Georgia Agencies Are Rushing to Spend Federal Cybersecurity Grants Before Time Runs Out
A $9.9M wave of SLCGP subgrant awards issued March 25 has triggered a procurement surge, and FY2025 is the last year of the federal program funding it.
Georgia's public agencies issued 8 cybersecurity RFPs in the past 30 days, more than double the 12-month average of roughly 3.4 per month. The timing is not coincidental. On March 25, 2026, GEMA/HS and the Georgia Technology Authority jointly announced $9,873,903 in State and Local Cybersecurity Grant Program awards to 44 Georgia entities, and within weeks, solicitations began hitting procurement portals across the state.
The surge is qualitatively different from Georgia's last spike in cybersecurity RFP activity. Last July, 26 RFPs hit in a single month, almost entirely driven by K-12 school districts filing Form 470 competitive-bidding documents under the FCC's separate $200M Schools and Libraries Cybersecurity Pilot Program. The current wave is smaller in volume but broader in institutional reach: the Georgia Department of Administrative Services has posted "Cybersecurity Assessment, Compliance, and Governance Services" solicitations covering the Departments of Corrections and Juvenile Justice, while the cities of Norcross and Smyrna have filed their own municipal solicitations. That specific framing, assessment, compliance, and governance, maps directly onto the planning deliverables SLCGP grantees are required to complete before spending down awards.
The reason agencies are moving now has as much to do with calendar as with cash. The FY2024 SLCGP subgrant application window opened April 1, 2026, with a May 15 deadline. The FY2025 window opens September 1. More consequentially, FY2025 is the final year of the SLCGP nationally: the program was created under the Bipartisan Infrastructure Law with $1 billion allocated over five years, and CISA has confirmed FY2025 closes the cycle, with $91.75 million available in the last round. Entities that have not converted their awards into contracted services by the time grant periods close will have nothing to show federal auditors.
Georgia's SLCGP execution clock, 2026
Source: NationGraph.
Georgia's total active SLCGP federal grant portfolio now runs to at least $10.08 million: $7.59 million under the FY2024 award running through December 2028, and $2.49 million under the FY2025 award running through August 2029. That gives Georgia more runway than some states, but the compliance clock on earlier awards is already ticking, which explains why assessment RFPs are appearing now rather than after the September FY2025 window opens.
Georgia CIO Shawnzia Thomas has been explicit about what 2026 is supposed to accomplish. In a January 2026 Government Technology profile, she described "cyber discipline" as the organizing lens for every major state technology decision and framed this year as the transition from groundwork to execution: fewer initiatives, completed. That framing is visible in the current RFPs. Correctional agencies and municipalities are not typically early movers on cybersecurity procurement; their appearance in the solicitation pipeline suggests the GEMA/HS and GTA award notices are functioning as institutional permission slips, converting abstract grant eligibility into concrete procurement action.
The political environment adds another layer of pressure. The GTA asked the 2026 legislature for $15 million in one-time state cybersecurity funds to complement the federal program. The House cut that request to $5 million, and Thomas asked the Senate to restore $2.5 million of the difference. The outcome of that budget negotiation will determine how much state co-investment backs the federal dollars, but it also signals that state leaders see 2026 as a spending year, not a planning year.
Georgia operates a dual-track cybersecurity infrastructure that gives the current surge some structural staying power. GEMA/HS and GTA administer the SLCGP jointly, creating a cleaner subgrant pipeline than states where a single agency manages both federal passthrough and direct state programs. Georgia Tech Research Corporation holds more than $6 million in active Department of Energy CESER grants focused on grid and distributed energy resource cybersecurity, running through 2027, which means the state has a federally funded research node that can support technical standards work in parallel with the procurement surge.
For local governments and state agencies that have not yet filed SLCGP subgrant applications, the May 15 deadline for FY2024 awards is the immediate signal to watch. Entities that miss that window will face the FY2025 application in September but will be competing in the final round of a sunsetting program with no guarantee of a successor. The RFPs appearing now are, in effect, the early movers translating grant award letters into vendor contracts before the window closes for good.