FINAL - FY2023_CYBERSECURITY_NOTICE_OF_FUNDING_OPPORTUNITY.pdf

PDF 301 KB Posted

Attached to
Cybersecurity for Small Business Pilot Program Federal grant opportunity
Opportunity number
OED-2023-01
Issued by
Small Business Administration

About this file

Notice of Funding Opportunity

View the file

Other files for this federal grant opportunity

Other files attached to Cybersecurity for Small Business Pilot Program, newest first.
File Type Posted
Cybersecurity for Small Business FAQ OED- 2023-001_.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Small Business Administration Office of Entrepreneurial Development

Funding Opportunity No. OED-2023-01

Page | 1

CYBERSECURITY FOR SMALL BUSINESS

PILOT PROGRAM

FUNDING OPPORTUNITY

FY 2023

FUNDING OPPORTUNITY NO.

OED-2023-001

The purpose of this Funding Opportunity is to invite proposals for funding from state government entities

(within US). For-profit businesses are not eligible for this award. The following states are ineligible, Arkansas, South Dakota, and Maryland.

Opening Date for Proposals: March 10, 2023

Closing Date for Proposals: May 12, 2023

Proposals responding to this program Funding Opportunity notice must be posted to www.grants.gov by 11:59 PM Eastern Time (ET) on May 12, 2023. No other methods of submission will be permitted.

Proposals submitted after the stipulated deadline will be rejected without being evaluated. GrantSolutions is the official grant system used for this award.

http://www.granssolution.gov/

Page | 2

TABLE OF CONTENTS

Section I. Funding Opportunity Description 3

Program Overview

Background

Purpose

SBA Involvement and Oversight

Changes or Cancellation

Section II. Award Information 5

Expected Number of Awards

Period of Performance/Budget Period

Funding Information

Funding Instrument

Match Requirement

Section III. Eligibility 6

General

Eligible Applicants

Ineligible Applicants

Section IV. Application and Submission Information 7

Application Instructions

Submission Instructions

Required Proposal Submission Date

Section V. Application Review Information 17

General

Evaluation Criteria

Review and Selection Process

Section VI. Award Administration 19

Award Notification

Administrative and National Policy Requirements

Reporting

Record Keeping Requirements

Section VII. Agency Contacts 21

Program Point of Contact

Financial/Grants Management Point of Contact

Section VIII. Other Information 21

Definitions, Guidelines, and Checklist

Page | 3

Section I – Funding Opportunity Description

1.0 Program Overview

1.1.1. Federal Agency Name U. S. Small Business Administration, Office of Entrepreneurial Development

1.1.2. Funding Opportunity

Title

Cybersecurity for Small Business Pilot Program

1.1.3. Announcement Type Initial

1.1.4. Funding Opportunity

Number:

Funding Opportunity No. OED-2023-001

1.1.5. CFDA Number 59.079

1.1.6. Closing Date for

Submissions:

May 12, 2023, Proposal due via www.grants.gov at 11:59 P.M. ET for Funding Opportunity No. OED-2023-001;

1.1.7. Authority: 15 USC 648(a)(8)

1.1.8. Duration of Authority: Permanent

1.1.9. Funding Instrument: Grant

1.1.10. Funding: Funding is for a twenty-four-month period.

1.1.11. Award

Amount/Funding Range:

The amount of Cybersecurity for Small Business Pilot Program funding in FY2023 is $6,000,000 subject to the availability of funds.

Applicants can apply for awards ranging from $800,000 (minimum) to $1,000,000 (maximum) for the period of performance.

1.1.12. Project Duration: Awards will be made for a period of 24 months.

1.1.13. Project Starting Date: Within 30 calendar days of the start date of the Project Period.

1.1.14. Proposal Evaluation: An initial screening for eligibility (in accordance with Section 3.1) will be conducted by the program office. Proposals will be reviewed for sufficiency and quality as detailed in Sections 4 and 5. SBA may ask Applicant for clarification of technical proposal and cost aspects of proposals.

1.1.15. Agency Programmatic

Point of Contact:

Philip T. Gibson, U.S. Small Business Administration Headquarters

Interested parties may submit questions to OEE email inbox (OEE@SBA.gov) during the Q&A open period (April 17 through April 21). SBA will post answers to the questions on Grants.gov by April 28, 2023. No additional questions will be collected after April 21, 2023.

http://www.grants.gov/

Page | 4

Introduction

In 2021, the FBI’s Internet Crime Complaint Center received 847,376 complaints regarding cyberattacks and malicious cyber activity with nearly $7 billion in losses, the majority of which targeted small businesses. Small businesses are attractive targets because they have information that cybercriminals want, and they typically lack the security infrastructure of larger businesses.

According to a recent SBA survey, 88% of small business owners felt their business was vulnerable to a cyber-attack.

Yet many businesses can’t afford professional IT solutions, have limited time to devote to cybersecurity, or they don’t know where to begin.

The Consolidated Appropriations Acts, 2022 and 2023, authorized the U.S. Small Business Administration to make grants to States, and the equivalent thereof, to carry out projects that help new small business concerns with tools to combat cybersecurity threats during their formative and most vulnerable years.

