E-Rate 2027 and Cybersecurity: What Schools Can and Can’t Fund
Sep 24, 2026 Jeana Renshaw Industry - Education 11 min read
For schools planning E-Rate 2027, cybersecurity should be part of the technology conversation, but not every cybersecurity expense belongs in an E-Rate application.
That distinction matters.
Traditional E-Rate provides discounts for eligible connectivity, telecommunications, internal connections, managed internal broadband services, and basic maintenance of internal connections. It does not function as a general-purpose cybersecurity funding program. (USAC Eligible Services Overview)
At the same time, cybersecurity is deeply connected to the infrastructure E-Rate can support. A school may be upgrading switches, wireless access points, routers, cabling, firewalls, or managed network services while also investing in identity security, endpoint protection, security monitoring, and incident response.
The right approach is not to ask, "How much of our cybersecurity can E-Rate pay for?"
It is to ask:
"Which technology investments are E-Rate eligible, which cybersecurity investments require other funding, and how should they work together as one security architecture?"
That distinction is especially important for schools operating Microsoft 365 environments, where identity, endpoints, cloud applications, network infrastructure, and security operations increasingly overlap.
What Does E-Rate Cover for Cybersecurity?
Traditional E-Rate is organized around two primary funding categories.
Category One: Connectivity
Category One generally covers eligible data transmission and internet access services.
USAC describes Category One as including services such as broadband connectivity and other eligible data transmission services. (USAC Eligible Services Overview)
These services provide the connectivity foundation that schools need to operate their technology environments.
But connectivity funding should not automatically be interpreted as cybersecurity funding.
For example, an organization may need:
- Internet access
- Wide-area connectivity
- Fiber connectivity
- Broadband transport
Those may qualify under Category One depending on the specific service and applicable E-Rate rules.
Separate security services layered on top of that connectivity may have different eligibility requirements.
Category Two: Internal Network Infrastructure
Category Two covers eligible internal connections, managed internal broadband services, and basic maintenance of internal connections.
Eligible infrastructure can include items such as:
- Switches
- Routers
- Wireless access points
- Cabling
- Wireless controllers
- Certain firewall services and firewall components
- Managed internal broadband services
- Basic maintenance of eligible internal connections
The specific eligibility rules and limitations are defined in the applicable annual Eligible Services List. (USAC Eligible Services List)
This is where the distinction between network infrastructure and cybersecurity capability becomes important.
A firewall can sit at the intersection of both.
The underlying eligible component may qualify under Category Two, while additional security functionality, licensing, services, or other components may be ineligible or subject to specific limitations.
The correct answer depends on the specific product, service, configuration, and funding year.
E-Rate Is Not a General Cybersecurity Budget
The most important planning rule is simple:
Do not assume that a security product is E-Rate eligible simply because it protects an E-Rate-funded network.
USAC's Eligible Services List defines what can receive E-Rate discounts each funding year. It specifically separates Category One and Category Two services and provides eligibility limitations for individual products and services. (USAC Eligible Services List)
That means schools should evaluate cybersecurity investments individually.
Consider a typical school technology environment:
| Technology investment | E-Rate planning question |
|---|---|
| Internet connectivity | Is the service eligible under Category One? |
| Switches | Is the equipment eligible as an internal connection? |
| Wireless access points | Does the equipment meet Category Two requirements? |
| Firewall | Which components and services are eligible? |
| Managed network services | Does the service qualify as MIBS? |
| Microsoft 365 security | Is the specific security service eligible? |
| Endpoint detection and response | Is it eligible under the applicable program? |
| Identity protection | Should it be funded separately? |
| Security operations / SOC | Is the service eligible, or does it require another funding source? |
| Incident response | What funding mechanism applies? |
| Security awareness training | Is it covered by the program or another budget? |
The answer should come from the current year's eligibility rules, not from the fact that a product is marketed as a "security solution."
