After the MS-ISAC Funding Change: How States Can Protect Shared Cyber Coverage
Back to Signal
State & LocalCybersecurityGovernmentCritical Infrastructure

After the MS-ISAC Funding Change: How States Can Protect Shared Cyber Coverage

September 17, 2026Jess Loban
Image: Spartan X Corp

What changed in the funding model

MS-ISAC has provided state, local, tribal, and territorial governments with shared threat intelligence, security operations support, and other cybersecurity resources. Its operator, the Center for Internet Security (CIS), confirms that federal support ended September 30, 2025, and that a member-funded model began October 1. The loss of the subsidy changed the economics of participation; it did not mean the shared-service model ceased to exist. A jurisdiction that could not independently staff a round-the-clock security function may still benefit from pooled services, but it must now identify a sustainable purchasing arrangement.

Our focus is the continuity question that follows a funding change: which protections remain available, to whom, and on what terms? CIS: MS-ISAC membership FAQ and transition dates.

Coverage changes depend on the actual agreement

CIS describes phased offboarding for organizations that do not engage in the membership process, as well as specific transition arrangements for existing paid services and federally funded endpoint coverage. Those details matter more than a simple paid-versus-unprotected label. A statewide membership may cover multiple entities, but the buyer must confirm enrollment and included capabilities. An organization may also retain other protections from its state, a commercial provider, or its own team. Single-organization membership also remains an option; statewide purchasing is not the only route to coverage.

Budget pressure creates a risk of service gaps; it does not prove every nonmember has no protection.

Why affordability can become a security gap

A paid model can produce an affordability problem. A large security program may absorb a recurring fee more easily than a small county with one or two general IT staff. The smaller jurisdiction may also have greater dependence on shared expertise. The effect will depend on local budgets, existing coverage, and access to other services. States should measure the impact directly: which entities lost access, which substituted another service, and which are now missing monitoring or response support?

That inventory lets leaders target assistance rather than assume that either universal coverage or universal abandonment followed the funding change. Shared purchasing, regional cooperation, and targeted support can be evaluated against those observed gaps.

Check grant eligibility instead of assuming it

Federal grant availability and allowable costs need their own review. A request to restore or reauthorize a program is not an enacted appropriation, and the expiry of an authorization does not establish that every prior award or service ended on that date. NASCIO's 2026 advocacy priorities call for continued support for state and local cybersecurity. Buyers considering State and Local Cybersecurity Grant Program funds should check the current award terms, applicable guidance, and any required prior approval with the administering agency. Do not assume either that MS-ISAC membership is always eligible or that it is categorically prohibited under every award.

Record the determination in the funding plan, along with a fallback if approval or future funds do not materialize.

For FY 2025, CISA's published SLCGP changes specifically require FEMA approval in advance for membership costs and describe a four-year award performance period. Those are concrete conditions to bring to the grant administrator; neither implies automatic approval for a particular membership. CISA FY 2025 guidance.

Retain enough internal capacity to direct the response

The deeper lesson is the difference between purchasing help and retaining responsibility. A shared service can extend a state's capability, but the state still needs people who know its assets, can make containment decisions, and can direct restoration. It is not necessary—or affordable—for every small jurisdiction to reproduce a full SOC internally. It is necessary to know which decisions remain local and which tasks the provider performs. Building staff, regional partnerships, and response procedures takes time; a sudden contract or funding change exposes that dependency.

Preserve system ownership, incident contacts, essential documentation, and the ability to work with a replacement provider. That is a more practical resilience objective than treating self-sufficiency as an all-or-nothing requirement.

Make continuity part of every shared-service contract

Shared-service procurement should include the possibility that price, scope, funding, or access will change. Evaluate the total cost of continuity, not simply the annual membership line. Ask how alerts, retained evidence, reports, configurations, and knowledge transfer will be handled at exit. Identify which functions require uninterrupted operation and which can tolerate a temporary manual process. Set review dates early enough to make a purchasing decision before coverage expires. Shared services can remain the right economic choice, especially for smaller jurisdictions; the lesson is to make dependencies explicit and manageable.

A tested fallback and a named risk owner turn a funding surprise into a planned transition rather than an unassigned operational gap.

Check coverage before the renewal window closes

A continuity plan needs a service-by-service answer, including the capabilities that are easiest to overlook.

  1. Inventory the services actually used. List intelligence feeds, monitoring, incident response, training, endpoint coverage, and add-ons with an owner and renewal date for each.
  2. Confirm coverage in writing. Verify whether a statewide arrangement covers local entities, what onboarding is required, and which services have separate fees or transition dates.
  3. Test the replacement before access ends. Confirm alert delivery, escalation contacts, log availability, and who will investigate an incident outside office hours.
  4. Check funding allowability. Obtain the grant administrator's written determination and any required FEMA approval before budgeting a membership charge to a federal award.
  5. Practice operating without the service. Run a short continuity exercise, preserve critical contacts and evidence, and document which capabilities cannot be maintained internally.

Sources and further reading

Spartan X's cybersecurity and program execution perspective is straightforward: shared services are valuable when their dependencies are understood, their responsibilities are explicit, and the customer retains a workable path through change.

Share this article
LinkedIn

BUILD WITH US

Ready to Solve Hard Problems?

Spartan X builds AI systems, autonomous platforms, and cybersecurity solutions for defense and national security.