For schools planning E-Rate 2027, cybersecurity should be part of the technology conversation, but not every cybersecurity expense belongs in an E-Rate application.
That distinction matters.
Traditional E-Rate provides discounts for eligible connectivity, telecommunications, internal connections, managed internal broadband services, and basic maintenance of internal connections. It does not function as a general-purpose cybersecurity funding program. (USAC Eligible Services Overview)
At the same time, cybersecurity is deeply connected to the infrastructure E-Rate can support. A school may be upgrading switches, wireless access points, routers, cabling, firewalls, or managed network services while also investing in identity security, endpoint protection, security monitoring, and incident response.
The right approach is not to ask, "How much of our cybersecurity can E-Rate pay for?"
It is to ask:
"Which technology investments are E-Rate eligible, which cybersecurity investments require other funding, and how should they work together as one security architecture?"
That distinction is especially important for schools operating Microsoft 365 environments, where identity, endpoints, cloud applications, network infrastructure, and security operations increasingly overlap.
Traditional E-Rate is organized around two primary funding categories.
Category One generally covers eligible data transmission and internet access services.
USAC describes Category One as including services such as broadband connectivity and other eligible data transmission services. (USAC Eligible Services Overview)
These services provide the connectivity foundation that schools need to operate their technology environments.
But connectivity funding should not automatically be interpreted as cybersecurity funding.
For example, an organization may need:
Those may qualify under Category One depending on the specific service and applicable E-Rate rules.
Separate security services layered on top of that connectivity may have different eligibility requirements.
Category Two covers eligible internal connections, managed internal broadband services, and basic maintenance of internal connections.
Eligible infrastructure can include items such as:
The specific eligibility rules and limitations are defined in the applicable annual Eligible Services List. (USAC Eligible Services List)
This is where the distinction between network infrastructure and cybersecurity capability becomes important.
A firewall can sit at the intersection of both.
The underlying eligible component may qualify under Category Two, while additional security functionality, licensing, services, or other components may be ineligible or subject to specific limitations.
The correct answer depends on the specific product, service, configuration, and funding year.
The most important planning rule is simple:
Do not assume that a security product is E-Rate eligible simply because it protects an E-Rate-funded network.
USAC's Eligible Services List defines what can receive E-Rate discounts each funding year. It specifically separates Category One and Category Two services and provides eligibility limitations for individual products and services. (USAC Eligible Services List)
That means schools should evaluate cybersecurity investments individually.
Consider a typical school technology environment:
| Technology investment | E-Rate planning question |
|---|---|
| Internet connectivity | Is the service eligible under Category One? |
| Switches | Is the equipment eligible as an internal connection? |
| Wireless access points | Does the equipment meet Category Two requirements? |
| Firewall | Which components and services are eligible? |
| Managed network services | Does the service qualify as MIBS? |
| Microsoft 365 security | Is the specific security service eligible? |
| Endpoint detection and response | Is it eligible under the applicable program? |
| Identity protection | Should it be funded separately? |
| Security operations / SOC | Is the service eligible, or does it require another funding source? |
| Incident response | What funding mechanism applies? |
| Security awareness training | Is it covered by the program or another budget? |
The answer should come from the current year's eligibility rules, not from the fact that a product is marketed as a "security solution."
The distinction between traditional E-Rate and cybersecurity funding became especially important with the creation of the Schools and Libraries Cybersecurity Pilot Program.
The FCC created the three-year Pilot to gather information about whether and how universal service funds could support cybersecurity services and equipment for schools and libraries. The program provides up to $200 million in support for eligible cybersecurity services and equipment. (USAC Cybersecurity Pilot Program)
The Pilot is separate from the traditional E-Rate program, even though many of its processes are modeled on E-Rate.
USAC describes the Pilot as supporting a much broader range of cybersecurity capabilities, including examples such as:
(USAC Pilot Applicant Process)
That distinction is critical for school IT leaders.
Traditional E-Rate: primarily supports eligible connectivity and internal network infrastructure.
Cybersecurity Pilot: specifically tests whether universal service funding can support a broader set of cybersecurity services and equipment.
They should not be treated as interchangeable programs.
Cybersecurity has expanded far beyond the network perimeter.
A modern school may need:
Some of these capabilities may be related to an E-Rate-funded infrastructure environment.
That does not automatically make them E-Rate eligible.
This is one of the most useful changes a school IT leader can make.
Instead of designing a security program around what a particular funding program will pay for, design the security architecture first.
Then classify each component:
E-Rate eligible
Cybersecurity Pilot eligible, if applicable
Other funding required
Partially eligible or requires cost allocation
Not currently eligible
This approach keeps the security strategy intact even when funding rules change.
Firewalls are a useful example because they demonstrate why eligibility needs to be evaluated at the component level.
