Skip to content

CMMC Compliance Costs: What FAR Part 31 Lets You Recover

The July 2026 CMMC memo did not remove the requirement in your subcontract.

It changed the government's own contracts and solicitations. Your CMMC requirement came from your prime, and it sits in a contract the memo never touches 32 CFR 170.23(a).

Amerifusion Bookkeeping built this article around one question. What you recover from a CMMC dollar depends on how you recorded it, not on what the certification schedule does next.

Key Takeaways

  • If your CMMC rule flows down through a prime, the July 2026 memo does not remove it. 32 CFR 170.23(a) still requires the flowdown.
  • CMMC costs pass the FAR 31.201-2 five-part test when you document them right. A retainer needs four things, not the one item this article used to name FAR 31.205-33(e).
  • An unallowable CMMC cost does not vanish from your claim on its own. You identify it, set it apart, and keep it out of every bill or claim FAR 31.201-6; CAS 9904.405.
  • DOJ settled a $4.6 million cybersecurity fraud case in FY2025. The company knew its score was wrong and never fixed it. Bad records, not the bad score, closed the case.

Why the July 2026 Memo Didn't Reach Your Subcontract

CMMC rules flow down the supply chain by regulation, not by choice. A prime's suspension relief does not pass down on its own to a sub holding the same rule under a signed subcontract.

The rule is direct. 32 CFR 170.23(a) states it in full:

"Prime contractors shall comply and shall require subcontractors to comply with and to flow down CMMC requirements, such that compliance will be required throughout the supply chain at all tiers."

That flowdown duty sits with the prime, not with the Department. DFARS 252.204-7021(f) tells a prime to write the CMMC clause into its subcontracts. It also tells the prime to confirm, before award, the subcontractor holds a current CMMC status DFARS 252.204-7021(f).

CIO memorandum 26-P-1023, issued July 13, 2026, suspends Phase 2 of CMMC. It targets a narrower group than the headline suggests. Every order in it names "Program Managers and requiring activities" or "contracting officers and agreements officers." It tells those government actors to amend active solicitations. It tells them to remove Level 2 (C3PAO) and Level 3 (DIBCAC) rules from existing contracts by modification.

That is contract surgery on government paperwork. It says nothing about a flowdown clause a prime already wrote into an awarded subcontract. Nothing in the memo tells a prime to strip that clause out.

The suspension does not stop everything, either. The memo's own opening line says the Department will still enforce baseline compliance with NIST SP 800-171 Rev 2. It does this "through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments." Those last four words carry the distinction.

The memo bars program managers from designating a Level 2 (C3PAO) or Level 3 (DIBCAC) assessment as a condition of award. It does not stop the Department from assessing you. Enforcement continues through a different door. DFARS 252.204-7012, the clause requiring safeguards for covered defense information, stays in force. Program Managers and requiring activities "may require additional cybersecurity protections as commensurate with law and regulation." The suspension redirects the certification path. It does not stop every cost tied to it.

When the duty to flow down ends, your clause does not vanish with it

There is a real question underneath this one. If the government removes the CMMC requirement from your prime's contract, the rule that told the prime to flow it down to you stops applying. Your own obligation, though, does not end with it.

The reason is worth understanding, because it decides what your books have to carry.

Two different documents are doing two different jobs. 32 CFR 170.23(a) tells the prime what it must put into your subcontract. Your subcontract is what actually binds you. When the regulation stops requiring the prime to impose the clause, that ends the prime's duty to impose it. It does not reach into a subcontract already signed and delete a clause sitting there. A regulation changing does not rewrite a contract between two private parties.

So the clause stays until someone removes it. The event that changes your position is a modification from your prime to your subcontract. Not the memo, not the CFR, not your prime's own contract being modified. Until that modification arrives, the requirement in your subcontract is still the requirement you are working to.

What that means for your accounting is specific. Keep the CMMC cost coded and supported exactly as before. If and when your prime issues that modification, date it and keep it, because it is the document that marks the change. Your cost treatment before that date and after it differs, and the modification is your evidence for where the line falls.

Whether your prime is required to remove the flowdown, is permitted to, or intends to is a contract question between you and the prime. Take it to the prime and to counsel. Ask in writing, and keep the answer.