The Schools and Libraries Cybersecurity Pilot Is Different
The distinction between traditional E-Rate and cybersecurity funding became especially important with the creation of the Schools and Libraries Cybersecurity Pilot Program.
The FCC created the three-year Pilot to gather information about whether and how universal service funds could support cybersecurity services and equipment for schools and libraries. The program provides up to $200 million in support for eligible cybersecurity services and equipment. (USAC Cybersecurity Pilot Program)
The Pilot is separate from the traditional E-Rate program, even though many of its processes are modeled on E-Rate.
USAC describes the Pilot as supporting a much broader range of cybersecurity capabilities, including examples such as:
- Advanced and next-generation firewalls
- Endpoint protection
- Identity protection
- Authentication monitoring
- Detection and response capabilities
(USAC Pilot Applicant Process)
That distinction is critical for school IT leaders.
Traditional E-Rate: primarily supports eligible connectivity and internal network infrastructure.
Cybersecurity Pilot: specifically tests whether universal service funding can support a broader set of cybersecurity services and equipment.
They should not be treated as interchangeable programs.
What Schools Should Not Assume E-Rate Will Fund
Cybersecurity has expanded far beyond the network perimeter.
A modern school may need:
- Endpoint detection and response
- Managed detection and response
- Identity threat detection
- Microsoft 365 security monitoring
- Email security
- Security information and event management
- Security operations
- Incident response
- Security awareness training
- Vulnerability management
- Managed security services
- Identity governance
- Privileged access management
Some of these capabilities may be related to an E-Rate-funded infrastructure environment.
That does not automatically make them E-Rate eligible.
Separate the security architecture from the funding mechanism
This is one of the most useful changes a school IT leader can make.
Instead of designing a security program around what a particular funding program will pay for, design the security architecture first.
Then classify each component:
E-Rate eligible
Cybersecurity Pilot eligible, if applicable
Other funding required
Partially eligible or requires cost allocation
Not currently eligible
This approach keeps the security strategy intact even when funding rules change.
Where Firewalls Fit Into E-Rate Cybersecurity Planning
Firewalls are a useful example because they demonstrate why eligibility needs to be evaluated at the component level.
The FCC's current Category Two rules include firewall services and firewall components that are separate from basic firewall protection provided as a standard component of an internet access service. (FCC FY2026 Eligible Services List)
That does not mean every firewall-related expense automatically qualifies.
A firewall procurement may include:
- Hardware
- Software
- Security subscriptions
- Installation
- Configuration
- Management
- Monitoring
- Support
- Advanced security capabilities
Each component needs to be evaluated against the applicable E-Rate eligibility rules.
The practical lesson
Do not put an entire security platform into an E-Rate request simply because a firewall is one component of it.
Instead, work with the current Eligible Services List and determine which portions of the solution are eligible, which are not, and whether cost allocation is required.
USAC specifically notes that some services and equipment can be partially or conditionally eligible and that applicants may need to cost allocate the ineligible portion. (USAC Service Provider Process)
Managed Network Services Can Connect Infrastructure and Security
Managed Internal Broadband Services, or MIBS, provide another example of where infrastructure management and security can overlap.
USAC describes MIBS as third-party services that operate, manage, and monitor eligible broadband internal connection components. Support is limited to eligible expenses or portions of expenses that directly support and are necessary for broadband connectivity within schools and libraries. (USAC Eligible Services Overview)
This can be relevant when evaluating a managed network provider.
But schools should distinguish between:
Managing the network infrastructure
and
Operating a broader cybersecurity program.
A provider may offer both services as part of a larger managed service package, but the E-Rate eligibility analysis still needs to be performed on the individual services and costs.
That makes clear service descriptions and cost allocation particularly important.
Microsoft 365 Security Still Needs Its Own Funding Strategy
Most schools using Microsoft 365 already have security capabilities built into their broader technology environment.
Depending on the school's licensing and configuration, that may include capabilities related to:
- Identity and access management
- Multifactor authentication
- Endpoint security
- Email protection
- Device management
- Security monitoring
- Data protection
These capabilities should be part of the school's overall cybersecurity architecture.