The FCC's current Category Two rules include firewall services and firewall components that are separate from basic firewall protection provided as a standard component of an internet access service. (FCC FY2026 Eligible Services List)
That does not mean every firewall-related expense automatically qualifies.
A firewall procurement may include:
Each component needs to be evaluated against the applicable E-Rate eligibility rules.
Do not put an entire security platform into an E-Rate request simply because a firewall is one component of it.
Instead, work with the current Eligible Services List and determine which portions of the solution are eligible, which are not, and whether cost allocation is required.
USAC specifically notes that some services and equipment can be partially or conditionally eligible and that applicants may need to cost allocate the ineligible portion. (USAC Service Provider Process)
Managed Internal Broadband Services, or MIBS, provide another example of where infrastructure management and security can overlap.
USAC describes MIBS as third-party services that operate, manage, and monitor eligible broadband internal connection components. Support is limited to eligible expenses or portions of expenses that directly support and are necessary for broadband connectivity within schools and libraries. (USAC Eligible Services Overview)
This can be relevant when evaluating a managed network provider.
But schools should distinguish between:
Managing the network infrastructure
and
Operating a broader cybersecurity program.
A provider may offer both services as part of a larger managed service package, but the E-Rate eligibility analysis still needs to be performed on the individual services and costs.
That makes clear service descriptions and cost allocation particularly important.
Most schools using Microsoft 365 already have security capabilities built into their broader technology environment.
Depending on the school's licensing and configuration, that may include capabilities related to:
These capabilities should be part of the school's overall cybersecurity architecture.
But a Microsoft 365 security capability should not be assumed to qualify for traditional E-Rate simply because it protects users who connect through an E-Rate-funded network.
The funding question and the security question are different.
For Microsoft 365 environments, identity is one of the most important areas to address independently of E-Rate.
A practical identity security baseline should consider:
The school can then determine how these controls interact with the network infrastructure being funded through E-Rate.
The result is a more coherent architecture:
E-Rate-funded infrastructure → secure network access → identity controls → endpoint security → monitoring and response
Rather than expecting one funding program to cover the entire stack.
One of the easiest ways to create a fragmented technology strategy is to begin with the question:
"What will E-Rate pay for?"
A better starting point is:
"What are our most important technology and cybersecurity risks?"
For a school, that assessment might identify:
Once those risks are understood, map the required controls to available funding sources.
Suppose a district identifies three priorities:
Priority 1: Replace aging switches
Potential funding path: E-Rate Category Two, subject to eligibility requirements.
Priority 2: Improve identity security
Potential funding path: technology or security operating budget, or another applicable funding source.
Priority 3: Add managed security monitoring
Potential funding path: security operating budget or another applicable program, depending on the specific service and funding opportunity.
The district has one cybersecurity strategy, but potentially three different funding mechanisms.
That is normal.
A simple funding matrix can make this process much easier for leadership.
| Security or technology capability | Primary purpose | E-Rate review | Planning action |
|---|---|---|---|
| Internet connectivity | Network access | Category One | Evaluate eligibility |
| Switches | Internal connectivity | Category Two | Evaluate eligibility |
| Wireless access points | Internal connectivity | Category Two | Evaluate eligibility |
| Firewall components | Network security/connectivity | Category Two, subject to rules | Review specific components |
| Managed network services | Network operations | Category Two | Separate eligible scope |
| Microsoft 365 identity security | Identity protection | Do not assume eligibility | Plan separately |
| Endpoint protection | Device security | Do not assume eligibility | Plan separately |
| Security monitoring | Detection and response | Do not assume traditional E-Rate eligibility | Evaluate other funding |
| Incident response | Cyber resilience | Do not assume traditional E-Rate eligibility | Include in security program |
| Security awareness | User behavior | Do not assume traditional E-Rate eligibility | Include in security program |
This matrix should be treated as a planning tool, not an eligibility determination.
The applicable funding year's Eligible Services List and FCC/USAC guidance should always be used to make the final eligibility determination.
For schools selected to participate in the Cybersecurity Pilot, the funding discussion becomes broader.
The Pilot allows eligible participants to seek reimbursement for a wider range of cybersecurity services and equipment than traditional E-Rate. USAC's Pilot resources include an eligible services list covering categories such as endpoint protection, identity protection, authentication monitoring, and detection and response. (USAC Cybersecurity Pilot Applicant Process)
The Pilot also has its own competitive bidding requirements.
Participants must generally conduct a fair and open competitive bidding process and wait at least 28 days after posting the Pilot Form 470 before selecting a provider and entering into a legally binding agreement. (USAC Cybersecurity Pilot Competitive Bidding)
Schools should not build their entire cybersecurity strategy around Pilot funding.
Instead, use the opportunity to evaluate:
The important question is not simply whether a cybersecurity service can be reimbursed.
It is whether the service produces a sustainable improvement in the school's security posture.
Cybersecurity funding should ultimately be tied to measurable outcomes.
