1,000+ Opportunities
Find the right grant
Search federal, foundation, and corporate grants with AI — or browse by agency, topic, and state.
This listing may be outdated. Verify details at the official source before applying.
Find similar grantsCyber Grants Alliance (CMMC Gap Assessment) is sponsored by New Mexico Economic Development Department. This program offers in-kind grants for Cybersecurity Maturity Model Certification (CMMC) gap assessments to New Mexico defense contractors. It's open to U.
S.
Get a weekly digest of new grants like this
A free weekly digest of new foundation and federal funding opportunities as they're added to Granted. Unsubscribe anytime.
Or search similar grants →Extracted from the official opportunity page/RFP to help you evaluate fit faster.
CMMC Level 2 Gap Assessment Grant, Free CMMC Grants... | CGA Sponsored by CMMC Ready Now CMMC Level 2 Gap Assessment Grant Know exactly where your organization stands against all 110 NIST SP 800-171 controls. Our grant funded gap assessment gives you full visibility into your compliance posture so you can make informed decisions about your CMMC journey.
Apply for CMMC Level 2 Gap Assessment Grant NIST SP 800-171 Controls Evaluated Control Families Assessed Grant funded for qualified contractors The CMMC Level 2 Gap Assessment Grant provides a free $5,000 in-kind gap assessment for defense contractors preparing for CMMC Level 2 certification.
Eligible organizations must be active in the Defense Industrial Base (DIB), handle Controlled Unclassified Information (CUI), and have fewer than 500 employees. The assessment identifies compliance gaps against NIST SP 800-171 and produces a prioritized remediation roadmap.
This grant is designed for established organizations that require professional cybersecurity assessments to maintain compliance and protect their business operations. Recipients will receive a $5,000 in-kind comprehensive CMMC Level 2 gap assessment service that includes vulnerability identification, risk assessment, and detailed remediation recommendations.
Disclosure: This grant is funded by CMMC Ready Now through the Cyber Grants Alliance grant program. Grant recipients may be contacted by the sponsoring organization.
Full evaluation of all 110 NIST SP 800-171 controls Technical infrastructure review Policy and procedure assessment Operational practices evaluation Gap identification across all 14 control families Prioritized list of compliance gaps by severity Clear picture of your current compliance posture Detailed written assessment report C3PAO readiness preparation Plan of Action and Milestones (POA&M) These services are available as add-ons through Capital Cyber after your initial gap assessment is complete.
NIST SP 800-171 Controls Evaluated Control Families Assessed Grant funded for qualified contractors This grant is designed for small and medium-sized businesses that need to understand their CMMC compliance posture. Defense Industrial Base (DIB) Contractors Companies in the defense supply chain that handle CUI and must maintain NIST SP 800-171 compliance under DFARS 252. 204-7012.
Small & Mid-Size Businesses Organizations handling Controlled Unclassified Information (CUI) that lack internal compliance resources. Businesses pursuing or renewing federal contracts that require demonstrated cybersecurity compliance. Manufacturing companies in the supply chain that need to protect sensitive technical data and meet DoD requirements.
From application to assessment completion in four simple steps. Complete the grant application form. We review eligibility based on your business size, industry, and compliance needs.
Once approved, you are matched with a certified assessor who will coordinate the assessment timeline with your team. Your organization is evaluated against all 110 NIST SP 800-171 controls covering infrastructure, policies, and practices. Receive your gap identification with prioritized findings.
You will know exactly where you stand and what to focus on next. Apply for CMMC Level 2 Gap Assessment Grant CMMC Level 2 Gap Assessment Grant Application Form Please provide accurate information about your organization. All fields are required.
We’ll review your application within 5-7 business days. CMMC Grants: What Defense Contractors Need to Know in 2026 The Department of Defense's Cybersecurity Maturity Model Certification (CMMC) program remains the most significant compliance mandate to hit the Defense Industrial Base (DIB) in decades. On July 13, 2026, the DoD paused CMMC Phase 2 pending a 60-day policy review.
