Under the Federal Acquisition Regulation, much of what you spend to protect Controlled Unclassified Information is an allowable cost, which means it can be recovered on your government work. The spend is real. The recovery is real too, when you set it up correctly.

What does "allowable cost" mean under FAR Part 31?

FAR Part 31 is the rulebook for which costs you can charge to, and recover on, a government contract. A cost passes the test in FAR 31.201-2 when it is:

  • Reasonable for the circumstances
  • Allocable to the work
  • Consistent with generally accepted accounting principles and any applicable Cost Accounting Standards
  • In line with your contract terms
  • Not specifically listed as unallowable under FAR 31.205

Clear those bars and the cost is allowable. You can review the full rule at acquisition.gov.

Are CMMC and cybersecurity compliance costs allowable?

In most cases, yes. Nothing in FAR Part 31 or DFARS makes the cost of meeting your DFARS and NIST 800-171 obligations unallowable, as long as you incur it the right way. In practice that covers the work you are already paying for:

  • Security assessments and gap assessments
  • Continuous monitoring and vulnerability management
  • Security software licenses and subscriptions
  • Salaries of in-house security staff
  • Fees paid to a managed security provider

These are ordinary costs of doing business in the defense industrial base, and the government expects you to incur them.

Direct, indirect, and how the money comes back

How you recover depends on your contract type.

On a cost-reimbursement contract, allowable costs are billed either directly to a specific contract or, more often for baseline compliance work, through your indirect rates. Most routine CMMC and 800-171 costs are treated as indirect. You do not bill them to one job. You spread them across your business base and recoup them over time in your overhead or general and administrative rate.

On a firm fixed price contract, you do not bill compliance costs separately at all. You price them into your bids, which makes the discipline simple to state and hard to execute: know your real compliance cost, and build it into what you charge.

The catch: allocating and documenting your CMMC costs

Allowable is not the same as automatically recovered. The hard part is allocating the cost consistently and documenting it so it survives a review. Spread it the wrong way, or fail to tie each expense to the requirement it satisfies, and you invite scrutiny from the Defense Contract Audit Agency. This is where most contractors leave money on the table — the cost was allowable, but the records were not clean enough to claim it.

A short example

Two contractors buy the same managed security service. One books it as a vague line item with no link to a requirement. The other maps every service to the NIST 800-171 control and the DFARS clause it satisfies, then assigns it to a documented indirect pool. When the auditor asks, only one of them can defend the claim.

How Capital Cyber makes your CMMC compliance costs defensible

We build and run the compliance program, and we give you the paper trail to back it. That means invoices that map each service to the control and the DFARS or CMMC requirement it satisfies, a documented security cost base, and a program your accountant can drop into the right indirect pool. Our Managed Compliance Services and CMMC Compliance Services are designed to be defensible, not just functional, so the cost you incur to win and keep defense work is a cost you can actually account for and recover.

Important Note

A note on who decides allowability

This article describes the framework, not a determination. Whether a specific cost is allowable, and how it should be allocated, is ultimately the call of your contracting officer, the Defense Contract Audit Agency, and a qualified government contracts accountant. Bring them in early. We will give them clean inputs to work with.

Frequently asked questions

Are CMMC compliance costs allowable under FAR Part 31?

In most cases, yes. No provision in FAR Part 31 or DFARS makes the cost of meeting NIST 800-171 and DFARS requirements unallowable, provided the cost is reasonable, allocable to the work, and properly documented.

Are CMMC costs a direct or indirect cost?

Most routine compliance work is treated as an indirect cost, spread across your business base and recovered through your overhead or general and administrative rate. Project-specific security work can sometimes be charged directly to a contract.

Can I recover CMMC costs on a firm fixed price contract?

Not as a separate line item. You recover it by pricing it into your bids, which means you need to know your true compliance cost before you quote.

What stops a contractor from recovering allowable costs?

Poor allocation and weak documentation. If you cannot tie each expense to the requirement it satisfies, the Defense Contract Audit Agency can challenge the claim.

Your next step

The first move is knowing where your compliance program stands today. Request a NIST Gap Assessment from Capital Cyber and we will help you build the program and the documentation that turn your CMMC spend from a sunk cost into a recoverable one.

If you are a defense contractor, you may also qualify for a fully funded CMMC Gap Assessment Grant through Cyber Grants Alliance, which covers all 110 NIST 800-171 controls at no cost to you.

Request a NIST Gap Assessment
Disclaimer: This article is for general informational purposes only and does not constitute legal, accounting, or contract compliance advice. FAR and DFARS rules change. Always consult your contracting officer, the Defense Contract Audit Agency guidance, and a qualified government contracts accountant before making cost allocation decisions.