If you are preparing a security grant application, you have probably seen the term vulnerability assessment and wondered whether you need to hire someone to write a thick professional report. For most applicants, you do not. This post explains what the assessment actually is, what it has to accomplish, and when it makes sense to bring in outside help.
A vulnerability assessment is a written record of the security gaps at one of your buildings. For the Nonprofit Security Grant Program (NSGP) and most state programs, it is usually a standardized worksheet the program gives you, not a custom report you commission. You can complete it yourself. Its real job is simple: every item you ask the grant to pay for should point back to a specific weakness the assessment names.
What the assessment actually is
The Nonprofit Security Grant Program, or NSGP, is a federal grant that helps at-risk nonprofits and houses of worship pay for security improvements. Many states run their own versions with similar rules. Every one of these programs asks for a vulnerability assessment before it will fund anything.
The assessment is a structured look at a single building. It records the ways someone could get in or cause harm, the security measures already in place, and the gaps that remain. One facility gets one assessment. If you are applying for two locations, you complete two.
Here is the part worth understanding clearly. The people who score your application read what you submit. They are not visiting your property or walking your parking lot. The assessment is the evidence behind your request. If a gap is not written down, the reviewer has no way to know it exists, and the funding you asked for to fix it has nothing to stand on.
It is usually a worksheet, not a long report
A common worry is that the assessment has to be a long, professionally written document. In most cases it does not.
Several programs hand you a fill-in worksheet and ask you to use it.
- In California, the Cal OES Vulnerability Assessment Worksheet is the required form. The state is direct about what it is: a tool to help you complete your application, not a security checklist, and it is not scored on its own.
- In New York, the SCAHC program requires a Vulnerability Self-Assessment Tool, one for each facility, submitted through the state grants system.
At the federal level, FEMA does not hand you a single required form, but the Investment Justification, the main written part of your application, has to describe the findings from a completed assessment. The assessment supports the application. The application is what gets scored.
The one job the assessment has to do
Whatever form your assessment takes, it has one core job: connect every funded item to a real weakness.
Reviewers look for a clear line from problem to solution. If you ask for cameras, the assessment should show where you currently cannot see. If you ask for a fence, it should show where the perimeter is open. The federal program scores this directly. An item that is not tied to a documented gap tends to lose points or get cut.
This is why vague language hurts you. “Improve security at the rear of the building” is not a gap a reviewer can act on. “The rear staff door is unlit after dark and has no camera covering it” is. The second version gives your request something to point to.
What to look at when you walk your building
You do not need security training to spot most of what belongs in an assessment. Walk your property once during a busy service or event, and once after dark, and look at each of these:
- Entrances. Not just the front doors. Side doors, the staff entrance, the kitchen or delivery door, and any door propped open during events. Note the door material, the lock, and whether anyone can see it.
- Windows and glass. Ground-floor windows, glass next to main doors, and large lobby or sanctuary windows. Glass is one of the most common ways into a building and one of the most overlooked.
- Lighting. Lighting at noon is not lighting at 8 p.m. in December. Look at your entrances and parking after dark, when your evening programs actually run.
- Cameras and blind spots. Where do your current cameras reach, and where can no one see at all?
- Parking and perimeter. Fences, gates, gaps, and how close a vehicle can get to the building.
- Roof and utility access. Outside ladders, low roof access, and the doors to mechanical, electrical, and utility rooms.
If something does not apply to your building, say so. A blank where a reviewer expects an answer reads as something you missed.
Federal and state programs: a few examples
The basic idea is the same everywhere, but the specifics vary by program. Two examples from current materials:
- California. The Cal OES Vulnerability Assessment Worksheet is required for both the state program (CSNSGP) and the federal NSGP application, which the state administers. The worksheet must be signed. Self-assessments are allowed, and the state does not review who completed it or how. One useful rule to know: if a security company writes your assessment, that company cannot then bid on the equipment or work the grant pays for.
- New York (SCAHC). Uses the state’s Vulnerability Self-Assessment Tool, one per facility. You also submit a ground-level photo of the front of each building, plus photos of any spot where you plan to do work, such as the exact location where a new fence would go. An assessment completed within the past year can be reused if it still reflects your building.
These details change from year to year and from state to state. Always work from the current notice for your program, and confirm the exact form your state wants before you start.
Can you do it yourself?
For the federal program and most state programs, yes. There is no federal rule that your assessment be written by a former police officer or a certified professional. California states plainly that self-assessments are accepted and that it does not review the assessor’s credentials.
Doing it yourself works well when your building is straightforward and your leadership knows it well. Outside help tends to earn its cost in three situations: a large or multi-building campus, a first application where you want the written gaps to line up cleanly with the items you are requesting, and cases where an internal walk keeps missing the same back-of-house doors, utility rooms, and roof access points.
One caution from the California example applies more broadly. If you hire a security company to assess your building, check whether your program bars that same company from selling you the equipment afterward. Keeping the assessment independent of the sale protects both you and your application.
What this means for your organization
For most houses of worship and nonprofits, the vulnerability assessment is more manageable than it sounds. It is often a worksheet the program provides, you are allowed to complete it yourself, and its purpose is practical: give every dollar you request a specific weakness to point back to.
The applications that struggle are not the ones with simple assessments. They are the ones where the assessment is vague, skips obvious entry points, or never mentions the gap a budget line is supposed to fix. Walk your building honestly, write down what you find in plain terms, and make sure each item in your budget answers something on that list.
A few common questions
Do we have to hire a professional? No. The federal program and California both accept self-assessments. Outside help is optional and most useful for large campuses or first-time applicants.
Does one assessment cover multiple facilities? No. These programs work facility. Each location gets its own assessment and, in most programs, its own application.
Is the assessment itself scored? At the federal level, reviewers score how well your application describes the findings. California states that its worksheet is not scored on its own. Either way, the assessment exists to support the request.
What if we have never had an incident? That does not matter for this section. The assessment documents the gaps that exist today, not your history. A building with no past incidents completes the same assessment as one with several.
Still have questions?
Figuring out which form your program wants, and making sure your assessment supports the funding you are requesting, is the kind of thing that goes faster with a second set of eyes. If you want to talk through how this applies to your organization, we’re happy to help. You can book a free consultation with SGA here: [link]