• July 2026

Multi-Site NSGP Applications: How to Win Funding Across Multiple Facilities

The Nonprofit Security Grant Program (NSGP) allows one Investment Justification (IJ) per facility. An organization with three buildings can submit three parallel IJs; a federation with nine members, nine.

Reviewers know this. They also know what happens when one writer drafts all of them in a hurry. Parallel IJs that share opening paragraphs, repeat the same risk citations with the building name swapped, and propose identical equipment lists at different addresses get downgraded together. An application that should have produced four awards produces one.

A multi-site NSGP application is a coordinated strategy: deciding which sites to submit, differentiating each IJ around that site’s risk picture, coordinating budgets, and routing everything through the State Administrative Agency (SAA). This guide covers federal and state caps, site selection, IJ differentiation, the failure pattern reviewers flag most, central versus decentralized models, and post-award management.

Federal NSGP Multi-Site Caps

Federal NSGP publishes per-site and per-organization rules in the annual Notice of Funding Opportunity (NOFO) at https://www.fema.gov/grants/preparedness/nonprofit-security and through https://www.grants.gov/. The 2024 and 2025 NOFOs set the per-site maximum at $200,000; the 2026 NOFO retained that figure. A nonprofit applying for three facilities can request up to $600,000 across three IJs, each capped at $200,000.

Federal NSGP separates the funding stream into two pools:

  • NSGP-UA (Urban Area): facilities inside a FEMA-designated Urban Area Security Initiative (UASI) area. The UASI list is at https://www.fema.gov/grants/preparedness/urban-area-security-initiative.
  • NSGP-S (State): facilities outside the UASI footprint.

Pool selection is per-site, not per-organization. A synagogue federation with one site in Brooklyn and one in Buffalo files Brooklyn under NSGP-UA and Buffalo under NSGP-S; the two IJs compete in separate scoring pools.

Federal NSGP does not cap the number of facilities one organization can submit. The practical cap is whatever the SAA will forward, and several SAAs publish internal per-organization limits below the federal cap. SAA contacts are listed on the FEMA program page.

State-Program Multi-Site Caps

State NSGP-style programs run independently of federal NSGP and set their own multi-site rules. The caps below reflect 2025 and early 2026 guidance; confirm with the state SAA before scoping.

Illinois NSGP-IL allows up to three facilities per organization at $150,000 per site, $450,000 total. The state portal accepts one submission with three attachments.

New Jersey NSGP awards one grant per nonprofit per cycle. A multi-site New Jersey nonprofit chooses its strongest single facility; the others defer or apply through federal NSGP if eligible.

New York SCAHC (Securing Communities Against Hate Crimes) has held a per-site figure of $200,000 with a varying per-organization cap. New York federations coordinate SCAHC with federal NSGP-UA submissions in the same cycle.

California CSNSGP publishes per-site and per-organization caps in each NOFO. The 2025 cycle capped per-site at $200,000 with no organization-wide cap.

Pennsylvania NSGFP, Maryland PAHC, Ohio OSG, Tennessee HOW, Massachusetts CNSGP, Connecticut NSGP, Arizona NSGP, Washington NROSGP, Georgia FPC, and Colorado NSGP each publish their own rules; none mirror the federal cap exactly. A nonprofit operating across state lines treats each SAA as a separate jurisdiction with its own portal, deadline, template, and cap.

Stacking federal and state awards for the same facility is allowed in most states, but equipment funded by each program must be distinct. Two programs cannot pay for the same bollard at the same entrance. Equipment lines are carved between the federal and state IJs before submission, not after award.

Site Selection: Which Facilities to Submit

Site selection separates applicants that get multiple awards from those that get one award and three denials. Submitting every facility the organization owns is rarely the right strategy: reviewers see thin IJs at facilities with no documented risk and downgrade the strong ones beside them by association.