Your accounting does not need to wait on that answer. Keep a cost pool and file ready for both outcomes: the flowdown survives, or it gets dropped later. Either way, the spending still needs a cost pool, a written reason for that pool, and support behind it.

The Cost You Already Committed

A contractor who signed a C3PAO engagement letter before July 13, 2026 has a real cost on the books already. That cost does not vanish because the rule above it changed.

A Level 2 C3PAO assessment runs about $31,000 to $75,000 for the third-party event itself. That range is an industry planning estimate, not a DoD figure. Get a quote from an accredited C3PAO before you budget against it. That cost usually sits under professional and consultant services FAR 31.205-33. It flows to G&A or overhead, depending on scope of benefit.

Your books need three things, no matter what happens next. First, the engagement letter or statement of work naming what the C3PAO was hired to do. Second, the invoice tying the fee to that scope. Third, a record of when you incurred the cost, tied to the requirement live at that time. An auditor will ask whether the cost was reasonable and allocable when you spent it. Today's requirement status does not change that test.

Whether a committed cost stays recoverable once its requirement gets modified out is an entitlement question. Entitlement is a contract-law call, not an accounting one. Route it to your contracting officer (the CO) and your counsel. Do not treat a modification as automatic forgiveness, or automatic loss, until one of them tells you which.

One classification point helps either way. DoD's own Regulatory Impact Analysis for CMMC, the RIA, draws a clear line. It separates what is new with the CMMC Program from what came before it. On DFARS 252.204-7012, the clause behind the actual security controls, the RIA says a "certification requirement to assess a contractor or subcontractor's compliance of those required information security controls is new with the CMMC Program." The security-control duty itself, the RIA adds, "predate[s] CMMC by many years."

This is about money already on your books. Split it. Keep the C3PAO assessment and affirmation fees in one account, and your remediation spending in another. The assessment is the new, CMMC-specific cost. Remediation, in DoD's own words, is closer to a duty you already carried under DFARS 252.204-7012.

There is no forward assessment cost to budget yet. Until the review closes and DoD says what the program requires next, the only CMMC assessment spending to classify is what you have already committed. Split it now, while you still remember what each invoice bought. That gives you a cleaner file whichever way the entitlement question resolves.

Is a CMMC Cost Allowable? The Five-Part Test

A CMMC cost clears FAR 31.201-2 when it passes all five parts, not only the first one most guides quote.

Part What it asks
(1) Reasonable.
(2) Allocable to the contract.
(3) Matches CAS, if CAS applies, or GAAP if it does not.
(4) Fits your contract terms.
(5) Clears any limits set in FAR Subpart 31.2.

Part five is not a ban list. The rule says "any limitations set forth in this subpart," and a limit reaches further than a flat ban. No express ban on cybersecurity spending is not, by itself, enough. Each cost still has to clear all five parts on its own.

Two more paragraphs of FAR 31.201-2 get cited far less than they should, and they carry real weight. Paragraph (c) deals with accounting practices that do not follow Subpart 31.2. If your practice is inconsistent with the subpart, the rule makes unallowable the amount your claim exceeds what a consistent practice would have produced. The excess is what you lose, not the whole cost.

Paragraph (d) puts documentation on you directly. You are "responsible for accounting for costs appropriately and for maintaining records, including supporting documentation, adequate to demonstrate that costs claimed have been incurred, are allocable to the contract, and comply with applicable cost principles." The CO "may disallow all or part of a claimed cost that is inadequately supported" FAR 31.201-2(c), (d). A missing record does more than raise a "question." It gives the CO the power to disallow.

A retainer with an MSSP or vCISO gets its own test under FAR 31.205-33(e). It has four parts:

  • The services under the retainer are necessary and standard for the field.
  • Past service levels justify the retainer amount.
  • The fee compares fairly to running that same work in-house.
  • The actual work performed is on record under paragraph (f).

Part 2 has a carve-out worth knowing before you assume the worst. "If no services were rendered, fees are not automatically unallowable" FAR 31.205-33(e)(2). A quiet month on a retainer does not, by itself, kill the fee.

