SOC 2 Readiness
24/7 Security Monitoring
Canadian-Based SOC
Government Security

State and Local Government Cybersecurity: Federal Requirements

Navigating the federal mandates, grant conditions, and frameworks that now govern SLTT security

GuardsArm Security Research7 min read6 chapters

Executive Summary

State, local, tribal, and territorial (SLTT) governments run the systems citizens depend on daily — benefits, courts, utilities, elections, and public safety — often on constrained budgets and aging infrastructure. They have become a favored target for ransomware operators, who correctly judge that a county that cannot process payments or a city that cannot dispatch emergency services is under intense pressure to pay.

In response, the federal government has moved from encouragement to conditions and requirements. Access to funding — most notably the State and Local Cybersecurity Grant Program (SLCGP) created by the Infrastructure Investment and Jobs Act — now depends on adopting specific security practices. Handling federal data, tax information, or criminal justice records has long carried its own binding standards.

Federal cybersecurity requirements for SLTT entities are no longer aspirational. They are increasingly the price of the grants, data-sharing agreements, and programs that state and local governments rely on.

This whitepaper maps the requirement landscape SLTT security leaders must navigate:

  • The SLCGP and the cybersecurity plan and control commitments attached to it.
  • Data-specific mandates: IRS Publication 1075, the FBI CJIS Security Policy, and HIPAA where applicable.
  • The role of CISA, the MS-ISAC, and the NIST Cybersecurity Framework as the common baseline.
  • How to translate a patchwork of mandates into one coherent, auditable program.

The Threat Reality Driving Federal Action

Federal requirements did not appear in a vacuum. They are a direct response to a wave of attacks that repeatedly crippled public services.

Why SLTT is targeted

Attackers pursue SLTT entities because they combine high impact with soft defenses. A ransomware incident that halts a city's operations creates immediate public pressure, and many jurisdictions historically lacked dedicated security staff, current systems, or incident response plans.

The ransomware pattern

High-profile incidents against major cities and county governments demonstrated a consistent story: initial access through phishing or an exposed remote service, lateral movement across a flat network, encryption of critical systems, and weeks of disrupted services and costly recovery — frequently exceeding any ransom demand.

Interconnected risk

SLTT systems connect to federal programs, share data with each other, and increasingly rely on the same vendors. A compromise in one jurisdiction can expose shared services and data, which is precisely why the federal government treats SLTT security as a national concern rather than a purely local one.

The federal calculus is straightforward: SLTT entities operate critical services and connect to federal systems, so their weaknesses become everyone's exposure. That logic underpins every requirement that follows.

The State and Local Cybersecurity Grant Program

The most significant federal lever is funding tied to conditions. The State and Local Cybersecurity Grant Program (SLCGP), administered by CISA and FEMA, directs substantial funding to SLTT entities — but attaches requirements.

Funding with strings

To receive SLCGP funds, a state must establish a Cybersecurity Planning Committee and develop a Cybersecurity Plan that meets program elements. A defined share of funding must pass through to local governments, and rural jurisdictions must receive a minimum allocation.

Required plan elements

The cybersecurity plan must address federally specified elements, including:

  • Adopting the NIST Cybersecurity Framework as the organizing structure.
  • Implementing baseline practices such as multi-factor authentication, encryption, and eliminating unsupported systems.
  • Migrating to .gov domains for official state and local sites.
  • Enhancing preparedness through the MS-ISAC and CISA services.

Required best practices

Program guidance directs entities toward specific controls: phishing-resistant MFA, robust logging, a move away from end-of-life software, and adoption of CISA's Cyber Hygiene services. The grant, in effect, funds a defined maturity uplift rather than open-ended spending.

SLTT leaders should treat the cybersecurity plan not as a grant formality but as the actual roadmap the funding is meant to execute.

Data-Specific Mandates: CJIS, IRS 1075, and HIPAA

Independent of grants, any SLTT entity that handles particular categories of federal or regulated data is bound by long-standing, enforceable security standards.

FBI CJIS Security Policy

Agencies that access criminal justice information — law enforcement, courts, and their vendors — must comply with the FBI CJIS Security Policy. It mandates advanced authentication, encryption, audit logging, personnel screening, and physical protection, and compliance is audited. Recent revisions have strengthened multi-factor authentication expectations.

IRS Publication 1075

Entities that receive Federal Tax Information (FTI) — many state revenue, benefits, and child-support agencies — must meet IRS Publication 1075, which maps to NIST SP 800-53 controls. Non-compliance can cut off access to the federal data a program depends on, and the IRS conducts safeguard reviews.

HIPAA and CMS requirements

SLTT health and human-services agencies handling protected health information are subject to the HIPAA Security Rule, and Medicaid systems face additional CMS security expectations.

These mandates predate the grant programs and are not optional. A single agency often falls under several at once — a county sheriff's office may face CJIS, while the adjacent tax office faces IRS 1075 — so requirements must be reconciled, not handled in isolation.

