The Investment Justification (IJ) is the scored narrative section of the Nonprofit Security Grant Program (NSGP) application. Reviewers read it against the criteria published in the current Notice of Funding Opportunity. Funding decisions are made from what the IJ proves, not from what the applicant claims about its mission.
This guide walks through every section the IJ requires, what reviewers score, and the specific gaps that put credible applications outside the funded range.
What the Investment Justification Is
The IJ is a structured document required by the Federal Emergency Management Agency (FEMA) for every facility a nonprofit wants funded under NSGP. One facility, one IJ. Multi-site applicants submit one IJ per facility, with a separate vulnerability assessment per site.
The current FEMA NSGP Notice of Funding Opportunity (NOFO) specifies the IJ template and the scoring rubric. The template is published on the official FEMA NSGP page (https://www.fema.gov/grants/preparedness/nonprofit-security) ahead of each cycle and through the federal grants portal at https://www.grants.gov/. FEMA offers the IJ as a fillable form and, in recent cycles, as a web version through Grants.gov.
Each narrative section has a length limit, and going over it truncates the text without warning. Confirm the current limits against the live NOFO and IJ form for the cycle you are applying in before you start writing.
Editor note (verify before publish): As of the date this publishes, confirm whether the FY2026 federal NOFO has been released. Early in 2026, several State Administrative Agencies opened pre-application windows ahead of the federal NOFO, which FEMA signaled it expected to publish later in the year. Funding levels for FY2026 were still unsettled. Do not state FY2026 limits or amounts as settled until the federal NOFO is live.
The Scored Sections of the IJ
The federal IJ is scored across several weighted requirements published in the NOFO’s evaluation appendix. They are not a single four-part chain. Reviewers score each requirement on its own, and off-rubric content earns nothing.
The scored requirements in the FY2025 federal NOFO were:
| IJ section | What reviewers look for | Common failure |
|---|---|---|
| Applicant Information | Complete, accurate identifying information (pass/fail completeness check) | Missing fields, which can reduce or disqualify |
| Background Information | The organization, its mission, the symbolic value that makes it a possible target, and any role in responding to or recovering from attacks | Generic description with no symbolic-value connection |
| Risk | Documented threat picture, the facility’s vulnerabilities, and the consequences if an attack succeeds | National references with no local documentation; adjectives instead of numbers |
| Facility Hardening | Proposed equipment and projects tied directly to the vulnerabilities named in the Risk section | Budget items with no underlying assessment finding |
| Milestones | A realistic schedule that fits inside the 36-month period of performance and accounts for environmental review | Timelines that ignore long-lead equipment or the review process |
| Project Management | Who will run the project and why they can | Section left blank or treated as an afterthought |
| Impact | Measurable outcomes that would show the investment worked | Restating the budget instead of describing the result |
The requirements still read best as one coherent argument. A documented risk that connects to a clear vulnerability, a facility hardening proposal that closes that vulnerability, a feasible schedule, a capable team, and a measurable result: that is a fundable IJ. When the sections disconnect, the score drops.
Applicants also self-identify an organization type inside the IJ. The FY2025 categories were Ideology-based/Spiritual/Religious (which covers houses of worship, religious schools, and faith-affiliated facilities), Educational (secular), Medical (secular), and Other. The organization type is a factor in the final score, so the self-identification and the Mission Statement need to line up.
A note on state programs: state NSGP-style programs do not all use the federal structure. California’s CSNSGP scores six sections on a 48-point scale. New York’s SCAHC scores on its own 100-point structure with the Vulnerability Assessment and Risk Assessment weighted heavily. If you are applying to a state program, score against that state’s published rubric, not the federal one.
Section 1: Background Information
Background sets the organizational and facility context and establishes why the site could be a target. Reviewers use it to understand who the applicant is before they read the risk picture.
What goes here:
- Legal name of the 501(c)(3) and the IRS determination date
- Type of organization (synagogue, church, mosque, day school, community center, cultural institution)
- Facility address and what operates there
- Total square footage and number of public-access points
- Typical and peak occupancy
- Hours of operation and major recurring events
- Number of staff, volunteers, and members served
- The symbolic value of the site: what makes it a recognized national, historical, or community institution that could draw an attack
- Any role the organization has played in responding to or recovering from an attack, and how that connects to broader state or local preparedness
Background is not the place to paste the IRS-filed mission statement. The Mission Statement is a separate required document, and repeating it here wastes space the symbolic-value and response-role content needs.
Section 2: Risk
In the federal IJ, Risk is one scored section that brings together three elements: the threat picture, the facility’s vulnerabilities, and the consequences if an attack succeeds. Reviewers want named threats, specific incidents, and numbers, not statements about national patterns.
Threat
The threat picture is the documented case that this organization, in this place, faces a real risk.