FAR 31.205-33 does not require a signed statement of work for every consultant or retainer arrangement. The rule says the reverse: "Retainer agreements generally are not based on specific statements of work" FAR 31.205-33(f). What it asks for instead is the terms of the agreement, invoices with real detail on time and services, and the consultant's own work product, meaning reports, meeting notes and memos FAR 31.205-33(f)(1)-(3). Build your retainer file around those three. Do not chase a statement of work your provider is unlikely to write.

Which Cost Pool: G&A, Overhead, or Direct

Most CMMC costs sit in G&A. Most of them protect the whole firm, not one contract or one team. The test is scope of benefit. FAR 31.203(c) says it plainly: group indirect costs by logic, and split them by the benefit each cost objective gets.

An enterprise SIEM tool or a company-wide security training program benefits every contract, so it points to G&A. A tool used by one team or one enclave points to overhead. A cost serving only one contract, and documented that way, goes direct to that contract FAR 31.202(a).

If you run a CAS-exempt small firm, a common mix-up trips people here. CAS-exempt does not mean consistency-exempt. The CAS exemption drops the CAS 9904.402 rule. FAR 31.203's grouping and consistency rules still apply. Most Amerifusion Bookkeeping clients at 60 people or fewer are CAS-exempt. That means the CAS 402 and CAS 418 material other CMMC guides lean on never reaches them. FAR 31.203 does, whether or not CAS does.

If you hold a full accounting system adequacy finding under DFARS 252.242-7006, that clause adds its own consistency rule on top, apart from CAS. Use "or," not "and," for these two rules. FAR 31.203 covers consistency for every contractor, CAS-covered or not. DFARS 252.242-7006 layers on top only when your contract carries that clause. A fixed-price small firm with no full CAS coverage and no 252.242-7006 finding gets neither extra layer. FAR 31.203 still applies.

Two more fixes worth making now, before they cost you a questioned cost:

Drop the rental cost rule for SaaS and cloud subscriptions. FAR 31.205-36 covers the cost of "renting or leasing real or personal property" under an operating lease. A GCC High subscription or a managed SIEM plan is a service, not a leased asset. It does not fit under 31.205-36. Treat it as a professional or IT service cost instead.

If a CMMC change touches your shop floor or manufacturing setup, check FAR 31.205-25 before you default to one treatment. Manufacturing and production engineering costs sit there. But development work meant for a product or service you plan to sell routes to 31.205-18, independent research and development costs, instead FAR 31.205-25(b)(2). The two rules carry different allowability tests. Pick the one that matches the actual work.

Can You Actually Bill It? Recovery by Contract Type

Allowable and recoverable are different words. A cost can clear all five parts of FAR 31.201-2 and still never reach the government, because your contract has no mechanism to carry it. Contract type decides whether the mechanism exists.

Your contract How a CMMC cost reaches the government What you do
Cost-reimbursable (CPFF, CPAF) Through your indirect rate. Billed at the provisional rate, settled at the final audited rate. Keep the pool clean and the records behind it. The mechanism is automatic.
Time-and-materials Through the indirect rate loaded into your labor rates. Same as above, and watch the provisional rate.
Firm-fixed-price, already awarded It does not. The price is the price. Absorb it, or negotiate. See below.
Firm-fixed-price, not yet bid In the price you propose. Price it in. This is the only clean path.

Most small subcontracts are firm-fixed-price, so for a large share of readers the honest answer is the third row. Your CMMC spending raises your indirect rates, those rates hit a price that is already fixed, and the difference comes out of your margin. No amount of correct cost accounting changes that.

Three things are still worth doing on a fixed-price contract:

  • Price it into everything you have not yet bid. Your competitors face the same cost. The field is level and the cost is real.
  • Keep the records anyway. If a requirement was added to your contract by modification after award, whether that supports an adjustment is a contract-entitlement question for your contracting officer and counsel. Your file is what that conversation runs on, and it has to exist before the conversation starts.
  • Know what the under-recovery actually costs you Put a number on it before you decide how hard to push. Model it on your own base rather than arguing from a feeling.

Accounting for Unallowable CMMC Costs

Naming an unallowable cost is not the same as accounting for it. FAR 31.201-6(a) sets the real rule. An expressly unallowable cost, plus any cost it directly causes, "shall be identified and excluded from any billing, claim, or proposal applicable to a Government contract." CAS 9904.405 spells out how you present that cost, and it reaches you even with no CAS coverage at all.

