AnalysisAnalysis

How Much Does CMMC Level 2 Cost for a Small Defense Contractor?

A small contractor may need about ,500 for a narrow, mature self-assessment environment, or ,000 to ,000 with certification readiness and a C3PAO reserve.

ByMilitary Contractor Editorial
PublishedSeptember 5, 2026
Last checkedSeptember 4, 2026
Reading time11 minutes
A defense cybersecurity official discusses CMMC during a Pentagon briefing
A Pentagon briefing on the Cybersecurity Maturity Model Certification program. The image illustrates the official program context, not a contractor assessment outcome.

The C3PAO invoice is only one line. The complete budget also includes scoping, gap analysis, remediation, documentation, tools, outside support, internal labor, possible enclave work, recurring operations, and contingency. As of September 4, 2026, the Department of War has suspended CMMC Phase II, so requiring activities may call only for Level 1 or Level 2 self-assessments during the suspension. The duty to protect covered defense information under DFARS 252.204-7012 remains.

In This Guide

Start with three different cost numbers

Executives often ask for one CMMC number, but three numbers answer three different decisions:

  1. The current self-assessment budget is what the company needs to define its CUI boundary, meet the applicable NIST SP 800-171 Revision 2 requirements, document the system, assess itself, and sustain the controls.
  2. The certification-assessment reserve is money held for an eventual C3PAO engagement if a future solicitation, prime-contractor condition, or revised implementation policy makes certification necessary.
  3. The complete first-cycle budget combines preparation, remediation, internal labor, technology, external support, assessment, and a recurring operating reserve.

That distinction matters now. The July 2026 suspension memo directs requiring activities not to designate Level 2 C3PAO or Level 3 DIBCAC assessments during the suspension. It does not erase existing safeguarding duties, the need to know where CUI resides, or the business value of a credible NIST SP 800-171 program. A contractor should therefore fund the work its contracts and data require today while showing any certification reserve as a separate, conditional line.

Use the government estimate correctly

The 2024 CMMC program rule modeled $104,670 across three years for a small entity's Level 2 certification-assessment process. The table breaks that estimate into $20,699 to plan and prepare, $76,743 to conduct the assessment, $2,851 to report results, and $4,377 for affirmations across the three-year period.

That $104,670 is not a published C3PAO fee schedule. It is a federal regulatory cost model that combines burden attributed to the organization seeking certification and the assessment process under government assumptions. It also does not price a contractor's preexisting security gap, new cloud environment, hardware replacement, licenses, managed services, outside remediation, or all internal operating labor.

Public commercial examples show why the lines should stay separate. Fourth IT publishes $7,500 to $12,000 for a scoped gap assessment and $30,000 to $45,000 for readiness work, while explicitly stating that it is not a C3PAO. FieldLedger publishes a $20,000 to $80,000 C3PAO assessment range and identifies scope, environment complexity, documentation quality, sites, and assessor selection as drivers. These are vendor-published examples, not a representative market survey. Obtain comparable written proposals before treating either range as a budget commitment.

Build a small-contractor planning scenario

The following examples show how a finance team can calculate a range. They are editorial planning scenarios. Replace every assumption with the company's asset counts, loaded labor rates, quotes, and contract requirements.

ScenarioAssumptions and calculationIncludedExcludedFirst-year planning total
Narrow and already mature, self-assessment path160 internal hours at $75 = $12,000; $7,500 gap review; $15,000 remediation allowance; $12,000 tools and recurring operationsScope confirmation, evidence cleanup, limited remediation, annual operating expenseC3PAO assessment, major migration, new facility, extensive travel$46,500
Certification-ready small enclave300 internal hours at $75 = $22,500; $30,000 readiness; $25,000 remediation; $15,000 tools; $20,000 to $60,000 C3PAO reserve; $10,000 travel or closeout allowance; $15,000 to $21,000 contingencyPreparation, documentation, moderate fixes, technology, conditional assessment reserve, limited reworkLarge legacy replacement, multiple sites, unusual OT or engineering systems$137,500 to $183,500
Broad or weakly documented environment600 internal hours at $90 = $54,000; $12,000 gap review; $45,000 readiness; $100,000 remediation; $40,000 tools and services; $80,000 assessment reserve; $20,000 travel or rework; $57,000 contingencyMulti-team preparation, extensive remediation, broader tools and support, high assessment reserveBusiness interruption, major custom-system replacement, indefinite delay$408,000

The first scenario is not a shortcut to compliance. It assumes the company already operates a small, truthful CUI boundary with mature controls and usable evidence. The third is not a prediction. It is a sensitivity case showing how broad scope, high loaded labor, weak documentation, and substantial remediation compound.