But a Microsoft 365 security capability should not be assumed to qualify for traditional E-Rate simply because it protects users who connect through an E-Rate-funded network.
The funding question and the security question are different.
Start with identity
For Microsoft 365 environments, identity is one of the most important areas to address independently of E-Rate.
A practical identity security baseline should consider:
- MFA coverage
- Privileged accounts
- Administrative role assignments
- Conditional access
- Dormant accounts
- Service accounts
- Guest accounts
- Authentication monitoring
- Account recovery procedures
The school can then determine how these controls interact with the network infrastructure being funded through E-Rate.
The result is a more coherent architecture:
E-Rate-funded infrastructure → secure network access → identity controls → endpoint security → monitoring and response
Rather than expecting one funding program to cover the entire stack.
Cybersecurity Planning Should Start With Risk, Not Eligibility
One of the easiest ways to create a fragmented technology strategy is to begin with the question:
"What will E-Rate pay for?"
A better starting point is:
"What are our most important technology and cybersecurity risks?"
For a school, that assessment might identify:
- Excessive administrative access
- Weak identity controls
- Unsupported network infrastructure
- Poor network segmentation
- Inadequate wireless security
- Unmanaged endpoints
- Limited security monitoring
- Unclear incident response procedures
- Aging network equipment
- Lack of visibility across Microsoft 365
- Inconsistent patching
- Limited backup and recovery testing
Once those risks are understood, map the required controls to available funding sources.
Example
Suppose a district identifies three priorities:
Priority 1: Replace aging switches
Potential funding path: E-Rate Category Two, subject to eligibility requirements.
Priority 2: Improve identity security
Potential funding path: technology or security operating budget, or another applicable funding source.
Priority 3: Add managed security monitoring
Potential funding path: security operating budget or another applicable program, depending on the specific service and funding opportunity.
The district has one cybersecurity strategy, but potentially three different funding mechanisms.
That is normal.
Build an E-Rate and Cybersecurity Funding Matrix
A simple funding matrix can make this process much easier for leadership.
| Security or technology capability | Primary purpose | E-Rate review | Planning action |
|---|---|---|---|
| Internet connectivity | Network access | Category One | Evaluate eligibility |
| Switches | Internal connectivity | Category Two | Evaluate eligibility |
| Wireless access points | Internal connectivity | Category Two | Evaluate eligibility |
| Firewall components | Network security/connectivity | Category Two, subject to rules | Review specific components |
| Managed network services | Network operations | Category Two | Separate eligible scope |
| Microsoft 365 identity security | Identity protection | Do not assume eligibility | Plan separately |
| Endpoint protection | Device security | Do not assume eligibility | Plan separately |
| Security monitoring | Detection and response | Do not assume traditional E-Rate eligibility | Evaluate other funding |
| Incident response | Cyber resilience | Do not assume traditional E-Rate eligibility | Include in security program |
| Security awareness | User behavior | Do not assume traditional E-Rate eligibility | Include in security program |
This matrix should be treated as a planning tool, not an eligibility determination.
The applicable funding year's Eligible Services List and FCC/USAC guidance should always be used to make the final eligibility determination.
How the Cybersecurity Pilot Changes the Conversation
For schools selected to participate in the Cybersecurity Pilot, the funding discussion becomes broader.
The Pilot allows eligible participants to seek reimbursement for a wider range of cybersecurity services and equipment than traditional E-Rate. USAC's Pilot resources include an eligible services list covering categories such as endpoint protection, identity protection, authentication monitoring, and detection and response. (USAC Cybersecurity Pilot Applicant Process)
The Pilot also has its own competitive bidding requirements.
Participants must generally conduct a fair and open competitive bidding process and wait at least 28 days after posting the Pilot Form 470 before selecting a provider and entering into a legally binding agreement. (USAC Cybersecurity Pilot Competitive Bidding)
The Pilot should still be treated as a separate program
Schools should not build their entire cybersecurity strategy around Pilot funding.
