Photo: Unsplash
If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) for the US Department of Defense, CMMC decides whether you can keep winning contracts. The first question most contractors ask is what it will cost. The answer depends mostly on which CMMC level your contracts require and how far your environment is from the underlying NIST requirements. This guide breaks down CMMC certification costs by level, the hidden costs that usually outweigh the assessment fee, and how to keep the total down.
Key takeaways
- Your required level sets the cost. Level 1 is an annual self-assessment. Level 2 is either a self-assessment or a third-party C3PAO assessment every three years. Level 3 adds a government-led assessment on top of Level 2.
- The assessment fee is rarely the biggest cost. Closing gaps against NIST SP 800-171, writing your System Security Plan, and building an enclave for CUI usually cost more than the assessment itself.
- DoD published its own estimates. The regulatory impact analysis for the CMMC program rule estimated roughly $6,000 per year for a small business Level 1 self-assessment and roughly $105,000 for a Level 2 C3PAO certification assessment over a three-year cycle, excluding remediation.
- Shrinking the CUI boundary is the biggest cost lever. Every system, person, and vendor that touches CUI adds to what you must secure and what the assessor must test.
- Timelines matter. CMMC requirements are being phased into DoD contracts, and C3PAO capacity is limited, so late starters tend to pay more.
CMMC levels at a glance
| Level 1 (Foundational) | Level 2 (Advanced) | Level 3 (Expert) | |
|---|---|---|---|
| Protects | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) | CUI in the highest-priority programs |
| Requirements | 15 basic safeguarding requirements from FAR 52.204-21 | The 110 requirements of NIST SP 800-171 Rev. 2 | Level 2 plus 24 selected requirements from NIST SP 800-172 |
| Assessment | Annual self-assessment | Self-assessment or C3PAO certification assessment, depending on the contract | C3PAO Level 2 assessment first, then a government-led assessment by DIBCAC |
| Frequency | Every year, with an annual affirmation | Every three years, with annual affirmations | Every three years, with annual affirmations |
| POA&M allowed | No | Limited, with a minimum score and 180 days to close | Limited |
Your contract, or the solicitation for it, states which level applies. Most contractors that handle CUI will need Level 2, and many of those will need the C3PAO version.
What CMMC costs, by level
The figures below come from DoD's regulatory impact analysis for the CMMC program rule (32 CFR Part 170) for small businesses, rounded. They cover the assessment and affirmation activities only, not the cost of implementing the security requirements.
| Assessment | DoD estimate for a small business | Notes |
|---|---|---|
| Level 1 self-assessment | About $6,000 per year | Mostly internal time to assess and affirm |
| Level 2 self-assessment | About $37,000 per three-year cycle | Includes the triennial assessment and annual affirmations |
| Level 2 C3PAO certification assessment | About $105,000 per three-year cycle | Includes the C3PAO fee, preparation, and affirmations |
| Level 3 | Substantially more | Includes the Level 2 C3PAO assessment plus the DIBCAC assessment and the added NIST SP 800-172 controls |
Market quotes vary with your scope, the number of assets and locations, and how ready you are. Treat DoD's numbers as a planning baseline, not a quote.
The costs that usually matter more
For most contractors, preparation and remediation cost more than the assessment:
- Gap assessment. A structured review of your environment against the 110 NIST SP 800-171 requirements, usually the first paid step.
- System Security Plan (SSP). Required documentation describing your CUI environment and how each requirement is met. Assessors test against it.
- Remediation. Commonly MFA everywhere CUI is accessed, FIPS-validated encryption, centralized logging and review, vulnerability management, incident response, configuration baselines, and media protection.
- A CUI enclave or compliant cloud. Many small contractors move CUI into a dedicated environment, such as a government cloud tenant, instead of securing their whole company. This has setup and licensing costs but can shrink scope dramatically.
- Policies, procedures, and training. Written procedures for every requirement family, plus workforce training records.
- Evidence and ongoing operations. Logs reviewed, access reviewed, vulnerabilities scanned, and changes controlled, every month, not only before the assessment.
- Internal time. Someone must own the program. For a first assessment, expect significant time from IT, security, and leadership over several months.
- Consultants or a managed service. Optional, but common for small contractors without in-house compliance staff.
What drives CMMC cost up or down
- Required level. Level 1 is a fraction of the cost of Level 2 with a C3PAO.
- Size of the CUI boundary. Fewer systems, users, and locations handling CUI means fewer assets to secure and test.
- Starting point. Contractors that already implemented NIST SP 800-171 for DFARS 252.204-7012 and maintain an accurate SPRS score are far ahead.
- External service providers. Cloud and managed service providers that handle CUI must meet the relevant requirements too, and their documentation affects your assessment.
- Documentation quality. A clear SSP and organized evidence shorten assessor time.
How to reduce your CMMC cost
- Confirm your level first. Read your contracts and upcoming solicitations. Do not build for Level 2 C3PAO if your work only involves FCI.
- Minimize and isolate CUI. Keep CUI in as few systems as possible, and consider an enclave instead of your whole corporate environment.
- Start from NIST SP 800-171 and your SPRS score. If you already report a score, your gap list exists. Update it honestly.
- Write the SSP early. It forces the scoping decisions that drive every other cost.
- Use inheritance from compliant providers. Controls your cloud or managed provider operates can be documented as inherited, with their evidence.
- Collect evidence continuously. Assessors test that controls operate. Evidence captured as you go costs less than evidence reconstructed before the assessment.
- Book a C3PAO early. Assessment capacity is limited, and rushed schedules cost more.
For a step-by-step plan, see our CMMC certification checklist.
How SecureSlate helps
SecureSlate's CMMC program combines compliance software with a dedicated compliance lead for one fixed price, so you know the cost of getting ready before you start:
- Your compliance lead scopes your CUI environment and writes your System Security Plan and POA&M.
- The platform maps your controls to the 110 NIST SP 800-171 requirements and collects evidence continuously from the tools you already use.
- Security scanning of code, cloud configuration, and domains evidences the technical requirements.
- You are prepared for a self-assessment or a C3PAO assessment, whichever your contracts require.
FAQ
How much does CMMC certification cost?
It depends on the level. DoD's estimates for small businesses are about $6,000 per year for a Level 1 self-assessment, about $37,000 per three-year cycle for a Level 2 self-assessment, and about $105,000 per three-year cycle for a Level 2 C3PAO certification. These exclude remediation, which is often the larger cost.
How much does a CMMC Level 2 assessment cost?
DoD estimated roughly $105,000 over a three-year cycle for a small business Level 2 C3PAO certification assessment, including preparation and annual affirmations. Actual C3PAO quotes vary with scope and readiness.
Is CMMC Level 1 free?
There is no assessor fee, because Level 1 is a self-assessment, but it still takes internal time to assess the 15 requirements, document the results, and submit the annual affirmation in SPRS.
How long is a CMMC certification valid?
Level 1 self-assessments are repeated every year. Level 2 and Level 3 assessments are valid for three years, with an annual affirmation by a senior company official that the requirements are still met.
Can small businesses afford CMMC?
Yes, especially when they keep the CUI boundary small. Isolating CUI in an enclave or compliant cloud environment, rather than securing the entire company, is the most common way small contractors control cost.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory, or professional advice. CMMC requirements and implementation timelines are set by DoD rules and contract clauses, which change over time. Cost figures are estimates. Consult qualified advisors and your contracting officer for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
