Every U.S. house of worship needs a written, CISA-aligned church security plan. Start today with three actions: form a security committee, complete the CISA Faith-Based Community Self-Assessment to rate your facility’s current posture, and schedule a walk-through with your local law enforcement liaison or fire marshal. Those three steps cost nothing and give you the foundation every other element of your plan builds on.

Key Takeaways

A written, CISA-aligned church security plan with assigned roles, documented training, and a tested emergency operations plan is the single most effective step any U.S. house of worship can take to protect its congregation.

Point Details
Start with the CISA self-assessment Complete the free self-assessment first; it scores your posture and prioritizes your next actions.
Written plan is a grant prerequisite FEMA’s Nonprofit Security Grant Program requires documented plans and training records for eligibility.
Layered perimeters preserve welcome Outer, middle, and inner perimeter measures protect without creating a fortress atmosphere.
Test quarterly, review annually Tabletop exercises every quarter and a full-scale drill at least annually keep the plan operational.
Hubsecurityandinvestigativegroup Provides professional risk assessments, training support, and guard services tailored to houses of worship.

Table of Contents

Why does your congregation need a formal church security plan?

Houses of worship in the United States face a documented and widening threat profile. Targeted attacks, arson, active-shooter incidents, bomb threats, and cybercrime against donor databases have all affected faith communities across the country. The openness that defines congregational life — unlocked doors, welcoming greeters, large public gatherings — creates real vulnerabilities that a written plan directly addresses.

A formal plan does four things that informal awareness cannot:

Pro Tip: Run the CISA self-assessment before your first committee meeting. The output gives you a prioritized list of low-cost, high-impact changes — lighting, door hardware, greeter positioning — that you can implement within weeks and present to leadership as quick wins.

What core components must every church security plan include?

A complete plan is a living document, not a one-page memo. Practitioner guidance confirms that documented procedures paired with trained volunteers consistently outperform technology-only approaches. Each section below should be a named chapter in your written plan.

How do you develop and implement a church security plan step by step?

The process follows multiple phases in sequence. Small volunteer-run congregations can compress the timeline; larger multi-site churches may need more time at each stage.

  1. Planning kickoff (Days 1–30). Secure written buy-in from senior leadership. Appoint a security committee chair and recruit volunteers for each functional role. Set a project calendar with milestone dates.

  2. Assessment (Days 15–45). Complete the CISA self-assessment. Conduct a physical site survey — walk every entry point, parking area, and interior space. Document findings in writing with photos.

  3. Prioritize mitigations (Days 30–60). Sort findings into three tiers: immediate low-cost fixes (lighting, signage, greeter positioning), medium-term investments (camera systems, door hardware, visitor check-in software), and longer-term capital items (barriers, managed access control). Address tier-one items before writing the full plan.

  4. Write the plan (Days 45–90). Draft each section using the component list above. Assign an owner and a review date to every section. Have pastoral leadership and legal counsel review the final draft before approval.

  5. Train staff and volunteers (Days 60–120). Deliver role-specific training: STOP THE BLEED for medical responders, active-threat awareness for all volunteers, and communications drills for the notifications lead. Document every session.

  6. Run exercises and update (Days 90–180+). Conduct a tabletop exercise within 90 days of plan approval. Schedule a full-scale drill within six months. Use after-action reports to update the plan and training records.

Implementation checklist by phase:

Pro Tip: Document every decision made during the planning process — meeting minutes, assessment findings, training rosters. That paper trail is often the deciding factor in a FEMA Nonprofit Security Grant Program application and in any post-incident liability review.

How do you form, vet, and train your church security team?

The security committee is the operational core of your plan. CISA guidance is explicit: a named security manager or committee, written plans, and regular training are the three non-negotiable foundations of effective house of worship security.

Roles to fill:

Volunteer screening essentials:

Role Core Responsibilities Minimum Training Frequency
Security manager Plan ownership, law enforcement liaison, incident command Quarterly tabletop + annual full drill
Ushers / greeters Observation, access monitoring, behavioral reporting Semi-annual awareness training
Medical responders First aid, CPR, STOP THE BLEED response Annual recertification
Communications lead Alert system operation, 9-1-1 liaison, media management Semi-annual communications drill
Facilities lead Access control, key management, physical plant Annual review + after each incident

Pro Tip: Volunteer turnover is the single most common reason church security plans fail in practice. Build a succession plan for every role — a named backup who receives the same training as the primary — so a resignation does not leave a critical gap.

How does the outer, middle, and inner perimeter model work for churches?

The CISA Houses of Worship Security Guide recommends a holistic, layered approach built around three concentric perimeters. The goal is to slow, detect, and respond to a threat at the earliest possible point while keeping the environment welcoming for the congregation.

