Maryland Local Cybersecurity Support Fund (LCSF) Program

​​​​​​​​
CPU HOME

A header image of computer code overlaid with the logo of the Cyber Preparedness Unit 

Maryland Local Cybersecurity Support Fund (LCSF) Program

General Info:

Md. Code, Pub. Safety § 14-104.2 has codified the Local Cybersecurity Support Fund (the “Fund”). This Fund will support “Local government” which includes local school systems, local school boards, municipalities, and local health departments to improve their cybersecurity preparedness. The multi-fiscal-year purpose of the Fund is defined in Md. Code, Pub. Safety § 14-104.2.

MDEM has been designated as the State Administrative Agency (SAA) for the “Fund”. In line with the Fund’s requirements, MDEM will distribute funds to the best applicants to bring them to baseline capabilities level or help them achieve advanced capabilities.

 (Read the official information on this Public Code here)


Background & Purpose
Md. Code, Pub. Safety § 14-104.2 has codified the Local Cybersecurity Support Fund (the “Fund”). This Fund will support “Local government” which includes local school systems, local school boards, and local health departments to improve their cybersecurity preparedness. The multi-fiscal-year purpose of the Fund is defined in Md. Code, Pub. Safety § 14-104.2.

The Maryland Department of Emergency Management (MDEM) is the state’s lead agency for the Local Cybersecurity Support Fund (LCSF). MDEM manages the program on behalf of the State of Maryland, provides administrative oversight, and serves as the main point of contact for eligible applicants. Once projects are awarded, MDEM also helps recipients by processing reimbursement requests and making sure all state fund requirements are met.

The goal of the program is to ensure that resources reach the jurisdictions that need them most and to build long-term cybersecurity capacity across Maryland.


Application Deadline, Project Types & Requirements, General Information

Application Deadline

   

Application Submission Deadline: August 28, 2026 at 11:59:59 PM ET
 

   

All applications must be received by the established deadline. The Fund administrator(s) will not consider or review applications that are received after the deadline.

   

Allowable Project Types & Requirements   

Per Md. Code, Pub. Safety § 14-104.2, “Local Cybersecurity Support Fund", these are the project types an applicant may apply for:​

   

  1. Cybersecurity Capabilities Assessment

    If an eligible entity has not completed a cybersecurity assessment within, at a minimum, the last 12 months, it may submit a request for LCSF funding to be used towards the completion of a cybersecurity assessment by a vendor approved by the Maryland Department of Information Technology (DoIT).

    Applicants will complete the “Cybersecurity Capabilities Assessment Project Form" and the “Budget Narrative & Justification Form". Applicants may be expected to provide a summary of results after the completion of the assessment for review by the Maryland Department of Information Technology. 

    Be aware that a cybersecurity assessment completed in the last 12 months or to be completed within the next 12 months is a requirement to apply for other LCSF project types.​ (Note: The MD Department of Information Technology does also provide a free assessment that will meet this requirement, if an entity does not want to pay an outside vendor. Applying to this program can be done by completing the “Cybersecurity Capabilities Assessment Project Form".)

  2. Other Allowable Projects

    In addition to the use of funds for the completion of Cybersecurity Capabilities Assessments, the Fund may also be used for the following:
    1. Ad​option or Enhancement of Cybersecurity Best Practices:
      • updating current devices and networks with the most up-to-date cybersecurity protections.
      • supporting the purchase of new hardware, software, devices, and firewalls to improve cybersecurity preparedness.
      • conducting cybersecurity vulnerability assessments.
      • addressing high-risk cybersecurity vulnerabilities identified by vulnerability assessments.
      • implementing and maintaining integrators and other similar intelligence-sharing infrastructure that enable connection with the Information Sharing and Analysis Center in the Department of Information Technology.
    1. Cybersecurity Workforce Development:
      • recruiting and hiring information technology staff focused on cybersecurity.
      • paying outside vendors for cybersecurity staff training.
    1. Addressing Specific Cybersecurity Needs:
      • supporting the security of local wastewater treatment plants, including bi-county, county, and municipal plants, by acquiring or implementing cybersecurity-related upgrades to the plants.
    1. Applying for Federal Cybersecurity Preparedness Grants:
      • local governments can use funds to assist in applying for federal cybersecurity preparedness grants.
    1. Management and Administration (M&A):
      • for administrative expenses associated with the project types listed above. Not to exceed 5% of the total project cost.
    ​ Md. Code, Pub. Safety § 14-104.2, Local Cybersecurity Support Fund ​
​General Application Information
   


Documents List

Maryland Local Cybersecurity Support Fund Notice of Funding Opportunity (NOFO)
Cybersecurity Capabilities Assessment Letter of Completion Status (NOFO: Appendix A)
Cybersecurity Capabilities Assessment Project Form (NOFO: Appendix B).
Local Cybersecurity Support Fund Project Proposal Application (NOFO: Appendix C)​
Maryland DoIT Cybersecurity Capabilities Assessment Verification Form & Instructions (NOFO: Appendix D)
Budget Narrative & Justification Template

Steps to Apply:

Applying for this award is a multi-step process and requires time to complete. Please read the overview below on how to apply.
 
  1. Review All Mandatory Instructional Documents & Forms:
    1. Maryland Local Cybersecurity Support Fund Notice Of Funding Opportunity (NOFO)
  2. Download & Complete the Following Documents:​

  3. To be completed by ALL Applicants:    

      1. Budget Narrative & Justification Template
      2. Cybersecurity Capabilities Assessment Letter of Completion Status form (Appendix A).

    To be completed, if applying for a Non-assessment Project.     