Background

Since its inception in 1953, SBA has served to aid, counsel, assist and protect the interests of small businesses. While

SBA is best known for its financial support of small businesses through its many lending programs, the Agency also plays a critical role in providing funding to organizations that deliver technical assistance in the form of counseling and training to small business concerns and nascent entrepreneurs in order to promote growth, expansion, innovation, increased productivity, and management improvement. The mission of SBA’s Office of Entrepreneurial

Development, which bears responsibility for administering and overseeing the Cybersecurity for Small Business Pilot

Program, is to provide assistance to the small business community by linking the resources of Federal, state, and local governments with the resources of the educational community and the private sector.

Purpose

Eligible organizations, as defined in Section 3.2, may apply to SBA for an award of financial assistance under this

Funding Opportunity.

Leveraging of Resources

Applicants selected for awards under this Funding Opportunity announcement are encouraged to maximize their efforts to leverage SBA funding by working in conjunction with SBA District Offices and other Federal, state, local and tribal government small business development programs and activities; SBA resource partners such as Small

Business Development Centers (SBDCs), SCORE, Women’s Business Centers (WBCs), Veterans Business Outreach

Centers (VBOCs), SBA Community Navigators, 7(j) Technical Assistance providers, Small Business Investment

Companies (SBICs), U.S. Export Assistance Centers (USEACs), Certified Development Companies (CDCs) and

SBA lenders; universities, colleges, and other institutions of higher education; and private organizations such as chambers of commerce and trade and industry groups and associations.

SBA Involvement and Oversight

The Cybersecurity for Small Business Pilot Program is managed by the Office of Entrepreneurial Development

(OED) at SBA Headquarters. The SBA will administer, monitor, and oversee the grant. OED shall assign a Grants

Management Officer (GMO) to review the budget and all fiscal documentation for compliance with applicable

Federal and program requirements and issue the Notice of Award. A Program Manager within OED will serve as the

Grants Officer Technical Representative (GOTR) responsible for overall monitoring and oversight of the Recipient’s

Page | 5 award, including compliance with the terms and conditions of the Grant and program service delivery and performance.

Changes or Cancellation

SBA reserves the right to amend or cancel this Funding Opportunity, in whole or in part, at the Agency’s discretion.

Should SBA make material changes to this Funding Opportunity, the Agency will extend the closing date as necessary to afford Applicants sufficient opportunity to address such changes.

Section II – Award Information

Estimated Funding

SBA expects to issue awards based on the funds appropriated. The Federal budget for the Cybersecurity for Small

Business Program for program year 2023-2024 is $6,000,000.

Subject to the availability of funds and compliance with the terms and conditions of the Grant, SBA has the discretion to increase the award to an amount consistent with the authorized funding level under the federal appropriations law.

Expected Number of Awards

SBA expects to award up to six awards with no single award exceeding $1,000,000. Individual award amounts are anticipated in the range of $800,000 to $1,000,000.

Period of Performance/Budget Periods

The period of performance for this award is one-year (24-months).

Project Start Dates

The project start dates are:

August 31, 2023, or 30 days after notification of award for states responding to Funding Opportunity No. OED-

2023-001.

Funding Information

Funds provided under the Cybersecurity for Small Business Pilot Program must be used solely for the purposes stipulated in this Funding Opportunity and the Notice of Award and may not be commingled with any other monies.

All costs proposed in an Applicant’s budget must be allowable, allocable, and reasonable as set forth in the applicable

Office of Management and Budget (OMB) cost principles.

Reimbursement of indirect costs from Federal funds will be capped at a maximum of 20 percent, regardless of the amount stipulated in an Applicant’s indirect cost rate (ICR) Agreement.

Funding Instrument

The funding instrument is a grant.

Page | 6

Matching Requirement

Awards made under this Announcement will require no contribution of non-Federal matching funds.

No program income is approved for this award.

Section III – Eligibility Information

General

An organization may NOT submit more than one proposal per geographic community (state) in response to this

Funding Opportunity. In the event SBA receives multiple proposals from a single organization, all proposals submitted by that organization will be automatically rejected without evaluation.

Eligible Applicants

To be eligible for this Funding Opportunity an Applicant must be a “State,” meaning any of the United States, the

District of Columbia, the Commonwealth of Puerto Rico, the U.S. Virgin Islands, Guam, the Commonwealth of

Northern Mariana Islands, and American Samoa. Therefore, only non-Federal entities that meet this definition are eligible to apply for and administer an award under this Notice of Funding Opportunity. For purposes of this Notice of Funding Opportunity, the term “eligible non-Federal entity” means a State agency or other entity that, prior to the date of application for this Announcement, has been officially designated by the State Governor, or equivalent thereof (e.g., Mayor of the District of Columbia), as the sole applicant and lead entity for conducting the State’s cybersecurity education and/or resolution services. The following states are ineligible, Arkansas, South Dakota, and Maryland.

i. Only those proposals accompanied by the written designation of the State Governor, or his/her designee, may submit an application for evaluation and funding consideration.

ii. Should the Governor, or equivalent thereof, assign to a designee the signatory responsibility for the designation letter, the designation letter must include an acknowledgement that the Governor, or his/her equivalent, has authorized the designee to sign the letter on his/her behalf.

iii. For insular areas, the equivalent of a State Governor is the appropriate signatory.

