CMMC Level 1 Gap Assessment Grant
Recipient
The CMMC Level 1 Gap Assessment Grant provides a free assessment for defense contractors verifying compliance with the 17 basic cyber hygiene practices required for CMMC Level 1. This grant is designed for small businesses new to CMMC that need to confirm they meet Foundational requirements before pursuing higher certification levels. Sponsored by CMMC Ready Now, the grant delivers a $3,000 in-kind evaluation covering all 6 Level 1 control families at no cost to the recipient.
This grant is designed for small and medium-sized businesses in the DoD supply chain that handle Federal Contract Information (FCI) and need to understand their CMMC Level 1 compliance posture. Recipients receive a $3,000 in-kind Level 1 gap assessment that evaluates all 17 practices required under FAR 52.204-21, covering the 6 Level 1 control families.
Disclosure: This grant is funded by CMMC Ready Now through the Cyber Grants Alliance grant program. Grant recipients may be contacted by the sponsoring organization.
What the grant covers
A focused readiness check for small DoD suppliers whose obligation tops out at Level 1. We show you where you stand so you can complete the annual self assessment and affirmation with confidence.
Included
- Full evaluation of all 17 CMMC Level 1 practices
- Technical infrastructure review of how you handle FCI
- Policy and procedure assessment
- Operational practices evaluation
- Gap identification across all 6 Level 1 control families
- Prioritized list of compliance gaps by severity
- A clear picture of your self assessment readiness
Not included
- Detailed written assessment report
- Remediation roadmap
- Plan of Action and Milestones (POA&M)
- SPRS submission and affirmation support
Who Is This For?
CMMC Level 1 is the floor for doing business with the Department of Defense. If you handle Federal Contract Information but not Controlled Unclassified Information, this is your tier.
Defense Industrial Base (DIB) Contractors
Companies in the defense supply chain that handle FCI and need to meet the Level 1 baseline under FAR 52.204-21.
Small and Mid-Size Manufacturers
Manufacturers and subcontractors supplying DoD work who do not handle CUI and need to confirm their Level 1 compliance posture.
Government Contractors
Businesses pursuing or renewing federal contracts that require demonstrated cybersecurity compliance at the Level 1 baseline.
Suppliers and Subcontractors
Any supplier providing services or products into the DoD supply chain beyond purely commercial off the shelf items.
How It Works
From application to assessment completion in four simple steps.
Apply Online
Complete the grant application form. We review eligibility based on your business size, industry, and compliance needs.
Grant Approval
Once approved, you are matched with a certified assessor who will coordinate the assessment timeline with your team.
Level 1 Assessment
Your environment is evaluated against all 17 CMMC Level 1 practices covering infrastructure, policies, and procedures.
Results and Next Steps
Receive your gap identification with prioritized findings. You will know exactly where you stand and what to focus on next.
Apply for CMMC Level 1 Gap Assessment Grant
Please provide accurate information about your organization. All fields are required. We will review your application within 5 to 7 business days.
CMMC Level 1: What Defense Contractors Need to Know
CMMC Level 1 is the entry-level cybersecurity baseline for every company in the Department of Defense supply chain that handles Federal Contract Information (FCI). Defined by FAR 52.204-21, Level 1 requires annual self assessment and affirmation against 17 cybersecurity practices spread across 6 control families. If your company holds a DoD contract and generates or processes FCI, Level 1 compliance is mandatory.
The challenge is knowing whether you actually meet all 17 practices. Many small contractors assume they do, but have never been objectively evaluated. Missing even one practice puts your self-affirmation and contract eligibility at risk. The CMMC Level 1 Gap Assessment Grant removes that uncertainty by funding a professional evaluation at no cost to your organization.
⏰ CMMC requirements are already appearing in DoD contracts. If you have not completed a Level 1 gap assessment, you may be self-affirming compliance you cannot actually demonstrate.
Why a Level 1 Gap Assessment Matters
CMMC Level 1 self assessment requires you to evaluate your organization against all 17 practices and submit an affirmation through the Supplier Performance Risk System (SPRS). A false affirmation carries legal risk under the False Claims Act. Before you self-affirm, you need to know where you actually stand.
A professional Level 1 gap assessment gives you:
- An objective evaluation of all 17 Level 1 practices against your actual environment
- A clear list of which practices you meet and which ones you do not
- The information needed to correct gaps before submitting your annual self assessment
- A defensible record that you took compliance seriously
The NIST Manufacturing Extension Partnership (MEP) recommends that all small DIB suppliers receive professional guidance before completing their first CMMC self assessment. Without an independent review, you risk affirming gaps you did not know existed.
How CMMC Level 1 Fits Into the Broader Grant Landscape
The CMMC Level 1 Gap Assessment Grant is part of a broader suite of cybersecurity grant programs offered by Cyber Grants Alliance. Each program targets a different stage of the compliance journey:
State-Level CMMC Grant Programs
In addition to CGA's national grant programs, several states offer manufacturing extension and cybersecurity assistance programs for small defense contractors. The NIST MEP funds state-level assistance centers that provide subsidized CMMC readiness support to small manufacturers. See the full list of state CMMC grant programs to find funding available in your state.
CMMC Level 1: The 17 Practices Across 6 Control Families
CMMC Level 1 evaluates 17 practices drawn from FAR 52.204-21 across 6 control families: Access Control, Identification and Authentication, Media Protection, Physical Protection, System and Communications Protection, and System and Information Integrity. The Level 1 Gap Assessment Grant evaluates your organization across all 17 practices and all 6 families, giving you a complete picture of your Level 1 posture before your annual self assessment and affirmation.
Ready to start? Apply for the CMMC Level 1 Gap Assessment Grant above or explore the Level 2 Gap Assessment Grant if your contracts involve Controlled Unclassified Information.
Frequently Asked Questions
Common questions about the CMMC Level 1 Gap Assessment Grant.
What is a CMMC Level 1 Gap Assessment?
It is a structured review of your environment against the 17 practices that make up CMMC Level 1. It shows you which practices you already meet and which ones you do not, so you can prepare for your annual self assessment and affirmation with confidence.
Who needs CMMC Level 1?
Almost every company in the DoD supply chain. If you generate or handle Federal Contract Information under a government contract and you are not selling purely commercial off the shelf products, you must meet at least Level 1.
What is the difference between Level 1 and Level 2?
Level 1 protects Federal Contract Information with 17 practices and an annual self assessment. Level 2 protects Controlled Unclassified Information with 110 NIST SP 800-171 controls. If you do not handle CUI, Level 1 is your requirement. If you do handle CUI, see the CMMC Gap Assessment Grant.
How much does this grant cost?
This assessment is fully grant funded for qualifying small and medium-sized businesses. There is no cost to you for the gap assessment itself. The grant covers a $3,000 in-kind assessment service. Additional services such as the detailed written report and remediation roadmap are available separately.
Why are the detailed report and remediation roadmap not included?
This grant funds the assessment itself so you can see your gaps clearly. The written report, remediation roadmap, and hands-on support are available as paid services if you want help closing the gaps identified.
How long does the Level 1 assessment take?
Most Level 1 assessments are completed quickly because the scope is focused on 17 practices. Your assessor will confirm timing after approval, typically within one to two weeks depending on your organization's size and availability.
Ready to Know Where You Stand?
Apply for your grant-funded CMMC Level 1 Gap Assessment today. Limited availability for qualifying small and medium-sized businesses.