Planning & Cost

CMMC Grants & Funding
Programs that help cover the cost

Federal programs, state grants, and contract cost recovery options available to defense contractors pursuing CMMC Level 2 certification.

Last verified April 2026 — program availability changes. Confirm details directly with each program before applying.

Start here Free programs FAR Part 31 State grants Tax credits How to stack

Start here before spending anything

CMMC Level 2 compliance costs real money. The DoD's own estimate for a small business runs roughly $488,000 over three years when you include implementation, documentation, and the triennial C3PAO assessment cycle. Industry-reported costs for the first compliance cycle typically fall between $75,000 and $300,000, depending heavily on how many systems handle CUI and how much remediation is required.

Those numbers are accurate. They are also the starting point before any funding programs are applied. A contractor who works through the programs on this page in the right order can recover a meaningful portion of those costs, and in some cases eliminate them entirely for specific line items.

The right order matters. Free programs should come before paid engagements. Contract cost recovery should be built into every future proposal. State grants, where available, are first-come first-served and close without warning. The sections below follow that sequence.

Phase 2 enforcement
CMMC Level 2 requirements began appearing in DoD solicitations after November 10, 2025. Most CUI contracts will require C3PAO certification at award going forward. State grant funding is first-come, first-served and some programs have already allocated their current rounds. Starting early is the only way to access the full range of options.

Free federal programs

These programs cost nothing and should be the first calls any contractor makes. They do not replace a C3PAO assessment or a qualified consultant, but they provide genuine value at zero cost, and several of them can directly reduce the billable hours you need from paid resources later.

APEX Accelerators

APEX Accelerators are DoD-funded offices at more than 300 locations across the country, specifically chartered to help defense contractors navigate compliance requirements. For CMMC, they offer free gap assessments, documentation help, and compliance planning. Many offices have staff who have worked through CMMC readiness with dozens of local contractors and know the common gaps for your industry sector.

This is not marketing material or an introduction to sell you something. APEX Accelerators are funded to help contractors, and the service is free. If you have not contacted your local office, do that before engaging any paid consultant. The DoD operates a locator at napex.us/locations.

Project Spectrum

A free platform from the DoD Office of Small Business Programs. It includes a CMMC readiness check, training on CUI handling, SSP basics, and POA&M development. It will not replace a professional assessment, but it gives you a documented starting picture and identifies gaps before you bring in paid resources. Create a free account at projectspectrum.io.

SBDCs (Small Business Development Centers)

The SBA funds more than 900 Small Business Development Centers across the country. SBDC advisers can help you understand how to structure CMMC costs as allowable under your existing contracts, which is the foundation of FAR Part 31 cost recovery. If you are unsure whether your contract type supports cost recovery, an SBDC adviser is the right first conversation. Find your local center at americassbdc.org.

CSIAC (Cybersecurity and Information Systems Information Analysis Center)

CSIAC provides free technical inquiry support from DoD analysts. You can submit specific cybersecurity questions and receive a researched answer, up to four hours of analyst time at no cost. Response time is approximately 10 business days. Access requires a CAC, ECA certificate, or PIV credential. Useful for getting authoritative answers on specific control implementation questions before committing to a design decision. Submit inquiries at csiac.dtic.mil.

DCISE (Defense Cyber Crime Center)

The Defense Industrial Security Collaboration Environment provides threat intelligence sharing for DIB contractors. Free to join. Most useful once your security program is operational rather than as a starting point, but worth noting as an ongoing resource once you are past the implementation phase. More information at dc3.mil.

FAR Part 31 cost recovery

This is the most underused funding mechanism available to defense contractors, and the one with the highest potential value. Under FAR Part 31, costs that are allowable, allocable, and reasonable can be recovered through federal contract pricing. CMMC compliance costs meet those criteria.

What that means in practice depends on your contract type.

Cost-reimbursable contracts

On a cost-plus contract, you can charge CMMC costs directly to the contract as they are incurred. This includes C3PAO assessment fees, remediation work, compliance tools, and consultant engagements. Direct costs go to the contract. Indirect costs (such as internal staff time spent on compliance activities) can flow through your overhead or G&A rate and be recovered across your entire contract base.

Fixed-price contracts

You cannot retroactively recover costs on a fixed-price contract that is already in place. But every future proposal should have CMMC costs built into the price. That means identifying your recurring annual compliance labor, tool costs, and the amortized cost of the triennial C3PAO assessment, and including them in your overhead or G&A rate before bidding. Contractors who do not do this are absorbing CMMC costs out of margin.

Overhead rates

Ongoing compliance costs, including staff time, training, tool subscriptions, and preparation activities between assessments, can be structured as indirect costs and included in your overhead rate. This spreads the cost across your contract base and keeps it off your direct margin.

One important nuance
The DoD's position is that NIST SP 800-171 compliance was required of contractors since DFARS 252.204-7012 took effect in 2017. That framing means only the C3PAO assessment itself is strictly "new" cost from the government's perspective. In practice, most contractors and their contracts managers treat remediation costs as recoverable overhead, and DCAA auditors have generally accepted this when documentation is reasonable. If your organization is DCAA-audited, discuss the specific treatment with your contracts manager before structuring these costs.

The reference document is FAR Part 31. If you have not read it, your local SBDC adviser can walk through the relevant provisions with you at no cost.

