CMMC & Compliance

How Much Does CMMC Compliance Actually Cost?

Every consultant answers this with “it depends.” That is true and useless.

So let me give you the actual numbers — the Department’s own published estimates — and then tell you which parts of them you can absorb yourself and which you cannot.

The government published its own cost estimates

When the CMMC rule was written, the Department had to publish a regulatory impact analysis. Those figures are public, and they are the most defensible starting point anyone has.

For a small entity, per the rule’s own analysis:

PathCost
Level 1 self-assessment (initial)about $5,977
Level 1 annual affirmationabout $560/year
Level 2 self-assessment (three-year cycle)about $34,277
Level 2 certification via C3PAO (or whatever replaces it)about $101,752
Level 2 annual affirmationabout $1,459/year

Those live at 89 FR 83185–86 if you want to read them yourself.

Two things jump out.

First, the gap between self-assessment and certification for Level 2 is roughly $67,000. That is the single largest number in your compliance decision.

Second — and this is the part almost nobody says out loud — the C3PAO’s own fee is only about $31,234 of that $101,752. Under a third. The assessor is not what makes certification expensive. Getting ready for the assessor is.

Which means the honest answer is: it depends on what you already have

The roughly $70,000 that is not assessor fees is preparation. Documentation, remediation, evidence, and the labour to produce all three.

That number is not fixed. It is a function of two things you control:

How much is in scope. A shop that has confined CUI to a deliberate enclave is assessing a handful of systems. A shop where CUI drifted into email, three shared drives, two laptops and a Dropbox is assessing everything it owns. Same contract, same standard, wildly different bill.

How much of the writing you do yourself. An SSP is a description of your own environment. Nobody knows your environment better than you do. Paying $250 an hour for someone to interview you and type your answers into a template is the most common way small contractors overspend on CMMC.

Right now, the certification number is theoretical anyway

Phase II third-party assessment as a condition of award was suspended on July 13, 2026. The reform task force reports around September 13.

So today the realistic Level 2 number for most small contractors is the self-assessment path — the roughly $34,000 figure — and a good chunk of even that is your own labour rather than cash out the door.

Which makes this a genuinely good moment to do the expensive-but-cheap work: scoping and documentation. Both survive every reform outcome on the table.

How to read a consultant’s quote

Three questions will tell you more than the number will.

“What is your assumed scope?” If the quote does not state how many systems and users it assumes, it is not a quote, it is a placeholder. Scope is the multiplier on everything.

“What am I writing versus what are you writing?” A quote where the consultant writes every policy and procedure will be two to three times one where they review and correct yours. Both are legitimate. Only one is necessary.

“What happens if the reform changes the requirement?” Anyone quoting you a fixed certification package right now, during a suspension, with a report due in September, should have an answer for that. If they do not, they are selling you the old world.

What about Level 3?

Short version: if you are asking this article’s question, you are almost certainly not Level 3.

Level 3 applies to a narrow set of high-sensitivity programs, requires Level 2 certification first, and is assessed by the government rather than a C3PAO. The engineering investment it implies is a different category of decision entirely — one that comes with a program office conversation, not a blog post.

If a consultant is steering a small shop toward Level 3 unprompted, get a second opinion.

Where the money actually goes

From what I see in small shops, in rough order of size:

1. Scope, and therefore everything else. Covered above. This is not a line item; it is a multiplier on every other line item.

2. Remediation of real gaps. MFA, logging, encryption at rest, backup, vulnerability management. This is genuine spend and mostly genuine value — you would want most of it even with no contract requirement.

3. Documentation. SSP, POA&M, policies, procedures, evidence artefacts. High effort, low cash if you do it, high cash if you outsource it.

4. A compliant place to put CUI. If you need one, this is a real recurring cost. External providers handling CUI generally need FedRAMP Moderate authorisation or equivalent, which narrows your options and raises your floor.

5. Assessment fees. Currently suspended for Level 2. Historically about a third of the certification total.

6. Annual upkeep. Affirmations, re-assessment cycles, keeping the documentation true as the business changes. Small per year, permanent.

One more cost nobody quotes you

Time.

Not billable hours — yours. The founder or the one IT person is the bottleneck in almost every small-contractor CMMC project, because they are the only one who actually knows how the network grew and why that server is still there.

Budget that honestly. A project that looks like $30,000 and three months on paper becomes nine months when the person who has to answer every question also runs the business. That slip is not a compliance failure, it is a capacity failure, and it is the most common reason these projects stall past the point where the spend was worth it.

If you take one operational thing from this: block the calendar time before you sign the engagement.

What I tell people who ask for one number

If you are a small shop handling CUI, have never done this, and want a planning figure rather than a quote:

  • Level 1 only, FCI and no CUI: low four figures, mostly your own time. Genuinely a DIY exercise.
  • Level 2, tight scope, you write your own documentation: five figures, low end. Dominated by remediation of real gaps.
  • Level 2, sprawling scope, everything outsourced: the Department’s $100K figure is not an exaggeration, and I have seen quotes above it.

The distance between the second and third line is not the standard. It is scoping and how much of the writing you keep in-house.

The three ways small contractors overspend

Buying tools before drawing the boundary. Every dollar of tooling gets multiplied by the number of in-scope systems. Scope first. Always.

Outsourcing the SSP wholesale. Have someone review it, structure it, tell you where it is thin. Do not pay them to discover your own network.

Treating the suspension as either an emergency or a holiday. It is neither. It is a window with a known closing date.

What to do next

Find out where you actually stand before you price anything. The CMMC readiness quiz takes two minutes and will tell you which of those three planning figures you are looking at.

If you want the full picture of the requirement rather than just the cost, the CMMC guide covers the whole path for small defense contractors.

And if the answer is “Level 1 and I want to just do it myself” — the Level 1 packet is free, because for most FCI-only shops it genuinely should be.

I’m Ken Haynes. I run CyberCloudAI — CMMC readiness, fractional CISO leadership, and AI tooling for defense contractors. Figures cited are the Department’s own published estimates from the CMMC rule and are planning numbers, not quotes; your costs depend on your scope and your starting position.


Discover more from CyberCloudAI.tech

Subscribe to get the latest posts sent to your email.

Scroll to Top