Ineligible Applicants

The following will automatically be considered ineligible, and their applications will be rejected without being evaluated:

i. Any organization that has not been officially designated by a State Governor as the sole applicant and lead entity for conducting the State’s cybersecurity education and/or remediation services (See Section - Eligible non-Federal entity, above.);

ii. Any organization that owes an outstanding and unresolved financial obligation to the Federal government;

iii. Any organization that is currently suspended, debarred, or otherwise prohibited from receiving awards of contracts, grants, or cooperative agreements from the Federal government;

iv. Any organization with an outstanding and unresolved material deficiency reported under the requirements of the

Single Audit Act or OMB Circular A-133 within the past three years;

Page | 7

v. Any organization that has had a grant or cooperative agreement involuntarily terminated or non-renewed by SBA for cause within the past one year;

vi. Any organization that has filed for bankruptcy within the past five years;

vii. Any organization that proposes to serve as a pass-through and permits another organization to manage the day-to-day operations of the project; and/or

viii. Any organization that was convicted or had an officer or agent acting on its behalf convicted, of a felony criminal violation under any Federal law within the past two years.

Section IV – Application and Submission Information

Application Instructions

General

i. A State may submit only one proposal in response to this Notice of Funding Opportunity.

ii. Any additional applications from a State will automatically be rejected without being evaluated. (Only the latest application successfully submitted by an eligible non-Federal entity to Grants.gov will be screened for potential evaluation for an award.)

iii. Non-Federal entities must round all monetary values to the nearest whole dollar in all budgetary and financial application document submissions.

Multiple states/territories are allowed to apply jointly if each is eligible under the terms of the Notice of Funding

Opportunity.

Under such circumstances, the application should identify each eligible entity within the submitted application, including designation by each applicable Governor, the roles and budget applicable to each eligible entity covered by the application, the lead applicant which is submitting the application, and detailed agreement on overall project management including performance reporting.

All applications successfully submitted to SBA via Grants.gov will undergo a screening process, consisting of a review for Applicant eligibility and application completeness. Applications will be rejected without further evaluation if they are submitted by ineligible entities, or they are non-responsive to the requirements of this Notice of Funding

Opportunity.

The following documents are completed as part of the electronic application form on Grants.gov:

1) SF-424, Application Federal Assistance,

2) SF-424A, Budget Information, All documents must be submitted as separate attachments due to new Grants.gov workspace requirements.

Documents cannot be bundled together.

Instructions for file naming conventions: Please include the following attachments separately using the exact name and standard order outlined below. The Application elements as described below should be named with the

Page | 8

Attachment number [#], Applicant’s State abbreviation (do not spell out state name), and name of document

(identified in the left-hand side of chart below). Do not add the word “attachment” in the file name.

For example: [1] [State abbreviation] Cover Letter. Applications must upload the following elements as attachments in Grants.gov.

REQUIRED APPLICATION ELEMENTS

The following Financial Assistance General Certifications and Representations are located within the System for

Award Management (SAM.gov) and do not need to be submitted with this application:

• Lobbying Disclosure Act of 1995, 2 U.S.C. 1601 et seq.

• Financial Management Certification – 2 CFR 200.302 & 2 CFR 200.303

• Debarment and Suspension – 2 CFR Part 180

• Drug-Free Workplace – 41 U.S.C. 8103

• Tax Compliance – Section 543 of PL 112-55

• Conflict of Interest – 2 CFR 200.112

Cover Letter (Maximum 1 page)

[1] Cover Letter - (Signed) PDF format

The first element of the application must be a cover letter containing a summary of each non-Federal entity’s key proposed cybersecurity activities. Submit the Cover Letter electronically in .PDF format. The cover letter is not counted in the 12-page requirement and must be one page and include the following information:

i. Non-Federal entity’s name and address (which must match the Governor’s Letter of designation);

ii. Non-Federal entity’s website address;

iii. Non-Federal entity’s cybersecurity webpage, if one already exists;

iv. Name, telephone number, fax number, and email address of the non-Federal entity’s designated point of contact

(the Authorized Organizational Representative);

v. Dollar amount of Federal assistance being requested;

vi. A one paragraph summary (110-125 words) of the proposed cybersecurity activities supporting the proposed milestone goals. Use the following language to start this requirement:

“The (fill in State name) will use Cybersecurity for Small Business Pilot Program award funds to support cybersecurity for eligible small business concerns to include (insert the proposed activities)”.

Technical Proposal (Maximum 12 pages)

[2] [State abbreviation] Technical Proposal-Word format

To expedite the proposal review process, Applicants must submit their Technical Proposal referenced in application instructions Appendix. The proposal elements must be in the same order as the evaluation criteria in Section 5.2 of the Notice of Funding Opportunity. The proposal may not exceed 12 pages (excluding title page and cover page) and must be double-spaced on 8 ½ x 11- inch paper (electronic document format). Times New Roman in 12-point font is

Page | 9 required. Only the first 12 pages will be reviewed and evaluated. An applicant will not be notified and consulted if additional pages are eliminated and not reviewed.

