Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Center of Excellence for Microsoft

Maximize your Microsoft investment through strategy, security, modernization, adoption, and continuous optimization.

Untitled design (3)

Commercial Industries

We understand what most managed service providers don’t – when it comes to industry-specific technology, one-size-fits-all solutions don’t exist.

Untitled design (3)

Public Sector

Specialized IT, cybersecurity, and compliance support for schools, BOCES, local governments, and utilities — backed by 40+ years of public-sector experience.  

Untitled design (3)

Locations

We serve clients across the lower 48, with regional concentration in the Northeast, Mid-Atlantic, Southeast, Mountain West, and West.  

Untitled design (3)

The Sourcepass Story

Built and run by technology, security, and managed services people who were tired of how IT gets delivered – and decided to do it differently. 

Untitled design (3)

The Sourcepass Experience

Excellent service, strategic guidance, and technology delivered with innovation – the operating model behind every Sourcepass engagement, across IT, security, Microsoft, and AI. 

Untitled design (3)

 

E-Rate 2027 and Cybersecurity: What Schools Can and Can’t Fund

 
E-Rate 2027 and Cybersecurity: What Schools Can and Can’t Fund

For schools planning E-Rate 2027, cybersecurity should be part of the technology conversation, but not every cybersecurity expense belongs in an E-Rate application.

That distinction matters.

Traditional E-Rate provides discounts for eligible connectivity, telecommunications, internal connections, managed internal broadband services, and basic maintenance of internal connections. It does not function as a general-purpose cybersecurity funding program. (USAC Eligible Services Overview)

At the same time, cybersecurity is deeply connected to the infrastructure E-Rate can support. A school may be upgrading switches, wireless access points, routers, cabling, firewalls, or managed network services while also investing in identity security, endpoint protection, security monitoring, and incident response.

The right approach is not to ask, "How much of our cybersecurity can E-Rate pay for?"

It is to ask:

"Which technology investments are E-Rate eligible, which cybersecurity investments require other funding, and how should they work together as one security architecture?"

That distinction is especially important for schools operating Microsoft 365 environments, where identity, endpoints, cloud applications, network infrastructure, and security operations increasingly overlap.

 

What Does E-Rate Cover for Cybersecurity?

Traditional E-Rate is organized around two primary funding categories.

 

Category One: Connectivity

Category One generally covers eligible data transmission and internet access services.

USAC describes Category One as including services such as broadband connectivity and other eligible data transmission services. (USAC Eligible Services Overview)

These services provide the connectivity foundation that schools need to operate their technology environments.

But connectivity funding should not automatically be interpreted as cybersecurity funding.

For example, an organization may need:

  • Internet access
  • Wide-area connectivity
  • Fiber connectivity
  • Broadband transport

Those may qualify under Category One depending on the specific service and applicable E-Rate rules.

Separate security services layered on top of that connectivity may have different eligibility requirements.

 

Category Two: Internal Network Infrastructure

Category Two covers eligible internal connections, managed internal broadband services, and basic maintenance of internal connections.

Eligible infrastructure can include items such as:

  • Switches
  • Routers
  • Wireless access points
  • Cabling
  • Wireless controllers
  • Certain firewall services and firewall components
  • Managed internal broadband services
  • Basic maintenance of eligible internal connections

The specific eligibility rules and limitations are defined in the applicable annual Eligible Services List. (USAC Eligible Services List)

This is where the distinction between network infrastructure and cybersecurity capability becomes important.

A firewall can sit at the intersection of both.

The underlying eligible component may qualify under Category Two, while additional security functionality, licensing, services, or other components may be ineligible or subject to specific limitations.

The correct answer depends on the specific product, service, configuration, and funding year.

 

E-Rate Is Not a General Cybersecurity Budget

The most important planning rule is simple:

Do not assume that a security product is E-Rate eligible simply because it protects an E-Rate-funded network.

USAC's Eligible Services List defines what can receive E-Rate discounts each funding year. It specifically separates Category One and Category Two services and provides eligibility limitations for individual products and services. (USAC Eligible Services List)

That means schools should evaluate cybersecurity investments individually.