Outer perimeter (parking lot and property boundary):

Middle perimeter (building exterior and entry points):

Inner perimeter (interior spaces):

Pro Tip: Design landscaping and greeter positioning to create natural surveillance — a greeter at the parking lot entrance sees the entire lot and the main door simultaneously. That sightline costs nothing and removes the need for an additional camera position.

What emergency response procedures should your plan include?

Security volunteer using radio in church drill

Every incident type needs its own protocol skeleton. The FBI’s emergency operations planning guide for houses of worship structures these across three phases: pre-incident (prevention and preparedness), incident (response), and recovery. Your plan should follow the same structure for each scenario.

Active shooter

  1. Designated security manager or first observer calls 9-1-1 immediately.
  2. Communications lead activates the mass-notification system (lockdown announcement).
  3. Volunteers direct congregation to shelter-in-place locations or evacuation routes per the pre-assigned floor plan.
  4. No one re-enters the building until law enforcement gives the all-clear.
  5. Security manager meets responding officers at a pre-designated exterior point.
  6. Communications lead manages congregation inquiries; no media statements until law enforcement clears.

Medical emergency

  1. Nearest trained volunteer calls 9-1-1 and begins first aid or CPR.
  2. Second volunteer retrieves the AED and first-aid kit.
  3. STOP THE BLEED-trained responder applies hemorrhage control if needed.
  4. Facilities lead clears a path for EMS entry and meets them at the main entrance.
  5. Communications lead notifies family members and pastoral staff.

Fire

  1. Any person discovering fire activates the nearest pull station and calls 9-1-1.
  2. Communications lead announces evacuation over the PA system.
  3. Ushers guide congregation to pre-assigned exterior assembly points.
  4. Facilities lead confirms all interior spaces are cleared and reports to the incident commander.
  5. No re-entry until the fire marshal authorizes it.

Severe weather

  1. Communications lead monitors National Weather Service alerts and activates shelter-in-place when a warning is issued.
  2. Ushers direct congregation to interior rooms away from windows (pre-identified in the plan).
  3. Security manager monitors conditions and coordinates with local emergency management.

Suspicious package or bomb threat

  1. Do not touch or move the item.
  2. Security manager calls 9-1-1 and follows dispatcher instructions.
  3. Evacuate a minimum 300-foot radius as directed by law enforcement.
  4. Communications lead manages congregation communication; no social media posts until law enforcement clears.

Missing child reunification

  1. Childcare staff immediately notifies the security manager and locks down the childcare area.
  2. Security manager calls 9-1-1 and initiates a building-wide search with assigned volunteers.
  3. No child is released to any adult until identity is verified against the check-in record.
  4. Reunification takes place at a designated, controlled location with a witness present.

Pro Tip: Pre-assign every role in each protocol by name, not just by title. When an incident starts, people default to their name being called — not their job description.

What cybersecurity basics should your church security plan cover?

Churches hold sensitive data: donor financial records, children’s personal information, staff payroll details, and cloud-based access control credentials. A breach of those systems can compromise physical security as well — camera systems, electronic door locks, and alarm panels are all network-connected in modern facilities.

Cybersecurity checklist for your plan:

Cyber risks intersect with physical security in ways that are easy to overlook. A compromised camera system can be disabled remotely before a physical intrusion. An email phishing attack targeting the treasurer can drain the operating account. Both belong in the same security plan.

Pro Tip: Many congregations have a member with IT experience willing to volunteer a few hours for basic hardening — MFA setup, network segmentation, and a backup audit. A low-cost managed security service provider (MSSP) can handle ongoing monitoring for a monthly fee that is often grant-eligible.

How do you work with law enforcement, CISA, and grant programs?

External partnerships multiply your resources without adding to your budget. The CISA Protecting Places of Worship resources page lists Protective Security Advisors (PSAs) in every region — federal employees who provide free site assessments, connect you to exercises, and help you navigate grant applications.

Steps to build external partnerships:

Grant funding sources:

Apply to Grants.gov for a consolidated view of federal opportunities. State homeland security agencies also administer sub-grants that may have less competition than federal direct awards.

How often should you test and maintain your church security plan?

A plan that is written once and never tested is not a security plan — it is a document. CISA’s guidance calls for regular training and exercises as a core requirement, not an optional enhancement.

Recommended exercise schedule:

  1. Tabletop exercises: quarterly. Gather the security committee and walk through a scenario (active shooter, medical emergency, severe weather) using the written protocols. No physical movement required — the goal is to identify gaps in the plan and decision-making.

  2. Full-scale drills: annually or biannually. Conduct a live exercise involving the full congregation or a representative group. Coordinate with local law enforcement or fire department when possible — their participation adds realism and strengthens the relationship.

  3. After-action review: within 72 hours of any exercise or real incident. Document what worked, what failed, and what needs to change. Assign a named owner and a deadline to every corrective action.

