Help Center

Cybersecurity Grants FAQ

Everything you need to know about CGA grant programs, CMMC compliance, eligibility, and how to apply.

Apply for a Grant →

About Cyber Grants Alliance

What is Cyber Grants Alliance?

Cyber Grants Alliance (CGA) is a grant program organization that provides in-kind cybersecurity grants to small and mid-size businesses in the Defense Industrial Base (DIB). CGA was created to help defense contractors and manufacturers navigate and pay for CMMC compliance, penetration testing, employee cyber training, and cybersecurity certifications at no cost to qualifying organizations.

CGA connects eligible businesses with funded cybersecurity services, removing the financial barrier that prevents many small manufacturers from getting compliant before the November 2026 deadline.

Is CGA a government agency?

No. CGA is not a government agency and is not affiliated with the Department of Defense. CGA is a private organization funded through sponsor partnerships with cybersecurity firms, MEP centers, and industry partners who want to support small businesses in the defense supply chain.

How does CGA fund its grant programs?

CGA's grant programs are funded through sponsorships and partnerships with cybersecurity companies, regional Manufacturing Extension Partnership (MEP) centers, C3PAOs, and other organizations that serve the defense industrial base. Sponsors provide the services or funding that CGA then distributes as in-kind grants to qualifying businesses.

You can learn more about CGA's sponsor and partner programs if your organization is interested in supporting the program.

Where is CGA located?

CGA has offices in Atlanta, Georgia (10 Glenlake Pkwy NE, Suite 130) and Ashburn, Virginia (42841 Creek View Plaza, Suite 120). CGA serves defense contractors and manufacturers across the United States. You can reach us at info@cybergrantsalliance.org or +1 (888) 323-9991.

Eligibility

Who qualifies for CGA grants?

CGA grants are designed for small and mid-size businesses (generally under 500 employees) that meet one or more of the following criteria:

  • You hold or expect to hold DoD contracts
  • You are a subcontractor in the defense supply chain
  • You handle or expect to handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI)
  • You are pursuing or need to achieve CMMC certification

See the full eligibility guidelines for each program.

Can I apply if I am a subcontractor, not a prime contractor?

Yes. Subcontractors are among the most common applicants for CGA grants. If your subcontract includes DFARS clause 252.204-7012 or any language referencing CUI or cybersecurity requirements, you almost certainly need CMMC compliance and are eligible for CGA programs. See our CMMC subcontractor guide for more detail.

Can I apply if I do not yet have a DoD contract?

In most cases, yes. If you are actively pursuing DoD contracts or expect to enter the defense supply chain, you may still qualify. CGA reviews each application individually. We recommend applying and explaining your situation: many organizations begin their compliance journey before their first DoD contract is awarded.

Can I apply for more than one CGA grant?

Yes. Many qualifying organizations receive multiple CGA grants across different programs. A common sequence is: start with the CMMC Gap Assessment Grant, then apply for the Pen Testing Grant and Employees Cyber Training Grant as your compliance program progresses. Each grant program has its own eligibility and application process.

The Grant Programs

What grants does CGA currently offer?

CGA currently offers the following grant programs:

Grant availability changes as funding cycles open and close. Apply early: grants are awarded on a first-come, first-served basis.

What is an in-kind grant?

An in-kind grant provides a service rather than a cash payment. CGA funds the cybersecurity service directly and delivers it to your organization at no cost. You receive the completed work (gap assessment report, pen test findings, training program, etc.), not a reimbursement check. There is no federal paperwork, no repayment obligation, and no cost to you.

What does the CMMC Gap Assessment Grant cover?

The CMMC Gap Assessment Grant covers a complete evaluation of your organization against all 110 NIST SP 800-171 security controls. You receive:

  • A System Security Plan (SSP) documenting your current posture
  • A Plan of Action and Milestones (POA&M) identifying your gaps
  • A prioritized remediation roadmap
  • Guidance on next steps toward CMMC Level 2 certification

The grant is valued at $5,000 and is delivered by qualified assessors at no cost to you.

What is the difference between the Level 1 and Level 2 gap assessment grants?

The CMMC Level 2 Gap Assessment Grant ($5,000) evaluates your organization against all 110 NIST SP 800-171 controls required for CMMC Level 2 certification. This is for organizations that handle Controlled Unclassified Information (CUI).