A defensible process evaluates each candidate facility against four filters:

Risk picture. The site needs a documented threat record specific to its address, denomination, ideology, or community role. National data alone is not enough. Local police reports, denominational security advisories, peer incident research within a regional radius, and threats received by mail, phone, or in person all qualify. FBI Hate Crime Statistics (https://www.fbi.gov/services/cjis/ucr/hate-crime) and denominational reporting (Secure Community Network, Catholic Mutual Group) build the file. A site without a documentable risk file is not winnable in the current cycle.

Vulnerability assessment readiness. The site needs an assessment completed within 18 months covering every access point. Older assessments are refreshed or the site is deferred.

Peak occupancy and program role. Reviewers score consequences against specific occupancy numbers tied to specific events. Peak occupancy of 950 on High Holy Days outranks a satellite with peak occupancy of 80 at a midweek meeting. A smaller site can still be submitted if its programs serve a high-consequence population (a preschool inside a synagogue, a polling location inside a mosque).

Geographic role. Sites that serve a unique community function (the only synagogue in a 50-mile radius, the largest mosque in the region) score higher on consequences than sites in dense clusters where neighbors could absorb displaced congregants.

The output is a ranked list with a defensible reason each candidate is in the slate or deferred. A nonprofit with seven facilities might submit four federally, two through state programs, and defer one until its assessment is current.

If your nonprofit operates three or more facilities and is weighing which to submit this cycle, the wrong combination produces parallel IJs that reviewers downgrade for sounding identical. We run multi-site selection workshops before scoping any application. Book a free consultation with SGA here.

Per-Site IJ Differentiation

Once the slate is set, each IJ must reflect its facility’s actual risk, vulnerability, consequences, and effect of funding. Differentiation is not a flourish; it is what reviewers score.

The parent congregation IJ might lead with peak occupancy of 1,200 at Christmas Eve service, signage facing a major arterial, and three documented vandalism incidents in the past 24 months. The satellite campus three miles away might lead with peak occupancy of 220 at the Wednesday youth program, a back entrance opening onto an unlit lot, and a different incident pattern tied to its block.

Per-site differentiation surfaces in five places:

  • Background: address, square footage, year built, hours, peak occupancy by event, programs at that site.
  • Risk: local police reports, peer incidents within a regional radius of that address, threats received at that address.
  • Vulnerability: gap findings from that facility’s assessment, with access points and mitigations specific to that building.
  • Consequences: peak occupancy at named events, populations served (preschool age, elderly, mobility-limited), community functions performed.
  • Effect of funding: the mitigation purchased for that site’s specific gaps, with the measurable reduction in that site’s consequence.

When all five carry site-specific content, the IJ reads as a standalone document for a real facility. When two or three sections repeat with only the building name changed, reviewers register the pattern and downgrade the whole package.

The Common Failure Mode: Boilerplate IJs Across Sites

Reviewers read state-pool submissions in batches. SAA staff see most of the IJs from one organization in the same session. Parallel IJs with shared paragraphs are visible at the first read.

The patterns reviewers flag most:

Identical risk paragraphs. The risk section opens with the same anti-religious-bias overview at every site, with no local incident data swapped in. Reviewers downgrade because the argument does not establish that this facility is targeted.

Identical consequences narrative. “Loss of life would be catastrophic” appears in all four IJs. No occupancy numbers, no named events, no site-specific programs at risk.

Identical budget shape with the address changed. Each IJ proposes the same six bollards, the same access control upgrade, the same camera count. Reviewers question whether four assessments surfaced identical gaps or one budget was templated.

Assessments with no facility identifier. When four assessment documents share photographs of generic doors with no facility context, reviewers downgrade. Photographs need timestamps and visible facility context.

One mission statement reused across all IJs. The IRS-filed mission statement is not the NSGP mission statement. The NSGP version is written for the risk picture and should reflect the specific community served at each site.

The failure mode is recoverable in writing. It is not recoverable after submission.

Central vs Decentralized Submission Models

Multi-site nonprofits choose between two operating models. Both are accepted by SAAs.