That surprises people, so here is the mechanism in the FAR's own words. FAR 31.201-2(b) says that business units "not otherwise subject to these standards under a CAS clause are subject to the selected standards only for the purpose of determining allowability of costs on Government contracts." FAR 31.201-6(c)(1) is the cost principle that selects CAS 405.

So the exemption that drops CAS 402 does not drop CAS 405. CAS 405 arrives through the FAR, not through your CAS status.

Three steps, and the second and third pull in opposite directions. That is deliberate, and getting it backwards inflates your rate on every contract you hold.

  • Identify the unallowable cost.
  • Exclude it from what you bill, claim, or propose FAR 31.201-6(a); CAS 9904.405-40(a). It comes out of the claim.
  • Leave it in the allocation base. CAS 9904.405-40(e): where unallowable costs "normally would be part of a regular indirect-cost allocation base or bases, they shall remain in such base or bases."

The pool and the base are not the same thing, and the rule treats them differently. Pull an unallowable cost out of the base to "clean up" your numbers and you shrink the denominator. That raises the rate you allocate to every contract, inside a proposal you certified.

One more wrinkle in the same paragraph. A directly associated cost that normally sits in an indirect-cost pool "shall be retained in the indirect-cost pool and be allocated through the regular allocation process" CAS 9904.405-40(e). It stays in the pool. It is still excluded from the claim under step 2. Identify and exclude are not the same operation as remove and re-allocate.

Two cost types need a sharper rule than "cannot be charged, ever." A False Claims Act settlement falls under FAR 31.205-47, not FAR 31.205-15. The settlement payment becomes unallowable once there is a finding of fraud-related liability, or once a fine is set FAR 31.205-47(b)(2).

Do not read that as an escape hatch for settling. FAR 31.205-47(b)(4) reaches a "disposition of the matter by consent or compromise if the proceeding could have led to" any of those outcomes. Every one of the four cases below settled without any determination of liability. Each DOJ release says so in the same words: the claims "are allegations only." A negotiated settlement is still caught. Some defense costs stay allowable if the settlement agreement with the government says so FAR 31.205-47(c)(1).

A fine for missing the 72-hour cyber incident report deadline DFARS 252.204-7012(c) sits under a different rule, FAR 31.205-15(a). That rule carries its own narrow exception. A fine tied to a specific contract term, or a CO's written order, stays allowable. Read together, the two rules allow exceptions rather than an absolute bar. That is our reading of the carve-outs, not language you will find in either section.

Grants and Credits: Why They Cut Against Your Claim

State Manufacturing Extension Partnership programs and SBA cybersecurity help both exist. Your local APEX Accelerator points you to what is live in your state right now. These were called Procurement Technical Assistance Centers, or PTACs, until the Department renamed the network in November 2022. Plenty of guidance still says PTAC. It is the same network. Before you take one of these grants, know what it does to your CMMC claim.

FAR 31.201-5 sets the rule for any credit tied to an allowable cost. "The applicable portion of any income, rebate, allowance, or other credit… received by or accruing to the contractor shall be credited to the Government either as a cost reduction or by cash refund." A grant that covers part of your remediation spend is a credit against that cost. It cuts what you claim. It does not sit beside the claim as free upside.

Net the grant against the cost pool before you bill it. Take a grant toward a SIEM buy and leave the full price in your G&A pool, and you bill the government for a cost its own program already helped fund.

The Real Consequence: A Certified Submission and a Penalty

The incurred cost submission (ICS) you file at fiscal year-end is not a formality. Once you propose final indirect cost rates, you certify them FAR 31.110(a). That step is not optional. "A proposal shall not be accepted and no agreement shall be made to establish final indirect cost rates unless the costs have been certified by the contractor" FAR 42.703-2(a).

If unallowable costs sit inside that certified proposal, a penalty follows. This runs apart from any legal exposure. FAR 42.709-2(a) sets the size: the penalty equals the disallowed cost tied to your contracts, plus interest on any part already paid. If the cost was already flagged unallowable for your firm before you filed, the penalty doubles. It does not matter whether the government even paid the cost FAR 42.709-2(a), (c). This penalty rule reaches contracts over $1 million. It skips firm-fixed-price contracts with no cost incentive, and firm-fixed-price commercial contracts FAR 42.709-1(b).

