Key Takeaways

  • The Institute for Security and Technology reports that federal grants still lack enforceable cybersecurity requirements
  • New guidance from the Office of the National Cyber Director offers a template, but agencies struggle to evaluate technical cyber plans
  • Growing threats to critical systems and updated federal funding guidelines are pressuring lawmakers to close security gaps in upcoming legislation

Federal policymakers received a policy memo from the Institute for Security and Technology pushing Congress and the Trump administration to tighten cybersecurity requirements across infrastructure grants and awards. The memo arrives at a moment when critical systems, from water utilities to power grids, face sustained pressure from foreign adversaries and automated attack tools.

Despite years of warnings, major spending bills have frequently failed to embed mandatory cyber conditions. Agencies have distributed billions in federal infrastructure funds without consistent processes to verify whether recipients can actively defend what they build.

Ongoing cyberattacks tied to groups like Volt Typhoon are intended to seed disruption capabilities inside U.S. critical infrastructure, elevating the push for stronger grant safeguards to an immediate national security concern. Artificial intelligence tools are simultaneously increasing the speed and precision of these network intrusions, a dynamic state and federal leaders have monitored for months.

Congress is preparing to take up the farm bill and surface transportation reauthorization, both of which offer legislative vehicles to attach new cyber provisions. The senior vice president for policy at the Institute for Security and Technology argues that past missed opportunities can be reversed if lawmakers explicitly align strategic security intentions with operational funding requirements, closing the gap between policy vision and localized implementation.

The Office of Management and Budget’s April 2024 update to the federal Uniform Guidance explicitly directs agencies to evaluate cybersecurity risk as part of their grant assessments, a policy shift summarized by CSH. This revision makes demonstrable cyber controls a condition of funding eligibility. Yet many federal agencies remain unequipped to review complex technical plans or judge whether proposed network safeguards meet the rule's criteria.

State IT leaders have raised similar capacity and resource concerns. In 2024, the National Association of State Chief Information Officers and the National Governors Association publicly warned against potential clawbacks to the State and Local Cybersecurity Grant Program. They stated that cutting roughly $100 million in upcoming planned support would leave many municipalities unable to keep pace with threats. Oversight bodies examining federal spending programs have documented inconsistent adoption of risk management practices and cyber controls across these funded projects.

The Energy Department’s Office of Cybersecurity, Energy Security, and Emergency Response currently reviews cyber plans within energy infrastructure awards. Analysts referenced by StateScoop have pointed to CESER as a potential model for other agencies. Because participation in that program remains voluntary, the Institute for Security and Technology recommends making such frameworks mandatory and auditable to close the accountability gap.

Released in 2024, the ONCD playbook offers draft language, templates, and process guidance to help agencies incorporate cyber risk planning into their grant lifecycles. A former deputy assistant national cyber director described the playbook as a mechanism to fix structural problems revealed during the Bipartisan Infrastructure Law rollout. During that period, concerns over regulatory burdens on small businesses and limited agency cyber expertise diluted stronger security requirements, resulting in notices of funding opportunities that contained only broad, unenforceable references to cybersecurity.

Uneven implementation stems largely from a lack of technical capability. Many grant-making offices lack personnel trained to evaluate NIST Cybersecurity Framework alignment or assess how risk templates translate into operational network controls. Consulting partners and vendors like Tenable, Rapid7, and Accenture Federal Services frequently assist state and local governments in interpreting federal guidance, but agencies still require their own internal auditing capabilities to verify compliance.

Financial flexibility remains another hurdle for mandatory controls. The Institute for Security and Technology proposes a cybersecurity set-aside that would carve out a dedicated slice of overall project funds. While some organizations spend roughly 10% of their IT budgets on security, physical infrastructure projects vary widely in their digital risk profiles. A fixed percentage could overfund low-risk projects while underfunding complex utility networks, though it would guarantee that cybersecurity is integrated early in the procurement cycle.

Research communities are monitoring how infrastructure modernization efforts frequently underestimate digital risks, particularly when operational technology and IT environments converge. These vulnerabilities parallel ongoing National Science Foundation research emphasizing the need to balance long-term cybersecurity advancements with the near-term protection of highly connected infrastructure.

If federal grants are financing digital capabilities that millions of Americans depend on, cyber planning must become a mandatory requirement for funding. The upcoming legislative windows will reveal whether Congress is prepared to treat cybersecurity as foundational infrastructure rather than a disconnected operational add-on.