Last updated: August 11, 2026
Quick Answer
Watch four public records. Renewal votes on tools the agency owns. Funded reviews and pen tests. Cyber insurance renewals. Consent agenda buys made through a state or regional contract. Each names a dollar amount. Each lands months before a formal bid. That is how you find a government cybersecurity RFP early.
- Civic IQ read 50 SLED security records dated May 12 to July 28, 2026, across 20 states and six agency types.
- The largest was $968,124 over a five-year term, approved by the City of Pasadena on May 19, 2026 for managed endpoint protection.
- Cherokee County, Georgia approved a $229,891 endpoint detection and response renewal on June 16, 2026.
- Waukegan CUSD 60 in Illinois budgeted $175,000 for security consulting and annual pen testing on June 22, 2026.
- Recorded city and district security spend in the sample reached at least $110,435.95, at the City of Arvada, Colorado.
What is the earliest public signal of a government security project?
The renewal vote on a tool they already own. Security money is rarely new money. It is a contract coming due. That renewal hits a public agenda with a number on it.
Cherokee County, Georgia is the clean example. On June 16, 2026 its IT team asked to renew endpoint detection and response. The amount was $229,891. That one record gives you the category, the budget, and the timing.
How do you find government security projects before the RFP?
Watch four record types. Each comes before a bid. All four are public.
- Renewals of existing security tools. A renewal is a live budget and a known incumbent.
- Funded assessments and pen tests. An assessment is the study that writes the next RFP.
- Cyber insurance renewals. Insurers impose controls. The control becomes a purchase, often one flagged in MS-ISAC advisories.
- Consent-agenda buys through a state or regional contract. These skip the local bid entirely, so the agenda item is the only notice you get.
The fourth matters most. It is also missed most. If an agency can buy off an existing contract, no RFP will ever post. See how vendors get on a cooperative purchasing contract.
Which agencies funded security work in the last 90 days?
These nine did, with amounts on the record. All are Civic IQ records from May to July 2026.
| Agency | State | Date (2026) | Amount | What it funds |
|---|---|---|---|---|
| City of Pasadena | California | May 19 | $968,124 | Managed endpoint protection and monitoring, five-year term |
| Cherokee County | Georgia | June 16 | $229,891 | Endpoint detection and response renewal |
| New Jersey agency, via NJ Edge | New Jersey | June 17 | $224,121 | SOC services, external pen test, vCISO consulting |
| Waukegan CUSD 60 | Illinois | June 22 | $175,000 | Cybersecurity consulting and annual pen testing |
| California school district | California | June 3 | $121,000 | Districtwide security review |
| Medford Public Schools | Massachusetts | June 2 | $109,255 | Cybersecurity package upgrade |
| South Dakota agency | South Dakota | July 13 | $85,123 | Endpoint Central cloud security subscription |
| Rhode Island Housing | Rhode Island | May 28 | $85,000 | IT security testing |
| Michigan agency | Michigan | July 16 | $34,848 | Three-year pen testing contract |
The signal that pays for itself
On May 19, 2026, Pasadena moved to approve managed endpoint protection. The cap was $968,124 over five years. A vendor reading that agenda knew the budget, the term, and the incumbent. Anyone watching bid boards knew none of it.
Who buys cybersecurity in state and local government?
More types than most vendors target. Our 50-record sample spanned six. Cities, counties, school districts, higher education, a public hospital, and a housing authority.
| Agency | State | Date (2026) | Signal |
|---|---|---|---|
| City of Carson | Nevada | May 12 | FY27 cybersecurity pen testing |
| Somerset County Vocational and Technical | New Jersey | June 22 | Endpoint protection purchase |
| Career and Technology Education center | Ohio | June 30 | Penetration testing engagement |
| Mammoth Hospital | California | May 21 | Security policy and SIEM work |
| Rhode Island Housing | Rhode Island | May 28 | Penetration testing and security consultation |
| Lehigh Career and Technical Institute | Pennsylvania | May 27 | Endpoint protection license |
| Pittsburg Unified | California | May 27 | Endpoint protection renewal |
Public hospitals and housing authorities buy security too. Almost nobody prospects them. That is a real gap. Many of them take their baseline controls from MS-ISAC and CIS. Their guidance shows what agencies fund next.
What do agencies actually spend on security?
Cities land in the tens of thousands a year. Districts and counties run higher. A platform renewal is what lifts them.
- City of Arvada, CO: at least $110,435.95 (Aug 9, 2023)
- Covina-Valley Unified, CA: at least $110,000.00 (Dec 12, 2023)
- City of Celina, TX: at least $95,385.00 (Feb 18, 2025)
- City of Fort Lupton, CO: at least $41,520.00 (Jan 1, 2024)
- City of Ellensburg, WA: at least $38,953.14 (Apr 18, 2023)
Each figure is a floor. Civic IQ keeps one purchase per vendor here. For the market view see government security spending in 2026.
How does this differ from watching bid boards?
Bid boards tell you a decision is final. Agendas tell you one is forming. The gap runs three to twelve months.
For schools, K12 SIX tracks district incidents and controls. NIGP publishes the buying standards. The method works past security. Finding SLED opportunities before the RFP applies the same record types to every category, and the SLED market guide explains who the buyers are.
If you sell into schools specifically, our K-12 cybersecurity vendor analysis has the district-side pricing detail.
Open RFPs related to this topic
Live opportunities surfaced by Civic IQ as of August 11, 2026. Status changes daily.
- Trinity Basin Preparatory Cybersecurity Pilot Program RFP, Trinity Basin Preparatory, Texas
- New Prague Managed Information Technology Services RFP 2026, City of New Prague, Minnesota
- Alabama Community College System technology, software, and hardware services RFP 2026, Alabama Community College System
Frequently asked questions
How do you find government security projects before the RFP?
Watch four public records. Renewals of tools they own. Funded reviews and pen tests. Cyber insurance renewals. Consent agenda buys made through a state or regional contract. Each names a dollar amount. All land before any bid posts.
Do all government security buys go through an RFP?
No, and that is the trap. Many are approved on a consent agenda using an existing state, regional, or cooperative contract, so no competitive bid is ever published. If you are only watching bid boards you never see those deals at all.
How much do cities and school districts spend on cybersecurity?
In our sample, funded items ran from $34,848 for a three-year pen testing contract to $968,124 for five years of managed endpoint protection. Recorded annual city spend reached at least $110,435.95 at the City of Arvada, Colorado.
Which agency types buy cybersecurity besides cities and schools?
Counties, higher education and career-technical centers, public hospitals, and housing authorities all funded security work in our 90-day sample. Public hospitals and housing authorities are rarely prospected, which makes them less competitive.
What does a funded security assessment tell a vendor?
That an RFP is being written. An assessment or pen test produces the findings that justify the next purchase, so the agency that just funded one is usually three to twelve months from buying remediation, tooling, or managed services.