Consider a typical school technology environment:

Technology investment E-Rate planning question
Internet connectivity Is the service eligible under Category One?
Switches Is the equipment eligible as an internal connection?
Wireless access points Does the equipment meet Category Two requirements?
Firewall Which components and services are eligible?
Managed network services Does the service qualify as MIBS?
Microsoft 365 security Is the specific security service eligible?
Endpoint detection and response Is it eligible under the applicable program?
Identity protection Should it be funded separately?
Security operations / SOC Is the service eligible, or does it require another funding source?
Incident response What funding mechanism applies?
Security awareness training Is it covered by the program or another budget?

 

The answer should come from the current year's eligibility rules, not from the fact that a product is marketed as a "security solution."

 

The Schools and Libraries Cybersecurity Pilot Is Different

The distinction between traditional E-Rate and cybersecurity funding became especially important with the creation of the Schools and Libraries Cybersecurity Pilot Program.

The FCC created the three-year Pilot to gather information about whether and how universal service funds could support cybersecurity services and equipment for schools and libraries. The program provides up to $200 million in support for eligible cybersecurity services and equipment. (USAC Cybersecurity Pilot Program)

The Pilot is separate from the traditional E-Rate program, even though many of its processes are modeled on E-Rate.

USAC describes the Pilot as supporting a much broader range of cybersecurity capabilities, including examples such as:

  • Advanced and next-generation firewalls
  • Endpoint protection
  • Identity protection
  • Authentication monitoring
  • Detection and response capabilities

(USAC Pilot Applicant Process)

That distinction is critical for school IT leaders.

Traditional E-Rate: primarily supports eligible connectivity and internal network infrastructure.

Cybersecurity Pilot: specifically tests whether universal service funding can support a broader set of cybersecurity services and equipment.

They should not be treated as interchangeable programs.

 

What Schools Should Not Assume E-Rate Will Fund

Cybersecurity has expanded far beyond the network perimeter.

A modern school may need:

  • Endpoint detection and response
  • Managed detection and response
  • Identity threat detection
  • Microsoft 365 security monitoring
  • Email security
  • Security information and event management
  • Security operations
  • Incident response
  • Security awareness training
  • Vulnerability management
  • Managed security services
  • Identity governance
  • Privileged access management

Some of these capabilities may be related to an E-Rate-funded infrastructure environment.

That does not automatically make them E-Rate eligible.

 

Separate the security architecture from the funding mechanism

This is one of the most useful changes a school IT leader can make.

Instead of designing a security program around what a particular funding program will pay for, design the security architecture first.

Then classify each component:

E-Rate eligible

Cybersecurity Pilot eligible, if applicable

Other funding required

Partially eligible or requires cost allocation

Not currently eligible

This approach keeps the security strategy intact even when funding rules change.

 

Where Firewalls Fit Into E-Rate Cybersecurity Planning

Firewalls are a useful example because they demonstrate why eligibility needs to be evaluated at the component level.

The FCC's current Category Two rules include firewall services and firewall components that are separate from basic firewall protection provided as a standard component of an internet access service. (FCC FY2026 Eligible Services List)

That does not mean every firewall-related expense automatically qualifies.

A firewall procurement may include:

  • Hardware
  • Software
  • Security subscriptions
  • Installation
  • Configuration
  • Management
  • Monitoring
  • Support
  • Advanced security capabilities

Each component needs to be evaluated against the applicable E-Rate eligibility rules.

 

The practical lesson

Do not put an entire security platform into an E-Rate request simply because a firewall is one component of it.

Instead, work with the current Eligible Services List and determine which portions of the solution are eligible, which are not, and whether cost allocation is required.

USAC specifically notes that some services and equipment can be partially or conditionally eligible and that applicants may need to cost allocate the ineligible portion. (USAC Service Provider Process)

 

Managed Network Services Can Connect Infrastructure and Security

Managed Internal Broadband Services, or MIBS, provide another example of where infrastructure management and security can overlap.

USAC describes MIBS as third-party services that operate, manage, and monitor eligible broadband internal connection components. Support is limited to eligible expenses or portions of expenses that directly support and are necessary for broadband connectivity within schools and libraries. (USAC Eligible Services Overview)

This can be relevant when evaluating a managed network provider.

