Every U.S. house of worship needs a written, CISA-aligned church security plan. Start today with three actions: form a security committee, complete the CISA Faith-Based Community Self-Assessment to rate your facility’s current posture, and schedule a walk-through with your local law enforcement liaison or fire marshal. Those three steps cost nothing and give you the foundation every other element of your plan builds on.
- Form a security committee. Appoint a security manager or chair and identify volunteers for key roles before you write a single policy.
- Complete the CISA self-assessment. The tool scores your posture from low to a highly enhanced level and maps each answer to practical options, so you know where to spend effort first.
- Meet with first responders. A single conversation with your local police precinct or fire station opens the door to free site assessments, training support, and grant referrals.
Key Takeaways
A written, CISA-aligned church security plan with assigned roles, documented training, and a tested emergency operations plan is the single most effective step any U.S. house of worship can take to protect its congregation.
| Point | Details |
|---|---|
| Start with the CISA self-assessment | Complete the free self-assessment first; it scores your posture and prioritizes your next actions. |
| Written plan is a grant prerequisite | FEMA’s Nonprofit Security Grant Program requires documented plans and training records for eligibility. |
| Layered perimeters preserve welcome | Outer, middle, and inner perimeter measures protect without creating a fortress atmosphere. |
| Test quarterly, review annually | Tabletop exercises every quarter and a full-scale drill at least annually keep the plan operational. |
| Hubsecurityandinvestigativegroup | Provides professional risk assessments, training support, and guard services tailored to houses of worship. |
Table of Contents
- Why does your congregation need a formal church security plan?
- What core components must every church security plan include?
- How do you develop and implement a church security plan step by step?
- How do you form, vet, and train your church security team?
- How does the outer, middle, and inner perimeter model work for churches?
- What emergency response procedures should your plan include?
- What cybersecurity basics should your church security plan cover?
- How do you work with law enforcement, CISA, and grant programs?
- How often should you test and maintain your church security plan?
- What does a fillable church security plan template look like?
- When should you hire professional security services?
- What we’ve learned working with houses of worship
- Hubsecurityandinvestigativegroup offers professional church security assessments
- Sources
Why does your congregation need a formal church security plan?
Houses of worship in the United States face a documented and widening threat profile. Targeted attacks, arson, active-shooter incidents, bomb threats, and cybercrime against donor databases have all affected faith communities across the country. The openness that defines congregational life — unlocked doors, welcoming greeters, large public gatherings — creates real vulnerabilities that a written plan directly addresses.
A formal plan does four things that informal awareness cannot:
- Reduces response time. When roles are pre-assigned and protocols are written down, volunteers act in seconds rather than minutes during an incident.
- Preserves a welcoming environment. CISA’s guidance on protecting places of worship stresses that layered, unobtrusive measures — lighting, sightlines, trained greeters — protect without turning a sanctuary into a checkpoint.
- Reduces legal exposure. A documented plan and regular training demonstrate reasonable duty of care, which matters if your congregation ever faces a liability claim.
- Unlocks grant funding. The FEMA Nonprofit Security Grant Program requires documented plans and training records as part of the application; without them, your congregation is ineligible regardless of need.
Pro Tip: Run the CISA self-assessment before your first committee meeting. The output gives you a prioritized list of low-cost, high-impact changes — lighting, door hardware, greeter positioning — that you can implement within weeks and present to leadership as quick wins.
What core components must every church security plan include?
A complete plan is a living document, not a one-page memo. Practitioner guidance confirms that documented procedures paired with trained volunteers consistently outperform technology-only approaches. Each section below should be a named chapter in your written plan.
- Governance. Names the security manager or committee chair, defines the committee’s authority, and lists decision-makers for each incident type.
- Risk and vulnerability assessment. Documents the self-assessment results, site survey findings, and the threat profile specific to your facility and neighborhood.
