Frequently Asked Questions
Everything you need to know about the grant.
What is a CMMC Gap Assessment?
A CMMC Gap Assessment evaluates your organization against all 110 security controls in NIST SP 800-171, which forms the foundation of CMMC Level 2. It identifies where you meet requirements and where gaps exist so you can plan your path to compliance.
How much does this cost?
This assessment is fully grant funded for qualifying small and medium-sized businesses. There is no cost to you for the gap assessment itself. Additional services such as remediation planning and C3PAO preparation are available separately.
What is the difference between this and a full CMMC assessment?
This is a gap assessment, not a formal CMMC certification assessment. It evaluates your current posture and identifies gaps. A formal CMMC Level 2 assessment must be conducted by an authorized C3PAO. This grant gives you the visibility you need to prepare for that formal assessment.
Why are the detailed report and remediation roadmap not included?
The grant covers the assessment and gap identification, which is the critical first step. Detailed reporting, POA&M development, and remediation roadmaps require additional expertise and customization specific to your environment. These are available as add-on services through Capital Cyber.
How long does the assessment take?
The assessment typically takes 1 to 2 weeks depending on the size and complexity of your organization. Your team will need to be available for interviews and to provide access to documentation and systems.
What is the CMMC Level 2 deadline?
CMMC Phase 2, which requires Level 2 certification for contracts involving CUI, is expected to take effect November 10, 2026. Starting your gap assessment now gives you the time needed to identify and close gaps before the deadline.