Washington Public Agencies Are Racing to Spend Cybersecurity Grants Before the Money Runs Out
Federal grant dollars from the SLCGP are finally reaching local sub-grantees just as the program's congressional reauthorization stalls, creating a narrow window agencies are rushing to use.
Washington public-sector agencies issued 6 cybersecurity RFPs in the trailing 30 days, 2.5 times the 12-month monthly average of roughly 2.4, and the spike is not random: three forces landed at the same moment, and local governments are responding by procuring as fast as their purchasing offices will allow.
The Port of Port Angeles, a small rural port in Clallam County, is the clearest illustration of what this looks like on the ground. The port has an active RFP for an Airport Security Operations Center and Disaster Recovery Network Infrastructure, due October 16, 2026, and has earmarked $87,000 for a Cybersecurity Master Plan in its 2027 capital budget. A year ago, the Port of Port Angeles did not have dedicated cybersecurity staff. Today it is building its own SOC. The reason is federal grant money, specifically the DHS State and Local Cybersecurity Grant Program, known as the SLCGP, which has delivered approximately $18.5 million to Washington across fiscal years 2022 through 2025.
The SLCGP flows from DHS and CISA to WaTech, the state technology agency, which then passes sub-grants to eligible local governments, tribal governments, school districts, and special-purpose districts. What makes Washington's version of this program unusually accessible is a state legislature decision to absorb the federal matching-fund requirement, removing the cost-share barrier that has limited local participation in other states. WaTech's FY25 sub-grant application cycle closed June 12, 2026. Project awards from that cycle are now clearing, and vendor RFPs are following within weeks.
WA public-sector cybersecurity RFPs by month (Apr 2025–Sep 2026)
Source: NationGraph.
The Washington State Auditor's Office added a separate layer of urgency this month. Its FY2026 penetration-testing report, published around September 21, 2026, identified 396 vulnerabilities across government IT systems tested between July 2025 and June 2026. The audit is a distinct mechanism from the SLCGP: it does not disburse funds, but it creates documented remediation need at named agencies, and agencies with findings now have a public record of exposure. A companion ransomware resiliency audit was scheduled for publication September 17, with a legislative committee hearing set for October 7. State Auditor Pat McCarthy has separately flagged that Washington has not adopted a whole-of-state cybersecurity model, a structural gap that a SAO performance audit is currently examining.
The third pressure is a deadline imposed by congressional inaction. The SLCGP's authorization lapsed in January 2026. The House passed the PILLAR Act in November 2025 to reauthorize the program through 2033, and the Senate introduced its own simpler reauthorization bill, S. 3251, but no final legislation has been enacted. Local entities operating under existing awards can still spend their allocated dollars, but the absence of a confirmed next round means that agencies which delay now may find no follow-on funding available when current projects end. That uncertainty is compressing timelines.
The result is a procurement burst that is geographically and institutionally diverse. The City of Redmond, home to Microsoft's headquarters, issued a fiber-management RFI with explicit cybersecurity requirements. The Chelan-Douglas Health District, a rural public health agency in Douglas County, is procuring managed IT and cybersecurity services. The Port of Port Angeles sits on the opposite end of Puget Sound from the state's technology corridor. These entities share a grant program and an audit regime, but they are each procuring independently, with no shared security operations center and no centralized threat intelligence feed.
That atomization is not incidental. WaTech CISO Ralph Johnson administers state cybersecurity policy and coordinates the SLCGP sub-grant process, but the auditor's finding that Washington lacks a whole-of-state coordination model means that the grant dollars are producing parallel efforts rather than a unified posture. A rural port, a suburban tech-hub city, and a county health district each building their own cyber infrastructure is better than none of them doing it, but it is an expensive and fragmented way to harden a state whose public-sector network perimeter sits adjacent to Microsoft, Boeing facilities, and multiple federal installations.
Washington's 30-day RFP count of 6 is second only to California's 8 among Western states, but Washington's ratio of current volume to its 12-month average is higher than California's, 2.05x versus 1.17x. The spike here is proportionally sharper, which reflects how compressed the procurement window has become.
The October 7 legislative committee hearing on the auditor's cybersecurity reports is the next public signal to watch. If the committee responds with remediation directives, agencies that have not yet issued RFPs under their sub-grant awards will face pressure to move faster. If Congress acts on SLCGP reauthorization before year's end, the urgency driving the current burst may extend into 2027. If it does not, the agencies that acted in May and September 2026 will have used their window. The ones still in planning will be waiting for a program that may not return.