If your NSGP application was denied, it almost never happened because the package was incomplete. Most Nonprofit Security Grant Program (NSGP) denials happen during scoring, after the submission passed administrative review. The score comes back below the funded line, and the applicant receives a notice with a number but no breakdown of which section pulled it down.
When SGA reads NSGP application denied cases — denial-cycle Investment Justifications (IJs) — the cause is almost always in how the narrative handles risk, vulnerability, consequences, and impact, the elements FEMA reviewers score inside the IJ. This article walks through the most common patterns behind a low score in each of these areas, and how to identify which one hit a specific application.
The Distinction Between Rejection and Denial
The two outcomes are often described with the same word, but they happen at different stages.
A rejection is an administrative-review failure. The State Administrative Agency (SAA) or the Federal Emergency Management Agency (FEMA) found a mechanical defect in the package: missing 501(c)(3) letter, expired SAM.gov UEI, wrong IJ template, wrong stream selected, missing mission statement. The package never reached scoring. Those process-side errors are covered in a separate article on common application mistakes.
An NSGP application denied for scoring reasons is different. The package passed administrative review. Reviewers read the IJ against the scored sections and assigned a numeric score. The score landed below the funded threshold, either at the SAA layer (the SAA did not forward the application to FEMA) or at the FEMA layer (the application reached FEMA but did not score high enough before the appropriation was exhausted).
Risk, vulnerability, and consequences are scored together as part of the IJ’s Risk section. Impact is scored separately, based on the measurable outcomes the funded project would produce. The IJ also scores background information, facility hardening, milestones, and project management, but risk and impact are where denial-cycle applications most often lose the points that matter.
Understanding why your NSGP application was denied starts with knowing which of these two categories you’re in. This article is about the scoring case. The reason is in the narrative, not the checklist.
Risk Pattern: Generic National References
The most common reason a credible IJ scores below the funded line — and a common driver behind an NSGP application denied outcome — is a risk section built on national statistics with no local connection.
The pattern: the applicant opens with the FBI Hate Crime Statistics summary for the prior year, cites national totals, mentions that incidents are rising, and quotes one or two high-profile attacks from elsewhere in the country. The risk section reads professionally and is sourced accurately.
Reviewers score it low because it does not document risk to the applicant. The same paragraph could appear in any IJ from any organization in the same denomination. Nothing is specific to the facility, the city, the congregation, or the region.
A high-scoring risk section does the opposite:
- Names the FBI Hate Crime Statistics figure for the applicant’s state or metro area, not the national total
- Cites incidents near the facility by date, location, and either a police report number or a news link
- Identifies the denominational, ideological, or community-profile reason the facility is a target, with a public-record citation
- References threats received directly (mail, phone, email, social media) with dates and the response taken
The reviewer’s question is not “is hate crime a problem in this country.” It is “is this facility, in this place, at documented risk this cycle.” When the section answers the second with named sources, the score climbs. When it answers the first, the score stalls below the line regardless of how well written the rest of the IJ is.
The FBI publishes the data on its Hate Crime Statistics page, broken out by state and, in many cases, by metro area. Citing the state-level figure is a one-sentence fix that moves the section out of the generic pattern.
Risk Pattern: Borrowed Risk Narrative
The second risk pattern shows up in applications from organizations sharing a denominational network. Templates and example paragraphs circulate through denominational security agencies, peer congregations, and consultant sample IJs. The risk section is lifted, lightly edited, and submitted.
FEMA reviewers read dozens of IJs per cycle from the same denomination. When the same paragraph appears in multiple applications, scoring on that section drops for all of them, and it’s a quiet, easy-to-miss way to end up with an NSGP application denied. Even when the borrowed paragraph is factually accurate, it fails the documentation test because the incidents are not connected to the applicant’s community.
This pattern is harder to self-diagnose than the generic-national one. The applicant sees specific incidents and citations and concludes the section is strong. The weakness is that the incidents and threats belong to the peer organization.
The fix is to rebuild the section from the applicant’s own incident log, police report file, and regional FBI Hate Crime Statistics. Borrowed paragraphs can serve as a structural model. The content has to be local.
Vulnerability Pattern: The Two-Sentence Vulnerability Section
The vulnerability assessment is a separate required document, often produced by a security consultant, and can run twenty or forty pages. The vulnerability portion of the IJ’s Risk section is much shorter under the current FEMA NSGP Notice of Funding Opportunity (NOFO).
In IJs with an NSGP application denied outcome, this portion often runs two or three sentences. The applicant assumes the reviewer will read the attached assessment for the detail. They will not. The reviewer scores the IJ. The assessment supports it; it does not substitute for it.
When the section is short, the reviewer cannot see which gaps the funding closes, cannot connect the budget back to findings, and cannot evaluate whether the mitigations match the vulnerabilities. The score comes back low because the reviewer had nothing to score.