Instead, use the opportunity to evaluate:
- Which risks the funded services address
- Which capabilities the school will need after the Pilot period
- What ongoing operating costs will remain
- What internal expertise will be required
- How the services integrate with existing Microsoft 365 and network controls
- How success will be measured
The important question is not simply whether a cybersecurity service can be reimbursed.
It is whether the service produces a sustainable improvement in the school's security posture.
What Should a School Measure?
Cybersecurity funding should ultimately be tied to measurable outcomes.
Instead of reporting only that the school purchased a security tool, leadership should understand what changed.
Useful measures include:
Identity
- Percentage of users protected by MFA
- Number of privileged accounts
- Number of dormant accounts
- Number of high-risk authentication events investigated
Endpoint security
- Percentage of managed endpoints
- Percentage meeting security configuration standards
- Number of unresolved critical endpoint vulnerabilities
- Mean time to remediate critical issues
Network security
- Number of unsupported network devices
- Percentage of network infrastructure under active management
- Number of undocumented network segments
- Number of unauthorized devices detected
Detection and response
- Mean time to detect
- Mean time to contain
- Number of security incidents investigated
- Percentage of high-priority alerts reviewed within the defined SLA
Resilience
- Backup success rate
- Recovery testing frequency
- Time to restore critical systems
- Percentage of incident response procedures tested
These metrics create a connection between funding, technology deployment, and risk reduction.
That is a much stronger basis for an executive conversation than a list of products purchased.
A Practical E-Rate and Cybersecurity Planning Process
For school IT leaders preparing for FY2027, the following process can keep infrastructure and security planning aligned.
1. Inventory the environment
Document:
- Network infrastructure
- Internet connectivity
- Wireless infrastructure
- Firewalls
- Endpoints
- Microsoft 365 environment
- Identity systems
- Critical applications
- Security tools
- Managed services
2. Identify the highest-impact risks
Prioritize risks based on:
- Business and educational impact
- Likelihood
- Exposure
- Existing controls
- Recovery capability
3. Build the technology roadmap
Identify what needs to be upgraded, replaced, implemented, or managed.
4. Map each investment to funding
Classify each project as:
- Traditional E-Rate
- Cybersecurity Pilot, if applicable
- Other grant or funding opportunity
- Operating budget
- Capital budget
- Shared or other funding source
5. Validate E-Rate eligibility
Use the applicable funding year's Eligible Services List and USAC guidance before including a service or product in an E-Rate request.
6. Separate eligible and ineligible costs
Where a solution contains both eligible and ineligible components, identify the distinction before procurement and determine whether cost allocation is required.
7. Build the security architecture
Make sure the funded infrastructure works with:
- Microsoft 365
- Identity security
- Endpoint controls
- Network segmentation
- Security monitoring
- Incident response
- Backup and recovery
8. Define measurable outcomes
For every major security investment, identify the risk it is intended to reduce and how leadership will know whether the control is working.
E-Rate Should Support the Security Strategy, Not Define It
E-Rate can be an important part of a school's technology funding strategy.
But it should not become the strategy itself.
A school may need stronger wireless infrastructure, network segmentation, firewall capabilities, identity security, endpoint protection, security monitoring, and incident response. Some of those investments may be eligible under traditional E-Rate, some may be eligible under the Cybersecurity Pilot for participating organizations, and others may require separate funding.
The strongest approach is to design the security architecture first and then determine how each component can be funded.
That prevents a common problem: building a cybersecurity program around what a funding program happens to cover rather than around the risks the school actually needs to manage.
For E-Rate 2027 cybersecurity planning, the practical sequence is:
Assess the risk → define the security architecture → identify the technology requirements → determine E-Rate eligibility → identify other funding sources → measure the resulting risk reduction.
For current eligibility requirements, applicants should consult USAC's E-Rate Eligible Services List and, where applicable, the Schools and Libraries Cybersecurity Pilot Program resources.