The CMMC Level 1 Gap Assessment Grant ($3,000) evaluates your organization against the 15 basic cybersecurity practices required for CMMC Level 1 compliance under FAR Clause 52.204-21. This is for organizations that handle only Federal Contract Information (FCI) and do not handle CUI. Not sure which applies to you? See our Level 1 vs Level 2 guide.

What does the Pen Testing Grant cover?

The Pen Testing Grant covers a professional penetration test of your systems by a qualified security firm. The grant includes external and internal network testing, a vulnerability assessment, a detailed findings report with severity ratings, and remediation guidance. The test validates that your security controls are actually working, not just documented, and provides independent evidence you can use in your C3PAO assessment.

CMMC Basics

What is CMMC?

CMMC stands for Cybersecurity Maturity Model Certification. It is a framework created by the Department of Defense to verify that companies in the defense supply chain have adequate cybersecurity protections in place. Unlike previous self-reporting frameworks, CMMC requires independent third-party verification for most companies handling sensitive defense information.

What is the difference between CMMC Level 1 and Level 2?

CMMC Level 1 applies to organizations that handle Federal Contract Information (FCI). It requires compliance with 15 basic cybersecurity practices and is satisfied through an annual self-assessment submitted to SPRS.

CMMC Level 2 applies to organizations that handle Controlled Unclassified Information (CUI). It requires compliance with all 110 controls in NIST SP 800-171 and, for most companies, requires a third-party assessment by a certified C3PAO. See our full Level 1 vs Level 2 guide.

What is the November 2026 CMMC deadline?

CMMC Phase 2 takes effect on November 10, 2026. After that date, DoD solicitations may require verified CMMC Level 2 certification as a condition of contract award. Companies without the required certification level may be ineligible to bid on or receive certain DoD contracts. Given that achieving CMMC Level 2 certification typically takes 12 to 18 months, the window to start is now. Read more in our CMMC deadline guide.

What is CUI?

Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but is not classified. In the defense supply chain, CUI commonly includes technical drawings, engineering specifications, test data, contract performance information, and export-controlled data. If your DoD contracts or subcontracts reference CUI, you almost certainly need CMMC Level 2.

How much does CMMC compliance cost?

Total costs vary widely based on how many of the 110 controls you already meet. Typical ranges for CMMC Level 2:

  • Gap assessment: $5,000 to $15,000
  • Remediation: $30,000 to $150,000
  • Documentation and SSP preparation: $5,000 to $20,000
  • C3PAO formal assessment: $20,000 to $50,000

CGA grant programs can cover the gap assessment, pen testing, employee training, and certifications at no cost, significantly reducing your out-of-pocket expenses. See our guide on how to fund CMMC compliance for a full breakdown of available programs.

The Application Process

How do I apply for a CGA grant?

Visit the grant program page for the specific grant you want to apply for, complete the application form, and submit. CGA reviews all applications personally. The process is straightforward: no lengthy federal paperwork, no cost, no obligation.

You can view all available programs and start your application on the Apply for Grants page.

How long does the application review take?

CGA reviews all applications personally and follows up within 5 to 7 business days. If your application is approved, CGA will contact you to coordinate next steps and schedule your grant service delivery.

Are grants awarded on a first-come, first-served basis?

Yes. Grant availability is limited within each funding cycle. Once available grants for a cycle are allocated, the program closes until the next round of funding opens. We recommend applying as early as possible rather than waiting until your compliance deadline is imminent.

What happens after my grant is approved?

After approval, CGA coordinates directly with your organization and the service provider to schedule and deliver the grant service. For gap assessments, this typically involves an intake call to scope your environment, followed by the assessment engagement. For pen tests, the provider will work with your team to define scope and schedule the engagement. Timelines vary by service but most engagements begin within two to four weeks of approval.

I still have questions. How do I contact CGA?

You can book a call directly with our team at cybergrantsalliance.org/rick, email us at info@cybergrantsalliance.org, or call +1 (888) 323-9991. All calls are by scheduled appointment. We review every inquiry personally.

Ready to apply for a cybersecurity grant?

Grants are awarded on a first-come, first-served basis. View all available programs and submit your application today.

Apply for a Grant →