Cost, Grants and Exposure
The CGA CMMC Gap Assessment Grant: What It Covers and Who Qualifies
How can you meet strict Department of Defense cybersecurity requirements when handling Controlled Unclassified Information or Federal Contract Information? The CMMC gap assessment grant from Cyber Grants Alliance offers in kind services that address all 110 NIST SP 800-171 Rev 2 controls for qualifying defense contractors.
What is the current status of CMMC requirements?
You may have heard conflicting reports about CMMC deadlines and requirements. As of July 13, 2026, the Department of War suspended the CMMC Phase II third party certification requirement, pending a 60-day strategic review. This means you are not currently required to obtain a C3PAO certification before contract award. However, this does not mean cybersecurity requirements have been lifted.
The following remain fully in force:
- DFARS 252.204-7012, requiring protection of CUI and incident reporting.
- NIST SP 800-171 Rev 2 controls for companies handling CUI.
- Level 1 and Level 2 annual self assessments.
- SPRS (Supplier Performance Risk System) score posting.
- Annual senior official affirmation of compliance.
The Department of War has stated it will continue to enforce these requirements through self assessments and select government led assessments. With the third party certification suspended, the senior official’s signature on your self assessment is now the sole assurance to the government. This increases your exposure under the False Claims Act if your score is inflated or unsupported.
What does the CMMC gap assessment grant cover?
The CGA CMMC gap assessment grant is an in kind grant delivered as services, not cash. For Level 2, it covers all 110 NIST SP 800-171 Rev 2 controls. For Level 1, it covers the 17 foundational practices aligned to FAR 52.204-21. The grant is valued at 3,000 dollars for Level 1 and 5,000 dollars for Level 2.
The assessment focuses on the following:
- Identification of gaps against the 110 NIST SP 800-171 Rev 2 controls (for Level 2).
- Review of documentation, including policies and procedures.
- Collection and review of evidence to support compliance.
- Analysis of scoping artifacts, such as your CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List.
- Recommendations to close gaps and improve your SPRS score.
The assessment is comprehensive, covering all 14 control families:
- Access Control (22 practices)
- Awareness and Training (3 practices)
- Audit and Accountability (9 practices)
- Configuration Management (9 practices)
- Identification and Authentication (11 practices)
- Incident Response (3 practices)
- Maintenance (6 practices)
- Media Protection (9 practices)
- Physical Protection (6 practices)
- Personnel Security (2 practices)
- Risk Assessment (3 practices)
- Security Assessment (4 practices)
- System and Communications Protection (16 practices)
- System and Information Integrity (7 practices)
To meet a control, every assessment objective under that control must be fully satisfied, as described in NIST SP 800-171A.
Who qualifies for the CMMC gap assessment grant?
The CMMC gap assessment grant is available to qualifying defense contractors. While the eligibility criteria are managed by Cyber Grants Alliance, you should be a company in the defense industrial base with requirements to comply with NIST 800-171 (Level 2) or FAR 52.204-21 (Level 1).
Level 2 is intended for companies handling Controlled Unclassified Information (CUI), while Level 1 applies to those managing only Federal Contract Information (FCI). If you are unsure of your level, a review of your contract clauses and the data you handle is the first step.
The grant is in kind and delivered as services, meaning you receive a professional gap assessment rather than cash or reimbursement. This assessment can help you identify where you stand, what you need to fix, and how to prepare for your next self assessment or a possible government led review.
Why is a CMMC gap assessment important for your business?
With the suspension of third party certification, the responsibility for demonstrating compliance now falls entirely on your organization. Your senior official’s affirmation is the only assurance the government receives. This makes it critical that your self assessment is accurate and your documentation is thorough.
The government continues to enforce compliance through:
- Self assessments and required SPRS score postings.
- Select government led assessments.
- False Claims Act actions for false certifications, as seen in cases involving contractors who failed to properly implement controls, maintain documentation, or used unauthorized systems.
For example, companies have faced False Claims Act settlements after failing to scan and remediate known vulnerabilities, using non FedRAMP email systems, or lacking a System Security Plan (SSP). The liability can extend to primes, subcontractors, affiliates, and even private equity owners. Whistleblowers can file actions on the government’s behalf.
A gap assessment identifies weaknesses before they become compliance or legal risks. It also helps you prepare the proof chain: policy, procedure, evidence, and assessment.
What does the typical path to CMMC Level 2 compliance look like?
Most companies start with a gap assessment, which can range from 10,000 to 50,000 dollars depending on scope and provider. Remediation costs for tools and configuration can range from 30,000 to 200,000 dollars, with documentation and policy writing between 15,000 and 60,000 dollars. Many companies also engage MSPs or Registered Provider Organizations (RPOs) for ongoing support, with costs ranging from 20,000 to 120,000 dollars per year.
If you eventually need a C3PAO assessment, fees can range from 30,000 to 150,000 dollars and booking lead times can be six to nine months. However, with the current suspension, self assessments are the primary mechanism for demonstrating compliance.
How ready are most defense contractors for NIST 800-171 compliance?
According to data from the Department of Defense, only about 0.5 percent of Level 2 companies have been certified as of CMMC Phase 1. The average SPRS score across the defense industrial base is about 60 out of the required 110. Fewer than half of companies have completed their System Security Plan (SSP) or Plan of Actions and Milestones (POA&M) documentation. There are around 83 active C3PAOs for roughly 118,000 Level 2 companies, highlighting the scale of the readiness gap.
Common questions
What makes the CGA CMMC gap assessment grant different from other grants? The CGA grant is in kind and delivered as professional services, not cash. It covers all 110 NIST SP 800-171 Rev 2 controls for Level 2 or the 17 Level 1 practices, providing a comprehensive and actionable assessment.
Is CMMC certification required right now? No, as of July 13, 2026, the requirement for a C3PAO certification before contract award is suspended. However, self assessments, SPRS score posting, and compliance with NIST SP 800-171 or FAR 52.204-21 are still required.
How can a gap assessment help with False Claims Act risk? A gap assessment helps ensure your self assessment and senior official affirmation are accurate and supported by evidence, reducing the risk of False Claims Act exposure for false or inflated claims.
How to Apply for the CGA CMMC Grant
If you are a defense contractor seeking to meet NIST 800-171 or CMMC Level 2 requirements, the Cyber Grants Alliance CMMC Gap Assessment Grant can help you identify and close compliance gaps. This in kind grant is delivered as services and covers all 110 controls for qualifying companies. Learn more and apply at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.