Georgia Agencies Are Racing to Spend $10 Million in Federal Cybersecurity Grants
The September 1 opening of SLCGP's FY2025 subgrant window triggered a procurement surge across state corrections, schools, and local governments facing a spend-or-lose deadline.
Six cybersecurity RFPs landed in Georgia's public procurement queue in the trailing 30 days, three times the prior 12-month average of roughly two per month, and the timing is no accident. On September 1, 2026, the Georgia Emergency Management and Homeland Security Agency opened its FY2025 subgrant application window under the federal State and Local Cybersecurity Grant Program (SLCGP), administered jointly with the Georgia Technology Authority. The window's opening converted a slow trickle of procurement activity into an overnight flood.
The immediate trigger is a deadline with real financial stakes. GEMA/HS holds approximately $10.1 million in committed, unoutlayed SLCGP awards from DHS: $7.59 million awarded in December 2024 and $2.49 million awarded in September 2025. Zero dollars of that total had been outlayed as of the most recent federal records, meaning agencies that received subgrant allocations are only now pushing funds through procurement. The SLCGP program, funded by the 2021 Infrastructure Investment and Jobs Act's $1 billion four-year appropriation, concludes its active funding phase in FY2026. Subrecipients whose periods of performance run through 2029 can still spend, but no new federal awards follow after this cycle. That asymmetry, money committed but not yet spent, with no future tranches coming, is what pushed agencies into procurement in September rather than waiting.
The entities filing RFPs this month illustrate how broadly SLCGP is designed to reach. The Georgia Department of Corrections, the Department of Juvenile Justice, Newton County Schools, and the City of Stonecrest all filed "Cybersecurity Risk Reduction" solicitations in September 2026. That mix of a state prison system, a juvenile justice agency, a county school district, and a small municipality is not accidental: SLCGP's authorizing rules require at least 80% of state-level awards to pass through to local entities, and at least 25% to reach rural communities. Georgia's subgrant structure is built to push money to exactly this kind of cross-sector, geographically distributed roster.
Georgia cybersecurity RFPs by month: two federal grant waves, one year apart
Source: NationGraph.
In March 2026, GEMA announced $9,873,903 in SLCGP subgrants to 44 Georgia entities, with GEMA Director Josh Lamb citing Center for Internet Security data showing 82% of reporting K-12 schools experienced cyber threat impacts between July 2023 and December 2024. That announcement seeded the subgrant pipeline; the September 1 FY2025 window opening is now harvesting it in the form of RFPs.
This surge is also distinct from an earlier wave that could easily be mistaken for the same phenomenon. In July 2025, Georgia saw 28 cybersecurity RFPs in a single month, driven by a completely separate federal program: the FCC Schools and Libraries Cybersecurity Pilot Program. That program, administered by the FCC rather than DHS or FEMA, targeted K-12 schools and libraries specifically, and drew procurement activity from Richmond County, Clayton County, Macon County, and Dougherty County school systems, among others. The two programs share no authorizing statute, no administering agency, and no procurement timeline. The FCC wave was school-specific and peaked; the current SLCGP wave is broader, covering corrections and municipalities as well as schools, and it is only beginning.
Nationally, FY2025 is the smallest SLCGP tranche on record: $91.75 million, down sharply from $279 million in FY2024. That compression makes the deadline pressure more acute for states like Georgia. There is no larger future round to catch up in. States that have not moved subrecipients through procurement by the end of the active funding phase will face the prospect of returning unspent federal dollars. Georgia's procurement activity suggests the state is working to avoid that outcome.
Georgia's position as a federal cyber research hub adds a layer of relevance for the agencies writing these RFPs. Georgia Tech holds multiple active cybersecurity grants from DHS, DOE, and NSF totaling more than $8 million, giving the state an unusually deep bench of vendors and research institutions capable of responding to government solicitations. Agencies procuring cybersecurity risk assessments or managed security services in Georgia are drawing from a richer vendor pool than most states of comparable size.
For residents, the most concrete near-term effect is that state agencies managing sensitive personal data, from prison records to juvenile justice files to school enrollment systems, are actively hardening their defenses right now. Whether those procurements result in durable improvements depends on what vendors are selected and how agencies implement recommendations. The RFP filing is the start of that process, not the end.
The next signal to watch is whether the 44 entities that received March 2026 SLCGP subgrants all move to procurement before their award periods close. Six RFPs in 30 days is the opening surge; the full wave, if it follows the grant distribution, would mean dozens more solicitations before year's end.