Maintenance triggers that require an unscheduled plan review:

Maintenance checklist:

What does a fillable church security plan template look like?

The structure below gives you a ready-to-populate outline. Copy it into a Word document or Google Doc, fill in the bracketed fields, and you have a working draft.

What does a fillable church security plan template look like? — overview diagram

Plan cover page fields: Congregation name | Facility address | Security manager name and contact | Date approved | Version number | Next review date

Section 1: Governance

Section 2: Risk and vulnerability assessment

Section 3: Emergency operations plan

Section 4: Access control and key management

Section 5: Childcare and youth safety

Section 6: Training and exercise records

Sample SOP snippet — Active threat immediate actions:

Trigger: Confirmed or credible report of an armed individual on property.

  1. First observer calls 9-1-1. State: location, number of individuals, description, last known direction.
  2. Communications lead activates lockdown announcement: “Attention — this is a lockdown. All persons shelter in place immediately. Do not open doors.”
  3. Ushers lock or barricade nearest interior doors and direct congregation away from windows and doors.
  4. Security manager proceeds to law enforcement staging point (pre-designated exterior location).
  5. All-clear: announced only after law enforcement verbal confirmation.

Sample SOP snippet — Child reunification:

Trigger: Missing child report or end-of-service reunification.

  1. Childcare staff locks down the childcare area and notifies the security manager.
  2. Security manager initiates building search with assigned volunteers; calls 9-1-1 if child not located within five minutes.
  3. No child released without matching the check-in record to the authorized adult’s photo ID.
  4. Reunification location: [designate a specific room].
  5. Witness required for every release; document in the incident log.
Contact list field Example entry
Security manager Jane Smith, 617-555-0100, [email protected]
Local police non-emergency contact number available upon request
Local fire non-emergency contact number available upon request
CISA PSA regional contact [From CISA PSA locator]
Counseling resource [Local EAP or pastoral counseling contact]

When should you hire professional security services?

Volunteer teams handle the majority of day-to-day faith community safety work well. Certain situations, though, call for professional expertise that goes beyond what a trained volunteer can reasonably provide.

Decision triggers for engaging professional services:

Questions to ask any prospective security provider:

Service type What it includes
Risk assessment Site survey, threat analysis, written findings, prioritized mitigation recommendations
Design and implementation Security system specification, access control design, vendor coordination, installation oversight
Training and exercises Role-specific volunteer training, tabletop facilitation, full-scale drill coordination, written AARs
Armed or unarmed guard services Uniformed presence during services or events, patrol, access control staffing

Pro Tip: Require any provider you hire to deliver a written after-action report for every training session or exercise they facilitate. That document becomes part of your grant application record and your legal due-diligence file.

What we’ve learned working with houses of worship

The congregations that build the most durable security programs share one trait: they treat the plan as a living commitment, not a compliance checkbox. In practice, that means the security manager shows up to every committee meeting, the after-action report from the last drill is on the table, and someone has already called the local precinct to schedule the next walk-through.

The pitfalls we see most often are predictable. Volunteer turnover quietly hollows out a plan that looked complete on paper. Childcare security gets deprioritized because it feels like an internal process issue rather than a security issue — until it isn’t. And the simplest physical fixes, the ones that cost under $500 and take an afternoon, sit on the to-do list for months because no one owns them. Assign an owner, set a deadline, and document the completion. That discipline is what separates a plan that protects people from one that protects no one.

Hubsecurityandinvestigativegroup offers professional church security assessments

For congregations ready to move beyond the self-assessment and into a professionally documented security program, Hubsecurityandinvestigativegroup brings over 75 years of combined law enforcement and loss prevention experience directly to your facility. Our approach follows a clear sequence: assess your current posture, prioritize mitigations by risk and budget, support implementation, and train your volunteer team. We work with houses of worship across the region and coordinate directly with local law enforcement so our findings align with what first responders already know about your site.

Hubsecurityandinvestigativegroup

This is not a one-size-fits-all package. Every engagement is scoped to your facility’s size, activity profile, and threat environment — the same tailored approach we apply to building security services for commercial clients. If your congregation hosts large events, operates a school or childcare program, or has received credible threats, a professional assessment gives you a written, defensible plan that satisfies grant requirements and insurance standards. Contact Hubsecurityandinvestigativegroup to schedule an initial consultation and get a clear picture of where your congregation stands.

Sources

Use these resources as you build and maintain your plan. Citing them in grant applications strengthens your case by demonstrating alignment with federal standards.

When citing these sources in a grant application or a request for a PSA visit, reference the specific document title and the issuing agency. That framing signals to reviewers that your planning process followed recognized federal standards — which is exactly what grant administrators and law enforcement partners want to see.