But schools should distinguish between:

Managing the network infrastructure

and

Operating a broader cybersecurity program.

A provider may offer both services as part of a larger managed service package, but the E-Rate eligibility analysis still needs to be performed on the individual services and costs.

That makes clear service descriptions and cost allocation particularly important.

 

Microsoft 365 Security Still Needs Its Own Funding Strategy

Most schools using Microsoft 365 already have security capabilities built into their broader technology environment.

Depending on the school's licensing and configuration, that may include capabilities related to:

  • Identity and access management
  • Multifactor authentication
  • Endpoint security
  • Email protection
  • Device management
  • Security monitoring
  • Data protection

These capabilities should be part of the school's overall cybersecurity architecture.

But a Microsoft 365 security capability should not be assumed to qualify for traditional E-Rate simply because it protects users who connect through an E-Rate-funded network.

The funding question and the security question are different.

 

Start with identity

For Microsoft 365 environments, identity is one of the most important areas to address independently of E-Rate.

A practical identity security baseline should consider:

  • MFA coverage
  • Privileged accounts
  • Administrative role assignments
  • Conditional access
  • Dormant accounts
  • Service accounts
  • Guest accounts
  • Authentication monitoring
  • Account recovery procedures

The school can then determine how these controls interact with the network infrastructure being funded through E-Rate.

The result is a more coherent architecture:

E-Rate-funded infrastructure → secure network access → identity controls → endpoint security → monitoring and response

Rather than expecting one funding program to cover the entire stack.

 

Cybersecurity Planning Should Start With Risk, Not Eligibility

One of the easiest ways to create a fragmented technology strategy is to begin with the question:

"What will E-Rate pay for?"

A better starting point is:

"What are our most important technology and cybersecurity risks?"

For a school, that assessment might identify:

  • Excessive administrative access
  • Weak identity controls
  • Unsupported network infrastructure
  • Poor network segmentation
  • Inadequate wireless security
  • Unmanaged endpoints
  • Limited security monitoring
  • Unclear incident response procedures
  • Aging network equipment
  • Lack of visibility across Microsoft 365
  • Inconsistent patching
  • Limited backup and recovery testing

Once those risks are understood, map the required controls to available funding sources.

 

Example

Suppose a district identifies three priorities:

Priority 1: Replace aging switches

Potential funding path: E-Rate Category Two, subject to eligibility requirements.

Priority 2: Improve identity security

Potential funding path: technology or security operating budget, or another applicable funding source.

Priority 3: Add managed security monitoring

Potential funding path: security operating budget or another applicable program, depending on the specific service and funding opportunity.

The district has one cybersecurity strategy, but potentially three different funding mechanisms.

That is normal.

 

Build an E-Rate and Cybersecurity Funding Matrix

A simple funding matrix can make this process much easier for leadership.

Security or technology capability Primary purpose E-Rate review Planning action
Internet connectivity Network access Category One Evaluate eligibility
Switches Internal connectivity Category Two Evaluate eligibility
Wireless access points Internal connectivity Category Two Evaluate eligibility
Firewall components Network security/connectivity Category Two, subject to rules Review specific components
Managed network services Network operations Category Two Separate eligible scope
Microsoft 365 identity security Identity protection Do not assume eligibility Plan separately
Endpoint protection Device security Do not assume eligibility Plan separately
Security monitoring Detection and response Do not assume traditional E-Rate eligibility Evaluate other funding
Incident response Cyber resilience Do not assume traditional E-Rate eligibility Include in security program
Security awareness User behavior Do not assume traditional E-Rate eligibility Include in security program

 

This matrix should be treated as a planning tool, not an eligibility determination.

The applicable funding year's Eligible Services List and FCC/USAC guidance should always be used to make the final eligibility determination.

 

How the Cybersecurity Pilot Changes the Conversation

For schools selected to participate in the Cybersecurity Pilot, the funding discussion becomes broader.

The Pilot allows eligible participants to seek reimbursement for a wider range of cybersecurity services and equipment than traditional E-Rate. USAC's Pilot resources include an eligible services list covering categories such as endpoint protection, identity protection, authentication monitoring, and detection and response. (USAC Cybersecurity Pilot Applicant Process)

The Pilot also has its own competitive bidding requirements.