Non-Federal entities are strongly encouraged to prepare focused proposals including, performance measures and metrics that support activities that can realistically be achieved within the 24-months performance period.

i. Introduction: Start the Technical Proposal with an ‘Introduction’ section on page one (not on the title page) that summarizes in no more than one (1) paragraph, your organization’s requested Federal and Non-Federal award amount, targeted number of eligible small business concerns, brief description of proposed statutory activities that will be achieved with Cybersecurity for Small Business Pilot Program funds in the 24-months performance period, the total expected cybersecurity clients served/trained, and anticipated number of cyber threats/attacks addressed or averted.

ii. Cybersecurity Experience: In an estimated (1) page, the organizational capability to achieve success in the past and/or present to educate, prepare and serve small business concerns on critical cybersecurity matters.

iii. Project Design: In an estimated 1-7 pages, labeled with the main heading ‘Project Design’, this section should demonstrate how credible and impactful the non-Federal entity’s organization can leverage partnerships to help identify, reach, and serve new small business concerns on critical cybersecurity matters.

This section must address all components as described in Section 5.2:

a. Performance Measures, Metrics & Outcomes;

b. Direct Benefit to Small Business Communities and Clients; and

c. Collaboration;

iv. Data Collection & Measurement of Outcomes - In an estimated 2 pages, labeled with the main heading ‘Data

Collection and Measurement of Outcomes’, this section must address the required data collection elements

(include metrics) identified in Section 5.2.7; and, the quality of Applicant’s ability to quantitatively measure progress towards achieving proposed outcomes. Cybersecurity for Small Business Pilot Program’s may include, but are not limited to, number of small business clients served, number of cybersecurity cases resolved, client satisfaction measurements, and potential or realized cost-savings of cybersecurity resolution/avoidance/mitigation to small business client(s).

Proposed Plan: Performance Measures & Outcomes

[3] [State abbreviation] Proposed Plan - Excel format

Non-Federal entities will be responsible for preparing a Proposed Plan including, Performance Measures and

Outcomes in an MS Excel spreadsheet.

The Proposed Plan serves as the data blueprint to measure the extent to which the Cybersecurity for Small Business

Pilot Program grant recipient achieves program activities and the results (outcomes) of those measures. If awarded a grant, the grant recipient will be assigned a Cybersecurity for Small Business Pilot Program. The Program Manager who is responsible for reviewing and approving your plan. Grant recipients will be required to report performance measures achieved, activities completed, and measurable results on a quarterly basis for the full two-year award period. SBA will collect, analyze, and utilize this data to evaluate the program’s overall success. Client data will be confidential and used by SBA only if permission is given by a representative of the eligible small business concern.

Page | 10

Budget

Each Applicant must provide budget information according to the specific instructions for each item. Submit budget information documents separately, in the following order, with the file name labeled as follows:

Standard Form (SF) 424, Application for Federal Assistance

[4] [State abbreviation] SF 424 Online and PDF format SF 424

Application for Federal Assistance. This standardized form requires basic information about your organization. The

Cybersecurity for Small Business Pilot Program Project Director must be listed in block 8f on the SF 424, not a grant writer or any other contact person, since this is where SBA obtains the contact information to generate the Notice of

Award for acceptance of the grant. Pertinent information regarding this announcement and all programmatic matters will also need to be provided to the Cybersecurity for Small Business Pilot Program Project Director listed in block

8f.

SF-424A, Budget Information (Non-Construction Programs)

[5] [State abbreviation] SF 424A - Online and PDF format

This form requires an estimate of the Applicant's total cost of executing Cybersecurity for Small Business Pilot

Program activities described in the technical proposal.

a. For Section A, fill in columns (a) with ‘Cybersecurity for Small Business Pilot Program’, (b) with 59.061, and appropriate total amounts in (e), (f), and (g);

Attachments A-9 through A-12 (Budget Detail Worksheets)

[6] [State abbreviation] A9 - A12- PDF format

a. A non-Federal entity Cybersecurity for Small Business Pilot Program Project Director must devote at least 50% of his/her time, to the Cybersecurity for Small Business Pilot Program project.

b. On the A-9, identify all personnel who will be funded by Federal amount or who will support the Cybersecurity for Small Business Pilot Program project without project funding (follow the sample shown on the A-9

‘Supplementary Instructions’ for personnel calculations; do not include the A-9 instruction page in the application package);

c. All subtotals and totals on the A-9 through A-12 must match all dollar amounts reflected on SF-424A; and,

d. Non-Federal entities may substitute their own forms or spreadsheets in place of the A-9 through A-12, provided these alternate forms include all the same cost elements and columns in the same order as the A-9 through A-12.

Budget Narrative

[7] [State abbreviation] Budget Narrative - PDF format

a. Provide a detailed explanation of the components of each budget cost category listed on the SF-424A; Section B.

b. Explain how each cost component directly benefits cybersecurity awareness/education and small business client success.

Page | 11

c. Indicate which cost category (item and dollar amount) comprises the proposed Non-activity related Federal

Expense that was entered in the yellow highlighted section at the bottom row (P 21) in the Proposed Plan.

Commitment letter(s)

[9] [State abbreviation] Commitment Letter - PDF format

CERTIFICATION FORMS AND ASSURANCES

Submit certification and assurances forms separately in the following order, with the file name labeled as follows

(Note: Where applicable, if the applicant has submitted these certifications and assurances via www.SAM.gov over the past 12 months, the applicant can rely on those forms instead of submitting new versions. Applicable forms are marked below.):

Cost Policy Statement

[10] [State abbreviation] Cost Policy Statement - (Signed) PDF format

The Cost Policy Statement must describe non-Federal entities general accounting policies and a description of their cost allocation methodology (how each type of proposed cost is allocated: direct, indirect, or match). This policy must be signed by the Chief Financial Officer (or equivalent thereof, holding analogous responsibilities, and having analogous expertise).