- Emergency operations plan (EOP) and incident SOPs. Covers active shooter, medical emergency, fire, severe weather, suspicious package, bomb threat, and missing child reunification — each as a separate, step-by-step protocol.
- Access control and key management. Lists who holds keys or access codes, how credentials are issued and revoked, and the schedule for lock audits.
- Visitor management. Describes check-in procedures for first-time visitors, contractors, and delivery personnel.
- Childcare and youth safety. Covers check-in/check-out procedures, volunteer screening, two-adult rules, and reunification protocols.
- Communications and mass notification. Names the primary and backup alert systems, the chain of notification, and the media spokesperson.
- Training and exercises. Schedules tabletop and live drills, documents completion, and tracks certifications.
- After-action review and recovery. Defines how incidents and exercises are debriefed, how lessons learned are recorded, and how counseling resources are activated.
- Cybersecurity. Covers password policies, multi-factor authentication, backup schedules, and donor-data protections.
- Plan maintenance. Sets the annual review date, names the owner of each section, and lists triggers for an unscheduled update.
How do you develop and implement a church security plan step by step?
The process follows multiple phases in sequence. Small volunteer-run congregations can compress the timeline; larger multi-site churches may need more time at each stage.
-
Planning kickoff (Days 1–30). Secure written buy-in from senior leadership. Appoint a security committee chair and recruit volunteers for each functional role. Set a project calendar with milestone dates.
-
Assessment (Days 15–45). Complete the CISA self-assessment. Conduct a physical site survey — walk every entry point, parking area, and interior space. Document findings in writing with photos.
-
Prioritize mitigations (Days 30–60). Sort findings into three tiers: immediate low-cost fixes (lighting, signage, greeter positioning), medium-term investments (camera systems, door hardware, visitor check-in software), and longer-term capital items (barriers, managed access control). Address tier-one items before writing the full plan.
-
Write the plan (Days 45–90). Draft each section using the component list above. Assign an owner and a review date to every section. Have pastoral leadership and legal counsel review the final draft before approval.
-
Train staff and volunteers (Days 60–120). Deliver role-specific training: STOP THE BLEED for medical responders, active-threat awareness for all volunteers, and communications drills for the notifications lead. Document every session.
-
Run exercises and update (Days 90–180+). Conduct a tabletop exercise within 90 days of plan approval. Schedule a full-scale drill within six months. Use after-action reports to update the plan and training records.
Implementation checklist by phase:
- [ ] Leadership sign-off obtained and documented
- [ ] Security committee roster finalized with contact information
- [ ] CISA self-assessment completed and results filed
- [ ] Site survey completed with written findings and photos
- [ ] Tier-one mitigations implemented and documented
- [ ] Full plan drafted, reviewed, and approved
- [ ] All volunteers trained and certifications recorded
- [ ] Tabletop exercise conducted and after-action report filed
- [ ] Full-scale drill scheduled
- [ ] Grant application timeline identified (see FEMA grants portal and Grants)
Pro Tip: Document every decision made during the planning process — meeting minutes, assessment findings, training rosters. That paper trail is often the deciding factor in a FEMA Nonprofit Security Grant Program application and in any post-incident liability review.
How do you form, vet, and train your church security team?
The security committee is the operational core of your plan. CISA guidance is explicit: a named security manager or committee, written plans, and regular training are the three non-negotiable foundations of effective house of worship security.
Roles to fill:
- Security committee chair / security manager. Owns the plan, coordinates with law enforcement, and makes real-time decisions during incidents.
- Ushers and greeters. First line of observation — trained to identify behavioral indicators and report concerns without confrontation.
- Medical responders. Certified in first aid, CPR, and STOP THE BLEED; positioned near first-aid kits during services.
- Communications lead. Operates the mass-notification system, liaises with 9-1-1 dispatchers, and manages media inquiries.
- Facilities lead. Owns access control, keys, and physical plant issues; coordinates with contractors.