Participants must generally conduct a fair and open competitive bidding process and wait at least 28 days after posting the Pilot Form 470 before selecting a provider and entering into a legally binding agreement. (USAC Cybersecurity Pilot Competitive Bidding)

 

The Pilot should still be treated as a separate program

Schools should not build their entire cybersecurity strategy around Pilot funding.

Instead, use the opportunity to evaluate:

  • Which risks the funded services address
  • Which capabilities the school will need after the Pilot period
  • What ongoing operating costs will remain
  • What internal expertise will be required
  • How the services integrate with existing Microsoft 365 and network controls
  • How success will be measured

The important question is not simply whether a cybersecurity service can be reimbursed.

It is whether the service produces a sustainable improvement in the school's security posture.

 

What Should a School Measure?

Cybersecurity funding should ultimately be tied to measurable outcomes.

Instead of reporting only that the school purchased a security tool, leadership should understand what changed.

Useful measures include:

 

Identity

  • Percentage of users protected by MFA
  • Number of privileged accounts
  • Number of dormant accounts
  • Number of high-risk authentication events investigated

 

Endpoint security

  • Percentage of managed endpoints
  • Percentage meeting security configuration standards
  • Number of unresolved critical endpoint vulnerabilities
  • Mean time to remediate critical issues

 

Network security

  • Number of unsupported network devices
  • Percentage of network infrastructure under active management
  • Number of undocumented network segments
  • Number of unauthorized devices detected

 

Detection and response

  • Mean time to detect
  • Mean time to contain
  • Number of security incidents investigated
  • Percentage of high-priority alerts reviewed within the defined SLA

 

Resilience

  • Backup success rate
  • Recovery testing frequency
  • Time to restore critical systems
  • Percentage of incident response procedures tested

These metrics create a connection between funding, technology deployment, and risk reduction.

That is a much stronger basis for an executive conversation than a list of products purchased.

 

A Practical E-Rate and Cybersecurity Planning Process

For school IT leaders preparing for FY2027, the following process can keep infrastructure and security planning aligned.

 

1. Inventory the environment

Document:

  • Network infrastructure
  • Internet connectivity
  • Wireless infrastructure
  • Firewalls
  • Endpoints
  • Microsoft 365 environment
  • Identity systems
  • Critical applications
  • Security tools
  • Managed services

 

2. Identify the highest-impact risks

Prioritize risks based on:

  • Business and educational impact
  • Likelihood
  • Exposure
  • Existing controls
  • Recovery capability

 

3. Build the technology roadmap

Identify what needs to be upgraded, replaced, implemented, or managed.

 

4. Map each investment to funding

Classify each project as:

  • Traditional E-Rate
  • Cybersecurity Pilot, if applicable
  • Other grant or funding opportunity
  • Operating budget
  • Capital budget
  • Shared or other funding source

 

5. Validate E-Rate eligibility

Use the applicable funding year's Eligible Services List and USAC guidance before including a service or product in an E-Rate request.

 

6. Separate eligible and ineligible costs

Where a solution contains both eligible and ineligible components, identify the distinction before procurement and determine whether cost allocation is required.

 

7. Build the security architecture

Make sure the funded infrastructure works with:

  • Microsoft 365
  • Identity security
  • Endpoint controls
  • Network segmentation
  • Security monitoring
  • Incident response
  • Backup and recovery

 

8. Define measurable outcomes

For every major security investment, identify the risk it is intended to reduce and how leadership will know whether the control is working.

 

E-Rate Should Support the Security Strategy, Not Define It

E-Rate can be an important part of a school's technology funding strategy.

But it should not become the strategy itself.

A school may need stronger wireless infrastructure, network segmentation, firewall capabilities, identity security, endpoint protection, security monitoring, and incident response. Some of those investments may be eligible under traditional E-Rate, some may be eligible under the Cybersecurity Pilot for participating organizations, and others may require separate funding.

The strongest approach is to design the security architecture first and then determine how each component can be funded.

That prevents a common problem: building a cybersecurity program around what a funding program happens to cover rather than around the risks the school actually needs to manage.