The second scenario's low total is $22,500 + $30,000 + $25,000 + $15,000 + $20,000 + $10,000 + $15,000. Replacing the $20,000 assessment reserve with $60,000 and increasing contingency to $21,000 produces the high total. This arithmetic makes the estimate auditable and exposes the assumptions management can change.

Price every budget line

Scoping and the CUI boundary

Scope determines how many users, endpoints, applications, cloud services, facilities, networks, backups, and external providers must be understood and evidenced. The Level 2 scoping guide distinguishes CUI assets, security-protection assets, contractor risk-managed assets, specialized assets, and out-of-scope assets. The labels must match real data flows.

A dedicated enclave can reduce the assessed surface when people actually keep CUI inside it. Budget for migration, controlled transfer methods, endpoint administration, backup, identity, integration, and user friction. An enclave that exists only on a diagram does not reduce risk or assessment work.

Gap assessment and remediation

A gap assessment identifies where practices, configurations, and evidence do not support the required outcome. Remediation is the work that closes those gaps. Keep these as separate lines so a low diagnostic fee does not disguise expensive implementation.

Remediation may include identity and access changes, multifactor authentication, endpoint configuration, logging, vulnerability management, backup, network segmentation, physical controls, incident processes, training, and replacement of unsupported systems. Price labor as well as licenses. A tool creates value only when someone configures, monitors, maintains, and documents it.

Documentation and evidence

The System Security Plan, policies, procedures, inventories, diagrams, training records, logs, tickets, and configuration evidence must agree with operations. The Level 2 Assessment Guide and CMMC Assessment Process describe pre-assessment scope and document review followed by examination, interviews, and tests. Documentation work therefore includes interviewing owners, reconciling records, fixing contradictions, and maintaining evidence after the initial push.

Internal labor

Internal labor is often the largest omitted cost. Build it by role rather than using one unexamined percentage. Include executive approval, contracts interpretation, security and IT work, engineering input, facilities, human resources, system owners, interviews, evidence collection, vendor coordination, and recurring reviews.

Use a loaded hourly rate that reflects compensation and overhead. Separate one-time hours from annual hours. If an engineer spends 80 hours changing a controlled workflow, that is a program cost even when no vendor sends an invoice.

Tooling, cloud services, and external support

Map each purchase to a specific requirement, owner, configuration, evidence output, renewal date, and exit plan. Include secure cloud or enclave subscriptions, identity, endpoint protection, monitoring, log retention, backup, scanning, ticketing, training, and provider support only when the environment needs them.

External advisers can accelerate scoping, documentation, architecture, remediation, or assessment preparation. Define the deliverable and independence boundary. A readiness consultant's fee does not include the C3PAO certification assessment unless a written proposal clearly says so, and the selected assessment organization must preserve the required independence.

Recurring cost and contingency

Recurring work includes licenses, provider retainers, monitoring, patching, vulnerability management, user changes, training, evidence retention, SSP updates, self-assessment activity, and annual affirmation support when applicable. Put recurring cost in an annual operating budget and show the triennial assessment reserve separately.

Contingency should have a basis. Apply it to uncertain remediation, schedule, travel, or assessment lines, not to the entire budget by habit. Record the event that releases it and the owner who approves its use.

Understand what moves the total

Costs usually move lower when the company has a small and accurate CUI boundary, few in-scope users and locations, standardized supported systems, mature identity and logging, current documentation, organized evidence, stable external providers, and staff who can perform preparation work without displacing higher-value contract delivery.

Costs move higher when CUI is distributed across ordinary business systems, multiple facilities or networks, unmanaged devices, engineering or operational technology, custom applications, many service providers, weak asset records, incomplete policies, inconsistent practice, or a compressed deadline. High employee turnover and unclear ownership add recurring work even after technical gaps close.

The key management question is not simply whether an enclave is cheaper. It is whether the enclave supports contract performance without uncontrolled copies, workarounds, or costly integration. Compare the full operating model, not only the subscription price.

Separate the C3PAO assessment

Treat a C3PAO proposal as its own procurement. Give each bidder the same written scope and ask for assumptions about users, assets, sites, external providers, assessment-team composition, remote and onsite work, travel, schedule, reporting, scope changes, and permitted conditional-status closeout.

