently-asked-questions | Information on risk status, M&A costs, and the distinction between risk and vulnerability.
FEMA | https://www.fema.gov/fact-sheet/fy-2025-nonprofit-security-grant-program-key-changes | Details on the reimbursement nature of the grant, maximum award amounts, and the 15-point bonus for new applicants.
North Carolina Department of Public Safety | https://www.ncdps.gov/NSGP | Confirmation of 501(c)(3) tax status eligibility.
Virginia Department of Emergency Management | https://www.vaemergency.gov/grant-opportunities/fy-2025-nonprofit-security-grant-program-nsgp | Confirmation that houses of worship are explicitly eligible.
FEMA | https://www.fema.gov/fact-sheet/department-homeland-security-dhs-nsgp-notice-funding-opportunity-nofo-fiscal-year-2025 | Guidance on contacting the SAA to determine the correct grant stream (UA vs. S).
Total Security Solutions | https://www.tssbulletproof.com/blog/nsgp-application-guide-for-schools | Confirmation that the TVRA is a mandatory part of the submission.
Florida Division of Emergency Management | https://portal.floridadisaster.org/preparedness/External/Grants-Unit/Nonprofit%20Security%20Grant%20Program/Completing%20the%20Investment%20Justifcation%20Tips.pdf | Guidance stating that a proposed project must mitigate a specific, identified vulnerability from the TVRA.
Montana Disaster and Emergency Services | https://des.mt.gov/Grant-Programs/Nonprofit-Security-Grant-Program-NSGP | Note that the Investment Justification should focus on current threats and risks.
CISA | https://www.cisa.gov/topics/physical-security/protecting-houses-worship/resources | Link to the CISA Houses of Worship Security Self-Assessment tool.
CISA | https://www.cisa.gov/resources-tools/resources/paper-based-houses-worship-security-self-assessment-and-user-guide | Information on how the CISA self-assessment can be used to inform the grant application.
Verkada | https://www.verkada.com/solutions/school-perimeter-security/ | Example of AI-powered camera systems for perimeter security.
Verkada | https://info.verkada.com/perimeter-security/ | Information on the layered defense principles of “Deter” and “Detect”.
Verkada | https://www.verkada.com/access-control/ | Example of integrated access control systems.
Verkada | https://www.verkada.com/docs/access-control-for-offices/ | Information on automated door schedules as an operational enhancement.
Spot AI | https://www.spot.ai/blog/poe-vs-wifi-security-cameras-enterprise-safety | Explanation of Power over Ethernet (PoE) for security cameras.
City of Savannah | https://agenda.savannahga.gov/content/files/cabling-scope-of-work.pdf | Example of standards-compliant structural wiring scope (CAT6 in conduit).
HPE | https://www.hpe.com/us/en/networking/hpe-aruba-networking-global-partners.html | Information on HPE Aruba Networking solutions.
HPE | https://www.hpe.com/us/en/networking/technology-partner-programs.html | Context on how managed services can lower Total Cost of Ownership (TCO).
KnowBe4 | https://home.knowbe4.com/home | Information on security awareness training solutions.
KnowBe4 | https://www.knowbe4.com/security-awareness-training | Details on topics covered in security awareness training.
Okta | https://www.okta.com/industries/nonprofits/ | Information on Okta’s Identity Platform for nonprofits.
SentinelOne | https://www.sentinelone.com/platform/federal-government/ | Information on autonomous prevention, detection, and response (XDR) solutions.
Arizona Department of Homeland Security | https://azdohs.gov/sites/default/files/fy2026_state_of_arizona_nsgp_guidance_0.pdf | Historical data point regarding short Period of Performance (POP) timelines in some states.