BlinklessChurch Security Readiness Checker(212) 470-2511

Free · no sign-up · nothing leaves your browser

Church security readiness checker & plan builder

Answer questions about your congregation and this writes your security plan: a readiness score across the nine areas CISA’s guide for houses of worship covers, the gaps ranked by what they cost you, a list of what to do that starts with the things that are free, every capital item mapped to the federal grant code that pays for it, and a straight answer on whether the hours nobody is in the building need watching. About eight minutes.

Step 1 of 7Your congregation

How many people, how much building, and who else uses it.

This only appears on your plan. Nothing you enter here leaves your browser. Your answers are kept in it so you can come back later, until you clear them.

What kind of congregation?
How many people at a typical main service?
What does the property look like?
Are there children on site?Childcare and schools carry their own requirements.
When is the building open?
Where are you?
Do you own the building?
Which state?Sets your funding stream and names the agency you would apply through.

Why this is a checker and not another checklist

Search for a church security checklist and you get nine results, all of them paper: two insurers’ self-inspection forms, a camera vendor’s guide, a training company’s walkthrough, a few listicles. They are decent documents. Each one is the same document for a 40-person rural chapel and a 2,000-seat campus with a day school, which means most of it doesn’t apply to you, and the part that does is buried.

The federal government publishes one good free tool in this space, CISA’s Houses of Worship Security Self-Assessment, and it says of itself, in its own words, that it is “a first step in building an effective security program; it is not intended to be an in-depth security assessment.” Use it. It is thorough and it exports to Word. It doesn’t weigh your answers against each other, tell you which of thirty things to do first when you have no money, write the plan, or connect any of it to the grant that pays for the expensive half. This page does those four things.

The nine areas, and where they come from

The framework is not ours. In December 2020 CISA published Mitigating Attacks on Houses of Worship, a security guide built on an original analysis of ten years of targeted attacks on houses of worship in the United States. It organises a congregation’s security into chapters, and those chapters are the nine areas scored above: roles and responsibilities, the vulnerability assessment, community readiness and training, the three physical perimeters, detection and response, children’s programmes, and cybersecurity.

The weightings are ours, and they come from what that analysis found. Three numbers do most of the work. In 78% of the incidents studied, the attacker had no prior association with the house of worship. That is why a greeter who says hello to a stranger scores more here than a camera. In 57% of cases the perpetrator showed some planning behaviour beforehand, telling someone or posting their intent. That is why “who would they tell?” is a scored question. And 43% of the attacks took place inside the inner perimeter, where the greatest loss of life occurs. That is why the separation between your front door and your worship space is weighted above the fence line.

Outer, middle, inner: the three perimeters

CISA’s physical-security chapter asks you to think of the property as three zones, and it is the most useful idea in the guide because it turns an overwhelming question into three answerable ones.

  • The outer perimeter is the parking, the grounds, the walkways and the approach: everything up to the walls. It is the first opportunity to notice anything, and almost everything that improves it is cheap: lighting, cutting back overgrowth, planters that stop a vehicle reaching the doors, and two people in high-visibility vests during arrival.
  • The middle perimeter is the skin of the buildings and anything else on campus: doors, walls, windows, the hall, the playground, the rectory. This is where the most valuable single change tends to sit: reducing the doors that are open during a service to one, and putting a person at it.
  • The inner perimeter is the worship space, the offices and the classrooms. CISA calls it the sanctum and says that it “requires the highest level of scrutiny, control, and monitoring”, because that is where your people are.

The open-door objection

Most congregations that start this conversation arrive at the same objection: we are supposed to be open. A house of worship that feels like an airport has lost the thing it was protecting. CISA puts it as a balance to be struck rather than a contradiction to be solved, and in practice the highest-value measures are the ones that do not read as security at all. A greeter is hospitality, and lighting is welcome. Two people counting the offering is good governance, and a named person to bring a worry to is pastoral care. Almost everything in the “start this month” list above is something a visitor would experience as warmth.