The penalty has a waiver, and it is not discretionary. FAR 42.709-6 says the contracting officer "shall waive" the 42.709-2(a) penalty in three situations:

  • You withdraw the proposal before the government formally initiates an audit of it, and submit a revised one. The rule defines that moment precisely: written notice, or an entrance conference, saying audit work on your specific proposal has begun.
  • The unallowable costs subject to the penalty total $10,000 or less.
  • You show the contracting officer that you have "established policies and personnel training and an internal control and review system" giving assurance that penalty-eligible unallowable costs are kept out of your rate proposals.

The third route is the whole argument for building the structure before you need it. The FAR is describing a contractor whose books were set up to catch this. The waiver is written for the firm that did the work in advance, and it is mandatory when the case is made. The first one is worth knowing too: if you find the problem yourself before the audit opens, there is a defined exit.

A separate question sits beside this one. Does a bad cybersecurity score also expose a contractor to a False Claims Act claim? That is a legal call. It turns on materiality, reliance, and the exact facts of a submission. Route that question to your CO and your counsel. The certification and penalty rule above applies no matter how that legal question is answered. It is the consequence closest to your own books: get the paperwork behind a bad cost wrong, and the exposure runs through your rate proposal, not only through the score itself.

MORSECORP: A $4.6 Million Records Lesson

DOJ settled nine cybersecurity fraud cases in FY2025 alone. It recovered over $52 million. The Department states plainly that these settlements "have more than tripled in each of the past two years." MORSECORP maps closest to a records failure, not a technical one.

MORSECORP Inc. agreed to pay $4.6 million in FY2025. DOJ's own account reads like a records story from start to finish. The company "submitted an inaccurate score for its implementation of required security controls." A third-party cybersecurity consultant then flagged that score as wrong, in writing. MORSECORP "did not promptly update it or notify the government." The firm also lacked a system security plan for its covered systems. It used a third-party email host without checking that host met the required security terms.

Three other cases sharpen the same point. Two settled in FY2025 alongside MORSECORP. The fourth, Aerojet, settled back in 2022 and is here because of who brought it.

Case Settlement What DOJ's release describes
MORSECORP $4.6 million A wrong score, a written warning it was wrong, no update, no word to the government.
Aerojet Rocketdyne $9 million Filed and fought by a former employee under the FCA's whistleblower rule, not brought by DOJ itself.
Penn State $1.25 million Honest scores showing non-compliance; the false part was the fix-it dates and the failure to follow through on the plan.
Georgia Tech (GTRC) $875,000 A score built on what DOJ calls a "fictitious" setup not matching the real campus network.

Aerojet's $9 million deserves the correct story. DOJ's release says the suit was "filed and litigated by former Aerojet employee Brian Markus" under the False Claims Act's whistleblower rule. He filed it in 2015, six years before DOJ's cybersecurity fraud push began. One employee, acting alone, recovered $9 million.

Penn State carries the line most worth remembering. DOJ said the university's scores "reflected it had not implemented certain controls." That is an honest score. The claimed misrepresentation sat in "the dates by which it would implement them," plus the school's failure to follow its own plans. An honest score is not, on its own, a full defense. Your plan of action dates are their own record, and they need the same care your score does.

The lesson across all four cases matches this article's whole point: one undifferentiated line, or one record you never updated, opens your whole balance to review. When a consultant or assessor flags a number as wrong, in writing, that notice starts a clock. Write down when you got it, what you did about it, and when you fixed the record.

Documentation That Holds Up Under a DCAA Audit

Seven record types cover what a DCAA auditor wants on a CMMC cost claim. Miss one, and an allowable cost turns into a questioned one.

