1,000+ Opportunities
Find the right grant
Search federal, foundation, and corporate grants with AI — or browse by agency, topic, and state.
This listing may be outdated. Verify details at the official source before applying.
Find similar grantsCMMC Grant Program (Proposed) is sponsored by U.S. Department of Defense (via Senate Armed Services Committee). This opportunity supports mission-aligned projects and measurable outcomes.
Get a weekly digest of new grants like this
A free weekly digest of new foundation and federal funding opportunities as they're added to Granted. Unsubscribe anytime.
Or search similar grants →Extracted from the official opportunity page/RFP to help you evaluate fit faster.
Senate NDAA proposes CMMC grant program | Federal News Network . async-hide { opacity: 0 ! important} Senate NDAA proposes CMMC grant program The Senate Armed Services Committee's bill also includes provisions on insider threat reporting for AI companies and new post-quantum cryptography deadlines.
Justin Doubleday @jdoubledayWFED The Senate Armed Services Committee has advanced legislation that would set up a grant program for small businesses and nontraditional contractors to cover the costs of Cybersecurity Maturity Model Certification (CMMC) compliance. The CMMC grant program is included in the full text of the committee’s fiscal 2027 defense authorization bill, released Tuesday.
The committee released the text Tuesday after approving the bill in a June 10 closed-door mark up. If passed into law, the provision would require the Defense Department to establish the CMMC grant program by July 1, 2027. DoD is ramping up CMMC “Level Two” requirements starting this November.
Those requirements are expected to apply to tens of thousands of companies. They generally require contractors that are expected to handle sensitive controlled unclassified information (CUI) to have their data security practices evaluated by a CMMC Third-party Assessment Organization (C3PAO). Which issues are dominating federal CFO priorities right now?
Join us Aug. 25-26 for the Federal Leader’s Guide to the CFO event to find out! The grant program in the Senate defense bill would be available to small businesses and new entrants to offset the costs of a C3PAO assessment.
The maximum amount per grant would be $100,000. The bill would cap the total funding allotted for the CMMC grant program at $50 million. It would also require the program to prioritize organizations that have not previously held a DoD contract or subcontract.
The bill would also require that the grant only be used to offset direct costs associated with a CMMC Level Two third-party assessment. The Senate bill’s language seeks to address persistent concerns around whether CMMC compliance could force small businesses to leave the defense industrial base or dissuade new companies from seeking defense contracts.
In the final CMMC program rule issued in 2024, DoD estimated that the Level Two certification costs for a small business would be a little more than $101,000. Those cost estimates don’t include the cost of building a cybersecurity program, as the Pentagon notes CMMC merely evaluates cyber requirements that have been on the books since 2016.
Instead, the estimates reflect the expected costs of preparing for a CMMC assessment – such as working with an external service provider – and then conducting the assessment, including paying a C3PAO.
While Pentagon officials have said the cybersecurity evaluations are necessary to ensure defense contractors can protect sensitive data, DoD has also sought to address some of the concerns raised by small business advocates about the burdens of the cyber compliance regime. Last year, DoD’s Office of Small Business Programs conducted a pulse survey to gauge CMMC readiness, concerns and challenges.
The Army has also launched a cloud-based, secure environment that small businesses can use to store data and meet the cyber requirements evaluated by CMMC. Earlier this year, the Army awarded contracts to eight companies worth a collective $49 million to provide services under the Next-Generation Commercial Operations in Defended Enclaves, or NCODE, program.
Insider threat reporting for AI companies The Senate bill would also establish insider threat reporting requirements for major artificial intelligence companies that do business with the Pentagon. The insider threat reporting rules would be aimed at protecting DoD “systems, missions, personnel, operations, and supply chains from counterintelligence, security, and other national security risks.
” The provision comes as the Pentagon works with major AI model manufacturers to integrate the technology across its operations. At the same time, the Trump administration recently prohibited any foreign access to Anthropic’s latest frontier model over national security concerns. The decision forced Anthropic to block all access to the tool.
The Senate bill’s provision would bring major AI companies into the same fold as classified defense contractors, which are required to maintain insider threat programs and provide training to their employees. The Senate bill also establishes deadlines for when DoD should adopt post-quantum cryptography algorithms approved by the National Institute of Standards and Technology. The bill would set a deadline of Dec.
31, 2030, for key establishment, which is used for establishing confidential communication using encryption among two or more parties, according to the Cybersecurity and Infrastructure Security Agency. The deadline for adopting PQC for digital signatures would be one year later under the Senate bill, on Dec. 31, 2031.
CISA says digital signatures are “often essential for authenticating the parties participating in a communication and for establishing the authenticity of data, products, and services. ” The deadlines would not apply to cryptographic keys generated and distributed by the National Security Agency for protecting classified and sensitive national security information.
Justin Doubleday covers cybersecurity, homeland security and the intelligence community for Federal News Network.
TSA to replace ‘Gold+’ in privatization push Workforce Rights/Governance GSA, Treasury kick off post-quantum initiatives to protect against cyber threats Cybersecurity Maturity Model Certification post quantum cryptography Federal Executive Forum 5G Strategies in Government Progress and Best Practices 2026 Federal Leader’s Guide to the CFO Federal News Network’s Workforce Reimagined 2026 Securing the states, a CISO series: North Carolina edition How To Maximize Your Federal Pension and TSP GSA, Treasury kick off post-quantum initiatives to protect against cyber threats Losses keep piling up for Trump administration over handling of RTO mandate Workforce Rights/Governance More troops reported sexual assaults last year as incidents fell Golden Dome cost estimate draws Pentagon pushback SBA wants to give 114,000 more companies access to small business contracts CMMC review: DoD’s inconsistent CUI marking continues to plague program The latest in Government Events powered by: Aberdeen AI/ML Technology Exchange &...
2026 ChannelPro DEFEND: Alexandria Software-Defined Radio Fundamentals Workshop...
According to the current listing, eligibility includes: Small businesses and non-traditional contractors seeking CMMC Level 2 certification, with priority for those not previously holding a DoD contract or subcontract. Confirm the full requirements in the official notice before applying.
The current listing shows up to $100,000 (with total program funding capped at $50 million). Verify award ceilings, matching requirements, and allowable costs in the official notice.
CMMC Grant Program (Proposed) is funded by U.S. Department of Defense (via Senate Armed Services Committee). Verify program details on the funder's official page before applying.
Start from the official opportunity page linked in this listing — it carries the sponsor's submission instructions.
Past winners and funding trends for this program
The memorandum of agreement was signed August 4 and 5, disclosed by House appropriators on September 3, and runs through 2036. It names no dollar figure. Here is what is actually established, what is still speculation, and what researchers holding or planning NIAID biodefense awards should do before September 30.
Read articleCDMRP reissued the FY26 BCRP Breakthrough Award Levels 1 and 2 and the Clinical Research Extension Award on September 3, 2026, with a November 4 pre-application deadline and a November 18 full application deadline. Round one closed July 8. The arithmetic across both windows accounts for nearly the entire FY26 appropriation — which tells you what kind of second chance this is.
Read articleThe Department's FY26 SBIR/STTR Release 3 opened June 24 with roughly 37 topics across DARPA, the Navy, the Air Force, and the defense components, all closing July 22. The compressed four-week window is unforgiving, but the bigger mistake founders make is treating every component the same. Here is how to read the release, the eligibility rules that disqualify good companies, and why the component you target matters more than the topic you pick.
Read article