The money, and why the grant is the answer to it

The expensive half (cameras, lighting, access control, security film, an alarm that someone answers) is where most congregations stop, because the budget isn’t there and won’t be out of general giving. It is also what the Nonprofit Security Grant Program exists to fund. NSGP is a FEMA programme that awards money to nonprofits at high risk of a terrorist or other extremist attack, and its scoring matrix multiplies a house of worship’s score by three. Every capital item this page recommends is drawn from the grant’s own Authorized Equipment List, and the plan above prints the code beside it.

Three things sink applications, and they are worth knowing before you start. You need an active SAM.gov registration with a Unique Entity Identifier, and the notice of funding opportunity says outright that this “can take several weeks. Begin that process today.” You need a site-specific vulnerability assessment for every physical address, the grant will not pay for it, and it must be your own work. Texas, for one, lists CISA’s self-assessment as an acceptable method and states that no prescribed format or template exists. And you apply through your State Administrative Agency, not to FEMA, on their deadline rather than the federal one.

Where remote guarding fits a house-of-worship plan

Every recommendation above that involves a camera comes with a choice CISA’s guide makes explicit and most buyers never hear about. A camera system can be one of three things: an unmonitored recording system, active monitoring without response, or, in the guide’s words, “a system actively monitored by contracted security and integrated with an incident response plan.” The first form is what most congregations own. It records for nobody, and its value arrives the morning after, as evidence. The third form is what Blinkless does, and the plan above says, from your own answers, whether it is the next thing to spend money on or something to come back to once the free list is done.

For a house of worship it works like this. Your cameras, the ones you have or the ones the grant buys, are watched live by trained operators during the hours you choose, which for most congregations means the hours the building is empty. When someone is on the property who should not be, the operator speaks to them through on-site speakers, and most incidents end there. If that fails, the operator calls police on a verified incident: a person seen, on a live feed, doing something. That verification is the part that decides whether anyone comes. A growing number of police departments no longer dispatch on an unverified alarm; our US alarm permit lookup documents which cities, and what a false alarm costs where they still do.

There are two limits. It won’t greet anyone: the highest-value measure on this page is a person at the door saying hello, and no camera does that. And during a service, with people in the building, the safety team is the response. Monitoring adds a second pair of eyes on the parking area and the approaches, which CISA’s guide lists as its own outer-perimeter option, but it does not replace the people inside. It covers the window a volunteer congregation cannot: the night, the weekday, the holiday week when the building sits dark. It is sold as a subscription rather than a wage, which is why the guard cost calculator exists: the honest comparison is against what the same hours would cost as a person on site.

On the money: the federal grant reaches it by three routes, and the plan above prints the equipment code beside the relevant item. As a subscription service supporting a camera network, which is an allowable equipment category. As a sustainment user fee on a system the grant funded, because the notice lists licences, upgrades and user fees as allowable. Or as contracted security personnel, which may take up to 100% of an award. These are mechanisms rather than promises; the person to structure the line with is your State Administrative Agency, and our NSGP page names yours.

Where this comes from

  • The framework, the perimeter model and the attack statistics: Cybersecurity and Infrastructure Security Agency, Mitigating Attacks on Houses of Worship Security Guide, December 2020. cisa.gov
  • The self-assessment this page complements: CISA, Houses of Worship Security Self-Assessment. cisa.gov
  • The specific measures, and the priority order: CISA, Physical Security Performance Goals for Faith-Based Communities, version 1.0, December 2023. The source for the landscaping measurements, the lighting types, greeters at every entry point, the single point of entry with photo identification where there is a school on site, and the after-action review. cisa.gov
  • The greeter method: CISA, Power of Hello Houses of Worship Guide, the OHNO approach: Observe, Initiate a hello, Navigate the risk, Obtain help. cisa.gov
  • On-site help, free: CISA Protective Security Advisors, described in the performance goals above as supporting faith-based communities “with vulnerability assessments, site visits, and training at no cost”. cisa.gov
  • Emergency planning: FEMA and DHS, Guide for Developing High-Quality Emergency Operations Plans for Houses of Worship, and CISA’s Active Shooter Emergency Action Plan template. fema.gov
  • Reporting suspicious activity: DHS, If You See Something, Say Something. dhs.gov
  • The grant, the equipment codes and the scoring matrix: FY2026 Nonprofit Security Grant Program notice of funding opportunity, Appendices B, C and D, transcribed in full on our NSGP page and sourced there.