Central submission. The parent organization assembles all IJs, assessments, mission statements, budgets, and SAM.gov registrations. One project lead coordinates with one SAA contact per state. The portal receives one organizational package containing N facility IJs. This works when the parent has bandwidth, the facilities trust the parent to represent them, and the SAA accepts multi-IJ packages from one submitter (most do). It collapses fastest when the project lead is also the executive director, development director, and volunteer coordinator.

Decentralized submission. Each facility submits its own IJ, assessment, mission statement, and budget, with its own SAM.gov UEI and SAA contact. The parent coordinates by setting standards and reviewing drafts, but the legal applicant is the facility itself. This works when each facility is its own 501(c)(3) (common in federations and denominational structures with autonomous congregations), has staff or volunteers to run the application, and the SAA accepts parallel single-IJ submissions from related organizations.

The hybrid model (parent runs the writing, each facility holds its own UEI and submits) fits multi-site congregations where the parent is a single 501(c)(3) but each campus has local leadership.

Decide early. Switching mid-cycle requires re-registering at SAM.gov (https://sam.gov/) and re-coordinating with the SAA; the SAM.gov window alone runs 10 to 15 business days for new registrants.

Multi-Site Vulnerability Assessment Strategy

Each facility needs its own vulnerability assessment. The federal NSGP NOFO is explicit and most state programs follow suit. One assessment covering multiple sites is not acceptable, even when sites share a security committee or denominational umbrella.

Consistent across a multi-site program:

  • Methodology. Same walkthrough protocol, access-point inventory framework, photograph standard, and gap-classification scheme across all facilities.
  • Assessor. One qualified assessor produces more consistent gap identification than four volunteers using four different mental models. The assessor visits each site separately and produces a facility-specific report.
  • Template. Same section headings, table structure, and recommended-mitigation language.

Varies per facility:

  • Identification. Address, square footage, year built, current posture, access-point inventory for that building.
  • Photographs. Timestamped, with visible facility context (signage, room layout, exterior features) tying them to that address.
  • Gap findings. Specific gaps numbered against that walkthrough.
  • Mitigations. Specific equipment, training, or planning recommendations that close those gaps.

When methodology is consistent and content varies, the IJs inherit the variation. When assessments are copy-paste, so are the IJs.

Multi-Site Budget Coordination

Multi-site budgets coordinate vendor pricing without double-counting costs.

Multi-site vendor pricing. A vendor supplying bollards across four facilities can quote a multi-site rate that runs lower than four single-facility quotes. The budget in each IJ still reflects facility-specific quantity and installation cost. The quote references the coordinated unit price, with the SAM.gov exclusions check (https://sam.gov/) run once at the organizational level and documented on each facility’s procurement file.

No double-counting. A camera installed at the parent facility cannot be charged to a satellite’s budget. Each piece of equipment is funded by the IJ for the facility where it physically operates. Indirect costs (project management, financial controls) can be allocated across sites under the indirect cost category, but direct equipment lines are facility-specific.

Allocation between sites. When one security committee oversees all sites, the planning category can fund that committee’s work and be allocated by a documented formula (square footage, peak occupancy, or facility count).

Carving federal and state. When a site is funded by both federal NSGP and a state program in the same cycle, equipment funded by each must be distinct line items. Splitting one piece between two awards is not allowed; the carve is documented in both IJs before submission.

Multi-Site Post-Award Coordination

The award notice opens a three-year period of performance for each funded IJ. A nonprofit with four awards manages them in parallel, each with its own drawdown schedule, procurement file, Environmental and Historic Preservation (EHP) review where applicable, and SAA reporting cadence.

Project lead. One person (security director, operations manager, or grant administrator) holds responsibility for all multi-site awards. Distributing post-award work across four facility-level volunteers produces inconsistent files, missed deadlines, and reporting that does not roll up.

Financial controls. The accounting system separates each award by facility, even when one bank account receives reimbursements. Each award’s drawdowns, expenses, and remaining balance are reconciled monthly. SAM.gov registration stays active and is renewed annually.

