• June 2026

Why NSGP Applications Get Denied: The Scoring Patterns Behind Below-Threshold Scores

Most Nonprofit Security Grant Program (NSGP) denials do not happen because the application package was incomplete. They happen during scoring, after the submission passed administrative review. The score comes back below the funded line, and the applicant receives a notice with a number but no breakdown of which section pulled it down.

When SGA reads denial-cycle Investment Justifications (IJs), the cause is almost always one of four narrative patterns across the four scored criteria: Risk, Vulnerability, Consequences, and Effect of Funding. This article walks through each pattern and how to identify which one hit a specific application.

The Distinction Between Rejection and Denial

The two outcomes are often described with the same word, but they happen at different stages.

A rejection is an administrative-review failure. The State Administrative Agency (SAA) or the Federal Emergency Management Agency (FEMA) found a mechanical defect in the package: missing 501(c)(3) letter, expired SAM.gov UEI, wrong IJ template, wrong stream selected, missing mission statement. The package never reached scoring. Those process-side errors are covered in a separate article on common application mistakes.

A denial is a scoring failure. The package passed administrative review. Reviewers read the IJ against the four criteria and assigned a numeric score. The score landed below the funded threshold, either at the SAA layer (the SAA did not forward the application to FEMA) or at the FEMA layer (the application reached FEMA but did not score high enough before the appropriation was exhausted).

This article is about the second case. The reason is in the narrative, not the checklist.

Risk Pattern: Generic National References

The most common reason a credible IJ scores below the funded line is a risk section built on national statistics with no local connection.

The pattern: the applicant opens with the FBI Hate Crime Statistics summary for the prior year, cites national totals, mentions that incidents are rising, and quotes one or two high-profile attacks from elsewhere in the country. The risk section reads professionally and is sourced accurately.

Reviewers score it low because it does not document risk to the applicant. The same paragraph could appear in any IJ from any organization in the same denomination. Nothing is specific to the facility, the city, the congregation, or the region.

A high-scoring risk section does the opposite:

  • Names the FBI Hate Crime Statistics figure for the applicant’s state or metro area, not the national total
  • Cites incidents within a defined radius of the facility (25 to 50 miles is the standard window) by date, location, and either a police report number or a news link
  • Identifies the denominational, ideological, or community-profile reason the facility is a target, with a public-record citation
  • References threats received directly (mail, phone, email, social media) with dates and the response taken

The reviewer’s question is not “is hate crime a problem in this country.” It is “is this facility, in this place, at documented risk this cycle.” When the section answers the second with named sources, the score climbs. When it answers the first, the score stalls below the line regardless of how well written the rest of the IJ is.

The FBI publishes the data at https://www.fbi.gov/services/cjis/ucr/hate-crime, broken out by state and (in many cases) by metro area. Citing the state-level figure is a one-sentence fix that moves the section out of the generic pattern.

Risk Pattern: Borrowed Risk Narrative

The second risk pattern shows up in applications from organizations sharing a denominational network. Templates and example paragraphs circulate through denominational security agencies, peer congregations, and consultant sample IJs. The risk section is lifted, lightly edited, and submitted.

FEMA reviewers read dozens of IJs per cycle from the same denomination. When the same paragraph appears in multiple applications, scoring on that section drops for all of them. Even when the borrowed paragraph is factually accurate, it fails the documentation test because the incidents are not connected to the applicant’s community.

This pattern is harder to self-diagnose than the generic-national one. The applicant sees specific incidents and citations and concludes the section is strong. The weakness is that the incidents and threats belong to the peer organization.

The fix is to rebuild the section from the applicant’s own incident log, police report file, and regional FBI Hate Crime Statistics. Borrowed paragraphs can serve as a structural model. The content has to be local.

Vulnerability Pattern: Two-Sentence Vulnerability Section

The vulnerability assessment is a separate required document, often produced by a security consultant, and can run twenty or forty pages. The vulnerability section of the IJ has 5,000 characters under the current FEMA NSGP Notice of Funding Opportunity (NOFO), published at https://www.fema.gov/grants/preparedness/nonprofit-security.

In denied IJs, this section often runs two or three sentences. The applicant assumes the reviewer will read the attached assessment for the detail. They will not. The reviewer scores the IJ. The assessment supports it; it does not substitute for it.

When the section is short, the reviewer cannot see which gaps the funding closes, cannot connect the budget back to findings, and cannot evaluate whether the mitigations match the vulnerabilities. The score comes back low because the reviewer had nothing to score.

A high-scoring vulnerability section surfaces the assessment inside the IJ. It names the access points evaluated, lists the gaps found, and ties each to a numbered finding the reviewer can verify. It uses the full character allowance.

If your nonprofit was denied in the most recent NSGP cycle and you cannot tell which of the four scoring criteria pulled the score down, the denial narrative usually contains a fingerprint. We diagnose denials in a 30-minute call. Book a free consultation with SGA here.