Everything on this page is a planning aid. It is not a vulnerability assessment, not legal advice and not a guarantee of a grant award. Grant rules, deadlines and allowable costs change every cycle; confirm them against the current notice of funding opportunity and your State Administrative Agency before you rely on them.

Frequently asked questions

What should be on a church security checklist?

A useful one covers 9 areas, and they are the chapters of CISA's Mitigating Attacks on Houses of Worship Security Guide: who is responsible for security, whether a vulnerability assessment has been done, how prepared the congregation is, the outer perimeter (parking, grounds, lighting, the vehicle approach), the middle perimeter (doors, walls, windows), the inner perimeter (the worship space, offices and classrooms), what detects an incident and who responds, children's programmes, and cybersecurity. The reason a generic checklist disappoints is that the right answer in each area depends on how many people you have, how much building, and who else uses it. A 40-person chapel and a 2,000-seat campus with a day school do not have the same nine answers. The checker on this page asks about those things first and then produces the checklist.

How do I write a church security plan?

Start with a vulnerability assessment, because everything else refers back to it, then write down five things: who is responsible, what you found, what you will do about it in each of the three perimeters, how the congregation is trained and warned, and when you will review it. CISA treats this as a cycle rather than a document you finish: you re-read the plan at least once a year and after any incident, or it stops describing the building you have. The tool on this page writes that plan from your answers, section by section, with blanks left where the decision is yours to make.

Is this the same as the CISA self-assessment?

No, and it is not a replacement for it. CISA's Houses of Worship Security Self-Assessment is a good free government tool that asks every house of worship the same questions and exports an action list to Word and Excel; it describes itself as "a first step in building an effective security program" and says that it "is not intended to be an in-depth security assessment". This page does three things it does not: it weighs your answers against each other and scores them, so you know what to do first; it writes the security plan rather than a list; and it maps every capital item to the federal grant code that would pay for it. Use both. CISA's output is also accepted by some states as the vulnerability assessment a grant application requires.

We have no budget. What can we do?

Most of what protects a congregation is free. CISA's own analysis of ten years of attacks points the same way. In 78% of the incidents studied, the attacker had no prior association with the house of worship, which makes a greeter trained to say hello to a stranger the single highest-value measure available to you. In 57% of cases the perpetrator showed planning behaviour beforehand (telling someone, leaving messages, posting online), which makes naming one person that concerns go to almost as valuable. Add to those: reducing the doors open during a service to one, writing a closing list with a name against it, cutting back overgrowth that hides the building, never letting one person count the offering alone, identifying which rooms you would shelter in, and asking your police department for a walk-through. Each of those costs a decision and somebody's time.

Does the government pay for church security cameras?

The Nonprofit Security Grant Program does, for nonprofits at high risk of a terrorist or other extremist attack, and the scoring matrix multiplies a house of worship’s score by three. It is a FEMA programme, assistance listing 97.008, and it funds equipment from a fixed list of 36 Authorized Equipment List codes (cameras, lighting, access control, alarm systems, impact-resistant doors, mass notification) plus planning, training, exercises and contracted security personnel. Two exclusions catch people out: licence plate readers and facial recognition software are prohibited by name. You apply through your State Administrative Agency rather than to FEMA, on their deadline, and the checker above names yours.

What is a vulnerability assessment, and do we need a consultant?