Volunteer screening essentials:
- Criminal background check before any security role assignment
- Reference check with at least two contacts outside the congregation
- Clear written role description with defined authority limits
- Signed acknowledgment of confidentiality and conduct expectations
| Role | Core Responsibilities | Minimum Training Frequency |
|---|---|---|
| Security manager | Plan ownership, law enforcement liaison, incident command | Quarterly tabletop + annual full drill |
| Ushers / greeters | Observation, access monitoring, behavioral reporting | Semi-annual awareness training |
| Medical responders | First aid, CPR, STOP THE BLEED response | Annual recertification |
| Communications lead | Alert system operation, 9-1-1 liaison, media management | Semi-annual communications drill |
| Facilities lead | Access control, key management, physical plant | Annual review + after each incident |
Pro Tip: Volunteer turnover is the single most common reason church security plans fail in practice. Build a succession plan for every role — a named backup who receives the same training as the primary — so a resignation does not leave a critical gap.
How does the outer, middle, and inner perimeter model work for churches?
The CISA Houses of Worship Security Guide recommends a holistic, layered approach built around three concentric perimeters. The goal is to slow, detect, and respond to a threat at the earliest possible point while keeping the environment welcoming for the congregation.
Outer perimeter (parking lot and property boundary):
- Adequate lighting across the full parking area, including pathways to entrances
- Clear sightlines — trim hedges and trees that create concealment near entry points
- Signage directing visitors to a single monitored entrance
- Parking attendants or greeters visible at the lot entrance during services
- Vehicle barriers (planters, bollards, or concrete curbing) at high-traffic pedestrian areas for larger facilities
Middle perimeter (building exterior and entry points):
- Controlled entry: designate one primary public entrance during services; lock or monitor all others
- Visitor check-in station with a greeter and, for childcare, a sign-in system with ID verification
- Camera coverage of all exterior doors, parking areas, and the main lobby
- Door hardware: deadbolts, door viewers, and reinforced strike plates on all exterior doors
- Nursery and childcare entry controlled separately with a dedicated check-in process
Inner perimeter (interior spaces):
- Interior cameras covering main gathering spaces, hallways, and nursery areas
- Designated safe rooms or shelter-in-place locations identified in the plan
- Trained volunteers positioned at interior observation points during services
- First-aid kits and AED units in accessible, marked locations
Pro Tip: Design landscaping and greeter positioning to create natural surveillance — a greeter at the parking lot entrance sees the entire lot and the main door simultaneously. That sightline costs nothing and removes the need for an additional camera position.
What emergency response procedures should your plan include?

Every incident type needs its own protocol skeleton. The FBI’s emergency operations planning guide for houses of worship structures these across three phases: pre-incident (prevention and preparedness), incident (response), and recovery. Your plan should follow the same structure for each scenario.
Active shooter
- Designated security manager or first observer calls 9-1-1 immediately.
- Communications lead activates the mass-notification system (lockdown announcement).
- Volunteers direct congregation to shelter-in-place locations or evacuation routes per the pre-assigned floor plan.
- No one re-enters the building until law enforcement gives the all-clear.
- Security manager meets responding officers at a pre-designated exterior point.
- Communications lead manages congregation inquiries; no media statements until law enforcement clears.
Medical emergency
- Nearest trained volunteer calls 9-1-1 and begins first aid or CPR.
- Second volunteer retrieves the AED and first-aid kit.
- STOP THE BLEED-trained responder applies hemorrhage control if needed.
- Facilities lead clears a path for EMS entry and meets them at the main entrance.
- Communications lead notifies family members and pastoral staff.
Fire
- Any person discovering fire activates the nearest pull station and calls 9-1-1.
- Communications lead announces evacuation over the PA system.
- Ushers guide congregation to pre-assigned exterior assembly points.
- Facilities lead confirms all interior spaces are cleared and reports to the incident commander.
- No re-entry until the fire marshal authorizes it.
