CWX-028-CESER: Rural and Municipal Utility Cybersecurity (RMUC) Program’s Advanced Cybersecurity Technical Assistance (TA)

Active Solicitation

Submission Deadline: October 20th, 2026 2PM ET.
Questions? Reach out to us at [email protected]

Description

The Rural and Municipal Utility Cybersecurity (RMUC) Program’s Advanced Cybersecurity Technical Assistance (TA) Program provides support funded by section 40124 of the Infrastructure Investment and Jobs Act (IIJA), codified at 42 U.S.C. § 18723. The cybersecurity landscape for critical infrastructure, particularly the electric grid, is constantly evolving, with increasing threats from various actors. Rural and municipal utilities, despite their vital role in delivering electricity, often face unique challenges in securing their systems due to limited financial, technical, and personnel resources. This leaves them vulnerable to cyberattacks that could disrupt power supply, impact economic activity, and undermine national security.

This program specifically addresses the cybersecurity needs of these underserved utilities. The primary focus of this initiative is to leverage the expertise and reach of relevant organizations, specifically not-for-profit entities demonstrating a partnership with six or more utilities, to achieve widespread impact and facilitate critical improvements across the sector.

The selected not-for-profit entities will provide technical assistance and facilitate information sharing, directly supporting the resilience and reliability of the bulk-power system and defense-critical electric infrastructure across the United States. It aligns with broader Department of Energy (DOE) efforts to modernize and secure energy infrastructure.

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) anticipates seeking applications from eligible not-for-profit organizations through the RMUC TA Partnership Intermediary Agreement (PIA).

The anticipated opportunity will provide funding to selected not-for-profit performers to deliver cybersecurity technical assistance, technologies, services, and other support to eligible electric utilities. Applicants are expected to demonstrate formal partnerships with no fewer than six (6) qualifying electric utilities and the capability to deliver meaningful cybersecurity improvements across participating utilities.

Applicants may propose activities under one or both of two focus areas:

  • System Hardening/Technical Assistance
  • Cybersecurity Threat Information Sharing

Supported activities may include, but are not limited to: cybersecurity assessments and planning; workforce training and certification; exercises and readiness; implementation and integration of cybersecurity tools and technologies; verification and validation; cybersecurity threat information-sharing activities; and other activities that support measurable improvements in the cybersecurity posture and resilience of eligible utilities.

DOE has made $100 million available for the RMUC TA program. Additional information regarding eligibility, anticipated award amounts, periods of performance, application requirements, evaluation criteria, milestones, and the opportunity schedule is provided below.

ConnectWerx (CWX), a DOE Partnership Intermediary, will administer the opportunity in collaboration with CESER. This announcement is a funding opportunity and interested organizations should submit applications in response to this notice.

How to Apply

First, request access to AMP. Once access has been granted, you may proceed with submitting your proposal through the CWX Submission Portal.

Complete your application through the CWX submission portal and all required project information and supporting documentation. Submissions must include the required documents as indicated in the chart below, using the provided templates (hyperlinked below).

Submissions are due no later than October 20, 2026 at 2 PM ET.

File TitleMax PagesFile Type
Project Overview & Plan6 (Times New Roman 12 font, which includes graphs and pictures on all PDFs)PDF
Project Schedule & Gantt ChartPDF
Cost Proposal/Project Budget1 page per period of performance (submitted as one file)XLS
Key Personnel (Resumes)2 pages per person (submitted as one file)PDF
Letters of Support5PDF

Submission Requirements

Responses shall be submitted by the date and time specified above.

Files shall be submitted in Microsoft Office or Adobe Acrobat format, no larger than 5MB. ZIP files and other application formats are not acceptable. All files shall be print-capable, without a password. Filenames must contain the appropriate extension and shall not contain special characters*. Appropriate files extensions are:

Application / FileValid Extensions
Portable Document Files (Adobe Acrobat PDF).pdf
Microsoft Word (MS Word).doc / .docx
Microsoft Excel.xls

Late submissions will not be accepted. Submissions can be made in advance of the deadline and edited (or files replaced) up to the deadline.

