CybertronIT is a CMMC Registered Provider Organization (RPO). We help suppliers get ready. We are not a C3PAO and do not issue certifications.
If you typed "CMMC grants" into a search bar this month, you're in good company. It's one of the most common questions we hear in exploratory calls with Wichita-area suppliers, and the honest answer is short. There is no federal grant program that pays for CMMC compliance today. There's no CMMC loan program and no CMMC tax credit either. Several have been proposed. None has passed.
That's the bad news, and it's worth sitting with for a second before moving on, because the search for money usually hides a better question. The suppliers we see spending the most in prospect assessments aren't the ones who couldn't find a grant. They're the ones who bought tools and enclaves before they knew where their CUI actually lived. Scope sets the bill, and financing only decides who carries it.
Here's the straight read on both.
The closest thing to a real CMMC grant is a provision in the Senate's FY2027 defense authorization bill. Section 1626 would direct DoD to stand up a Level 2 assessment grant program for small businesses and new entrants, capped at $100,000 per award and $50 million in total, with a July 1, 2027 deadline to establish it. As of late September 2026 the Senate bill is stalled after a failed procedural vote, and even if it passes conference it still has to be funded through appropriations. Watch it. Don't budget against it.
A 30 percent tax credit for cybersecurity spending at companies under 50 employees has been floated in Congress and has drawn public support from DoD leadership. It hasn't been enacted. Same advice.
What does exist is less exciting but real. APEX Accelerators (the old PTACs) are DoD-funded and free. Kansas has one, and its counselors will walk a supplier through Level 1 and the front end of Level 2 at no charge. The NIST Manufacturing Extension Partnership network cost-shares readiness projects for small manufacturers, and Kansas Manufacturing Solutions is the Kansas center. Project Spectrum, a DoD-funded program, offers no-cost assessments and training. A few nonprofits run in-kind gap assessment grants for defense suppliers, typically a few thousand dollars of assessment work rather than cash. Your prime may also have supplier development resources it hasn't advertised. Ask.
On the tax side, compliance spending is generally deductible as an ordinary business expense, and hardware may qualify for accelerated depreciation under Section 179. Confirm both with your CPA. None of that is a program, just how the code already works, but it does change the after-tax number.
Loans are the same story. Nothing CMMC-specific. Standard SBA 7(a) and 504 financing covers equipment and working capital for a compliance project the same way it covers a new CNC machine.
On July 13, 2026, the Department of War suspended the transition to CMMC Phase 2, which would have started putting third-party Level 2 assessment requirements into contracts on November 10, 2026. A September 3 class deviation made the suspension binding on contracting officers. The stated reason was cost and assessor capacity. In its own filings the SBA Office of Advocacy put third-party certification near $593,800 and a self-assessment near $388,600, against roughly 100 approved assessors for more than 120,000 small DIB businesses (Secureframe CMMC news tracker, September 2026).
Two things follow from that. First, the money question is being taken seriously in Washington precisely because the numbers are that large, which is why the grant bills exist. Second, nothing underneath Phase 2 moved. DFARS 252.204-7012, NIST SP 800-171, your SPRS score, the Level 1 and Level 2 self-assessments, and the annual affirmation your company signs are all still in force. An inaccurate affirmation still carries False Claims Act exposure, and on September 1 the Justice Department announced a $2 million settlement with a large aerospace contractor over alleged 800-171 shortfalls from 2020 to 2023, before any CMMC assessment requirement existed in contracts (Secureframe, September 2026).
So the pause buys time. It doesn't buy relief. Use the time to scope correctly instead of sprinting toward a date that no longer exists.

Across the prospect assessments we run for suppliers, the cost problem almost never traces back to a missing grant. It traces back to three scoping decisions that got made by default.
The first is level. A surprising share of suppliers assume they need Level 2 because a prime mentioned CMMC, when the data they actually receive is Federal Contract Information and Level 1 is the requirement. Level 1 is 15 practices and a self-assessment, while Level 2 runs to 110 controls. Confirm what you handle before you buy anything, and get it in writing from the prime if the contract language is vague.
The second is boundary. If CUI touches every workstation, every file share and every email account in the building, all of it is in scope and all of it has to meet 110 controls. If CUI lives in a segmented enclave that a handful of people access, the assessment boundary shrinks to that enclave, and so does the bill. This one decision moves the number more than any funding program that's ever been proposed. We find, more often than we'd like to, that a supplier has already paid to bring the whole network up to Level 2 when a third of it never needed to be there.
The third is stack. Buying a separate product for every control family produces a pile of overlapping licenses and a documentation burden that outlives the project. Two or three platforms covering most of the families, run by the same team that operates the environment day to day, is cheaper to build and far cheaper to keep true. The System Security Plan has to describe the systems as they actually run. When one company writes the SSP and another company runs the network, the two drift apart within weeks, and the drift is what an assessor finds.
We build PCs and servers on our own line and have lived inside the DFARS flowdown as a manufacturer, which is part of why we push the boundary conversation before the product conversation. Segmentation and hardware placement are cheaper to get right on paper than to re-do after the enclave is built.
Confirm your level with your prime, in writing. Map where CUI enters, moves and sits, and draw the smallest boundary that contains it. Call the Kansas APEX Accelerator and Kansas Manufacturing Solutions before you pay a consultant for anything you can get free. Keep your SPRS score honest and your affirmation current, because the government stopped checking the homework but you're still signing it.
Then, before you spend on tools or a full 110-control build, get someone who knows the framework to look at the scope. That's the conversation we'd rather have first. Our CMMC readiness work is bundled with Managed IT because the documentation and the live systems have to be operated by the same team, and the first call is about whether your scope, your contract and your timing make that worth doing at all. If they don't, we'll say so.
Book a 30-minute exploratory call. Bring your contract clauses and a rough idea of where CUI lands. We'll tell you what's in scope and what isn't before anyone talks about buying anything.
Not today. The Senate FY2027 NDAA includes a proposed $50 million Level 2 assessment grant program for small businesses, capped at $100,000 per award, but the bill is stalled and the program would not exist before July 2027 even if enacted.
Compliance spending is generally deductible as an ordinary business expense, and qualifying hardware may be eligible for Section 179 accelerated depreciation. Confirm treatment with your CPA. No CMMC-specific tax credit has been enacted.
No. The pause suspended third-party Level 2 assessment requirements. DFARS 252.204-7012, NIST SP 800-171, SPRS scoring and the annual self-assessment affirmation all remain in force, and an inaccurate affirmation carries False Claims Act exposure.
The Kansas APEX Accelerator offers free one-on-one counseling for DoD contractors. Kansas Manufacturing Solutions, the state's NIST MEP center, cost-shares readiness projects. Project Spectrum offers no-cost assessments and training online.
Confirming the correct level, shrinking the CUI boundary to a segmented enclave, and consolidating the tool stack. These scoping decisions typically move the total more than any grant or credit currently proposed.
Comments