A high-scoring vulnerability section surfaces the assessment inside the IJ. It names the access points evaluated, lists the gaps found, and ties each to a numbered finding the reviewer can verify.
If your nonprofit had an NSGP application denied in the most recent cycle and you cannot tell which section pulled the score down, the denial narrative usually contains a fingerprint. SGA diagnoses denials in a 30-minute call. [Book a free consultation with SGA here.]([VERIFY URL] — link to your contact/consultation page)
Vulnerability Pattern: Budget Without an Assessment Trail
The second vulnerability pattern is structural. The IJ describes a set of vulnerabilities. The budget proposes a set of line items. The two lists do not match.
Two versions are common. In the first, the budget includes items the vulnerability section never mentions, a large line for security cameras when camera coverage is never identified as a gap. In the second, the vulnerability section identifies a critical gap the budget does not fund: an entrance is named as undefended against vehicle approach, but the budget includes no bollards.
Reviewers score facility hardening and impact against this trail. When a budget item has no upstream vulnerability, the reviewer cannot evaluate why the funding is needed. When a documented vulnerability has no budget line, the reviewer concludes the IJ is not internally consistent — another common thread in an NSGP application denied at the scoring stage.
The fix is mechanical. Build a two-column list during drafting: vulnerabilities on one side, budget lines on the other. Every entry needs a counterpart.
Consequences Pattern: Adjectives Instead of Numbers
The consequences portion of the Risk section is where reviewers most often see writing that reads well and scores poorly. The pattern: the applicant describes the impact of a successful attack with adjectives (“devastating,” “catastrophic,” “significant,” “irreplaceable”) and abstract groupings (“the community,” “our members,” “future generations”).
Adjectives do not score. The reviewer cannot rank a “devastating” loss against a “catastrophic” one. There is no scale. What can be scored is specificity:
- Number of staff, members, students, or visitors on the facility on a typical day, a peak day, and during the highest-occupancy named event of the year
- Number of children in any on-site program with the age range
- Number of elderly or mobility-limited individuals in regularly scheduled programs
- Named community functions beyond the primary mission, such as a polling location, food pantry, emergency shelter, or blood drive site
- Recovery timeline for the programs that would be displaced
- Geographic role, such as the only congregation of its kind in a county or the largest facility serving a metro area
Each item is a number, a name, or a documented role. A consequences section built from items like these scores in the funded range because the reviewer can compare it directly against other applications.
Consequences Pattern: Missing Peak-Occupancy Specificity
The second consequences pattern recurs in faith-based applications, and it’s another quiet cause of an NSGP application denied outcome. The IJ describes weekly service occupancy and does not address the peak-attendance event of the year.
Peak occupancy is the scoring inflection point because it represents the worst-case scenario. An attack at peak produces casualty figures far higher than at average occupancy. Reviewers want the date or event that produces peak named, with conditions described.
Named events vary by tradition: High Holy Days for Jewish congregations, Christmas Eve and Easter for Christian congregations, Eid al-Fitr and Eid al-Adha for Muslim congregations, Diwali for Hindu temples, Vaisakhi and Gurpurab for Sikh gurdwaras, graduation and major performances for schools, festival days for community centers.
An IJ that says “occupancy increases during religious holidays” loses points. An IJ that names the specific event, the attendance figure, and the breakdown by age group does not.
Impact Pattern: Budget Restated as an Equipment List
Impact is one of the most misunderstood sections of the IJ. The pattern in applications where the NSGP application was denied is to restate the budget as if reading it aloud were the assignment. The section lists equipment, prices, and vendors, then ends.
The reviewer already has the budget as a separate document. Impact is scored on the measurable outcomes the project produces, tied back to the vulnerabilities and consequences already described, not on a repeat of what was purchased.
A strong paragraph reads:
Installation of six ASTM F2656 M30 rated bollards at the south entrance closes the documented vehicle-approach vulnerability identified in the attached assessment. At peak occupancy of 1,150 during High Holy Days, a vehicle attempting to reach the structure at 35 mph would be stopped at the bollard line approximately 12 feet from the building. The mitigation also preserves street-side accessibility for elderly congregants without losing the standoff distance the assessment recommended.
It names the funded item, ties it to a numbered assessment finding, describes the scenario the mitigation addresses, and quantifies the change. The budget is implied. The outcome is explicit.
Impact Pattern: The Broken Chain
The chain these sections form is the scoring mechanism behind most cases where an NSGP application was denied. Each section can read adequately alone, and the application still falls below the funded line because the chain breaks somewhere.
