← Back to search

Cybersecurity And Infrastructure Security Agency, Homeland Security, Department Of

CISA Cyber Security Awareness Campaign

Federal program · Assistance Listing 97.128 · also called “Cybersecurity Awareness Campaign”

Key facts

Open right now
No open notice at the moment
Type of help
Cooperative Agreements
Typical award
CISA awarded a competitive cooperative agreement to a single non-profit organization in FY 2023 with a 29-month period of performance comprised of three budget periods. The funding awarded for the initial 1-year...
Deadlines
The Notice of Funding Opportunity will identify the open application period and deadline for applying for a Cybersecurity Awareness Campaign Program cooperative agreement. The application period is generally at least...

What it pays for

CISA’s mission is to lead the national effort to understand, manage, and reduce risk to our cyber and physical infrastructure. In carrying out this mission, Section 2202 of the Homeland Security Act of 2002 assigns CISA with the responsibilities to coordinate a national effort to secure and protect against critical infrastructure risks, carry out cybersecurity and critical infrastructure stakeholder outreach and engagement, and encourage and build cybersecurity awareness and competency across the United States. In carrying out its mission and pursuant to these authorities, CISA provides financial assistance under the CAC Program to non-federal entities to perform cybersecurity awareness activities to reduce cybersecurity risks through messaging, tools, and resources to encourage individuals and organizations to reduce their exposure to malicious cyber activity. Through strategies implemented year-round with a focal point of the Cybersecurity Awareness Month in October, a recipient under this federal award engaged in efforts to improve the public’s understanding of cyber threats, amplify opportunities that individuals and non-federal entities can leverage to strengthen their own cybersecurity posture, and encourage discussion, engagement, and actions that can be taken to reduce cyber risk. For the CAC program, CISA established the following six goals: 1. Strengthen the security and resilience of critical infrastructure; 2. Assess and counter evolving cybersecurity risks through actions that promote threat risk reduction; 3. Build a national culture of preparedness for...

Who can apply

Nonprofit organizations, other than institutions of higher education, with an effective ruling letter from the U.S. Internal Revenue Service granting tax exemption under Section 501(c)(3) of the Internal Revenue Code of 1986 A recipient under the Cybersecurity Awareness Campaign Program must be a nonprofit organization with an effective ruling letter from the U.S. Internal Revenue Service granting tax exemption under Section 501(c)(3) of the Internal Revenue Code of 1986. A nonprofit organization means any organization that: (1) is operated primarily for scientific, educational, service, charitable, or similar purposes in the public interest; (2) is not organized primarily for profit; (3) uses net proceeds to maintain, improve, or expand the organization’s operations; and (4) is not an institution of higher education as defined at 20 U.S.C. 1001.

How applications are judged

The Notice of Funding Opportunity will set forth the criteria that CISA will use in evaluating and scoring applications. These criteria include program design and rationale; project management and organizational capability; demonstrated experience and past performance; and project plan and budget. CISA will also review information about an applicant through any OMB-designated repositories of governmentwide eligibility qualification or financial integrity information as required by 31 U.S.C. 3354 (enacted by the Payment Integrity Information Act of 2019, Pub. L. No. 116-117, 2 (2020)), 41 U.S.C. 2313, and 2 C.F.R. 200.206. Therefore, evaluation criteria will include risk-based considerations concerning an applicant’s financial stability, quality of management systems and ability to meet management standards, history of performance in managing federal awards, reports and findings from audits, and ability to effectively implement statutory, regulatory, or other requirements. CISA, in cases where the project federal award exceeds the simplified acquisition threshold (currently $250,000), is also required by 41 U.S.C. 2313 and 2 C.F.R. 200.206 to review and consider any information about the applicant in the Federal Awardee Performance and Integrity Information System.

Matching requirements

This program has no statutory formula. Matching requirements are not applicable to this assistance listing. MOE requirements are not applicable to this assistance listing.

Examples of funded projects

Fiscal Year2025: Cybersecurity Awareness Month (October 2025) Cyber Partnership Engagement Cybersecurity Research Cyber Promotions (campaign, programs, resources, careers) Cyber Outreach (social media, newsletter) Website Updates

Official program listing (SAM.gov) Program website