Designation Letter

[11] [State abbreviation] Governor Designation Letter - (Signed) PDF format

Governor’s letter, or equivalent thereof (e.g., Mayor of the District of Columbia), designating the Applicant as the

State’s sole applicant and lead entity for conducting the State’s cybersecurity activities.

Address letter and send electronically to:

Mr. Philip T. Gibson, Office of Entrepreneurial Education

Email: OEE@sba.gov

For insular areas, the Governor, or equivalent must state that the Applicant is an agency or instrumentality of the area to receive potential funding award. See Section 3.1.

ORGANIZATIONAL MANAGEMENT

Each Applicant must provide budget information according to the specific instructions for each item. Submit organizational management documents separately in the following order, with the file name labeled as follows:

Key Personnel Résumés and Position Descriptions

[13] [State abbreviation] Key Personnel Resumes and Position Descriptions - PDF format

Résumés and position descriptions for ALL key personnel (including vacant positions) supporting the

Cybersecurity for Small Business Pilot Program project.

mailto:OEE@sba.gov

Page | 12

a. Résumé of Cybersecurity for Small Business Pilot Program Project Director should reflect knowledge and experience with both administering a Federal award and executing the proposed cybersecurity activities.

b. Other résumés must reflect experience and education relevant to the proposed Cybersecurity for Small Business

Pilot Program project.

Résumés may not be more than two pages in length. Each resume will be reviewed and evaluated. An applicant will not be notified and consulted if additional pages are eliminated and not reviewed.

Lists of Contractual and Consulting Agreements

[14] [State abbreviation] List of Contractual and Consulting- PDF format

Provides two separate lists of Contracts and Agreements as follows:

1. List of Contractual and Consulting Agreements - List of all extant or anticipated contractual and consulting agreements that directly support the Applicant’s proposed cybersecurity activities which must include: a. Contract provider name or TBD if contractor is anticipated;

b. Manner in which the provider was or will be selected (i.e., competitively, or sole source);

c. Summary of support provided;

d. Actual or estimated contract cost to support the proposed Cybersecurity for Small Business Pilot Program activities;

e. Identity of the employee or official of the Applicant organization who will be responsible for overseeing the agreements; and,

f. Description of oversight process.

Non-Federal entity may follow their own procurement policies and procedures when contracting with Project Funds but must comply with the requirements of 2 C.F.R. §§ 200.317-200.326.: Additionally, when using Project Funds to procure supplies and/or equipment, You are encouraged to purchase American-manufactured goods to the maximum extent practicable. American-manufactured goods are those products for which the cost of their component parts that were mined, produced, or manufactured in the United States exceeds 50 percent of the total cost of all their components. For further guidance regarding what constitutes an American-manufactured good (also known as a domestic end product), see 48 C.F.R. Part 25.

The following additional rules apply to contracts involving $10,000 or less:

a. You do not need to submit copies of the proposed contracts to the GOTR for approval before executing them.

b. The contracts are not required to be awarded via competition if Your organization considers their prices to be reasonable.

The following additional rules apply to contracts involving between $10,001 and $250,000 in Project Funds:

a. You do not need to submit copies of the proposed contracts to the GOTR for approval before executing them.

b. You must obtain price quotes (either orally or in writing) from at least three qualified sources and inform SBA of these quotes in the corresponding payment requests/financial reports.

Page | 13

c. If You do not choose to go with the lowest price quote, you must explain why.

The following additional rules apply to contracts involving more than $250,000 in Project Funds:

a. You must submit copies of the proposed contracts to the GOTR for approval before executing the contract.

The contracts must be awarded via competition. Non-competitive contracting at this level is only allowed if You can demonstrate to SBA’s satisfaction either: (i) there is only one possible source for a particular good or service or (ii) there is an emergency involving the risk of imminent damage to property or injury to people.

2. List of contracts that the non-Federal entity proposes to charge against the project as a direct cost or to meet matching funds requirement that will be outside the indirect cost rate agreement (e.g., a facilities lease).

a. Contract provider/lessor name.

b. Summary of support provided.

c. Actual or estimated contract cost.

If non-Federal entity does not propose any contract support for this award, include this attachment marked “N/A.”

FINANCIAL MANAGEMENT

Each Applicant must provide financial management information according to the specific instructions for each item. Submit financial management documents separately in the following order, with the file name labeled as follows:

A-133 Audit Report

[15] [State abbreviation] Audit Report - PDF format

Attach the most recent A-133 audit report. If the Non-Federal entity is not subject to the requirements of the Single

Audit Act, the non-Federal entity must instead submit a copy of its most recently audited financial statement and the

CPA opinion of this audit (e.g., unqualified, qualified, adverse, etc.)

Note: if the Non-Federal entity’s A-133 or most recent financial statement audit is large, provide a blank page with website link and instruction on where to locate the audit.