The Federal Support Ecosystem

Alongside requirements, the federal government provides resources SLTT entities are expected — and sometimes required — to use. Knowing this ecosystem is part of meeting the mandates efficiently.

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) is the federal lead for SLTT support. It offers no-cost services: Cyber Hygiene vulnerability scanning, penetration testing, incident response assistance, and the Known Exploited Vulnerabilities catalog that prioritizes patching.

The MS-ISAC

The Multi-State Information Sharing and Analysis Center (MS-ISAC), operated by the Center for Internet Security under CISA sponsorship, is the focal point for SLTT threat intelligence. Membership is free and provides advisories, a 24/7 security operations center, Malicious Domain Blocking, and incident response support. SLCGP guidance actively steers entities toward MS-ISAC participation.

The CIS benchmarks and controls

The CIS Critical Security Controls and CIS Benchmarks give SLTT entities a concrete, prioritized implementation path that complements the higher-level NIST framework.

These resources are largely free. An SLTT entity that is not enrolled in the MS-ISAC and not using CISA's no-cost scanning is leaving both security value and grant-alignment on the table — usually the first gap GuardsArm flags in an assessment.

NIST CSF as the Unifying Baseline

Faced with CJIS, IRS 1075, HIPAA, and grant conditions, SLTT leaders need a single organizing framework. The NIST Cybersecurity Framework (CSF) is that common denominator — and grant programs explicitly point to it.

The CSF functions

CSF 2.0 organizes security around six functions:

  • Govern — establishing roles, policy, and risk oversight (new in 2.0).
  • Identify — inventorying assets, data, and risks.
  • Protect — access control, training, and safeguards.
  • Detect — monitoring and detection.
  • Respond — incident response and communications.
  • Recover — restoration and resilience.

Why CSF for SLTT

The CSF is flexible enough to scale from a small township to a large state, and it maps to the underlying NIST SP 800-53 controls that CJIS and IRS 1075 draw on. Building a program around CSF lets an entity satisfy multiple mandates with one control set rather than maintaining separate stovepipes.

Mapping mandates to one framework

The efficient approach is to build a single CSF-aligned control set, then map each control to the mandates it satisfies — MFA to SLCGP and CJIS, encryption to IRS 1075 and HIPAA, logging to all of them. GuardsArm's compliance readiness assessments build exactly this crosswalk so SLTT clients prove multiple requirements from one program.

Building a Compliant, Fundable Program

Meeting federal requirements is a program, not a purchase. SLTT entities that treat it as a coherent effort satisfy mandates and position themselves for continued funding.

Start with assessment and a plan

Inventory systems and data, determine which mandates apply, and score current maturity against the NIST CSF. The gaps become the roadmap — and, conveniently, the substance of the cybersecurity plan the SLCGP requires.

Prioritize high-impact baseline controls

  • Phishing-resistant MFA everywhere, prioritizing remote access and privileged accounts.
  • Eliminate end-of-life systems and enforce timely patching against the KEV catalog.
  • Segment networks so one compromise does not become jurisdiction-wide.
  • Establish and test an incident response plan with defined roles and MS-ISAC contacts.
  • Deploy logging and monitoring sufficient to detect and investigate intrusions.

Address the resource gap

Many SLTT entities lack in-house security staff. Shared services, cooperative purchasing, and managed security partners are legitimate — often expected — ways to meet requirements. Grant funds can support these arrangements.

GuardsArm supports SLTT organizations with gap assessments, incident response readiness, and managed detection — helping smaller jurisdictions meet federal requirements they cannot staff for internally, while building genuine resilience rather than paper compliance.

Key Takeaways

  • 1.Federal cybersecurity requirements for SLTT governments are now enforced through grant conditions and data-sharing mandates, not just guidance.
  • 2.The SLCGP funds a defined maturity uplift — a NIST CSF-based cybersecurity plan, MFA, encryption, .gov migration, and retirement of unsupported systems.
  • 3.Handling regulated data triggers binding, audited standards: FBI CJIS for criminal justice, IRS Publication 1075 for federal tax information, and HIPAA for health data.
  • 4.CISA's no-cost services and free MS-ISAC membership are core expected resources; not using them leaves both security value and grant alignment unclaimed.
  • 5.Build one NIST CSF-aligned control set and map each control to the mandates it satisfies, so a single program proves compliance across CJIS, IRS 1075, HIPAA, and the SLCGP.

Sources & Further Reading

  1. CISA and FEMA, State and Local Cybersecurity Grant Program (SLCGP) Notice of Funding Opportunity
  2. NIST Cybersecurity Framework (CSF) 2.0
  3. FBI Criminal Justice Information Services (CJIS) Security Policy
  4. IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies
  5. Center for Internet Security, Multi-State ISAC (MS-ISAC) resources
  6. NIST Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations

Turn this research into a plan

Our team maps findings like these onto your environment and hands you a prioritized roadmap — not another report to file away.

Book a Free Consultation

Related Whitepapers