      1. Local Cybersecurity Support Fund Project Proposal Application

        

    Additional document to be completed by applicants that do not have a qualifying cybersecurity capabilities assessment completed in the last 12 months.    

      1. Cybersecurity Capabilities Assessment Project Form (Appendix B).

         
           

        This form is completed If you have not completed a cybersecurity assessment in the last 12 months, and are (1) submitting proof an assessment will be completed by a vendor within the next 12 months that will or will not require LCSF monies to support its completion, or (2) requesting to be signed on the the free Maryland Department of Information Technology Assessment Program to fulfill the cybersecurity assessment requirement.​

           

    (Note: Please email [email protected], if you are unable to download any of these documents).    

 
  1. ​​​​​ Email completed forms to [email protected]. Subject Line must be in this format:
    1. SFY27 LCSF- [Entity or Jurisdiction Name] [Project Title] Application Forms
    2. Example SFY27 LCSF- [MDEM]- [LCSF Project] Application Forms
  2. Maryland Department of Emergency Management will review project proposalsand provide contact information to the Maryland Department of Information Technology for Cybersecurity Capabilities Assessment Projects or Assessment Reviews.
  3. Applicants Project Manager will ensure that DoIT completes:
    1. Maryland DoIT Cybersecurity Capabilities Assessment Verification Form & Instructions (NOFO: Appendix D)
  1. DoIT/Applicant PM will send in Appendix D to[email protected].
  2. Receive project disposition
  3. MDEM will send the approved recipient an Award Agreement for signature
  4. Submit the Award Agreement within 30 Days to [email protected]. Subject Line must be in this format:
    1. SFY27 LCSF- [Jurisdiction Name] [Project Title] Award Agreement
    2. Example: SFY27 LCSF- [MDEM]- [LCSF Project] Award Agreement
  5. Funds are awarded by MDEM upon signature of the award agreement and its submission back to MDEM.

DO NOT START your project until you receive notification of MDEM approval AND have a fully executed Recipient Award Agreement (RA) contract in place.​
   

For a more comprehensive list of compliance instructions, refer to:   

  • the email received with your award notification
  • the published LCSF NOFO 

You can reach out to [email protected] with any questions.​   


Period of Performance (POP)
Your project must be completed within the period of performance for your fund cycle. Refer to the table below for performance dates as related to each fiscal year of funding:

  • FY2026 (application round one) - August 1st, 2026 – August 1st, 2028
  • FY2027 - TBD (based on the availability of additional funds)

Financial and Programmatic Reporting
Recipients are required to submit various financial and programmatic reports as a condition of award acceptance. Future awards and funds drawdown may be withheld if these reports are delinquent. Records of these reports, along with any additional documentation supporting the financial expenditures for the project should be held for at least 3 years after the end of the project's period of performance.

Financial (FPR) & Programmatic Performance Reporting (PPR) Requirements & Report Due Dates

I. Bi-annual Programmatic Report Form (PRF) - Recipients are responsible for providing updated performance reports on a bi-annual basis. The PFR should include a:

  • Brief narrative of overall project(s) status;
  • Summary of project expenditures;
  • Description of any potential issues that may affect project completion; and
  • Data collected for any additional Committee performance measure requirements.

II. Closeout Reporting (Final PRF)​ - Within 90 calendar days after the end of the period of performance for the prime award or after an amendment has been issued to close out an award before the original period of performance ends, recipients must liquidate all financial obligations and must submit the following:

  • The final request for payment, if applicable;
  • The final PRF;
  • The final progress report detailing all accomplishments, including a narrative summary of the impact of those accomplishments throughout the period of performance; and
  • Other documents required by this NOFO, terms and conditions of the award, or other Fund administrator(s) guidance.

After the prime award closeout reports have been reviewed and approved by the administrator(s), a closeout notice will be completed to close out the Fund. The notice will indicate the period of performance as closed, and address the requirement of maintaining the Fund’s records for at least three years from the date of the final PRF. The record retention period may be longer, such as due to an audit or litigation, for equipment or real property used beyond the period of performance, or due to other circumstances.

The recipient is responsible for refunding to the Fund administrator(s) any balances of unobligated cash that was paid that are not authorized to be retained.

III. Reporting Periods and Due Dates - A Project Report Form (PRF) must be submitted bi-annually throughout the period of performance, including in periods where no Fund award activity occurs. The final PRF is due within 90 calendar days after the end of the period of performance. Future awards and fund drawdowns may be withheld if these reports are delinquent, demonstrate a lack of progress, or are insufficient in detail.

Except for the final PRF due at 90 days after the end of the period of performance for purposes of closeout, the following reporting periods and due dates apply for the PRF.

  • For the reporting period of September 1, 2026 - February 28, 2027 - Year 1: Report 1, reports are due March 31, 2027.
  • For the reporting period of March 1, 2027 - August 31, 2027 - Year 1: Report 2, reports are due September 30, 2027.
  • For the reporting period of September 1, 2027 - February 28, 2028 - Year 2: Report 1, reports are due March 31, 2028.
  • For the reporting period of March 1, 2028 - August 31, 2028 - Final PRF, reports are due September 30, 2028.

          

Reimbursement Process
The LCSF is a reimbursement-based program. Recipients must submit requests to the SAA for approved project-related expenses.

When submitting a reimbursement request, subrecipients must ensure that all documentation is complete and accurate to prevent delays in the payment process. Documentation should clearly demonstrate an allowable purchase, directly related to the scope of work from your approved proposal and include both proof of purchase and the proof of payment.

Reimbursement requests and documentation must be emailed to: [email protected].

Download the LCSF Reimbursement Form here.


​​


Want to Learn More?

If you have any questions about the LCSF program, please email [email protected].

​ ​



​​​