Severe weather
- Communications lead monitors National Weather Service alerts and activates shelter-in-place when a warning is issued.
- Ushers direct congregation to interior rooms away from windows (pre-identified in the plan).
- Security manager monitors conditions and coordinates with local emergency management.
Suspicious package or bomb threat
- Do not touch or move the item.
- Security manager calls 9-1-1 and follows dispatcher instructions.
- Evacuate a minimum 300-foot radius as directed by law enforcement.
- Communications lead manages congregation communication; no social media posts until law enforcement clears.
Missing child reunification
- Childcare staff immediately notifies the security manager and locks down the childcare area.
- Security manager calls 9-1-1 and initiates a building-wide search with assigned volunteers.
- No child is released to any adult until identity is verified against the check-in record.
- Reunification takes place at a designated, controlled location with a witness present.
Pro Tip: Pre-assign every role in each protocol by name, not just by title. When an incident starts, people default to their name being called — not their job description.
What cybersecurity basics should your church security plan cover?
Churches hold sensitive data: donor financial records, children’s personal information, staff payroll details, and cloud-based access control credentials. A breach of those systems can compromise physical security as well — camera systems, electronic door locks, and alarm panels are all network-connected in modern facilities.
Cybersecurity checklist for your plan:
- Unique, strong passwords for every administrative account; no shared login credentials
- Multi-factor authentication (MFA) enabled on email, cloud storage, financial platforms, and access control systems
- Automated, off-site backups of all critical data on a weekly schedule minimum
- Vendor account audit: revoke access for any contractor or former employee within 24 hours of departure
- Donor and payment data handled only through PCI-compliant processors; no credit card numbers stored locally
- Annual phishing-awareness training for all staff and volunteers who handle email or financial systems
- Separate Wi-Fi network for congregation guests, isolated from administrative systems
Cyber risks intersect with physical security in ways that are easy to overlook. A compromised camera system can be disabled remotely before a physical intrusion. An email phishing attack targeting the treasurer can drain the operating account. Both belong in the same security plan.
Pro Tip: Many congregations have a member with IT experience willing to volunteer a few hours for basic hardening — MFA setup, network segmentation, and a backup audit. A low-cost managed security service provider (MSSP) can handle ongoing monitoring for a monthly fee that is often grant-eligible.
How do you work with law enforcement, CISA, and grant programs?
External partnerships multiply your resources without adding to your budget. The CISA Protecting Places of Worship resources page lists Protective Security Advisors (PSAs) in every region — federal employees who provide free site assessments, connect you to exercises, and help you navigate grant applications.
Steps to build external partnerships:
- Contact your local police precinct’s community liaison officer and request a security walk-through of your facility.
- Reach out to your regional FBI field office; the FBI’s community outreach program includes resources specifically for houses of worship.
- Request a PSA visit through the CISA website — PSAs provide no-cost vulnerability assessments and can connect you to regional training exercises.
- Invite your local fire marshal to review your evacuation plan and identify any code compliance gaps.
Grant funding sources:
- FEMA Nonprofit Security Grant Program (NSGP). The primary federal funding source for physical security improvements, planning, and training at nonprofit organizations including houses of worship. A written, approved plan is a prerequisite for most award categories.
- DHS Targeted Violence and Terrorism Prevention (TVTP) grants. Fund prevention-focused programs including training and community outreach.
- DOJ funding. The Department of Justice offers grants through several programs that support community safety planning.
Apply to Grants.gov for a consolidated view of federal opportunities. State homeland security agencies also administer sub-grants that may have less competition than federal direct awards.
How often should you test and maintain your church security plan?
A plan that is written once and never tested is not a security plan — it is a document. CISA’s guidance calls for regular training and exercises as a core requirement, not an optional enhancement.
Recommended exercise schedule:
-
Tabletop exercises: quarterly. Gather the security committee and walk through a scenario (active shooter, medical emergency, severe weather) using the written protocols. No physical movement required — the goal is to identify gaps in the plan and decision-making.