Instead of reporting only that the school purchased a security tool, leadership should understand what changed.
Useful measures include:
These metrics create a connection between funding, technology deployment, and risk reduction.
That is a much stronger basis for an executive conversation than a list of products purchased.
For school IT leaders preparing for FY2027, the following process can keep infrastructure and security planning aligned.
Document:
Prioritize risks based on:
Identify what needs to be upgraded, replaced, implemented, or managed.
Classify each project as:
Use the applicable funding year's Eligible Services List and USAC guidance before including a service or product in an E-Rate request.
Where a solution contains both eligible and ineligible components, identify the distinction before procurement and determine whether cost allocation is required.
Make sure the funded infrastructure works with:
For every major security investment, identify the risk it is intended to reduce and how leadership will know whether the control is working.
E-Rate can be an important part of a school's technology funding strategy.
But it should not become the strategy itself.
A school may need stronger wireless infrastructure, network segmentation, firewall capabilities, identity security, endpoint protection, security monitoring, and incident response. Some of those investments may be eligible under traditional E-Rate, some may be eligible under the Cybersecurity Pilot for participating organizations, and others may require separate funding.
The strongest approach is to design the security architecture first and then determine how each component can be funded.
That prevents a common problem: building a cybersecurity program around what a funding program happens to cover rather than around the risks the school actually needs to manage.
For E-Rate 2027 cybersecurity planning, the practical sequence is:
Assess the risk → define the security architecture → identify the technology requirements → determine E-Rate eligibility → identify other funding sources → measure the resulting risk reduction.
For current eligibility requirements, applicants should consult USAC's E-Rate Eligible Services List and, where applicable, the Schools and Libraries Cybersecurity Pilot Program resources.
Traditional E-Rate does not function as a general cybersecurity funding program. It primarily supports eligible connectivity, internal connections, managed internal broadband services, and basic maintenance. Certain security-related infrastructure, such as qualifying firewall components, may be eligible under Category Two, but eligibility depends on the specific service, equipment, and applicable funding-year rules. (USAC Eligible Services List)
Some firewall services and firewall components can qualify under Category Two when they meet the applicable E-Rate requirements. However, schools should not assume that every firewall license, security service, subscription, or advanced security feature is eligible. The specific components should be reviewed against the applicable Eligible Services List, and ineligible portions may need to be cost allocated. (FCC Category Two guidance)
Schools should not automatically assume that Microsoft 365 security capabilities are eligible for traditional E-Rate. Identity protection, endpoint security, security monitoring, and other Microsoft 365 security capabilities should be evaluated against the applicable E-Rate eligibility rules and, where they do not qualify, planned through another funding source.
The Schools and Libraries Cybersecurity Pilot can support a broader range of cybersecurity services and equipment than traditional E-Rate. USAC identifies examples including advanced and next-generation firewalls, endpoint protection, identity protection, authentication monitoring, and detection and response. (USAC Cybersecurity Pilot Applicant Process)
No. The Schools and Libraries Cybersecurity Pilot is a separate program, although many of its processes are modeled on E-Rate. It was created to gather information about whether and how universal service funds can support cybersecurity services and equipment for schools and libraries. (USAC Cybersecurity Pilot Program)
Schools should not assume that a broad managed cybersecurity service is eligible under traditional E-Rate. Managed Internal Broadband Services can support eligible management and operation of internal broadband connections, but the E-Rate program does not automatically extend that eligibility to every managed security service. (USAC Eligible Services Overview)
Traditional E-Rate should not be treated as a general source of funding for endpoint protection. Endpoint protection is specifically identified among the types of cybersecurity services that may be eligible through the separate Cybersecurity Pilot for participating organizations. (USAC Cybersecurity Pilot Applicant Process)
Schools should evaluate security monitoring based on the specific service being purchased and the applicable funding program. Traditional E-Rate eligibility is centered on connectivity and internal broadband infrastructure, while broader detection and response capabilities are among the cybersecurity services addressed by the separate Cybersecurity Pilot. (USAC Cybersecurity Pilot Applicant Process)
Start with the cybersecurity requirements rather than the available E-Rate funding. Identify the school's risks and required controls, then classify each investment as potentially E-Rate eligible, potentially eligible under the Cybersecurity Pilot if applicable, or requiring another funding source. This creates a security roadmap that does not depend on one funding mechanism.
Use E-Rate to support eligible infrastructure where appropriate, then design the broader security architecture around it. Network infrastructure should work with identity security, Microsoft 365, endpoint protection, segmentation, monitoring, incident response, and recovery capabilities. The objective is one integrated security architecture with multiple funding sources, not separate technology projects built around individual grants.
Review the current funding-year Eligible Services List, identify exactly which products and services are eligible, separate eligible and ineligible costs, and document the connection between the requested infrastructure and the school's technology requirements. Do not rely solely on a vendor's description of a product's E-Rate eligibility.