BEAD applicants are required to have cybersecurity and supply chain risk management plans that meet very specific best practices requirements established by the NTIA. Individual states or Eligible Entities may also require additional measures, though most do not. 

These plans must be operational if applicants are providing service at the time of the grant, or ready to be operationalized if they are not yet providing service. 

If applicants make any substantive changes to their plans, a new version must be submitted to the state within 30 days. If they rely in whole or in part on network facilities owned or operated by a third party (e.g., purchases wholesale carriage on such facilities), the state will need to obtain attestations from the network provider for both cybersecurity and supply chain risk management practices.

  • Depending on your state, you may need to gather this information months before the application window opens. If this is the case, prioritize creating and certifying your mitigation plan in early 2024.