Objective

The overall objective of this program is to strengthen the operational and cybersecurity resilience of electric rural cooperatives, municipally owned utilities, or utilities owned by a State or political subdivision, by providing technical assistance and shared services.

$100M has been made available for the RMUC TA program. CESER will evaluate applications based on the eligibility requirements, merit of the application, and the selectee’s ability to maintain and manage a project that provides the required technical assistance support.

Key objectives include:

  • System Hardening: Technical assistance to support the selection and implementation of cybersecurity best practices, policies, and tools that result in verifiable documented improvements in cybersecurity posture.
  • Threat Intelligence Sharing: Establishing and maintaining improved utility capabilities to utilize and share threat intelligence using a streamlined framework among information sharing partners.
  • Infrastructure Protection: Promoting innovative solutions for overall energy infrastructure defense.

Scope of Supported Activities

Applicants may propose activities under one or both of the following Focus Areas, which may be submitted as a single combined proposal or as separate efforts:

Focus Area 1: Technical Assistance Program

Applicants develop and operate a technical assistance program for eligible utilities to improve their capability to protect against, detect, respond to, and/or recover from cybersecurity threats. Supported activities include, but are not limited to:

Guiding utilities through the implementation of relevant Executive Orders.

Purchasing, assisting, or integrating cybersecurity tools, software, operational tools, and related assets (including but not limited to Project Armor hardening initiatives).

Identifying, assessing, and supporting the mitigation of cybersecurity risks using assessment methodologies and tools appropriate to the utility’s cybersecurity maturity, capabilities, and available cybersecurity resources. Such methodologies and tools may include, but are not limited to, Consequence-driven, Cyber-Informed, Engineering (CCE) assessments, Cybersecurity Capability Maturity Model (C2M2) evaluations, the National Rural Electric Cooperative Association’s (NRECA) Cyber Goals, the American Public Power Association’s (APPA) Cybersecurity Accelerator Program assessment tools, and other relevant cybersecurity assessment, gap-analysis, or maturity frameworks.

Building cybersecurity improvement plans, incident response plans, and business continuity plans; modifying policies and procedures; and developing Standard Operating Procedures (SOPs).

Supporting and funding relevant cybersecurity training opportunities, including, but not limited to, professional training and certification-granting programs for eligible utility personnel. Associated travel costs may be considered subject to applicable program requirements and DOE approval.

Designing, facilitating, and executing functional readiness drills and Tabletop Exercises (TTXs) to evaluate threat response protocols.

Supporting post-implementation technical assistance and services to ensure changes in practices and integration of new tools successfully lower cybersecurity risk and provide follow-up support to address findings.

Focus Area 2: Cybersecurity Threat Information Sharing

Applicants develop and deliver a Protective Domain Name System (PDNS) service that strategically maximizes impact and strengthens cybersecurity posture. Program activities under this focus area encompass:

Providing essential capabilities via centralized DNS resolvers, including:

  • Real-time Threat Blocking
  • Granular Content Filtering
  • Customizable Policies
  • Global Server Load Balancing (GSLB) and Anycast Networks
  • DNSSEC Validation
  • Visibility, Reporting, and Analytics
  • Security Integration Capabilities
  • Deployment Flexibility
  • DDoS Protection

Coordinating with CESER’s Energy Threat Analysis Center (ETAC) and established threat-sharing programs like but not limited to the Cybersecurity Risk Information Sharing Program (CRISP) to ensure timely communication, exclusive threat sharing via PDNS resolver operational data, and PDNS vendor onboarding.

Ensuring all sensitive utility and intelligence data is handled and protected in accordance with federal requirements.

Event Updates

Program Planning: The program is currently aligning schedules and preparing for launch. Specific webinar dates and office hours will be posted here as soon as they are finalized.

How to Participate

  1. Review the Opportunity Details
    Eligibility requirements, evaluation criteria, and application instructions on the RMUC opportunity page.
  2. Review Office Hours Materials & Submit Questions
    Informational “Office Hours” presentation and submit any questions here.
  3. Download the Required Templates
    Project Overview & Plan, Project Schedule & Gantt Chart, and Cost Proposal/Project Budget templates. Complete and save the templates for submission.
  4. Register for the CWX Acquisition Management Portal (AMP)
    Request access to the CWX AMP by completing the registration form.
  5. Complete and Submit Your Application
    CWX-028-RMUC Submission Form and upload all required documents through the CWX AMP system. Applications must be submitted no later than October 20, 2026, at 2 PM ET.

Important Dates & Resources

Submission Deadlines

Tuesday, October 20, 2026 at 2 PM ET

Information “Office Hours” Session(s)

Informational “Office Hours” presentation is available for review and submit questions here.

Process Details

Timelines

  • September 30, 2026: Opportunity Announcement and Application Open
  • October 13, 2026: Deadline for Questions
  • October 20, 2026 at 2 PM ET: Application period closes

Eligibility & Review Criteria

Eligibility

Applicants must meet all the following eligibility criteria:

  1. Entity Status: Must be a not-for-profit entity.
  2. Partnership Requirement: Must demonstrate a formal partnership with no fewer than six (6) electric utilities that are:
    1. Rural electric cooperatives
    2. Municipally owned utilities, or
    3. Utilities owned by a State or political subdivision
  3. Demonstrated Need: Partners must show a demonstrated need for cybersecurity enhancement (e.g., resource-constrained utilities).
  4. Advanced Cybersecurity Alignment: Proposed projects must align with the “advanced cybersecurity technology” definition (enhancing security posture, protection, detection, response, and recovery).

Eligible Utility Beneficiaries

Services, technologies, and other benefits funded under this opportunity must be delivered to electric utility beneficiaries[1] that are eligible entities under the RMUC authorizing statute[2].  For purposes of this performer opportunity, eligible utility beneficiaries include:

  • Rural electric cooperatives.
  • Utilities owned by a political subdivision of a State, including municipally owned electric utilities.
  • Utilities owned by an agency, authority, corporation, or instrumentality of one or more political subdivisions of a State.
  • Investor-owned electric utilities that sell less than 4,000,000 megawatt-hours of electricity per year.

The selected not-for-profit performer is responsible for verifying and documenting beneficiary eligibility before providing RMUC-funded technical assistance or benefits, including, but not limited to, technical assistance, PDNS services, cybersecurity tools and technologies, assessments, training, implementation support, threat information-sharing services, and other activities or services supported under the RMUC program.

[1] If an eligible entity under IIJA Section 40124(a)(3)(E) (i.e. investor-owned electric utility that sells less than 4,000,000 megawatt hours of electricity per year) is owned by a holding company, the eligible entity, and not the holding company, must submit the prize submission package. If the cybersecurity resources of the eligible entity are part of a shared services agreement with a holding company, the holding company may participate in the program; however, the submission package must be submitted by the eligible entity, and funds awarded to the eligible entity may only be for the benefit of the eligible entity and may not be used for the benefit of noneligible subsidiaries of the holding company.

[2] Proposed projects must align with the “advanced cybersecurity technology” definition: “The term “advanced cybersecurity technology” means any technology, operational capability, or service, including computer hardware, software, or a related asset, that enhances the security posture of electric utilities through improvements in the ability to protect against, detect, respond to, or recover from a cybersecurity threat (as defined in section 102 of the Cybersecurity Act of 2015 (6 U.S.C. 1501)).” Section 41024 IIJA (42 U.S.C. §18723).

Review Criteria

DOE will evaluate eligible applications competitively based on the degree to which the proposed approach demonstrates the following:

The extent to which the proposed utility beneficiaries have limited cybersecurity resources, own assets critical to bulk-power system reliability, and/or own defense critical electric infrastructure.

The number and diversity of eligible utilities that will receive substantive services and the expected sector-wide impact. Proposals capable of effectively serving a larger number of eligible utilities may receive more favorable consideration when the proposed level of service remains meaningful, achievable, and adequately supported.

The strength of the proposed approach to deploy advanced cybersecurity technologies and/or increase participation in cybersecurity threat information-sharing programs, including alignment with the applicable Focus Area.

