North Carolina Is Pulling In More Federal Cybersecurity Dollars Than Any Other State
Three unrelated federal programs and a record state budget all closed in the same 90 days, creating a funding stack North Carolina now has to spend wisely.
North Carolina has pulled in $9.39 million in new federal cybersecurity grants over the past 90 days, more than double the $4.25 million awarded in the same window a year ago and more than any peer state in the country. Texas came in second at $7.4 million, Florida third at $6.1 million, Virginia fourth at $3.9 million, and California fifth at $3.3 million.
What makes that number unusual is not just its size but its origin. The $9.39 million did not come from a single program or a coordinated federal push. It arrived from three separate agencies, each running its own authority, on its own timeline, for its own purpose, and they all happened to close in the same quarter.
The largest piece is a $7.5 million NSF Technology, Innovation and Partnerships grant to UNC Charlotte, announced July 14, 2026, as the lead institution of the Carolinas Grid Modernization Engine. NSF selected the Charlotte-led consortium from nearly 300 competing teams nationally, making it one of only 12 Regional Innovation Engines in the second cohort. The grant is the opening tranche of a 10-year, up-to-$160 million commitment running through 2036, targeting research, workforce development, and commercialization of cyber-secure grid control systems across a 36-county Carolinas region with more than 100 partner organizations. This is an NSF research and ecosystem grant; it funds university laboratories and industry partnerships, not government agencies or utility operations.
New federal cybersecurity grants started in the last 90 days, by state
Source: NationGraph.
A separate $1.14 million award to the Fayetteville Public Works Commission came from a different agency entirely: DOE's Office of Cybersecurity, Energy Security, and Emergency Response, through its Rural and Municipal Utility Cybersecurity program. That program was established by Section 40124 of the Infrastructure Investment and Jobs Act, with $250 million allocated nationally over five years. Fiscal year 2026 is the program's final and largest disbursement year, which partly explains why Fayetteville's grant landed now. The money will go toward software-defined networking tools to harden the commission's electrical infrastructure, a utility operator award, entirely distinct from the NSF university track.
Rounding out the 90-day cohort are two NSF CyberAI Innovation workforce grants: $496,000 to Winston-Salem State University and $250,000 to NC State, both effective September 2026. These fund academic curriculum and student training pipelines in AI-security for public-sector careers, with an emphasis on HBCUs and regional universities. They share the NSF letterhead with the UNC Charlotte award but have a different program office, different purpose, and different selection criteria.
Beneath all three federal tracks sits a fourth, state-funded layer. Governor Josh Stein signed North Carolina's FY2026 budget in July 2026, committing $60 million to cybersecurity: $18 million in recurring annual funding and $42 million in one-time infrastructure upgrades. NCDIT Secretary Nate Denny called it a generational commitment, and Government Technology described it as the largest such investment in state history. That appropriation funds NCDIT operations and the SecureNC initiative, a whole-of-state security platform built with Tanium that launched in June 2026 to cover state agencies, counties, universities, and K-12 schools. The $60 million is state money; it does not flow through any of the four federal programs.
North Carolina also holds $10.88 million in active DHS/FEMA State and Local Cybersecurity Grant Program funds across its FY2024 and FY2025 cohorts, managed by NC DPS, with 80 percent required to pass through to local governments and 25 percent directed to rural communities. That program runs on a third federal authority, the IIJA's homeland security provisions, and targets city halls and county governments, not utilities or universities.
The reason North Carolina is capturing all of these simultaneously comes down to asset coverage. The state has a large research university system with existing NSF cybersecurity track records, a substantial rural electric cooperative and municipal utility base that qualifies for DOE's utility-specific grants, and a state government that institutionalized cybersecurity planning years before the current budget cycle. The Carolinas' electrical grid is also emerging as a national test bed for AI-driven demand surges from data centers and electric vehicle adoption, a vulnerability profile that sharpens federal interest. Residents lost $234 million to cybercrime in 2025, a figure that gives the political urgency numerical weight.
What changes now for North Carolina residents and organizations is less the existence of these programs and more the simultaneity of their activation. The IIJA's RMUC utility grants expire after FY2026, meaning Fayetteville's award is among the last of that cohort nationally. The NSF Regional Engine commitment, by contrast, locks in a 10-year federal partnership that will shape the state's grid-security research agenda well into the 2030s. The state budget's $18 million recurring line is the figure to watch: recurring appropriations are harder to cut than one-time spending, and it signals that the Stein administration intends SecureNC to outlast a single budget cycle.
The next concrete signal will be how quickly NC DPS moves the existing $10.88 million in SLCGP funds to local governments. Federal rules require most of it to reach sub-grantees; the pace of that distribution will indicate whether North Carolina's whole-of-state framing is administrative language or operational reality.