Indirect Cost Rate Agreement (ICRA) or Extension Letter (if applicable)

[16] [State abbreviation] ICRA - PDF format

For non-Federal entities that include indirect costs, provide a current, executed Indirect Cost Rate Agreement from the cognizant Federal agency or a letter from the non-Federal entities cognizant Federal agency approving an extension of a previous indirect cost rate for a period of time that covers the period of performance for this award. If the Non-Federal entity does not propose such charges for this award, include this attachment marked “N/A.”

Reimbursement of indirect costs from Federal funds will be capped at a maximum of 20 percent, regardless of the amount stipulated in an Applicant’s indirect cost rate (ICR) Agreement.

Page | 14

4.3 Submission Instructions

This section provides the application submission and receipt instructions for applications submitted for this

Announcement. Please read the following instructions carefully and completely.

1. Electronic Delivery

SBA is participating in the Grants.gov initiative to provide the grant community with a single site to find and apply for grant funding opportunities. Applicants must submit their applications online through Grants.gov.

2. How to Register to Apply through Grants.gov

All technical proposals, including attachments, must be submitted electronically via the government-wide financial assistance portal www.grants.gov. NO OTHER FORMS OF SUBMISSION WILL BE ACCEPTED. All required forms are provided in the grants.gov application package for this funding opportunity. Specific instructions for obtaining, completing, and applying via grants.gov, including animated tutorials, may be found at http://www.grants.gov/web/grants/applicants.html.

To apply via grants.gov, your organization must first:

• Have a UEI number (Unique Entity Identifier);

• Be registered with the System for Award Management (SAM); and

• Have a grants.gov username and password.

The process for meeting these three pre-submission requirements may take several weeks to complete. Additionally, Applicants may have to download or upgrade software to utilize grants.gov.

Therefore, applicants without these required identification items should begin the process immediately.

Applicants that experience unexpected delays or are otherwise unable to obtain these items risk having its application automatically rejected. Rejected applications do not reach SBA and cannot be considered.

Information about the grants.gov registration process can be found at http://www.grants.gov/applicants/get_registered.jsp. Applicants must register as organizations, not as individuals.

Organizations already registered with grants.gov do not need to re-register. However, all registered organizations must keep their SAM registration up to date.

As part of the grants.gov registration process, an Applicant must designate one or more Authorized Organizational

Representatives (AORs). AORs are the only individuals who may submit applications to grants.gov on behalf of an organization. If an application is submitted by anyone other than a designated AOR, it will be rejected by grants.gov and cannot be considered for funding.

Once an application is submitted, it undergoes a validation process through which it will either be accepted or rejected by the grants.gov system. The validation process may take up to 48 hours or more to complete. Applicants should save and print written proof of an electronic submission made at grants.gov. Applicants can expect to receive multiple emails regarding the status of their submission.

http://www.grants.gov/ http://www.grants.gov/web/grants/applicants.html http://www.grants.gov/applicants/get_registered.jsp

Page | 15

The first email will confirm receipt of the application. The second email will indicate whether the application has been successfully validated by the system and assigned an SBA tracking number or has been rejected due to errors.

An Applicant will receive a third email once SBA has downloaded its application from grants.gov for review.

If grants.gov notifies an Applicant that its application contains an error, the Applicant must correct the noted error(s) before the system will accept and validate the application. Applicants that submit on or close to the closing date may not receive email notification of an error with their applications until after the submission deadline, and thus will not have an opportunity to correct and resubmit their applications. APPLICATIONS THAT ARE REJECTED BY

GRANTS.GOV WILL NOT BE FORWARDED TO SBA AND CANNOT BE CONSIDERED FOR

FUNDING. It is the Applicant’s responsibility to verify that its submission was received and validated successfully at grants.gov. To check on the status of your application and see the date and time it was received, log on to grants.gov and click on the “Track My Application” link from the left-hand menu.

If you experience a technical difficulty with grants.gov (i.e., system problems or glitches with the operation of the grants.gov website itself) that you believe threatens your ability to submit your application, please (i) print any error message received; and (ii) call the grants.gov Contact Center at 1- 800-518-4726 for immediate assistance. Ensure that you obtain a case number regarding your communications with grants.gov. NOTE: Problems with an Applicant’s own computer system or equipment are not considered technical difficulties with grants.gov. Similarly, an Applicant’s failure to: (i) obtain a Unique Entity Identifier (UEI) number or complete the SAM or grants.gov registration process; (ii) ensure that an AOR submits the application; or (iii) take note of and act upon an email from grants.gov rejecting its application due to errors, are not considered technical difficulties. A grants.gov technical difficulty is an issue occurring in connection with the operations of grants.gov itself, such as the temporary loss of service by grants.gov due to an unexpected volume of traffic or failure of information technology systems, both of which are rare occurrences.

Applicants should use the following link to obtain assistance in navigating grants.gov and accessing a list of useful resources: http://www.grants.gov/web/grants/applicants.html. If you have a question that is not addressed under the “Applicant FAQs” or “Applicant User Guide,” contact grants.gov via email at support@grants.gov or telephone at 1-800-518-4726. The grants.gov Contact Center is open 24 hours a day, seven days a week.