It is a written record of what your congregation has to lose, what could threaten it, where it is exposed and what that would cost you, done for one physical address at a time. You may not need a consultant. CISA's guidance says that where the security picture is straightforward, as at a small or rural house of worship, the assessment "can likely be performed in-house", and CISA Protective Security Advisors will come and conduct one in person at no charge. For a federal grant application, the assessment is mandatory, must be site-specific for every address, and the grant will not pay for it, but it need not be third-party authored. Texas, for instance, lists CISA's self-assessment as an acceptable method and states that no prescribed format or template exists.

How do we start a church security team?

CISA describes three roles rather than one. A security coordinator is the single named person who owns the programme: a staff member or an engaged volunteer, and not required to be a security professional. A security planning team supports them with research and recommendations, and should be representative of the congregation: clergy, staff and members. A safety team is the wider group on duty (greeters, ushers, people in the parking area) whose job is to notice and to tell somebody, not to intervene. Before recruiting from outside, survey your own membership: police officers, nurses, emergency managers, IT people and accountants are often already sitting in your pews, and CISA recommends starting there.

Should our security team be armed?

That is a decision for your leadership, your insurer and your state's law, and this page does not take a position on it or score it. The evidence favours the measures that happen before anything starts: someone at the door who greets strangers, a reporting path that catches the planning behaviour 57% of perpetrators displayed, a plan the congregation has practised, and a building that is harder to enter unnoticed. Whatever you decide about arming, none of those becomes less necessary, and each of them is available to a congregation that decides against it.

How often should a church run a security drill?

At least once a year, with the whole congregation rather than the safety team alone, and again whenever the plan changes in a material way. CISA's case studies are blunt about why: in over half of the armed-assault incidents examined, congregants ran or hid once an attack began, improvising in the moment. A drill converts that into a decision made in advance. Start with evacuation and where to gather, which is uncontroversial and useful for fires anyway, then add lockdown. Ten minutes after a service, once a year, is the whole commitment.

Do the cameras we already have count for anything?

They count as evidence, which is worth having, and they do not count as security until somebody is watching them. A recorded camera documents what happened; it does not change what happens. That is the distinction the checker scores: cameras that nobody watches score a fraction of what monitored cameras score, because the gap between them is the gap between a police report and an intervention. CISA’s guide draws the same line, naming three forms of CCTV: an unmonitored recording system, active monitoring without response, and active monitoring with response integrated with an incident response plan. If you already own cameras, having them watched during the hours the building is empty turns the first form into the third, and NSGP can fund that as a subscription service supporting a camera network or as a sustainment user fee on a funded system.

Does anything here get sent to you?

No. Every answer stays in your browser. It is saved there so you can come back and finish, and only you can clear it. Nothing is transmitted, and there is no sign-up, no email wall and no account. If you choose to have the plan emailed to you, that form sends us a summary of your answers and your gaps so that whoever replies knows what you are looking at, and nothing else.

Where do the numbers on this page come from?

The framework, the outer/middle/inner perimeter model and every attack statistic come from one document: CISA's Mitigating Attacks on Houses of Worship Security Guide (December 2020), which is built on an original analysis of ten years of targeted attacks on houses of worship in the United States. The grant rules, equipment codes and scoring lines come from the FY2026 NSGP notice of funding opportunity, transcribed in full on our NSGP page. The weightings applied to the 9 areas are ours, and the page says which findings they rest on rather than presenting them as a standard.

The part of the plan that needs somebody awake

Almost everything above is yours to do, and most of it costs nothing. One line is not: the hours between the last person leaving and the first arriving, when a camera records for nobody. Blinkless covers those hours: trained operators on your cameras, a voice through the on-site speakers, police called on a verified incident. The plan above says whether that is your next dollar or a later one. If it is, send us the plan. We’ll price the hours it names, against the cameras you have or the ones the grant will buy, and tell you if the free list should come first.

How remote guarding works

Or call (212) 470-2511.