Vulnerability Pattern: Budget Without Assessment Trail

The second vulnerability pattern is structural. The IJ describes a set of vulnerabilities. The budget proposes a set of line items. The two lists do not match.

Two versions are common. In the first, the budget includes items the vulnerability section never mentions: a $32,000 line for security cameras when camera coverage is never identified as a gap. In the second, the vulnerability section identifies a critical gap the budget does not fund: the south sanctuary entrance is named as undefended against vehicle approach, but the budget includes no bollards.

Reviewers score effect of funding against this trail. When a budget item has no upstream vulnerability, the reviewer cannot evaluate why the funding is needed. When a documented vulnerability has no budget line, the reviewer concludes the IJ is not internally consistent.

The fix is mechanical. Build a two-column table during drafting: vulnerabilities left, budget lines right. Every cell needs a counterpart.

Consequences Pattern: Adjectives Instead of Numbers

The consequences section is where reviewers most often see writing that reads well and scores poorly. The pattern: the applicant describes the impact of a successful attack with adjectives (“devastating,” “catastrophic,” “significant,” “irreplaceable”) and abstract groupings (“the community,” “our members,” “future generations”).

Adjectives do not score. The reviewer cannot rank a “devastating” loss against a “catastrophic” one. There is no scale. What can be scored is specificity:

  • Number of staff, members, students, or visitors on the facility on a typical day, on a peak day, and during the highest-occupancy named event of the year
  • Number of children in any on-site program (day school, daycare, after-school) with the age range
  • Number of elderly or mobility-limited individuals in regularly scheduled programs
  • Named community functions beyond the primary mission (polling location, food pantry, emergency shelter, blood drive site)
  • Recovery timeline in weeks or months for the programs that would be displaced
  • Geographic role (the only Reform synagogue in a county, the largest mosque serving a metro area, the only Catholic school in a 30-mile radius)

Each item is a number, a name, or a documented role. A consequences section built from items like these scores in the funded range because the reviewer can compare it directly against other applications.

Consequences Pattern: Missing Peak-Occupancy Specificity

The second consequences pattern recurs in faith-based applications. The IJ describes weekly service occupancy and does not address the peak-attendance event of the year.

Peak occupancy is the scoring inflection point because it represents the worst-case scenario. An attack at peak produces casualty figures an order of magnitude higher than at average occupancy. Reviewers want the date or event that produces peak named, with conditions described.

Named events vary by tradition: High Holy Days for Jewish congregations, Christmas Eve and Easter for Christian congregations, Eid al-Fitr and Eid al-Adha for Muslim congregations, Diwali for Hindu temples, Vaisakhi and Gurpurab for Sikh gurdwaras, graduation and major performances for schools, festival days for community centers.

An IJ that says “occupancy increases during religious holidays” loses points. An IJ that says “Yom Kippur services in October draw 1,150 attendees including 95 children under 13 in supervised programming and 120 adults age 70 and over” does not.

Effect-of-Funding Pattern: Budget Restated as Effect

Effect of funding is the most misunderstood of the four criteria. The pattern in denied IJs is to restate the budget as if reading it aloud were a scoring criterion. The section lists equipment, prices, and vendors, then ends.

The reviewer already has the budget as a separate document. Effect of funding is supposed to explain what changes when the mitigations are installed. The reviewer scores the explanation, not the list.

A strong paragraph reads:

Installation of six ASTM F2656 M30 rated bollards at the south sanctuary entrance closes the documented vehicle-approach vulnerability (Finding 4 in the attached assessment). At peak occupancy of 1,150 during High Holy Days, a vehicle ramming attempt that today could reach the structure at 35 mph would be stopped at the bollard line approximately 12 feet from the building. The mitigation also preserves street-side accessibility for elderly congregants without losing the standoff distance the assessment recommended.

It names the funded item, ties it to a numbered assessment finding, describes the scenario the mitigation addresses, and quantifies the change. The budget is implied. The effect is explicit.

Effect-of-Funding Pattern: Broken Chain

The chain the four criteria form is the scoring mechanism in most denied IJs. Each criterion can score adequately alone, and the application still falls below the funded line because the chain breaks somewhere.

The chain:

  1. Risk documents a specific threat picture
  2. Vulnerability identifies the gaps that threat would exploit
  3. Budget funds mitigations for those gaps
  4. Consequences quantify what the mitigations protect
  5. Effect of funding ties the mitigations back to consequence reduction

Reviewers see a broken chain when risk describes one threat type and vulnerability addresses a different one. Risk emphasizes targeted ideologically motivated attacks. Vulnerability emphasizes property crime and unauthorized access by transients. Budget funds general-purpose access control. Effect of funding describes deterrence against the property-crime scenario, not the ideological one risk opened with.

Each section, read alone, is competent. Read together, they describe three different threat models. The reviewer cannot give the IJ a high score because it does not make one coherent argument.

Fixing a broken chain starts in the risk section. Identify the threat the IJ is built around, then audit every subsequent section to confirm it responds to the same threat.