Reporting roll-up. Each award reports separately to the SAA (quarterly performance reports plus annual federal financial reports in most cycles). The project lead consolidates so leadership sees one dashboard; the SAA still receives four.

EHP coordination. Construction or ground-disturbance projects (fencing, bollards, exterior lighting) trigger EHP review on each affected award separately. EHP can run 30 to 90 days. A package with EHP triggers at three of four facilities needs three parallel submissions, scheduled so procurement begins on each site as soon as it clears.

Staggered closeout. Each award closes 90 days after its period of performance ends. When all four were obligated on the same date, all four close within the same window, producing concentrated workload the project lead schedules into the prior year.

Frequently Asked Questions

Can a federation submit IJs on behalf of its member institutions?

A federation that is the legal applicant for all members (members as program sites under one 501(c)(3)) submits as one multi-site organization with one UEI. A federation whose members are independently 501(c)(3) registered submits one IJ per member, each with its own UEI. Federations sometimes assume the centralized model is always available and discover at SAM.gov that each member needs its own registration.

Do we need separate SAM.gov registrations for each facility?

When facilities operate under one 501(c)(3), one registration covers all. When each facility is its own 501(c)(3), each needs its own UEI. Registration takes 10 to 15 business days for new registrants. Missing the renewal window on any one facility blocks that facility from the cycle.

Can the same vulnerability assessor sign assessments for all our facilities?

Yes. One qualified assessor producing one report per facility is standard practice and is preferred over multiple assessors producing inconsistent documents. The reports must be facility-specific, but a single signature across the assessments is acceptable.

If one facility is denied and three are funded in the same cycle, can the denial be appealed?

NSGP appeal mechanics are limited. Most denial communications are scoring outcomes that fell below the funded threshold, not formal denials that trigger an appeal right. The standard re-applicant strategy identifies the weakest section (inferable from comparing funded sites against the denied site within the same organization), strengthens it, and resubmits in the next cycle.

Can a multi-site organization add facilities in year two?

Yes. Each cycle is independent. An organization that funds four facilities in 2026 can resubmit them for new projects in 2027, add facilities deferred in 2026, or shift the slate based on changes in the risk picture.

What We Do

Security Grant Advisors builds multi-site NSGP applications for nonprofits operating multiple facilities. Engagements scope site selection, per-site IJ differentiation, coordinated vulnerability assessments, and submission through one or multiple SAAs. For federations, the work spans member-level coordination, model selection, and the multi-UEI workflow. For multi-campus ministries, it covers parent-plus-satellite slate construction, vendor pricing, and post-award management for parallel awards.

If your organization has multiple facilities (a parent congregation plus religious schools, a multi-campus ministry, a federation, or a cultural organization with branches) and is planning a 2026 or 2027 NSGP submission, SGA runs multi-site strategy engagements that scope site selection, per-site IJ differentiation, and central submission coordination through the SAA. You can book a free consultation with SGA here.

Official Sources

Confirm the current per-site cap, per-organization cap, and multi-site submission rules at the URLs below before scoping. State SAA contacts are listed on the FEMA program page.

  • FEMA Nonprofit Security Grant Program (NSGP): https://www.fema.gov/grants/preparedness/nonprofit-security
  • FEMA Urban Area Security Initiative (UASI list): https://www.fema.gov/grants/preparedness/urban-area-security-initiative
  • Grants.gov opportunity portal: https://www.grants.gov/
  • SAM.gov (Unique Entity Identifier registration): https://sam.gov/
  • FBI Hate Crime Statistics: https://www.fbi.gov/services/cjis/ucr/hate-crime

Table of Contents

Is Your Nonprofit
NSGP-Ready?

Before you apply for up to $600,000 in federal security funding, make sure your application has every required element. 

More Resources

Church Security Grants: Federal NSGP + State Programs for Christian Congregations in 2026
Synagogue Security Grants: Federal NSGP + State Programs for Jewish Institutions in 2026

Unlock Your Free PDF

Just one quick step! Fill in your details below and your PDF will be ready to download.