Back to Insights
Insights5 min read

How to Find Government Cybersecurity Projects Before the RFP

Abbas Khan
Abbas KhanAugust 13, 2026
How to Find Government Cybersecurity Projects Before the RFP



Last updated: August 11, 2026

Quick Answer

Watch four public records. Renewal votes on tools the agency owns. Funded reviews and pen tests. Cyber insurance renewals. Consent agenda buys made through a state or regional contract. Each names a dollar amount. Each lands months before a formal bid. That is how you find a government cybersecurity RFP early.

  • Civic IQ read 50 SLED security records dated May 12 to July 28, 2026, across 20 states and six agency types.
  • The largest was $968,124 over a five-year term, approved by the City of Pasadena on May 19, 2026 for managed endpoint protection.
  • Cherokee County, Georgia approved a $229,891 endpoint detection and response renewal on June 16, 2026.
  • Waukegan CUSD 60 in Illinois budgeted $175,000 for security consulting and annual pen testing on June 22, 2026.
  • Recorded city and district security spend in the sample reached at least $110,435.95, at the City of Arvada, Colorado.

What is the earliest public signal of a government security project?

The renewal vote on a tool they already own. Security money is rarely new money. It is a contract coming due. That renewal hits a public agenda with a number on it.

Cherokee County, Georgia is the clean example. On June 16, 2026 its IT team asked to renew endpoint detection and response. The amount was $229,891. That one record gives you the category, the budget, and the timing.


How do you find government security projects before the RFP?

Watch four record types. Each comes before a bid. All four are public.

  1. Renewals of existing security tools. A renewal is a live budget and a known incumbent.
  2. Funded assessments and pen tests. An assessment is the study that writes the next RFP.
  3. Cyber insurance renewals. Insurers impose controls. The control becomes a purchase, often one flagged in MS-ISAC advisories.
  4. Consent-agenda buys through a state or regional contract. These skip the local bid entirely, so the agenda item is the only notice you get.

The fourth matters most. It is also missed most. If an agency can buy off an existing contract, no RFP will ever post. See how vendors get on a cooperative purchasing contract.


Which agencies funded security work in the last 90 days?

These nine did, with amounts on the record. All are Civic IQ records from May to July 2026.

Agency State Date (2026) Amount What it funds
City of Pasadena California May 19 $968,124 Managed endpoint protection and monitoring, five-year term
Cherokee County Georgia June 16 $229,891 Endpoint detection and response renewal
New Jersey agency, via NJ Edge New Jersey June 17 $224,121 SOC services, external pen test, vCISO consulting
Waukegan CUSD 60 Illinois June 22 $175,000 Cybersecurity consulting and annual pen testing
California school district California June 3 $121,000 Districtwide security review
Medford Public Schools Massachusetts June 2 $109,255 Cybersecurity package upgrade
South Dakota agency South Dakota July 13 $85,123 Endpoint Central cloud security subscription
Rhode Island Housing Rhode Island May 28 $85,000 IT security testing
Michigan agency Michigan July 16 $34,848 Three-year pen testing contract

The signal that pays for itself

On May 19, 2026, Pasadena moved to approve managed endpoint protection. The cap was $968,124 over five years. A vendor reading that agenda knew the budget, the term, and the incumbent. Anyone watching bid boards knew none of it.


Who buys cybersecurity in state and local government?

More types than most vendors target. Our 50-record sample spanned six. Cities, counties, school districts, higher education, a public hospital, and a housing authority.

Agency State Date (2026) Signal
City of Carson Nevada May 12 FY27 cybersecurity pen testing
Somerset County Vocational and Technical New Jersey June 22 Endpoint protection purchase
Career and Technology Education center Ohio June 30 Penetration testing engagement
Mammoth Hospital California May 21 Security policy and SIEM work
Rhode Island Housing Rhode Island May 28 Penetration testing and security consultation
Lehigh Career and Technical Institute Pennsylvania May 27 Endpoint protection license
Pittsburg Unified California May 27 Endpoint protection renewal

Public hospitals and housing authorities buy security too. Almost nobody prospects them. That is a real gap. Many of them take their baseline controls from MS-ISAC and CIS. Their guidance shows what agencies fund next.

Catch the renewal, not the RFP
Civic IQ read 50 SLED security records across 20 states in one 90-day window, most of them renewals and assessments that never became a public bid.

See Civic IQ →


What do agencies actually spend on security?

Cities land in the tens of thousands a year. Districts and counties run higher. A platform renewal is what lifts them.

  • City of Arvada, CO: at least $110,435.95 (Aug 9, 2023)
  • Covina-Valley Unified, CA: at least $110,000.00 (Dec 12, 2023)
  • City of Celina, TX: at least $95,385.00 (Feb 18, 2025)
  • City of Fort Lupton, CO: at least $41,520.00 (Jan 1, 2024)
  • City of Ellensburg, WA: at least $38,953.14 (Apr 18, 2023)

Each figure is a floor. Civic IQ keeps one purchase per vendor here. For the market view see government security spending in 2026.


How does this differ from watching bid boards?

Bid boards tell you a decision is final. Agendas tell you one is forming. The gap runs three to twelve months.

For schools, K12 SIX tracks district incidents and controls. NIGP publishes the buying standards. The method works past security. Finding SLED opportunities before the RFP applies the same record types to every category, and the SLED market guide explains who the buyers are.

If you sell into schools specifically, our K-12 cybersecurity vendor analysis has the district-side pricing detail.

Know the renewal date before the incumbent does
Civic IQ tracks security renewals, assessments, and consent agenda approvals across 80,000+ agencies, with the amount and term on the record.

Get a Demo →

Open RFPs related to this topic

Live opportunities surfaced by Civic IQ as of August 11, 2026. Status changes daily.

Track every RFP in your category with Civic IQ →

Frequently asked questions

How do you find government security projects before the RFP?

Watch four public records. Renewals of tools they own. Funded reviews and pen tests. Cyber insurance renewals. Consent agenda buys made through a state or regional contract. Each names a dollar amount. All land before any bid posts.

Do all government security buys go through an RFP?

No, and that is the trap. Many are approved on a consent agenda using an existing state, regional, or cooperative contract, so no competitive bid is ever published. If you are only watching bid boards you never see those deals at all.

How much do cities and school districts spend on cybersecurity?

In our sample, funded items ran from $34,848 for a three-year pen testing contract to $968,124 for five years of managed endpoint protection. Recorded annual city spend reached at least $110,435.95 at the City of Arvada, Colorado.

Which agency types buy cybersecurity besides cities and schools?

Counties, higher education and career-technical centers, public hospitals, and housing authorities all funded security work in our 90-day sample. Public hospitals and housing authorities are rarely prospected, which makes them less competitive.

What does a funded security assessment tell a vendor?

That an RFP is being written. An assessment or pen test produces the findings that justify the next purchase, so the agency that just funded one is usually three to twelve months from buying remediation, tooling, or managed services.

Abbas Khan

Written by

Abbas Khan

Bring us your territory.
We'll show you what is forming.

B2G and SLED sales intelligence. Surface government procurement signals from 80,000+ state, local, and education agencies months before the RFP.

Try Civic IQ for free