-
Full-scale drills: annually or biannually. Conduct a live exercise involving the full congregation or a representative group. Coordinate with local law enforcement or fire department when possible — their participation adds realism and strengthens the relationship.
-
After-action review: within 72 hours of any exercise or real incident. Document what worked, what failed, and what needs to change. Assign a named owner and a deadline to every corrective action.
Maintenance triggers that require an unscheduled plan review:
- A key staff member or volunteer leaves a security role
- A renovation changes entry points, sightlines, or interior layout
- A new threat or incident occurs at a nearby house of worship
- A new technology system (cameras, access control, notification) is installed
- An exercise or incident reveals a gap in the written protocol
Maintenance checklist:
- [ ] Annual review date set and calendared at plan approval
- [ ] Each section has a named owner responsible for updates
- [ ] After-action reports filed within 72 hours of exercises and incidents
- Training records updated after every drill or certification
- [ ] Plan version number and revision date updated on the cover page after every change
What does a fillable church security plan template look like?
The structure below gives you a ready-to-populate outline. Copy it into a Word document or Google Doc, fill in the bracketed fields, and you have a working draft.

Plan cover page fields: Congregation name | Facility address | Security manager name and contact | Date approved | Version number | Next review date
Section 1: Governance
- Security committee members (name, role, phone, email)
- Authority matrix: who can declare evacuation, shelter-in-place, lockdown
- Escalation chain: security manager → senior pastor → board chair
Section 2: Risk and vulnerability assessment
- Self-assessment date and score
- Site survey findings (by perimeter zone)
- Local threat profile summary
- Prioritized mitigation list with status
Section 3: Emergency operations plan
- One sub-section per incident type (use the protocol skeletons above)
- Each SOP includes: trigger, immediate actions, communications steps, all-clear criteria
Section 4: Access control and key management
- Key holder roster with role and contact
- Credential issuance and revocation procedure
- Lock audit schedule
Section 5: Childcare and youth safety
- Check-in/check-out procedure
- Two-adult rule policy
- Reunification protocol (see emergency procedures section)
Section 6: Training and exercise records
- Training log template: date | topic | trainer | attendees | certification earned
- Exercise log template: date | scenario | participants | findings | corrective actions
Sample SOP snippet — Active threat immediate actions:
Trigger: Confirmed or credible report of an armed individual on property.
- First observer calls 9-1-1. State: location, number of individuals, description, last known direction.
- Communications lead activates lockdown announcement: “Attention — this is a lockdown. All persons shelter in place immediately. Do not open doors.”
- Ushers lock or barricade nearest interior doors and direct congregation away from windows and doors.
- Security manager proceeds to law enforcement staging point (pre-designated exterior location).
- All-clear: announced only after law enforcement verbal confirmation.
Sample SOP snippet — Child reunification:
Trigger: Missing child report or end-of-service reunification.
- Childcare staff locks down the childcare area and notifies the security manager.
- Security manager initiates building search with assigned volunteers; calls 9-1-1 if child not located within five minutes.
- No child released without matching the check-in record to the authorized adult’s photo ID.
- Reunification location: [designate a specific room].
- Witness required for every release; document in the incident log.
| Contact list field | Example entry |
|---|---|
| Security manager | Jane Smith, 617-555-0100, [email protected] |
| Local police non-emergency | contact number available upon request |
| Local fire non-emergency | contact number available upon request |
| CISA PSA regional contact | [From CISA PSA locator] |
| Counseling resource | [Local EAP or pastoral counseling contact] |
When should you hire professional security services?
Volunteer teams handle the majority of day-to-day faith community safety work well. Certain situations, though, call for professional expertise that goes beyond what a trained volunteer can reasonably provide.