The C3PAO third-party audit requirement is on hold. DFARS 252. 204-7012 remains in every defense contract covering Controlled Unclassified Information (CUI) , NIST SP 800-171 Rev 2 is still the standard, the SPRS score still gets posted to PIEE, and an executive at your company still personally signs the affirmation of compliance.
The challenge for small and mid-size contractors is cost. A formal CMMC Level 2 assessment conducted by an authorized C3PAO (Certified Third-Party Assessment Organization) typically costs $30,000-$75,000. Remediation of gaps found during that assessment can cost an additional $50,000-$150,000, depending on your current posture.
For most small businesses, that's a prohibitive investment, especially without knowing where the gaps are. That's why the CMMC Level 2 Gap Assessment Grant exists. It removes the first, and most critical, barrier: understanding your current compliance posture against all 110 controls in NIST SP 800-171 Rev 2 .
⏰ CMMC Phase 2 is paused, but DFARS 252. 204-7012, your SPRS score, and the executive affirmation are still in full effect. A gap assessment tells you whether what your company's executive is about to sign is accurate.
Why a Gap Assessment Is the Right First Step for CMMC Grants Many contractors assume they're "close" to CMMC compliance because they've been doing business with the DoD for years. The reality is that most DIB companies score well below the 110-point threshold when objectively assessed against NIST SP 800-171, particularly in areas like Incident Response, Risk Assessment, and System and Communications Protection.
A gap assessment gives you: An objective baseline score across all 14 NIST control families A prioritized list of gaps, so you can focus resources where they matter most The documentation foundation needed to begin your Plan of Action & Milestones (POA&M) A defensible starting point if you're negotiating timelines with contracting officers APEX Accelerators, the SBA-funded network that helps small businesses navigate federal contracting, strongly recommends that all DIB suppliers complete a gap assessment before investing in remediation.
Without one, you risk spending money fixing the wrong things first. How This Grant Fits Into the Broader CMMC Grants Landscape The CMMC Level 2 Gap Assessment Grant is one of several cybersecurity grant programs available through Cyber Grants Alliance.
Each program addresses a different stage of the compliance journey: CMMC Level 2 Gap Assessment Grant $5,000 in-kind, Evaluate all 110 NIST SP 800-171 controls (this page) For contractors pursuing GSA Schedule or MAS contracts Penetration Testing Grant Identify exploitable vulnerabilities before auditors do Cybersecurity Training Grant CMMC-aligned security awareness training for your team State-Level CMMC Grant Programs In addition to CGA's national grant programs, several states offer manufacturing extension and cybersecurity assistance programs for small defense contractors.
The NIST Manufacturing Extension Partnership (MEP) funds state-level assistance centers that provide subsidized CMMC readiness support to small manufacturers in the DIB supply chain. See the full list of state CMMC grant programs to find funding available in your state.
CMMC Level 2: The 110 Controls You Need to Meet CMMC Level 2 is built on NIST Special Publication 800-171 Revision 2 , which defines 110 security requirements across 14 control families.
The CMMC Level 2 Gap Assessment Grant evaluates your organization across all 14 families, including Access Control (22 controls), Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Risk Assessment, System and Communications Protection, and more, giving you a comprehensive picture of your posture and the confidence to stand behind your SPRS score.
Frequently Asked Questions Everything you need to know about the CMMC Level 2 Gap Assessment Grant. What is a CMMC Level 2 Gap Assessment? A CMMC Level 2 Gap Assessment evaluates your organization against all 110 security controls in NIST SP 800-171, which forms the foundation of CMMC Level 2.
It identifies where you meet requirements and where gaps exist so you can plan your path to compliance. This assessment is fully grant funded for qualifying small and medium-sized businesses. There is no cost to you for the gap assessment itself.