  • Separate account codes. Split sub-accounts for assessment fees, consulting, software, hardware, training, and managed services. One "Cybersecurity" line tells an auditor nothing about what sits inside it.
  • A written allocation reason. Why a cost sits in G&A or overhead, tied to FAR 31.203(c)'s benefit test.
  • Consistency evidence. CAS 9904.402 records if you carry CAS coverage. FAR 31.203 records if you do not.
  • Vendor and consultant files. For retainers and services, keep the deal terms, invoices with time and service detail, and the consultant's work product, under FAR 31.205-33(f). Skip the signed SOW.
  • Time records. A separate indirect charge code for internal CMMC labor, opened before the hours are worked, not rebuilt after an audit starts.
  • Capital asset records. Depreciation schedules and useful-life calls for hardware and software above your capitalization line.
  • Management sign-off. A memo, meeting notes, or a budget approval showing the CMMC spend was a deliberate, approved call.

Frequently Asked Questions

Are CMMC compliance costs allowable under FAR?

Most CMMC compliance costs are allowable under FAR Part 31. No FAR 31.205 cost rule bars cybersecurity spending outright. Each cost still has to clear the five-part FAR 31.201-2 test: reasonable, allocable, matched to CAS or GAAP, within your contract terms, and clear of the limits in FAR Subpart 31.2. Weak records, not the spending itself, most often turn an allowable cost into a questioned one.

Does the July 2026 suspension reach my subcontract?

Probably not on its own. 32 CFR 170.23(a) makes primes flow CMMC rules down through every supply chain tier. The July 2026 memo orders government contracting officers to change government contracts and solicitations, not subcontract flowdown terms already in place. Whether your prime will drop that flowdown is a contract question. Take it to your prime and to counsel.

What happens to a CMMC cost I already committed before the suspension?

Keep your records no matter how the rule above it changes: the engagement letter, the invoice, and a note of when you spent the money against the requirement live at that time. Whether the cost stays recoverable once a requirement gets modified out is a contract-entitlement call for your CO and counsel, not an accounting one.

Should CMMC costs sit in G&A or overhead?

Most CMMC costs belong in G&A because they protect the whole firm, not one contract FAR 31.203(c). A cost benefiting one team or enclave belongs in overhead. If you are CAS-exempt, the exemption drops CAS 9904.402, not FAR 31.203's consistency rule, which still governs your split.

Does a modified-out CMMC requirement qualify for an equitable adjustment?

That is a contract-entitlement question, not an accounting one, and it turns on the exact clause and change involved. Three things stay in your control either way: know which cost pool the spend sits in, keep the records behind it, and know what an under-recovered rate costs you if the answer takes months. Send the entitlement question itself to your CO and counsel.

What records does DCAA expect for CMMC cost claims?

Seven types: separate account codes, a written allocation reason, consistency records matched to your CAS status, vendor and consultant files under FAR 31.205-33(f), time records on a dedicated CMMC charge code, capital asset records for depreciable buys, and management sign-off showing the spend was deliberate.

What happens if I put an unallowable CMMC cost in my incurred cost submission?

Your final indirect cost rates get certified before the CO accepts or settles them FAR 31.110(a); FAR 42.703-2(a). An unallowable cost inside that certified proposal carries a penalty equal to the disallowed amount plus interest, doubled if the cost was already known unallowable for your firm FAR 42.709-2(a). The rule reaches contracts over $1 million, apart from firm-fixed-price contracts with no cost incentive or firm-fixed-price commercial contracts FAR 42.709-1(b).


Amerifusion Bookkeeping is a CPA-managed firm built for government contract accounting, with a CISSP on staff for the cybersecurity side of this exact problem. If your books need to survive a DCAA audit on CMMC spending, review our DCAA compliance services, check the level-by-level cost detail in our CMMC assessment cost by level guide, or take the Compliance Readiness Check to see where your CMMC cost pools stand today.


Next in your learning path · Specialized DCAA Floor Checks for Remote and Hybrid Workforces
Joseph Kamara, CPA

Joseph Kamara CPA

Founder, Amerifusion Bookkeeping

Former KPMG financial auditor. Former Senior Manager for IS Assurance and Third-Party Risk Management at BDO Dallas (SOC 1/2, HITRUST, HIPAA). Former Senior Technology Risk Manager at Stryker. Specializing in DCAA-compliant accounting systems for government contractors.

Need help with DCAA compliance?

Book a free DCAA Readiness Call to see how Amerifusion can protect your next audit.

Book Your DCAA Readiness Call
Certified Intuit ProAdvisor, Gold tier DCAA Compliant CPA Oversight