Verify the organization's current status through The Cyber AB's assessing and certification resources before selection. Compare fixed price with time-and-materials terms, and identify what triggers a change order. Ask whether travel, quality review, evidence follow-up, a delayed start, or closeout work is included. Do not assume the readiness firm can also perform the certification assessment.

During the current Phase II suspension, keep this line conditional unless a real requirement or business decision supports it. A reserve can still be useful for planning, but it should not be presented to management as an unavoidable current government charge.

Build a budget management can approve

Use this sequence:

  1. List the contracts, clauses, CUI categories, and deadlines that create the need.
  2. Draw the real CUI data flow and count users, assets, sites, applications, and external providers.
  3. Record current control and evidence gaps with owners and remediation choices.
  4. Estimate one-time internal hours by role and loaded rate.
  5. Obtain separately scoped quotes for gap work, readiness support, remediation, services, and any C3PAO assessment.
  6. Price recurring labor, licenses, providers, evidence maintenance, and management review.
  7. Add a stated contingency to the uncertain lines.
  8. Run at least three sensitivity cases, such as adding a site, moving an engineering application into scope, or reducing the boundary through a workable enclave.
  9. Show exclusions, quote dates, assumptions, and the event that requires a re-estimate.

The resulting approval request should have a current-operating case and a certification case. That gives leaders a useful decision during the suspension and preserves visibility into what a future assessment could require.

Budget for the environment the company can sustain

The practical answer is not one universal CMMC price. A narrow, mature small-contractor environment may support a first-year self-assessment budget of about $46,500. Adding readiness support, remediation, internal labor, technology, and a C3PAO reserve can move a realistic planning case toward $140,000 to $185,000, while a broad or immature environment can exceed $300,000.

Build the company's number from its actual CUI boundary. Keep the C3PAO assessment separate, replace public pricing examples with written quotes, and fund recurring operation rather than treating assessment day as the finish line. The strongest budget is the one management can trace from contract need to system scope, control gap, responsible owner, source, and calculation.

Frequently Asked Questions

Is $104,670 the fee a C3PAO will charge?

No. It is the federal program rule's three-year small-entity cost model for the Level 2 certification-assessment process, including modeled planning, assessment, reporting, and affirmations. A C3PAO's commercial proposal and the contractor's complete implementation budget are separate numbers.

Does the Phase II suspension eliminate CMMC work?

No. The suspension prevents requiring activities from designating Level 2 C3PAO and Level 3 DIBCAC assessments during the review period, but Level 1 and Level 2 self-assessment requirements remain available and DFARS 252.204-7012 safeguarding duties remain in effect.

Does a CUI enclave make the rest of the company automatically out of scope?

No. Scope follows actual CUI processing, storage, transmission, and protection. Shared services, security-protection assets, external providers, and uncontrolled data movement can keep systems relevant even when an enclave is planned.

Should recurring costs be included in the first-year request?

Yes. Show the first year of licenses, monitoring, support, evidence maintenance, training, and internal administration, then carry those items into the annual operating plan. Keep any triennial assessment reserve visible as a separate future line.

Sources

These are the recoverable records used for this analysis. Dates describe the source record; access dates describe our verification pass.

  1. Cybersecurity Maturity Model Certification Program Final RuleU.S. Department of Defense and Federal Register · October 15, 2024 · checked September 4, 2026
  2. Cybersecurity Maturity Model Certification Program Acquisition Final RuleU.S. Department of Defense and Federal Register · September 10, 2025 · checked September 4, 2026
  3. Implementing Suspension of CMMC Phase IIU.S. Department of War Chief Information Officer · July 13, 2026 · checked September 4, 2026
  4. CMMC Level 2 Scoping GuideU.S. Department of Defense Chief Information Officer · Publication date not recorded · checked September 4, 2026
  5. CMMC Level 2 Assessment GuideU.S. Department of Defense Chief Information Officer · Publication date not recorded · checked September 4, 2026
  6. CMMC Assessment Process Version 2.0The Cyber AB · Publication date not recorded · checked September 4, 2026
  7. Assessing and Certification RolesThe Cyber AB · Publication date not recorded · checked September 4, 2026
  8. NIST SP 800-171 Revision 2National Institute of Standards and Technology · Publication date not recorded · checked September 4, 2026
  9. CMMC Engagements and PricingFourth IT · Publication date not recorded · checked September 4, 2026
  10. C3PAO Assessment Cost and TimelineFieldLedger · May 11, 2026 · checked September 4, 2026