Assistance Listing 97.128
CISA Cyber Security Awareness Campaign
Department of Homeland Security · Cybersecurity and Infrastructure Security Agency
Assistance Listing 97.128, “CISA Cyber Security Awareness Campaign,” is a federal program administered by Department of Homeland Security. It provides cooperative agreement assistance. GrantsJunction currently tracks 0 open, 0 forecasted and 1 closed opportunities under this listing. The agency reported $437K in obligations for fiscal year 2025.
- Funding down 21% (FY24→FY25)Actual obligations reported in the SAM.gov listing changed -21% from FY2024 to FY2025. Historical data, not a prediction. calculated by GrantsJunction
Program objective
CISA’s mission is to lead the national effort to understand, manage, and reduce risk to our cyber and physical infrastructure. In carrying out this mission, Section 2202 of the Homeland Security Act of 2002 assigns CISA with the responsibilities to coordinate a national effort to secure and protect against critical infrastructure risks, carry out cybersecurity and critical infrastructure stakeholder outreach and engagement, and encourage and build cybersecurity awareness and competency across the United States. In carrying out its mission and pursuant to these authorities, CISA provides financial assistance under the CAC Program to non-federal entities to perform cybersecurity awareness activities to reduce cybersecurity risks through messaging, tools, and resources to encourage individuals and organizations to reduce their exposure to malicious cyber activity. Through strategies implemented year-round with a focal point of the Cybersecurity Awareness Month in October, a recipient under this federal award engaged in efforts to improve the public’s understanding of cyber threats, amplify opportunities that individuals and non-federal entities can leverage to strengthen their own cybersecurity posture, and encourage discussion, engagement, and actions that can be taken to reduce cyber risk. For the CAC program, CISA established the following six goals: 1. Strengthen the security and resilience of critical infrastructure; 2. Assess and counter evolving cybersecurity risks through actions that promote threat risk reduction; 3. Build a national culture of preparedness for all Americans, ensuring equity and accessibility in our efforts to increase online and digital safety; 4. Build stakeholder relationships that encourage and support data-driven actions by governments, the private sector, tribes, non-profits, and the public that reduce cybersecurity risk; 5. Reinforce the importance of secure by default and secure by design industry practices that do not place the first line of cyber threat risk reduction on those with the least capabilities and resources; and 6. Encourage activities supported by data which result in key behavior change that reduce cyber risk. CISA established the following six objectives for the CAC Program: 1. Educate the public, small businesses, and industry about the dangers of cyber threats and key actions that can be taken to mitigate risks; 2. Promote sustainable cybersecurity and encourage the technology industry to provide secure-by-default technology products with strong security features right out of the box, without added costs; and technology that is secure-by-design, purposefully developed, built, and tested to significantly reduce the number of exploitable flaws before they are introduced into the market for broad use; 3. Identify effective approaches to increase cybersecurity awareness among the general public and target audiences, including vulnerable populations and those with disabilities that may make it challenging to take actions that reduce risk; 4. Build relationships and coalitions across cybersecurity stakeholders to support Cybersecurity Awareness Month; 5. Develop a baseline from which to measure the impact Cybersecurity Awareness Month campaign strategies and messaging has on changing behavior and increasing public awareness of cybersecurity risk; and 6. Contribute to the agency’s efforts to build a culture of preparedness, by informing and empowering communities and individuals to obtain the skills and take the preparatory actions necessary to become more resilient against threats and hazards Americans face.
As published in the SAM.gov Assistance Listing.
Current opportunities under 97.128
No open or forecasted opportunities are currently posted under this listing. Programs often post notices on an annual cycle — see recently closed opportunities below for timing.
Eligible applicants (program level)
- Nonprofit Organization
Nonprofit organizations, other than institutions of higher education, with an effective ruling letter from the U.S. Internal Revenue Service granting tax exemption under Section 501(c)(3) of the Internal Revenue Code of 1986 A recipient under the Cybersecurity Awareness Campaign Program must be a nonprofit organization with an effective ruling letter from the U.S. Internal Revenue Service granting tax exemption under Section 501(c)(3) of the Internal Revenue Code of 1986. A “nonprofit organization” means any organization that: (1) is operated primarily for scientific, educational, service, charitable, or similar purposes in the public interest; (2) is not organized primarily for profit; (3) uses net proceeds to maintain, improve, or expand the organization’s operations; and (4) is not an institution of higher education as defined at 20 U.S.C. § 1001.
Intended beneficiaries: Public nonprofit institution/organization.
Program-level eligibility from SAM.gov. Each funding notice sets its own requirements.
Reported obligations by fiscal year
Historical data · not a predictionRange and average of financial assistance (from the listing): CISA awarded a competitive cooperative agreement to a single non-profit organization in FY 2023 with a 29-month period of performance comprised of three budget periods. The funding awarded for the initial 1-year budget period was $549,996 and projected continuation funding to be awarded for the second 1-year budget period is $549,996. Therefore, the range of financial assistance per 1-year budget period is $549,996 and the average is $549,996.
Source: SAM.gov Assistance Listing 97.128. Hatched bars are agency estimates. These totals do not indicate approval rates.Recently closed under 97.128
| Opportunity | Status | Award range | Closes | ALN |
|---|---|---|---|---|
Internet Security - Information Sharing and Analysis Organizations (IS-ISAO) PilotOffice of Procurement Operations - Grants Division | Closed | $3M | Sep 17, 2018 | 97.128 |
Frequently asked questions
What is ALN 97.128?
97.128 is the Assistance Listing Number for “CISA Cyber Security Awareness Campaign.” Assistance Listing Numbers (formerly CFDA numbers) identify federal assistance programs; individual grant opportunities reference the listing they are funded under.
Who can apply under ALN 97.128?
The SAM.gov listing names these applicant types: Nonprofit Organization. Each funding notice under the program sets its own eligibility, so check the specific opportunity.
How much funding does 97.128 provide?
The agency reported $436,997 in obligations for FY2025 in the SAM.gov Assistance Listing. These are program-wide totals reported by the agency, not a prediction of future awards.