What Schools Should Know About the FCC K-12 Cybersecurity Pilot Program

What Schools Should Know About the FCC K-12 Cybersecurity Pilot Program

According to CISA, cyber incidents are now so prevalent in K-12 schools that, there’s more than one incident per school day. And according to recently gathered data from CIS (Center for Internet Security), 81% of school districts say their top concern around this issue is insufficient funding. 

With so many of our schools struggling to afford the basics, now they’re supposed to fight international cybercrime? That’s a huge ask, which is why the FCC will award $200 million to a variety of K-12 schools and libraries through its Schools and Libraries Cybersecurity Pilot Program.

Understanding the FCC Cybersecurity Pilot Program

Cybersecurity vulnerabilities are listed on a school blackboard in chalk.

The 3-year FCC Cybersecurity Pilot Program is a new initiative that was just launched on June 6th, 2024, to assess which cybersecurity services and equipment would provide the most help for K-12 schools and libraries, and then provide a total $200M in funding to help organizations shore up their cyber defenses.

This program will be administrated through the Universal Service Administrative Company (USAC)

What Could Selected School Districts Receive?

School districts that are selected for the pilot program could get up to $13.60/student. This funding could then be put towards an eligible service within the following categories: 

  • Advanced firewalls
  • Endpoint protection
  • Identity protection and authentication
  • Monitoring, detection, and response (MDR)

What Districts Are Eligible? 

Schools and libraries — or groups of schools and libraries — that meet the E-Rate program’s eligibility requirements may apply to participate. Applicants to this pilot program do not need to be current or former E-Rate program participants. 

How Will Participants Be Selected?

The FCC is hoping to award funding to a diverse group of schools and libraries — large and small, rural and urban — with a special emphasis on organizations serving low-income and Tribal communities.

How Schools Apply for the FCC Cybersecurity Pilot

A school administrator applying for the federal cybersecurity pilot program.

Interested school districts will eventually need to apply by filling out the Schools and Libraries Cybersecurity Pilot Program Application (FCC Form 484) when the filing window opens — which is expected to be in the fall. 

The FCC is currently recommending that schools familiarize themselves with the program and other resources by: 

How To Prepare for the FCC Cybersecurity Pilot 

The application will have two main parts. Applicants will initially complete the first part of the application (Part One), and if selected to participate, they should expect to provide additional information (Part Two). Here’s what schools should prepare to provide 

Part One

The first part of the application is expected to contain detailed questions pertaining to: 

  • Your organization’s cybersecurity expertise
  • Whether your organization is expecting to implement cybersecurity best practices
  • What your organization is currently doing — or plans to do — with federal resources 
  • What your organization would like to achieve if selected to receive funding through the pilot program
  • What services and equipment your organization anticipates purchasing with program funding, and their expected costs
  • The risks your organization is hoping to mitigate with those purchases

Part Two

Selected participants should expect to answer questions pertaining to: 

  • Your organization’s current cybersecurity posture, including prevention and mitigation tactics
  • Any cyber threats and attacks within the last year 
  • Current cybersecurity policies, procedures, and training 
  • Current cybersecurity challenges

What Happens if Your Organization Is Selected?

A school administrator and teaching staff celebrating their inclusion in the FCC cybersecurity pilot program in 2024.

The pilot program will announce its selected participants by Public Notice, which will also contain more information about the procurement process and submitting funding requests. 

Participants must adhere to all competitive bidding, document retention, and audit requirements throughout the process. 

What Should You Do if You’re Not Selected?

$200M is a lot of money, but when we’re talking about K-12 schools and libraries across the US, it’s not going to go as far as any of us would like. 

If you apply, but your organization isn’t selected, you still have options. At Marco, we’ve made a point of partnering with a variety of cooperative purchasing organizations, including E&I, CPC, and Sourcewell. These solutions can help you save money on a variety of services and equipment. 

Additionally, we can also partner with you to improve your cybersecurity — helping you apply your dollars where they’ll do the most good.Learn More About Becoming a Marco Managed Print Services Partner Contact Us

Related Posts

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

Classroom Sound Systems: How To Buy Smart
Classroom Sound Systems: How To Buy Smart

A student who can't hear their teacher clearly isn't just distracted — they're at a measurable disadvantage. It's a problem that's easy to overlook until you're in the back row of ...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...

Cybersecurity Tips for Small Business Owners
Cybersecurity Tips for Small Business Owners

Too many small business owners still think they’re “too small” to be targeted by a cybercriminal. Unfortunately, 43% of cyberattacks each year are aimed at small businesses.

5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

Why Is MFA Important — and Is Your Business Using It Correctly?
Why Is MFA Important — and Is Your Business Using It Correctly?

Passwords alone haven't been enough to protect business accounts for years. Most IT professionals know this. Most business owners have heard it. And yet credential theft remains on...

What Is Cloud-Native Security?
What Is Cloud-Native Security?

Most businesses didn't set out to build a cloud-native environment. They started using Microsoft 365, added a cloud-based phone system, migrated a few workloads to Azure or AWS, an...

The Security Strategy AI-Powered Attacks Demand
The Security Strategy AI-Powered Attacks Demand

The threat environment changed. Not gradually. Abruptly. Tools like Anthropic’s Claude Mythos and the latest generation of AI-assisted exploitation capabilities have fundamentally ...

Data Security Governance Best Practices for 2026
Data Security Governance Best Practices for 2026

Data security has reached a breaking point. Sensitive information now lives in more places than ever, sprawled across SaaS applications, cloud drives, on-premises servers, and incr...