Frequently Asked Questions
Common questions about the Cyber Pen Testing Grant.
What is the Cyber Pen Testing Grant?
The Cyber Pen Testing Grant provides a professional cybersecurity risk assessment and penetration test package for eligible organizations, funded through sponsor support rather than direct payment by the recipient. The service is positioned as a one-time engagement valued at approximately $5,000, focused on uncovering risks before they are exploited.
Who is eligible to apply?
The grant is designed for active organizations such as small and midsize businesses, nonprofits, and similar entities that have at least a basic operating footprint and cyber risk exposure. Programs typically prioritize organizations with minimum revenue and staff size thresholds, as well as those operating in sectors with higher cyber risk or compliance requirements.
What does the grant include?
Recipients receive a third-party penetration test, also known as a cybersecurity risk assessment, that can include external and internal testing, vulnerability identification, and validation of security controls. Deliverables usually include a detailed report with technical findings, executive-level summaries, and prioritized remediation recommendations that can be shared with leadership and auditors.
Does the grant cover all costs?
The grant covers the defined penetration testing and assessment service provided by the sponsoring cybersecurity firm, so the recipient does not pay for the testing itself. Organizations may still incur internal costs related to remediation efforts, changes to infrastructure, or follow-on projects that go beyond the scope of the grant engagement.
How do we apply and what is the timeline?
Organizations can start the process by submitting an application through the Cyber Grants Alliance website, providing basic organizational and cybersecurity information for review. Applications are reviewed on a rolling basis tied to available sponsored capacity, and selected applicants are contacted directly with next steps and scheduling details.