3. Required Proposal Submission Date

Each Applicant is required to submit its proposal electronically via www.grants.gov no later than 11:59

P.M. Eastern Time on May 12, 2023. Because of the conditions for submitting applications via grants.gov and the potential for encountering technical difficulties in using that site, Applicants are strongly encouraged to log on to the grants.gov and review the submission instructions early. DO NOT WAIT UNTIL THE CLOSING DATE TO

BEGIN THE SUBMISSION PROCESS. Applicants bear sole responsibility for ensuring their proposals are submitted and received before the closing date.

SBA will consider the date and time stamp on the validation generated by grants.gov as the official submission time.

A proposal that is not received by grants.gov before the closing date of this Announcement will be rejected without being evaluated, unless the Applicant can clearly demonstrate through documentation obtained from grants.gov that it attempted to submit its proposal in a timely manner but was unable to do so solely because of grants.gov systems issues. Additionally, SBA will not accept any changes, additions, revisions, or deletions to applications made after the closing date.

Applicants should save and print written proof of an electronic submission made at grants.gov. If problems occur while using grants.gov, the applicant is advised to (i) print any error message received; and (ii) contact grants.gov for http://www.grants.gov/web/grants/applicants.html mailto:support@grants.gov http://www.grants.gov/

Page | 16 immediate assistance. Applicants may obtain advice and assistance with grants.gov submission process by visiting http://www.grants.gov/web/grants/support.html or calling 1-800-518-4726.

Section V. Application Review Information

General

The entire application package, comprised of the Technical Proposal (using required template format), and all additional attachments, will be evaluated on its comprehensiveness, completeness, and overall quality.

All applications successfully submitted to SBA via Grants.gov will undergo a screening process, consisting of a review for eligibility and application completeness. Applications will be rejected without further evaluation if they are submitted by ineligible entities, or they are non-responsive to the requirements of this Notice of Funding

Opportunity.

In addition, an Applicant must disclose in its application if it currently holds any other financial assistance awards from SBA or has any other applications for SBA financial assistance awards still pending. If it does, the Applicant must identify how it will avoid duplication of efforts, commingling of funds, and overlapping or double claiming of costs among those projects. Applicants must treat each SBA project as separate and discrete with individual outcomes and deliverables and provide each application and award with its own reporting, accounting, and audit trails.

Failure to sufficiently distinguish between multiple applications from the same organization, or between an application and one or more current SBA awards, may result in rejection of an application on the ground that it is duplicative of proposed or existing efforts.

Review and Selection Process

Applications that are not rejected by Grants.gov or SBA’s screening process will be evaluated by teams of reviewers and scored based on how well they meet the criteria outlined above. These reviewers may be SBA employees or employees of other Federal agencies. Prior to evaluating applications received in response to this Notice of Funding

Opportunity, SBA will establish a minimum acceptable score. Only those applications that meet or exceed that threshold will be eligible for funding. Therefore, applicants are encouraged to design proposals that address each of the scoring criteria listed above as thoroughly as possible.

At SBA’s discretion, it may select qualified applicants not funded under this Notice of Funding Opportunity for awards in the future using subsequent fiscal year resources, subject to continuing program authority, and the availability of funds.

Evaluation (100 points total)

Technical Proposal - The Non-Federal entities will be evaluated based on their Technical Proposal and accompanying Proposed Plan (excel spreadsheet). The project design should be very clear, concise, and focused

(based on a careful assessment of top priorities, key cybersecurity industries and markets) on the non-Federal entity’s state or territory. It must address credible and impactful outcomes pertaining to the program’s objectives which are:

to increase the number of small businesses educated/trained on cybersecurity threats, protections, resources/tools, and prevention strategies; services to small businesses facing cybersecurity vulnerabilities; and resolution of cybersecurity incidences.

http://www.grants.gov/web/grants/support.html

Page | 17

i. Cybersecurity Experience (up to 25 points)– Non-Federal entities will be evaluated according to their organizational capability to achieve success with client education, awareness, satisfaction, and direct services.

ii. Performance Measures & Outcomes (up to 25 points) –Non-Federal entities will be evaluated on their capability and experience with developing credible and impactful performance measures and outcomes that are commensurate with statutory requirements.

iii. Directly Benefit to Small Businesses (up to 25 points) – The proposal must demonstrate the non-Federal entity’s capacity to recruit, prepare and assist new small business concerns. The proposal must include a plan to increase the number of SMALL BUSINESSs from Small Business Communities assisted (e.g., recruiting, preparing, and assisting SMALL BUSINESSES from Small Business Communities to participate in cybersecurity activities).

iv. Collaboration (up to 25 points) - Non-Federal entities are expected to establish and leverage collaborative partnerships with relevant organizations to accomplish the proposed performance measures and supporting cybersecurity activities. Based on information contained in the Technical Proposal, non- Federal entities will be evaluated on how well they will collaborate on proposed cybersecurity activities with each of their identified partners, drawn from the following entities: a. SBA’s District Offices and resource partners such as Small Business

Development Centers (SBDC), SCORE, Women’s Business Centers, Veterans Business Outreach Centers, Small

Business Investment Companies, Certified Development Companies, SBA lenders, SBA Community Navigators and other SBA award recipients;

b. Institutions of higher education (colleges & universities), trade and vocational schools; and

c. Private organizations, such as Chambers of Commerce, trade and industry groups, and associations.