The chain:
- Risk documents a specific threat picture
- Vulnerability identifies the gaps that threat would exploit
- Budget funds mitigations for those gaps
- Consequences quantify what the mitigations protect
- Impact ties the mitigations back to measurable outcomes tied to those consequences
Reviewers see a broken chain when risk describes one threat type and vulnerability addresses a different one. Risk emphasizes targeted, ideologically motivated attacks. Vulnerability emphasizes property crime and unauthorized access by transients. Budget funds general-purpose access control. Impact describes deterrence against the property-crime scenario, not the ideological one risk opened with.
Each section, read alone, is competent. Read together, they describe different threat models. The reviewer cannot give the IJ a high score because it does not make one coherent argument.
Fixing a broken chain starts in the risk section. Identify the threat the IJ is built around, then audit every subsequent section to confirm it responds to the same threat. Our [NSGP application services]([VERIFY URL] — link to your NSGP program page) walk through this chain section by section for clients preparing a re-application.
Why Was My NSGP Application Denied? How to Tell Which Pattern Hit Your IJ
FEMA returns a numeric score after the cycle closes, not a breakdown by section. Applicants receive a total and a notice that the application fell below the funded line, with no indication of which section was the cause.
Once you know your NSGP application was denied on scoring rather than rejected on paperwork, the diagnosis comes from reading the IJ against the patterns above. The fingerprint is in the document, not the FEMA response.
Self-diagnosis questions, in the order they surface the dominant pattern:
- Does the risk section cite a state or metro-area FBI Hate Crime Statistics figure, or only national totals?
- Does the risk section name incidents near the facility, with dates and citations?
- Is the vulnerability portion detailed and specific, or two or three sentences?
- Does every budget line have a corresponding gap in the vulnerability section?
- Does every gap in the vulnerability section have a corresponding budget line?
- Does the consequences section state peak occupancy as a number tied to a named event?
- Does the Impact section state a measurable outcome tied to risk and consequences, or does it just restate the budget?
- Read end to end, does the IJ describe one coherent threat model from risk through impact?
A “no” on 1 or 2 indicates the risk pattern. A “yes” on 3, if the vulnerability section is thin, or a “no” on 4 or 5, indicates the vulnerability pattern. A “no” on 6 or 7 indicates the consequences or Impact pattern. A “no” on 8 indicates the broken-chain pattern.
Applications with an NSGP application denied result usually show more than one pattern. The value of the diagnosis is identifying the dominant one, because that is the section the re-application has to rebuild rather than revise.
Frequently Asked Questions
Does FEMA tell applicants which section scored lowest?
No. FEMA returns a numeric total and a notice of whether the application fell above or below the funded line. The breakdown by section is not released. Diagnostic work happens on the applicant’s side, reading the submitted IJ against the patterns reviewers downgrade.
Is the SAA score and the FEMA score the same?
No. The SAA scores first and forwards the top scorers to FEMA, which scores survivors against the federal rubric. Both layers use the same scored sections but apply state-specific weighting in many cases. An application can pass the SAA layer and still have the NSGP application denied at FEMA, and the notice does not specify which layer it failed at.
If the IJ was denied this cycle, can the same IJ be submitted next cycle?
Submitting the same IJ unchanged is a common reason organizations see an NSGP application denied two or three cycles in a row. Each cycle is scored independently, but the patterns that pulled the score down do not change unless the narrative is rewritten. Re-applicants who submit with cosmetic edits tend to score within a narrow range of the prior result.
Can the patterns be fixed without a new vulnerability assessment?
Some can. Risk, consequences, and Impact patterns can often be addressed by rewriting against the existing assessment. Vulnerability patterns more often require a refreshed assessment, especially when the original did not document access points the IJ needs to address.
Is a denied application a signal the organization is not eligible?
No. Eligibility is determined at administrative review. An application that was scored was eligible. An NSGP application denied on score reflects the IJ narrative, not the organization’s qualification.
Does the U.S. Department of Homeland Security review IJs directly?
NSGP is administered by FEMA, a component of the U.S. Department of Homeland Security. Review panels are organized by FEMA. DHS sets the broader homeland security priorities, but cycle-by-cycle scoring is a FEMA function.
Where is the official application portal?
The federal grants portal is Grants.gov. State-level applications route through each state’s SAA portal, linked from the FEMA NSGP page.
What This Means for Your Organization
An NSGP application denied notice tells you a number, not a reason. The reason is almost always visible in the IJ itself, once you know which section to read closely.
Security Grant Advisors works with nonprofits that had an NSGP application denied in a recent cycle and are deciding whether to re-apply. The diagnostic call reads the prior IJ against the patterns above, identifies the section that scored lowest, and outlines what a rewrite would need to fix before the next cycle.
Still have questions about what happened to your application, or want a second set of eyes before you re-apply? You can [book a free consultation with SGA here]([VERIFY URL] — link to your contact/consultation page).
Official Sources
Confirm cycle requirements at the URLs below before re-submission.