How to Tell Which Pattern Hit Your IJ

FEMA returns a numeric score after the cycle closes, not a breakdown by criterion. Applicants receive a total and a notice that the application fell below the funded line, with no indication of which section was the cause.

The diagnosis comes from reading the IJ against the patterns above. The fingerprint is in the document, not the FEMA response.

Self-diagnosis questions, in the order they surface the dominant pattern:

  1. Does the risk section cite a state or metro-area FBI Hate Crime Statistics figure, or only national totals?
  2. Does the risk section name incidents within 50 miles of the facility, with dates and citations?
  3. Is the vulnerability section at least 4,000 characters, or under 1,500?
  4. Does every budget line have a corresponding gap in the vulnerability section?
  5. Does every gap in the vulnerability section have a corresponding budget line?
  6. Does the consequences section state peak occupancy as a number tied to a named event?
  7. Does the effect-of-funding section explain what changes after installation, or restate the budget?
  8. Read end to end, does the IJ describe one coherent threat model from risk through effect of funding?

A “no” on 1 or 2 indicates the risk pattern. A “yes” on 3 (under 1,500) or “no” on 4 or 5 indicates the vulnerability pattern. A “no” on 6 or 7 indicates the consequences or effect-of-funding pattern. A “no” on 8 indicates the broken-chain pattern.

Denied IJs usually have more than one pattern. The value of the diagnosis is identifying the dominant one, because that is the section the re-application has to rebuild rather than revise.

Frequently Asked Questions

Does FEMA tell applicants which section scored lowest?

No. FEMA returns a numeric total and a notice of whether the application fell above or below the funded line. The breakdown by criterion is not released. Diagnostic work happens on the applicant’s side, reading the submitted IJ against the patterns reviewers downgrade.

Is the SAA score and the FEMA score the same?

No. The SAA scores first and forwards the top scorers to FEMA, which scores survivors against the federal rubric. Both layers use the same four criteria but apply state-specific weighting in many cases. An application can pass the SAA layer and still fall below the funded line at FEMA, and the notice does not specify which layer it failed at.

If the IJ was denied this cycle, can the same IJ be submitted next cycle?

Submitting the same IJ unchanged is the most common reason organizations are denied two or three cycles in a row. Each cycle is scored independently, but the patterns that pulled the score down do not change unless the narrative is rewritten. Re-applicants who submit with cosmetic edits score within a narrow range of the prior result in most cases SGA has reviewed.

Can the patterns be fixed without a new vulnerability assessment?

Some can. Risk, consequences, and effect-of-funding patterns can be addressed by rewriting against the existing assessment. Vulnerability patterns often require a refreshed assessment, especially when the original did not document access points the IJ needs to address. Assessments older than 18 months almost always need a refresh before re-submission.

Is a denied application a signal the organization is not eligible?

No. Eligibility is determined at administrative review. An application that was scored was eligible. A denied score reflects the IJ narrative, not the organization’s qualification. Denied applicants who rebuild the IJ around the patterns above are funded at a higher rate in subsequent cycles.

Does the U.S. Department of Homeland Security review IJs directly?

NSGP is administered by FEMA, a component of the U.S. Department of Homeland Security (https://www.dhs.gov/). Review panels are organized by FEMA. DHS sets the broader homeland security priorities, but cycle-by-cycle scoring is a FEMA function.

Where is the official application portal?

The federal grants portal is https://www.grants.gov/. State-level applications route through each state’s SAA portal, linked from https://www.fema.gov/grants/preparedness/nonprofit-security.

What We Do

Security Grant Advisors works with nonprofits that were denied in the most recent NSGP cycle and are evaluating whether to re-apply. The diagnostic engagement reads the prior IJ against the patterns above, identifies the dominant scoring weakness, and produces a rewrite plan focused on the section that scored lowest.

If your nonprofit was denied in the 2024 or 2025 NSGP cycle and you are evaluating whether the 2026 re-application warrants a full IJ rewrite or a targeted revision of one criterion, SGA runs denial-diagnosis calls where we read the prior IJ against the patterns described in this article and identify the section that scored lowest. You can book a free consultation with SGA here.

Official Sources

Confirm cycle requirements at the URLs below before re-submission.

  • FEMA Nonprofit Security Grant Program (NSGP): https://www.fema.gov/grants/preparedness/nonprofit-security
  • U.S. Department of Homeland Security: https://www.dhs.gov/
  • FBI Hate Crime Statistics: https://www.fbi.gov/services/cjis/ucr/hate-crime
  • Grants.gov opportunity portal: https://www.grants.gov/

Table of Contents

Is Your Nonprofit
NSGP-Ready?

Before you apply for up to $600,000 in federal security funding, make sure your application has every required element. 

More Resources

Multi-Site NSGP Applications: How to Win Funding Across Multiple Facilities
What Can NSGP Money Be Used For? The Seven Allowable Cost Categories

Unlock Your Free PDF

Just one quick step! Fill in your details below and your PDF will be ready to download.