FAQ
Does E-Rate 2027 cover cybersecurity?
Traditional E-Rate does not function as a general cybersecurity funding program. It primarily supports eligible connectivity, internal connections, managed internal broadband services, and basic maintenance. Certain security-related infrastructure, such as qualifying firewall components, may be eligible under Category Two, but eligibility depends on the specific service, equipment, and applicable funding-year rules. (USAC Eligible Services List)
Can E-Rate pay for firewalls?
Some firewall services and firewall components can qualify under Category Two when they meet the applicable E-Rate requirements. However, schools should not assume that every firewall license, security service, subscription, or advanced security feature is eligible. The specific components should be reviewed against the applicable Eligible Services List, and ineligible portions may need to be cost allocated. (FCC Category Two guidance)
Can E-Rate pay for Microsoft 365 security?
Schools should not automatically assume that Microsoft 365 security capabilities are eligible for traditional E-Rate. Identity protection, endpoint security, security monitoring, and other Microsoft 365 security capabilities should be evaluated against the applicable E-Rate eligibility rules and, where they do not qualify, planned through another funding source.
What cybersecurity services does the E-Rate Cybersecurity Pilot cover?
The Schools and Libraries Cybersecurity Pilot can support a broader range of cybersecurity services and equipment than traditional E-Rate. USAC identifies examples including advanced and next-generation firewalls, endpoint protection, identity protection, authentication monitoring, and detection and response. (USAC Cybersecurity Pilot Applicant Process)
Is the Cybersecurity Pilot the same as E-Rate?
No. The Schools and Libraries Cybersecurity Pilot is a separate program, although many of its processes are modeled on E-Rate. It was created to gather information about whether and how universal service funds can support cybersecurity services and equipment for schools and libraries. (USAC Cybersecurity Pilot Program)
Can schools use E-Rate funding for managed cybersecurity services?
Schools should not assume that a broad managed cybersecurity service is eligible under traditional E-Rate. Managed Internal Broadband Services can support eligible management and operation of internal broadband connections, but the E-Rate program does not automatically extend that eligibility to every managed security service. (USAC Eligible Services Overview)
Can E-Rate pay for endpoint protection?
Traditional E-Rate should not be treated as a general source of funding for endpoint protection. Endpoint protection is specifically identified among the types of cybersecurity services that may be eligible through the separate Cybersecurity Pilot for participating organizations. (USAC Cybersecurity Pilot Applicant Process)
Can E-Rate pay for security monitoring?
Schools should evaluate security monitoring based on the specific service being purchased and the applicable funding program. Traditional E-Rate eligibility is centered on connectivity and internal broadband infrastructure, while broader detection and response capabilities are among the cybersecurity services addressed by the separate Cybersecurity Pilot. (USAC Cybersecurity Pilot Applicant Process)
How should schools budget for cybersecurity when planning E-Rate 2027?
Start with the cybersecurity requirements rather than the available E-Rate funding. Identify the school's risks and required controls, then classify each investment as potentially E-Rate eligible, potentially eligible under the Cybersecurity Pilot if applicable, or requiring another funding source. This creates a security roadmap that does not depend on one funding mechanism.
How can a school connect E-Rate infrastructure to its cybersecurity strategy?
Use E-Rate to support eligible infrastructure where appropriate, then design the broader security architecture around it. Network infrastructure should work with identity security, Microsoft 365, endpoint protection, segmentation, monitoring, incident response, and recovery capabilities. The objective is one integrated security architecture with multiple funding sources, not separate technology projects built around individual grants.
What should a school IT director do before including cybersecurity in an E-Rate application?
Review the current funding-year Eligible Services List, identify exactly which products and services are eligible, separate eligible and ineligible costs, and document the connection between the requested infrastructure and the school's technology requirements. Do not rely solely on a vendor's description of a product's E-Rate eligibility.
Subscribe To
Sourcepass Insights
Sourcepass Insights
Stay in the loop and never miss out on the latest updates by subscribing to our newsletter today!