If you are preparing a security grant application, you have probably seen the term NSGP vulnerability assessment and wondered whether you need to hire someone to write a thick professional report. For most applicants, you do not. This post explains what the assessment actually is, what it has to accomplish, and when it makes sense to bring in outside help.
A vulnerability assessment is a written record of the security gaps at one of your buildings. For the Nonprofit Security Grant Program (NSGP) and most state programs, it is usually a standardized worksheet the program gives you, not a custom report you commission. In most cases you can complete it yourself. Its real job is simple: every item you ask the grant to pay for should point back to a specific weakness the assessment names.
What the NSGP vulnerability assessment actually is
The Nonprofit Security Grant Program, or NSGP, is a federal grant that helps at-risk nonprofits and houses of worship pay for security improvements. Many states run their own versions with similar rules. Every one of these programs asks for a vulnerability assessment before it will fund anything.
The assessment is a structured look at a single building. It records the ways someone could get in or cause harm, the security measures already in place, and the gaps that remain. One facility gets one assessment. If you are applying for two locations, you complete two. The FY2026 NSGP Notice of Funding Opportunity is explicit that one vulnerability assessment is required per physical address, and that failing to provide a unique assessment for each site may result in the application being rejected.
Here is the part worth understanding clearly. The people who score your application read what you submit. They are not visiting your property or walking your parking lot. The assessment is the evidence behind your request. If a gap is not written down, the reviewer has no way to know it exists, and the funding you asked for to fix it has nothing to stand on.
It is usually a worksheet, not a long report
A common worry is that the assessment has to be a long, professionally written document. In most cases it does not.
Several programs hand you a fill-in worksheet and ask you to use it.
- California. The Cal OES Vulnerability Assessment Worksheet is the required form for the state program. Cal OES is direct about what it is: a tool to support completion of the application, not a security checklist, and not scored on its own.
- New York. The SCAHC program requires a Vulnerability Self-Assessment Tool, one for each facility where work is proposed, uploaded through the state grants management system.
At the federal level, the NOFO requires an assessment for each physical address but does not prescribe a particular template. What matters federally is that the Investment Justification, the main written part of your application, describes the findings from a completed assessment. The assessment supports the application. The application is what gets scored.
The one job the assessment has to do
Whatever form your assessment takes, it has one core job: connect every funded item to a real weakness.
Reviewers look for a clear line from problem to solution. If you ask for cameras, the assessment should show where you currently cannot see. If you ask for a fence, it should show where the perimeter is open. The federal review criteria include alignment between the project activities you request and the vulnerabilities identified in your assessment, and the scoring rubric asks directly whether all proposed equipment and activities are tied to a vulnerability they could reasonably address. An item with no documented gap behind it tends to lose points or get cut.
This is why vague language hurts you. “Improve security at the rear of the building” is not a gap a reviewer can act on. “The rear staff door is unlit after dark and has no camera covering it” is. The second version gives your request something to point to.
What to look at when you walk your building
You do not need security training to spot most of what belongs in an NSGP vulnerability assessment. Walk your property once during a busy service or event, and once after dark, and look at each of these:
- Entrances. Not just the front doors. Side doors, the staff entrance, the kitchen or delivery door, and any door propped open during events. Note the door material, the lock, and whether anyone can see it.
- Windows and glass. Ground-floor windows, glass next to main doors, and large lobby or sanctuary windows. Glass is one of the most common ways into a building and one of the most overlooked.
- Lighting. Lighting at noon is not lighting at 8 p.m. in December. Look at your entrances and parking after dark, when your evening programs actually run.
- Cameras and blind spots. Where do your current cameras reach, and where can no one see at all?
- Parking and perimeter. Fences, gates, gaps, and how close a vehicle can get to the building.
- Roof and utility access. Outside ladders, low roof access, and the doors to mechanical, electrical, and utility rooms.
If something does not apply to your building, say so. A blank where a reviewer expects an answer reads as something you missed.
Federal and state programs: a few examples
The basic idea is the same everywhere, but the specifics vary by program. Two examples from current materials:
California. The Cal OES Vulnerability Assessment Worksheet is a required component of a complete proposal for the state program, and it must be signed. Cal OES says the assessment should be performed by a person with a law enforcement, military, other security, or emergency services background, and self-assessments are allowed. The assessor’s title, credentials, or professional certification related to security are recorded in Section 1 of the worksheet, though Cal OES also states that who conducted the assessment, and how, is not reviewed. One further rule to know: if a security company prepares your assessment, that company is prohibited from bidding on or contracting for the products or services the grant pays for.
New York (SCAHC). Uses the state’s Vulnerability Self-Assessment Tool, with a separate assessment required for each facility where project work is proposed. You also submit a color, ground-level photo of the front façade of each facility, plus photos of every interior or exterior location where work is proposed, such as the full run where a new fence would go. An assessment completed within the past year can be reused if it still reflects current vulnerabilities at the facility. Missing any of these is a first-tier completeness failure, and an application that does not meet those conditions is subject to disqualification before it is ever scored.
These details change from year to year and from state to state. Always work from the current notice for your program, and confirm the exact form your state wants before you start.
Can you do it yourself?
For the federal program and most state programs, yes. Cal OES accepts self-assessments outright, and notes that an initial self-assessment should not be discounted. What the worksheet asks for is that you identify who performed it.
Doing it yourself works well when your building is straightforward and your leadership knows it well. Outside help tends to earn its cost in three situations: a large or multi-building campus, a first application where you want the written gaps to line up cleanly with the items you are requesting, and cases where an internal walk keeps missing the same back-of-house doors, utility rooms, and roof access points.
One caution from the California example applies more broadly. If you hire a security company to assess your building, check whether your program bars that same company from selling you the equipment afterward. Keeping the assessment independent of the sale protects both you and your application.
What this means for your organization
For most houses of worship and nonprofits, the vulnerability assessment is more manageable than it sounds. It is often a worksheet the program provides, you are generally allowed to complete it yourself, and its purpose is practical: give every dollar you request a specific weakness to point back to.
The applications that struggle are not the ones with simple assessments. They are the ones where the assessment is vague, skips obvious entry points, or never mentions the gap a budget line is supposed to fix. Walk your building honestly, write down what you find in plain terms, and make sure each item in your budget answers something on that list.
A few common questions
Do we have to hire a professional? No. Cal OES accepts self-assessments, and the federal notice does not require a credentialed assessor. Outside help is optional and most useful for large campuses or first-time applicants.
Does one assessment cover multiple facilities? No. These programs work facility by facility. Each location gets its own assessment. Federally, each site also gets its own Investment Justification within a single subapplication. In New York, multiple facilities can appear in one application, but each one needs its own assessment attached.
Is the assessment itself scored? It depends on the program. Federally, reviewers score how well your application describes the findings and whether your requested items align with the vulnerabilities you identified. Cal OES states that its worksheet is not scored on its own. New York scores the assessment directly, at up to 30 points, split across identifying the threats, identifying the vulnerabilities, and describing how the two connect, and uses that score as its first tiebreaker.
What if we have never had an incident? That does not matter for this section. The assessment documents the gaps that exist today, not your history. A building with no past incidents completes the same assessment as one with several.
Not sure where you stand?
Figuring out which form your program wants, and making sure your NSGP vulnerability assessment supports the funding you are requesting, is the kind of thing that goes faster with a second set of eyes. If any of this is confusing or you want to talk through how it applies to your organization, we’re happy to help.
If you want a review of where your current award stands, what is on time, and what is at risk, book a free consultation with SGA here or call (855) 674-7946.