For E-Rate 2027 cybersecurity planning, the practical sequence is:

Assess the risk → define the security architecture → identify the technology requirements → determine E-Rate eligibility → identify other funding sources → measure the resulting risk reduction.

For current eligibility requirements, applicants should consult USAC's E-Rate Eligible Services List and, where applicable, the Schools and Libraries Cybersecurity Pilot Program resources.

 

FAQ

Does E-Rate 2027 cover cybersecurity?

Traditional E-Rate does not function as a general cybersecurity funding program. It primarily supports eligible connectivity, internal connections, managed internal broadband services, and basic maintenance. Certain security-related infrastructure, such as qualifying firewall components, may be eligible under Category Two, but eligibility depends on the specific service, equipment, and applicable funding-year rules. (USAC Eligible Services List)

Can E-Rate pay for firewalls?

Some firewall services and firewall components can qualify under Category Two when they meet the applicable E-Rate requirements. However, schools should not assume that every firewall license, security service, subscription, or advanced security feature is eligible. The specific components should be reviewed against the applicable Eligible Services List, and ineligible portions may need to be cost allocated. (FCC Category Two guidance)

Can E-Rate pay for Microsoft 365 security?

Schools should not automatically assume that Microsoft 365 security capabilities are eligible for traditional E-Rate. Identity protection, endpoint security, security monitoring, and other Microsoft 365 security capabilities should be evaluated against the applicable E-Rate eligibility rules and, where they do not qualify, planned through another funding source.

What cybersecurity services does the E-Rate Cybersecurity Pilot cover?

The Schools and Libraries Cybersecurity Pilot can support a broader range of cybersecurity services and equipment than traditional E-Rate. USAC identifies examples including advanced and next-generation firewalls, endpoint protection, identity protection, authentication monitoring, and detection and response. (USAC Cybersecurity Pilot Applicant Process)

Is the Cybersecurity Pilot the same as E-Rate?

No. The Schools and Libraries Cybersecurity Pilot is a separate program, although many of its processes are modeled on E-Rate. It was created to gather information about whether and how universal service funds can support cybersecurity services and equipment for schools and libraries. (USAC Cybersecurity Pilot Program)

Can schools use E-Rate funding for managed cybersecurity services?

Schools should not assume that a broad managed cybersecurity service is eligible under traditional E-Rate. Managed Internal Broadband Services can support eligible management and operation of internal broadband connections, but the E-Rate program does not automatically extend that eligibility to every managed security service. (USAC Eligible Services Overview)

Can E-Rate pay for endpoint protection?

Traditional E-Rate should not be treated as a general source of funding for endpoint protection. Endpoint protection is specifically identified among the types of cybersecurity services that may be eligible through the separate Cybersecurity Pilot for participating organizations. (USAC Cybersecurity Pilot Applicant Process)

Can E-Rate pay for security monitoring?

Schools should evaluate security monitoring based on the specific service being purchased and the applicable funding program. Traditional E-Rate eligibility is centered on connectivity and internal broadband infrastructure, while broader detection and response capabilities are among the cybersecurity services addressed by the separate Cybersecurity Pilot. (USAC Cybersecurity Pilot Applicant Process)

How should schools budget for cybersecurity when planning E-Rate 2027?

Start with the cybersecurity requirements rather than the available E-Rate funding. Identify the school's risks and required controls, then classify each investment as potentially E-Rate eligible, potentially eligible under the Cybersecurity Pilot if applicable, or requiring another funding source. This creates a security roadmap that does not depend on one funding mechanism.

How can a school connect E-Rate infrastructure to its cybersecurity strategy?

Use E-Rate to support eligible infrastructure where appropriate, then design the broader security architecture around it. Network infrastructure should work with identity security, Microsoft 365, endpoint protection, segmentation, monitoring, incident response, and recovery capabilities. The objective is one integrated security architecture with multiple funding sources, not separate technology projects built around individual grants.

What should a school IT director do before including cybersecurity in an E-Rate application?

Review the current funding-year Eligible Services List, identify exactly which products and services are eligible, separate eligible and ineligible costs, and document the connection between the requested infrastructure and the school's technology requirements. Do not rely solely on a vendor's description of a product's E-Rate eligibility.