Decision triggers for engaging professional services:
- Volunteer bandwidth is insufficient to staff all security roles consistently
- Local threat intelligence indicates elevated risk (recent incidents at nearby facilities, credible threats)
- Multi-site operations require coordinated planning across locations
- Large-scale events — holiday services, concerts, community gatherings — draw crowds beyond normal capacity
- Grant requirements specify a professional assessment as a deliverable
- Leadership wants an independent, documented risk assessment to satisfy insurance or legal requirements
Questions to ask any prospective security provider:
- What certifications do your assessors hold, and do they have specific experience with houses of worship?
- Can you provide references from other faith-based clients?
- What does the assessment deliverable include — a written threat assessment, a prioritized mitigation plan, or both?
- How do you coordinate findings with local law enforcement?
- What are your liability coverage and insurance terms?
- Do you provide written after-action reports following any training or exercise you conduct?
| Service type | What it includes |
|---|---|
| Risk assessment | Site survey, threat analysis, written findings, prioritized mitigation recommendations |
| Design and implementation | Security system specification, access control design, vendor coordination, installation oversight |
| Training and exercises | Role-specific volunteer training, tabletop facilitation, full-scale drill coordination, written AARs |
| Armed or unarmed guard services | Uniformed presence during services or events, patrol, access control staffing |
Pro Tip: Require any provider you hire to deliver a written after-action report for every training session or exercise they facilitate. That document becomes part of your grant application record and your legal due-diligence file.
What we’ve learned working with houses of worship
The congregations that build the most durable security programs share one trait: they treat the plan as a living commitment, not a compliance checkbox. In practice, that means the security manager shows up to every committee meeting, the after-action report from the last drill is on the table, and someone has already called the local precinct to schedule the next walk-through.
The pitfalls we see most often are predictable. Volunteer turnover quietly hollows out a plan that looked complete on paper. Childcare security gets deprioritized because it feels like an internal process issue rather than a security issue — until it isn’t. And the simplest physical fixes, the ones that cost under $500 and take an afternoon, sit on the to-do list for months because no one owns them. Assign an owner, set a deadline, and document the completion. That discipline is what separates a plan that protects people from one that protects no one.
Hubsecurityandinvestigativegroup offers professional church security assessments
For congregations ready to move beyond the self-assessment and into a professionally documented security program, Hubsecurityandinvestigativegroup brings over 75 years of combined law enforcement and loss prevention experience directly to your facility. Our approach follows a clear sequence: assess your current posture, prioritize mitigations by risk and budget, support implementation, and train your volunteer team. We work with houses of worship across the region and coordinate directly with local law enforcement so our findings align with what first responders already know about your site.

This is not a one-size-fits-all package. Every engagement is scoped to your facility’s size, activity profile, and threat environment — the same tailored approach we apply to building security services for commercial clients. If your congregation hosts large events, operates a school or childcare program, or has received credible threats, a professional assessment gives you a written, defensible plan that satisfies grant requirements and insurance standards. Contact Hubsecurityandinvestigativegroup to schedule an initial consultation and get a clear picture of where your congregation stands.
Sources
Use these resources as you build and maintain your plan. Citing them in grant applications strengthens your case by demonstrating alignment with federal standards.
- Houses of Worship | CISA
- Developing Emergency Plans for Houses of Worship — FBI
- Nonprofit Security Grant Program | FEMA
- Church Security Plan: 7 Steps to Securing Your Facility
When citing these sources in a grant application or a request for a PSA visit, reference the specific document title and the issuing agency. That framing signals to reviewers that your planning process followed recognized federal standards — which is exactly what grant administrators and law enforcement partners want to see.
Recommended
- 1.The Growing Importance of Church Security and How Professional Security Services Can Help – Hub Security & Investigative Group
- 1.Church Security: Protecting Sacred Spaces in a Changing World – Hub Security & Investigative Group
- Church Security in Boston, MA: – Hub Security & Investigative Group
- 1.Workplace Security: Why Every Business Needs a Strong Protection Plan – Hub Security & Investigative Group