State grants and MEP programs

The Manufacturing Extension Partnership (MEP) is a national network of centers funded by NIST and state governments to support U.S. manufacturers. Every state has at least one MEP center, and many of them offer cybersecurity assistance, cost-share programs, and direct CMMC support. A smaller number of states have dedicated CMMC grant programs with defined funding amounts.

The table below covers programs that were open or recently active as of April 2026. State program availability changes quickly. Verify status directly with each program before planning around it.

Program State / Scope Value Status
Maryland Cybersecurity Tax Credit
commerce.maryland.gov →
Maryland Up to $50,000 Open (first-come)
CCAT Cybersecurity Adoption Program (CAP)
grants.ccat.us →
Connecticut Up to $35,000 Open (rolling)
MassTech Manufacturing Cybersecurity
cam.masstech.org →
Massachusetts Up to $30,000 Check availability
Maryland DCAP
mdmep.org →
Maryland Varies Open
Michigan DCAP
U of Michigan Economic Growth Institute
Michigan Varies Open
Texas TMAC
tmac.org →
Texas Varies Open
North Carolina MEP — Defense Industry Initiative
ies.ncsu.edu →
North Carolina Varies Open
Ohio MEP (6 regional partners)
ohiomep.org →
Ohio Varies Open
Pennsylvania MEP (7 Industrial Resource Centers)
pamep.org →
Pennsylvania Varies Open
Indiana Purdue MEP
mep.purdue.edu →
Indiana Free Check availability
California CMTC
cmtc.com →
California Free (technical assistance) Open
New York FuzeHub
fuzehub.com →
New York Varies Periodic rounds

If your state is not listed, your MEP center may still offer cybersecurity assistance or connect you with local funding sources. Find your state MEP center at nist.gov/mep/centers.

Tax credits

Proposed federal cybersecurity tax credit

A 30% tax credit on cybersecurity spending for companies with fewer than 50 employees has been discussed in Congress and has received public support from DoD leadership. As of April 2026, it has not been enacted into law. It is worth monitoring but should not be built into financial planning until it passes. The most recent coverage is at federalnewsnetwork.com.

Existing federal deductibility

CMMC compliance costs are generally deductible as ordinary business expenses under existing tax law. Hardware purchases may qualify for accelerated depreciation under Section 179. This is not a grant or a credit, but it does reduce your after-tax cost of compliance. Confirm the treatment with your tax adviser given your specific entity structure and tax situation.

Maryland Cybersecurity Tax Credit

Maryland operates a 50% tax credit for purchases of cybersecurity products or services from qualified Maryland vendors. The maximum credit is $50,000 per year. This program is first-come, first-served and some vendors have already reached their allocation cap for the current program year. Check current vendor eligibility at commerce.maryland.gov before planning around it.

How to sequence these programs

The programs on this page are not mutually exclusive. Most contractors who use them well combine several. The sequence matters because some programs require you to apply before starting work, and some are time-sensitive.

Step 1 — Free resources first

Contact your APEX Accelerator before hiring a consultant. Create a Project Spectrum account and run the readiness check. Talk to your SBDC about how FAR Part 31 applies to your contract types. None of this costs anything, and the information you gather makes every subsequent paid engagement more efficient.

Step 2 — Apply for state funding before starting paid work

Several state programs, including Connecticut's CAP grant, require you to apply before beginning the work you want reimbursed. If your state has a dedicated program, apply first. State grants are first-come, first-served and funding rounds close without advance notice.

Step 3 — Structure cost recovery into your contracts

If you hold cost-reimbursable contracts, begin tracking CMMC costs as allowable and allocable as soon as remediation work starts. For future proposals, build CMMC costs into your overhead or G&A rate before submitting bids. Contractors who do not do this absorb costs that the contract should be covering.

Step 4 — Verify tax treatment

Confirm with your tax adviser that CMMC costs are being treated as ordinary business expenses and that any qualifying hardware is captured under Section 179. If the proposed federal tax credit passes before your next filing, the timing of expenditures may matter.

On CUI scoping
The most effective cost reduction strategy is not a grant program. It is CUI scoping. Every system, user, and location removed from your CUI boundary reduces your assessment surface and every cost category that flows from it: fewer controls to implement, smaller SSP scope, shorter C3PAO engagement, lower tool licensing needs. Organizations that isolate CUI to a well-defined enclave before starting remediation consistently spend less than those who let scope grow unchecked. This is worth spending time on before any other cost reduction activity.

Using a compliance platform as a line item

One cost category that is recoverable under FAR Part 31 and eligible for state grant coverage in several programs is compliance software. A platform that produces C3PAO-ready documentation, tracks evidence, manages POA&Ms, and generates your SSP reduces the consultant hours required at every stage of the compliance lifecycle. If you are evaluating platforms as part of your CMMC budget, that cost belongs in the same analysis as your assessment fees and remediation expenses.

1TEN is an air-gapped, on-premises CMMC compliance platform built for small DIB contractors. It covers all 110 NIST SP 800-171 requirements, produces the documentation your C3PAO assessor needs, and runs on hardware inside your facility. If you are working through APEX or an MEP program and need a platform to support your documentation effort, the platform page has a full breakdown of what is included.

Built for the DIB.

1TEN tracks your control posture across all 110 NIST SP 800-171 requirements and generates C3PAO-ready documentation automatically.

Request a Demo