vi. Financial Assistance Plan-Non-Federal entities Financial Assistance Plan should address criteria and policies for the following elements. This Plan must conform to the Cybersecurity for Small Business Pilot Program parameters as described below. Non-Federal entities may not build in discretion to use Cybersecurity for Small Business Pilot

Program funds for other purposes not approved by SBA.

a. Application Process: Non-Federal entities application process for eligible small business concerns seeking

Cybersecurity for Small Business Pilot Program assistance including the following: • Criteria and selection process to become a Cybersecurity for Small Business Pilot Program client.

b. Internal Controls: The non-Federal entities financial management structure and systems – a clearly defined and documented internal control process that will ensure compliance related to the timely and reasonable expenditure of

Federal funds. • A specific response time (such as, 30-45 days) for issuing financial assistance awards to Cybersecurity for Small Business Pilot Program clients, processing payments, and submitting reimbursement request in order to expend and report Cybersecurity for Small Business Pilot Program funds in a timely manner must be outlined.

• The non-Federal entities’ process for ensuring that Cybersecurity for Small Business Pilot Program funding is spread out to allow a multiplicity of small business participation and encouraging support to new Cybersecurity for

Small Business Pilot Program clients.

Non-Federal entities are strongly encouraged to develop requirements for ‘building the pipeline’ so that companies can complete any formalized programs or client service periods within a reasonable duration.

Page | 18

vii. Data Collection and Measurement of Outcomes-Based on information contained in the Technical Proposal and their client Data Collection Instrument (DCI), the non-Federal entities will be evaluated on whether their Data

Collection Methodology is credible and includes the following critical elements necessary to obtain the sufficient cybersecurity sales data from small businesses. DCI elements: a. Cybersecurity for Small Business Pilot Program

Client’s level of cybersecurity experience (“market expansion” or “new-to-cybersecurity”).

b. Number and profiles of small business clients served;

c. Cyber threats and incidences trained on, successfully blocked/avoided, serviced, and/or resolved; and

e. Client satisfaction with services offered, client/host interactions, applicability, and quality of training/services.

Section VI. Award Administration Information

6.1. Award Notification

All non-Federal entities selected for an award and non-Federal entities not selected for an award will receive written notification. There will be no debriefing process for unsuccessful non-Federal entities. If you are selected for an award, you will be given instructions on how to register with GrantSolutions to access and sign the award.

6.2 Administrative and National Policy Requirements

All successful non-Federal entities will be required to comply with the requirements set forth in 2 C.F.R. Part 200 and

OMB Circular A-133 (as applicable); and the terms and conditions set forth in their Notices of Award.

The non-Federal entity must permit personnel from SBA’s Office of Inspector General (OIG), other SBA personnel involved in the examination and oversight of Cybersecurity for Small Business Pilot Program recipients, and/or their designated agents, unrestricted access to review and make copies of all products, materials, and data, including those prepared or stored electronically.

In addition, SBA may from time to time advise non-Federal entities of awards made under this announcement of new legal requirements and/or policy initiatives with which they must agree to comply.

6.3 Cybersecurity for Small Business Pilot Program Financial Requirements

Non-Federal entity proposals are not permitted to include costs associated with any of the following items or activities:

i. Transactions with suspended or debarred entities, as discussed in Part VIII (9.3) below;

ii. Construction or renovation of facilities or acquisition of real estate;

iii. Litigation, whether civil, criminal, or administrative;

iv. Providing matching contributions to any other Federal awards;

v. Meals, lodging, per diem, or other subsistence expenses associated with local travel (however, Project Funds may be used to pay transportation expenses for local travel). Local travel is any travel conducted entirely within a 50-mile radius of Your organization’s address of record;

vi. Travel by elected officials;

Page | 19

vii. Costs associated with printing materials; and

viii. National and regional association dues, travel to association events.

The underlying premise of the Cybersecurity for Small Business Pilot Program is to supplement the non-Federal entity with funds for cybersecurity activities, not to substitute Federal funds for costs non-Federal entities would normally or otherwise cover. Per 2 C.F.R. Section 200.408, use of Federal funds for the Cybersecurity for Small

Business Pilot Program is limited to the Cybersecurity for Small Business Pilot Program statutory uses of funds.

6.4 Reporting Requirements

All non-Federal entities are required to submit the reports identified below. SBA may withhold payment if reports are not received or are deemed inadequate. Failure to report in a timely manner will also be weighed against future applications for award funding from the same organization and the exercise of the option period. The reports, or portions thereof, provided by the non-Federal entity may be made public. In addition, SBA reserves the right to require non-Federal entities to post these reports on their web sites.

Financial Reports

Non-Federal entities will be required to submit quarterly financial reports to SBA using the form SF- 425, Federal

Financial Report (FFR) within 30 days of the completion of the first three quarters and within 120 days of the completion of the fourth and final quarter of the period of performance. Non- Federal entities are encouraged to submit final quarter reports prior to the end of the allowed 120 days.

Progress Reports

Non-Federal entities will be required to submit quarterly progress reports to SBA using the Grant Progress Report within 30 days of the completion of each of the first three quarters and within 120 days of the completion of the fourth (final) quarter of the performance period.

Summary of Participation Measurements: The non-Federal entity should submit along with its progress reports a one paragraph summary of…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .