CWX-028-CESER: Rural and Municipal Utility Cybersecurity (RMUC) Program’s Advanced Cybersecurity Technical Assistance (TA)
Submission Deadline: October 20th, 2026 2PM ET.
Questions? Reach out to us at [email protected]
The Rural and Municipal Utility Cybersecurity (RMUC) Program’s Advanced Cybersecurity Technical Assistance (TA) Program provides support funded by section 40124 of the Infrastructure Investment and Jobs Act (IIJA), codified at 42 U.S.C. § 18723. The cybersecurity landscape for critical infrastructure, particularly the electric grid, is constantly evolving, with increasing threats from various actors. Rural and municipal utilities, despite their vital role in delivering electricity, often face unique challenges in securing their systems due to limited financial, technical, and personnel resources. This leaves them vulnerable to cyberattacks that could disrupt power supply, impact economic activity, and undermine national security.
This program specifically addresses the cybersecurity needs of these underserved utilities. The primary focus of this initiative is to leverage the expertise and reach of relevant organizations, specifically not-for-profit entities demonstrating a partnership with six or more utilities, to achieve widespread impact and facilitate critical improvements across the sector.
The selected not-for-profit entities will provide technical assistance and facilitate information sharing, directly supporting the resilience and reliability of the bulk-power system and defense-critical electric infrastructure across the United States. It aligns with broader Department of Energy (DOE) efforts to modernize and secure energy infrastructure.
The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) anticipates seeking applications from eligible not-for-profit organizations through the RMUC TA Partnership Intermediary Agreement (PIA).
The anticipated opportunity will provide funding to selected not-for-profit performers to deliver cybersecurity technical assistance, technologies, services, and other support to eligible electric utilities. Applicants are expected to demonstrate formal partnerships with no fewer than six (6) qualifying electric utilities and the capability to deliver meaningful cybersecurity improvements across participating utilities.
Applicants may propose activities under one or both of two focus areas:
- System Hardening/Technical Assistance
- Cybersecurity Threat Information Sharing
Supported activities may include, but are not limited to: cybersecurity assessments and planning; workforce training and certification; exercises and readiness; implementation and integration of cybersecurity tools and technologies; verification and validation; cybersecurity threat information-sharing activities; and other activities that support measurable improvements in the cybersecurity posture and resilience of eligible utilities.
DOE has made $100 million available for the RMUC TA program. Additional information regarding eligibility, anticipated award amounts, periods of performance, application requirements, evaluation criteria, milestones, and the opportunity schedule is provided below.
ConnectWerx (CWX), a DOE Partnership Intermediary, will administer the opportunity in collaboration with CESER. This announcement is a funding opportunity and interested organizations should submit applications in response to this notice.
First, request access to AMP. Once access has been granted, you may proceed with submitting your proposal through the CWX Submission Portal.
Complete your application through the CWX submission portal and all required project information and supporting documentation. Submissions must include the required documents as indicated in the chart below, using the provided templates (hyperlinked below).
Submissions are due no later than October 20, 2026 at 2 PM ET.
| File Title | Max Pages | File Type |
|---|---|---|
| Project Overview & Plan | 6 (Times New Roman 12 font, which includes graphs and pictures on all PDFs) | |
| Project Schedule & Gantt Chart | ||
| Cost Proposal/Project Budget | 1 page per period of performance (submitted as one file) | XLS |
| Key Personnel (Resumes) | 2 pages per person (submitted as one file) | |
| Letters of Support | 5 |
Submission Requirements
Responses shall be submitted by the date and time specified above.
Files shall be submitted in Microsoft Office or Adobe Acrobat format, no larger than 5MB. ZIP files and other application formats are not acceptable. All files shall be print-capable, without a password. Filenames must contain the appropriate extension and shall not contain special characters*. Appropriate files extensions are:
| Application / File | Valid Extensions |
|---|---|
| Portable Document Files (Adobe Acrobat PDF) | |
| Microsoft Word (MS Word) | .doc / .docx |
| Microsoft Excel | .xls |
Late submissions will not be accepted. Submissions can be made in advance of the deadline and edited (or files replaced) up to the deadline.
The overall objective of this program is to strengthen the operational and cybersecurity resilience of electric rural cooperatives, municipally owned utilities, or utilities owned by a State or political subdivision, by providing technical assistance and shared services.
$100M has been made available for the RMUC TA program. CESER will evaluate applications based on the eligibility requirements, merit of the application, and the selectee’s ability to maintain and manage a project that provides the required technical assistance support.
Key objectives include:
- System Hardening: Technical assistance to support the selection and implementation of cybersecurity best practices, policies, and tools that result in verifiable documented improvements in cybersecurity posture.
- Threat Intelligence Sharing: Establishing and maintaining improved utility capabilities to utilize and share threat intelligence using a streamlined framework among information sharing partners.
- Infrastructure Protection: Promoting innovative solutions for overall energy infrastructure defense.
Applicants may propose activities under one or both of the following Focus Areas, which may be submitted as a single combined proposal or as separate efforts:
Focus Area 1: Technical Assistance Program
Applicants develop and operate a technical assistance program for eligible utilities to improve their capability to protect against, detect, respond to, and/or recover from cybersecurity threats. Supported activities include, but are not limited to:
Focus Area 2: Cybersecurity Threat Information Sharing
Applicants develop and deliver a Protective Domain Name System (PDNS) service that strategically maximizes impact and strengthens cybersecurity posture. Program activities under this focus area encompass:
Program Planning: The program is currently aligning schedules and preparing for launch. Specific webinar dates and office hours will be posted here as soon as they are finalized.
How to Participate
- Review the Opportunity Details
Eligibility requirements, evaluation criteria, and application instructions on the RMUC opportunity page. - Review Office Hours Materials & Submit Questions
Informational “Office Hours” presentation and submit any questions here. - Download the Required Templates
Project Overview & Plan, Project Schedule & Gantt Chart, and Cost Proposal/Project Budget templates. Complete and save the templates for submission. - Register for the CWX Acquisition Management Portal (AMP)
Request access to the CWX AMP by completing the registration form. - Complete and Submit Your Application
CWX-028-RMUC Submission Form and upload all required documents through the CWX AMP system. Applications must be submitted no later than October 20, 2026, at 2 PM ET.
Tuesday, October 20, 2026 at 2 PM ET
Informational “Office Hours” presentation is available for review and submit questions here.
- View the Presentation (PDF)
- September 30, 2026: Opportunity Announcement and Application Open
- October 13, 2026: Deadline for Questions
- October 20, 2026 at 2 PM ET: Application period closes
Applicants must meet all the following eligibility criteria:
- Entity Status: Must be a not-for-profit entity.
- Partnership Requirement: Must demonstrate a formal partnership with no fewer than six (6) electric utilities that are:
- Rural electric cooperatives
- Municipally owned utilities, or
- Utilities owned by a State or political subdivision
- Demonstrated Need: Partners must show a demonstrated need for cybersecurity enhancement (e.g., resource-constrained utilities).
- Advanced Cybersecurity Alignment: Proposed projects must align with the “advanced cybersecurity technology” definition (enhancing security posture, protection, detection, response, and recovery).
Eligible Utility Beneficiaries
Services, technologies, and other benefits funded under this opportunity must be delivered to electric utility beneficiaries[1] that are eligible entities under the RMUC authorizing statute[2]. For purposes of this performer opportunity, eligible utility beneficiaries include:
- Rural electric cooperatives.
- Utilities owned by a political subdivision of a State, including municipally owned electric utilities.
- Utilities owned by an agency, authority, corporation, or instrumentality of one or more political subdivisions of a State.
- Investor-owned electric utilities that sell less than 4,000,000 megawatt-hours of electricity per year.
The selected not-for-profit performer is responsible for verifying and documenting beneficiary eligibility before providing RMUC-funded technical assistance or benefits, including, but not limited to, technical assistance, PDNS services, cybersecurity tools and technologies, assessments, training, implementation support, threat information-sharing services, and other activities or services supported under the RMUC program.
[1] If an eligible entity under IIJA Section 40124(a)(3)(E) (i.e. investor-owned electric utility that sells less than 4,000,000 megawatt hours of electricity per year) is owned by a holding company, the eligible entity, and not the holding company, must submit the prize submission package. If the cybersecurity resources of the eligible entity are part of a shared services agreement with a holding company, the holding company may participate in the program; however, the submission package must be submitted by the eligible entity, and funds awarded to the eligible entity may only be for the benefit of the eligible entity and may not be used for the benefit of noneligible subsidiaries of the holding company.
[2] Proposed projects must align with the “advanced cybersecurity technology” definition: “The term “advanced cybersecurity technology” means any technology, operational capability, or service, including computer hardware, software, or a related asset, that enhances the security posture of electric utilities through improvements in the ability to protect against, detect, respond to, or recover from a cybersecurity threat (as defined in section 102 of the Cybersecurity Act of 2015 (6 U.S.C. 1501)).” Section 41024 IIJA (42 U.S.C. §18723).
DOE will evaluate eligible applications competitively based on the degree to which the proposed approach demonstrates the following:
Foreign Involvement and Domestic Certifications
Foreign involvement and domestic certifications are threshold eligibility/compliance requirements and are not, by themselves, competitive review criteria.
- Domestic Entity Qualification: The applicant must be organized, chartered, or incorporated under the laws of a US state or territory, have majority domestic ownership, and have a physical place of business in the United States.
- Country of Risk Certification: Applicants must certify that they are not owned by, controlled by, or subject to the jurisdiction or direction of a government of a Country of Risk (currently defined as China, Russia, North Korea, and Iran).
- Foreign Talent Recruitment Program Prohibition: No personnel participating on the project may participate in a Foreign Government-Sponsored Talent Recruitment Program from a Country of Risk. Immediate notification to DOE (within 5 business days) is required if any program violations are identified.