Additional services such as remediation planning and C3PAO preparation are available separately. What is the difference between this and a full CMMC assessment? This is a gap assessment, not a formal CMMC certification assessment.
It evaluates your current posture and identifies gaps. A formal CMMC Level 2 assessment must be conducted by an authorized C3PAO. This grant gives you the visibility you need to prepare for that formal assessment.
Why are the detailed report and remediation roadmap not included? The grant covers the assessment and gap identification, which is the critical first step. Detailed reporting, POA&M development, and remediation roadmaps require additional expertise and customization specific to your environment.
These are available as add-on services through Capital Cyber. How long does the assessment take? The assessment typically takes 1 to 2 weeks depending on the size and complexity of your organization.
Your team will need to be available for interviews and to provide access to documentation and systems. Is CMMC Phase 2 still happening after the DoD pause? On July 13, 2026, the Department of Defense paused CMMC Phase 2 pending a 60-day review.
The C3PAO third-party audit requirement is on hold. DFARS 252. 204-7012 remains in every defense contract, NIST SP 800-171 Rev 2 is still the standard, your SPRS score still gets posted to PIEE, and an executive at your company still personally signs the compliance affirmation.
A gap assessment tells you whether what that executive is about to sign is accurate. Ready to Know Where You Stand? Apply for your grant-funded CMMC Level 2 Gap Assessment today.
Limited availability for qualifying small and medium-sized businesses. info@cybergrantsalliance. org Apply for CMMC Level 2 Gap Assessment Grant
According to the current listing, eligibility includes: U. S. defense contractors and manufacturers in the DoD supply chain that hold or are pursuing DoD contracts and have not yet completed a CMMC assessment. Confirm the full requirements in the official notice before applying.
The current listing shows $5,000 in-kind award. Verify award ceilings, matching requirements, and allowable costs in the official notice.
Cyber Grants Alliance (CMMC Gap Assessment) is funded by New Mexico Economic Development Department. Verify program details on the funder's official page before applying.
Start from the official opportunity page linked in this listing — it carries the sponsor's submission instructions.
Business Development & Expansion Grant (Creative Industries Division) is sponsored by New Mexico Economic Development Department. This funding opportunity is designed for organizations with a demonstrated history of impactful work in supporting creative entrepreneurs and advancing creative industry development across New Mexico. This includes organizations that support creative industry companies and workers.
Creative Industries Division Grant Opportunities (Existing Creative Businesses) is sponsored by New Mexico Economic Development Department. This program supports existing creative businesses in New Mexico that have at least three years of operation. The Creative Industries Division offers various grants to support artists, creative businesses, and organizations with funding for growth, infrastructure, and innovation.
Business Development & Expansion Grant (New Mexico) is sponsored by New Mexico Economic Development Department. This program supports existing creative businesses in New Mexico with at least three years of operation. Funds can be used for inventory, equipment, marketing, promotion, digital presence, small infrastructure improvements, and technology/software improvements. Preferential points are given to businesses with fewer than ten employees and those in rural areas.
The Nasdaq Foundation's Economic Opportunity Grant Program awards up to $75,000 to nonprofits building financial literacy, access to capital, and long-term wealth. But the July 31 deadline is only an Expression of Interest — a two-stage gate that most applicants misread. Here is who is eligible, what the funder actually rewards, and how to write an EOI that earns the invitation to a full proposal.
Read articleWhile founders chase fixed grant deadlines, the Economic Development Administration runs two flagship programs on a rolling basis — no application window, applications accepted until the money runs out. Here is how Public Works and Economic Adjustment Assistance work in FY2026, why the CEDS requirement is the real gate, and how communities should sequence an application.
Read articleThe Small Business Innovation and Economic Security Act of 2026 saved the programs after a six-month lapse, but it also added $30M strategic-breakthrough awards, per-company proposal caps, and mandatory national-security screening. Here is what changed across all eleven SBIR agencies — and what it means for your next proposal.
Read article