Sources that strengthen it:
- FBI Hate Crime Statistics (https://www.fbi.gov/services/cjis/ucr/hate-crime) for bias-motivation data relevant to the applicant
- Local police reports filed by the organization
- Documented threats received by mail, phone, email, or social media
- Public statements by extremist groups naming the organization, denomination, or community
- Local news coverage of incidents at peer organizations in the region
- Denominational security agencies (Secure Community Network for Jewish institutions, Catholic Mutual Group, denomination-specific security offices)
What weakens it:
- Quoting only national incident summaries with no local connection
- Citing risk that applies to every nonprofit (general crime, weather events)
- Inflating threat language with no source documentation
- Listing incidents without dates or sources
Risk does not require a prior attack on the specific facility. A documented community-level pattern, denominational visibility, or received threats are enough when each claim has a citation.
Vulnerability
The vulnerability discussion draws on the vulnerability assessment. The gaps the IJ describes should trace back to the assessment, and the equipment the budget funds should trace back to those gaps. Reviewers score whether the vulnerabilities described are consistent with the assessment, so the two documents need to line up.
Consequences
Consequences cover what happens if an attack succeeds at the funded facility. Reviewers score how clearly and specifically the applicant describes the potential harm, including the people present, the programs and community functions the facility supports, and any cultural, historic, or geographic significance. Specific, concrete descriptions score better than general statements.
Section 3: Facility Hardening
Facility Hardening is where the proposed equipment and projects connect back to the vulnerabilities named in the Risk section. This is the section that most often disconnects from the rest of the IJ.
For each proposed item, reviewers want to see three things:
- What the activity, project, or equipment is
- Its estimated cost
- How it mitigates a specific vulnerability already described in the Risk section
The proposals also have to focus on preventing or protecting against the risk of an attack, not on general facility improvement. Reviewers score how well the proposed work aligns with the vulnerabilities already described. When a funded line connects to a documented vulnerability, this section scores well. When the budget contains items the Risk section never raised, it scores below the line.
Section 4: Milestones
The Milestones section lays out a schedule for the proposed work. Reviewers score whether that schedule is realistic and whether it fits inside the period of performance.
NSGP has a three-year (36-month) period of performance from the award date. Milestones should:
- Cover the proposed activities across the period of performance
- Not exceed 36 months
- Not begin before the period of performance starts
- Account for the Environmental and Historic Preservation (EHP) review, which projects with construction or ground disturbance must clear before procurement begins
Equipment with long lead times (specialized barriers, custom doors, integrated access control systems) needs the full period of performance from the start. An item that takes eighteen months to procure and install cannot be reasonably scheduled for year three. The EHP guidance is published at https://www.fema.gov/grants/tools/environmental-historic-preservation.
Section 5: Project Management
Project Management asks who will run the project and why they can deliver it. Reviewers score how well the applicant justifies the management team’s roles and the governance structure behind the work.
A strong response names the project manager, describes their relevant experience, and shows there is a structure in place to carry the project through procurement, installation, and reporting. This section is short, but applicants who leave it thin lose points they did not need to.
Section 6: Impact
Impact describes the outcomes and outputs that would show the investment succeeded. Reviewers want measurable results that link directly back to the vulnerabilities and consequences described in the Risk section.
This is not a restatement of the budget. The budget lists what is purchased. Impact describes what the purchase changes: the gap that closes, the access point that is now controlled, the scenario that the facility can now interrupt. Where you can attach a number or a clear before-and-after, do.
The Mission Statement (Separate Required Document)
The Mission Statement is not part of the IJ. It is a separate document submitted with the application, required for NSGP. The SAA uses it, together with the self-identification in the IJ, to validate the organization type, which feeds the final score.
What it establishes:
- The ideology, beliefs, mission, or symbolic profile that places the organization at risk
- Public visibility (signage, events, online presence, media coverage)
- The community served and its identifying characteristics
What it is not: the IRS-filed mission statement. The NSGP Mission Statement is built for the risk question, not the tax-exemption question. A strong one names the denomination, describes visible programs, and references documented community-level threats without overstating them.
Common Reasons IJs Fall Below the Funded Line
Across review cycles, the same patterns recur in IJs that clear eligibility but score below the funded threshold:
- Risk borrowed from a peer organization. Reviewers see the same paragraph in multiple applications from the same denomination or region. Risk has to be local.
- Vulnerability summarized in two sentences. Reviewers cannot evaluate gaps they cannot see. The assessment exists. Surface its findings.
- Consequences written in adjectives. General language about devastating or significant impact reads the same across every application. Specific descriptions score better.
- Facility hardening that restates the budget. The budget already lists what is purchased. This section has to connect each item to a documented vulnerability.
- Milestones and project management left thin. Both are scored. A schedule that ignores long-lead equipment, or a management section left nearly blank, gives away points.
- Cost categories outside the allowable list. The current NOFO publishes the allowable cost categories at https://www.fema.gov/grants/preparedness/nonprofit-security. Items outside those categories cannot be funded.
What to Submit Alongside the IJ
The IJ is one document in a larger submission package. The full federal NSGP submission typically includes:
- Investment Justification (one per facility)
- Vulnerability/risk assessment (one per facility, supports the IJ)
- Mission Statement
- Budget detail (line items, vendor quotes, cost basis)
- 501(c)(3) IRS determination letter
- A SAM.gov Unique Entity Identifier (UEI), active and not expired. Register or renew at https://sam.gov/
- SAA cover documents per state
Note that the Vulnerability/Risk Assessment and Mission Statement are maintained by the SAA rather than uploaded to the federal system, but must be available to FEMA on request. State NSGP-style programs require additional state-specific documents, and each state SAA publishes its own checklist.
