California Cities Are Buying Cybersecurity Services for the First Time
A federal grant deadline and the quiet elimination of a free threat-intelligence service have handed California localities an invoice they can no longer defer.
At least three California institutions issued their first-ever cybersecurity procurement requests in the last 30 days: the Long Beach Police Department on behalf of the Port of Long Beach, the City of Laguna Beach, and the Southern California Association of Governments. None had a recorded cybersecurity RFP history before this window. The immediate catalyst is a deadline, but the underlying pressure has been building since September 2025, when the federal government quietly ended a free service that hundreds of small agencies had been leaning on instead of buying anything at all.
The forcing function with a dollar sign attached is Cal OES's FFY2024 State and Local Cybersecurity Grant Program competitive funding cycle, which re-opened in September 2026 with $9.68 million available for local and tribal governments and another $1.82 million for state agencies. The SLCGP, authorized under the Infrastructure Investment and Jobs Act and administered nationally by CISA and FEMA, flows through Cal OES to local sub-recipients via a competitive application process. California has now obligated roughly $39 million across 116 sub-recipients since 2022. To compete for a share of the current round, localities need to demonstrate they have assessed their needs and are moving toward procurement, which is exactly what a first-time RFP signals.
But the grant deadline alone does not explain why this cohort is new. The structural change that pushed smaller agencies off the sidelines was the elimination of the Multi-State Information Sharing and Analysis Center, known as MS-ISAC, as a free federal service. CISA defunded it in September 2025 as part of DOGE budget cuts. MS-ISAC had provided continuous threat intelligence and incident response support to state and local governments at no cost; agencies that relied on it, as an IANS Research analysis noted, "now have to pay for it directly or find alternatives." This is a separate mechanism from the SLCGP: the grant provides dollars, the MS-ISAC cut creates unfunded need. Together they produce a first-time buyer.
State & local ransomware attacks are surging — and California localities are on the front line
Source: NationGraph.
The threat environment made deferral harder to justify. Foster City suffered a ransomware attack in March 2026 that forced the city to pause all non-emergency public services and potentially exposed resident data. Suisun City was hit in August 2026, with the attack disrupting 911 dispatch alongside Finance, Human Resources, and Public Works. Both are California municipalities well below the population thresholds that typically attract vendor attention or state support. Nationally, state and local ransomware attacks were up 65 percent year-over-year in early 2025. An April 2026 ITIF report identified "underfunded IT departments, aging critical infrastructure sectors, and a chronic shortage of cybersecurity professionals" as the core vulnerabilities that leave local governments exposed.
The three new entrants span distinct sectors in ways that matter. The Port of Long Beach's RFP, issued through the Long Beach Police Department, covers enterprise IT security, disaster recovery, and managed cybersecurity services for a facility that processes roughly a fifth of all U.S. containerized imports. Laguna Beach embedded cybersecurity requirements inside a GIS and public-safety CAD integration contract, a procurement structure that reflects how smaller cities are bundling security obligations into broader IT work rather than standing up dedicated security offices. SCAG's request is the most unusual: a regional planning body seeking a vulnerability study of transportation infrastructure against both cyber and physical disruption, with explicit framing around defense-related resources and supply chain continuity. A metropolitan planning organization treating cybersecurity as a transportation-resilience question is a framing that has rarely appeared in California procurement records.
California's decentralized procurement structure amplifies the significance of these signals. Unlike states that maintain master contracts localities can piggyback on, California requires each jurisdiction to run its own competitive process. A first-time RFP here is not an administrative formality; it is an agency deciding, often for the first time, that it needs a vendor relationship that does not yet exist.
For residents, the near-term consequence is a transition period. Agencies writing their first cybersecurity RFPs are also, almost by definition, building their first vendor evaluation frameworks. Procurement timelines for managed security services typically run three to six months from RFP issuance to contract award. The Foster City and Suisun City attacks both occurred during gaps in coverage, and the agencies now issuing first-time RFPs are in a comparable gap.
The next signal to watch is Cal OES's award decisions from the current SLCGP competitive cycle. Those awards will show which of the new entrants secured federal sub-grant backing and which are self-funding, a distinction that will determine how much of this first-time procurement activity translates into durable security contracts versus one-time assessments.