The credibility of the work plan, utility engagement strategy, staffing, schedule, vendor or technology approach, and ability to initiate and sustain performance.

The quality of proposed baselines, metrics, outcomes, and methods for demonstrating improvements in utilities’ ability to protect against, detect, respond to, and recover from cybersecurity threats.

The applicant’s relevant cybersecurity expertise, experience serving RMUC eligible utilities, strength of formal utility partnerships, and ability to manage technical assistance, vendors, sensitive information, and required reporting.

The reasonableness of proposed costs in relation to the number of utilities served, level of service, expected cybersecurity benefit, and potential to scale or replicate successful approaches.

The extent to which the proposed approach includes appropriate post-implementation verification and validation to demonstrate that funded cybersecurity improvements, technologies, practices, or capabilities have been successfully implemented and are achieving their intended cybersecurity outcomes. Applicants should describe methods for testing or otherwise validating effectiveness, documenting results, addressing identified deficiencies, and providing follow-up support, as appropriate to the proposed activities and utility environment.

The extent to which the proposed approach demonstrates a credible and feasible strategy for sustaining RMUC-funded cybersecurity improvements and capabilities beyond the period of performance. This may include, but is not limited to, utility ownership and maintenance of implemented capabilities, workforce development and knowledge transfer, ongoing service or funding models where feasible, partnerships, shared-service approaches, or other strategies appropriate to the participating utilities and proposed activities.

Foreign Involvement and Domestic Certifications

Foreign involvement and domestic certifications are threshold eligibility/compliance requirements and are not, by themselves, competitive review criteria.

  • Domestic Entity Qualification: The applicant must be organized, chartered, or incorporated under the laws of a US state or territory, have majority domestic ownership, and have a physical place of business in the United States.
  • Country of Risk Certification: Applicants must certify that they are not owned by, controlled by, or subject to the jurisdiction or direction of a government of a Country of Risk (currently defined as China, Russia, North Korea, and Iran).
  • Foreign Talent Recruitment Program Prohibition: No personnel participating on the project may participate in a Foreign Government-Sponsored Talent Recruitment Program from a Country of Risk. Immediate notification to DOE (within 5 business days) is required if any program violations are identified.

Frequently Asked Questions

Partnership Intermediary Agreements (PIAs) are agreements between the Federal government and non-Federal partners (partnership intermediaries or PIs) designed to increase outreach to and engagement with small business firms, institutes of higher education, and non-traditional partners.

Upon conclusion of selection from DOE Program Office Representative (POR) and finalization of milestone schedule, ConnectWerx will issue a business-to-business (B2B) agreement to the lead performer for review and execution. The B2B agreement will contain mandatory flow downs from the prime Partnership Intermediary Agreement (PIA) executed between DOE and Advanced Technology International.

Upon completion of milestones, invoices will be submitted to ConnectWerx for review with DOE and payment release. Incremental payments to the performer will be made in accordance with the established milestones and deliverables as written (and approved by DOE POR) in the B2B agreements. The payment schedule for each project is to be determined based on negotiated milestones and deliverables. Please be aware, additional documentation and support for expenditures may be requested as determined by DOE.

Information about how to apply, application materials, and deadlines will be available on the opportunity page.

DOE encourages proposals of various size and scale and will fund projects accordingly within the program budget.

Neither. This opportunity is run via a Partnership Intermediary Agreement. PIAs are agreements between the Federal government and non-Federal partners (partnership intermediaries or PIs) designed to support DOE’s missions to expand the development and deployment of transmission solutions, heighten energy security, and strengthen national energy ecosystems.

No. This opportunity does not have a cost share requirement.

FFRDCs (e.g. DOE/National Nuclear Security Administration National Laboratories) may participate as a subrecipient; however, DOE will not directly fund FFRDCs under this program. Selectees will receive full funding through one agreement with CWX.  Selectees are solely responsible for funding and executing necessary agreements with subrecipients.  CWX and DOE will not be involved in nor assist in these activities.  FFRDC effort, in aggregate, shall not exceed 10% of total federal share of the project.