Procurement Rules That Affect the Budget
Procurement under NSGP follows 2 CFR Part 200, the federal Uniform Guidance, published at https://www.ecfr.gov/current/title-2/subtitle-A/chapter-II/part-200. Above the micro-purchase threshold, purchases require documented competition. The procurement file must show:
- The vendor list contacted
- Quotes received, with dates and amounts
- The selection rationale
- A vendor responsibility check (confirm the vendor is not federally debarred via the SAM.gov exclusions search at https://sam.gov/content/exclusions)
- The contract or purchase order
- The invoice
- Proof of payment
Procurement gaps are a common reason an awarded organization cannot draw down funds. The IJ does not address procurement directly, but anticipating it at the IJ stage keeps the budget realistic and the schedule workable.
What Happens After Submission
The application moves through several review layers:
- State Administrative Agency review. Each SAA ranks the submissions in its state and forwards them to FEMA. SAA-level scoring determines how the application is ranked before it reaches FEMA.
- FEMA review and scoring. FEMA panels score the IJs against the published criteria. The highest-scoring IJs are funded until the appropriation is exhausted.
- Award notification. Typically late summer or early fall for spring submissions, though recent cycles have run late. The award notice opens the period of performance.
- Environmental and Historic Preservation (EHP) review. Funded projects with construction or ground disturbance require EHP clearance before procurement begins.
- Procurement and drawdown. Competitive procurement under 2 CFR Part 200, then reimbursement requests through the SAA portal.
The IJ is the gate. Everything downstream is operational.
Frequently Asked Questions
Does the IJ need to be written by a grant writer?
Technically, no. The NOFO does not require a credentialed grant writer. In practice, the IJs that score in the funded range almost always reflect three things most internal authors do not have together: pattern recognition across many prior cycles, calibration to the current NOFO rubric (which shifts between years), and an editor who reads the sections as one connected argument rather than a stack of paragraphs. Internal teams can produce a strong IJ when the executive director, security committee chair, and a writer all dedicate uninterrupted weeks to it and start from an assessment that is already solid. The most common pattern in denials is an internally written IJ that documents risk well, mentions vulnerability briefly, and never connects the facility hardening proposal back to the documented gaps.
Can the same IJ be used for state and federal programs?
The narrative content can be reused. The structure, length limits, and required attachments differ between federal NSGP and state programs, and state programs score on their own rubrics. State applications require state-specific forms and, in several states, additional documents such as photographs in the assessment. Copy-pasting the federal IJ into a state portal without restructuring is a common reason credible state applications are rejected at administrative review, before scoring even starts.
What if the vulnerability assessment is old?
As a rule of thumb, if the assessment is more than three years old, refresh it, and add photographs if the prior version did not have them. Reviewers downgrade IJs that cite assessments from prior cycles without updates. A professional reassessment often catches gaps a self-walkthrough misses.
Can the IJ reference incidents at peer organizations?
Yes, when the peer organization is geographically or denominationally relevant. National incident summaries are weaker than local peer incidents within the region. The strongest IJs cite several specific peer incidents with dates, locations, and either news links or police report numbers.
Does the IJ score affect future cycle applications?
No. Each cycle is scored independently, and re-applicants are not penalized for prior denials. The standard re-applicant strategy is to strengthen the section that scored lowest last time. The challenge is identifying which section that was, since FEMA returns a numeric score without a breakdown by criterion.
What We Do
Security Grant Advisors drafts IJs for nonprofits applying to federal NSGP and state programs. The work covers vulnerability assessment review, threat documentation, IJ drafting against the current NOFO rubric, budget assembly with vendor quotes, and submission through the SAA portal.
For organizations denied in prior cycles, we run a rewrite engagement focused on the lowest-scoring section. For first-time applicants, we run an engagement that produces the full submission package.
If any of this is confusing, or you want to talk through how it applies to your organization, we are happy to help. You can book a free consultation with SGA here: [link]
Official Sources
Confirm the current cycle requirements at the official URLs below before submission.
- FEMA Nonprofit Security Grant Program (NSGP): https://www.fema.gov/grants/preparedness/nonprofit-security
- Grants.gov opportunity portal: https://www.grants.gov/
- SAM.gov (Unique Entity Identifier registration): https://sam.gov/
- SAM.gov Exclusions (federal debarment search): https://sam.gov/content/exclusions
- 2 CFR Part 200 (Uniform Guidance for federal awards): https://www.ecfr.gov/current/title-2/subtitle-A/chapter-II/part-200
- FEMA Environmental and Historic Preservation (EHP) review: https://www.fema.gov/grants/tools/environmental-historic-preservation
- FBI Hate Crime Statistics: https://www.fbi.gov/services/cjis/ucr/hate-crime
- U.S. Department of Homeland Security: https://www.dhs.gov/
State Administrative Agencies publish state-specific NOFOs and submission portals. Confirm the current SAA contact for your state through the FEMA grants portal above.