CMMC Certification Cost in 2026: Complete Breakdown for Defense Contractors
DoD priced CMMC in its own rulemaking: $5,977 a year for a Level 1 self-assessment, $101,752 for a small entity's Level 2 certification assessment, and $2.7M plus $490K a year for Level 3 — figures from the CMMC final rule's Regulatory Impact Analysis, 89 FR 83185-86, not from market anecdote.
Cabrillo Club
Editorial Team · February 24, 2026 · Updated Jul 28, 2026 · 15 min read

CMMC program update — July 13, 2026
The Department of War has suspended CMMC Phase 2 requirements pending a 60-day program review. Phase 1 self-assessments, SPRS scores, and DFARS 252.204-7012 safeguarding obligations remain fully in force. Certification dates and third-party assessment requirements referenced in this article may change when the review concludes. Read the DoW release
Key Takeaways
- DoD's priced figures (89 FR 83185-86): Level 1 self-assessment $5,977/year for a small entity; Level 2 self-assessment $34,277; Level 2 certification assessment $101,752; Level 3 certification assessment $9,050 on top of $2.7M nonrecurring engineering
- Inside DoD's $101,752 Level 2 certification figure, the C3PAO assessor fee is $31,234 for a small entity — roughly 31% (89 FR 83185-86). The rest is your own labour
- "Small entity" in these figures is the SBA size standard, not a headcount band — DoD models only two brackets, small and other-than-small
- For Levels 1 and 2 these are assessment costs only. DoD assumed NIST SP 800-171 implementation was already mandatory, so remediation sits outside the model — which is why lived experience runs higher than the rule's numbers
- Recurring costs are priced separately and are easy to miss: $560/year to reaffirm at Level 1, $1,459/year at Level 2, and $490,000/year of recurring engineering at Level 3 — all small-entity figures (89 FR 83185-86 and 83188)
CMMC Certification Cost in 2026: Complete Breakdown for Defense Contractors
If you are a defense contractor asking what CMMC certification costs, there is a better source than any consultancy's price list: DoD had to price the program to publish the rule, and it published a per-entity cost model with labor categories, hour counts and rates. Every dollar figure in the sections below that carries a Federal Register cite comes from that model. It prices above what an independent consultancy charges, and unlike a vendor estimate, every line is quotable back to the government's own rulemaking.
What Does CMMC Certification Cost?
In DoD's own modelling, a Level 1 self-assessment plus affirmation costs a small entity $5,977 a year. A Level 2 self-assessment costs $34,277 for a small entity and $43,403 for an other-than-small entity, on a three-year cycle. A Level 2 certification assessment costs $101,752 for a small entity and $112,345 for an other-than-small entity, of which the C3PAO's own fee is $31,234 and $52,056 respectively. Level 3 adds nonrecurring engineering that DoD models at $2.7 million for a small entity and $21.1 million for an other-than-small entity, plus $490,000 and $4.12 million a year to sustain. Source: DoD's own Regulatory Impact Analysis for the CMMC final rule (89 FR 83185-86). One caveat matters more than any of the numbers: for Levels 1 and 2 these are assessment costs only. DoD assumed implementation was already required under FAR 52.204-21 and DFARS 252.204-7012, so remediation is not in them.
What follows breaks those figures down by level and by cost category, separates what DoD priced from what it deliberately left out, and says plainly where we have no source rather than filling the gap with an estimate.
Understanding CMMC 2.0 Certification Levels
Before diving into costs, it's essential to understand what you're certifying against. CMMC 2.0 simplified the original five-level framework into three tiers, each with different assessment requirements and cost implications.
Level 1: Foundational (15 Requirements)
Level 1 covers Federal Contract Information (FCI). Its security requirements are the 15 basic safeguarding requirements at 48 CFR 52.204-21(b)(1)(i) through (xv) — 32 CFR 170.14(c)(2) states the count in exactly those terms. (You will still see "17 practices" in circulation; that is the CMMC 1.0 figure and it is no longer the requirement set.) The cost advantage at Level 1 is that self-assessment is permitted: you do not need a third-party assessor. Your company conducts the evaluation and affirms compliance annually through the Supplier Performance Risk System (SPRS).
Level 2: Advanced (110 Requirements)
Level 2 is where most defense contractors land. 32 CFR 170.14(c)(3) makes its security requirements identical to those in NIST SP 800-171 Rev 2 — all 110, across 14 requirement families from Access Control to System and Information Integrity. Level 2 has two assessment paths: self-assessment, and certification assessment by a CMMC Third-Party Assessment Organization (C3PAO). CMMC Phase 2 — the phase that would have made C3PAO certification a condition of award — was suspended on 13 July 2026 pending programme review, so the certification path is not currently being imposed. What did not change: DFARS 252.204-7012, NIST SP 800-171 implementation, your SPRS score and your annual affirmation. For a detailed breakdown of every control, see our CMMC Level 2 requirements guide.
Level 3: Expert (110 + 24 Requirements)
Level 3 adds 24 selected requirements from NIST SP 800-172 on top of the 110 at Level 2; Table 1 to 32 CFR 170.14(c)(4) lists them as items (i) through (xxiv). Assessment is conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a government entity rather than a C3PAO. Level 3 is reserved for contractors supporting the most sensitive DoD programs.
CMMC Assessment Fees: What C3PAOs Charge
The direct assessment fee is the most visible cost, but it varies widely based on organization size, scope complexity, and C3PAO pricing.
Level 1 Self-Assessment
There is no assessor fee at Level 1 — you assess yourself — but the work is not free, and DoD priced it: $5,977 a year for a small entity and $4,042 for an other-than-small entity to perform the self-assessment and file the affirmation, with the annual reaffirmation priced separately at $560 and $584 (89 FR 83185–86). DoD publishes no Level 1 three-year total, and neither do we: it prints both an annual self-assessment cost and a separate annual reaffirmation cost without establishing how the two stack across three years, and picking one reading would mean presenting our guess as DoD's.
Level 2 Third-Party Assessment
DoD models a Level 2 certification assessment at $101,752 for a small entity and $112,345 for an other-than-small entity. The C3PAO's own fee inside those totals is $31,234 and $52,056 — DoD gets there by assuming a 3-person, 120-hour assessment team for a small entity and a 5-person, 200-hour team otherwise, at a blended external-provider rate of $260.28 an hour that it says includes labor, overhead, G&A and profit (89 FR 83185–86). Read those as modelling, not price lists — DoD says so itself: the estimates "do not include actual prices of C3PAO services available in the marketplace. Market forces of supply and demand will determine C3PAO pricing." The certification assessment runs on a three-year cycle (32 CFR 170.8).
DoD's modelled per-entity assessment cost (89 FR 83185–86)
What the chart is, exactly: DoD's modelled cost of the assessment, per entity, from the CMMC final rule's Regulatory Impact Analysis (89 FR 83185–86). It is not an all-in programme cost. For Levels 1 and 2 it excludes implementation entirely, because DoD assumed FAR 52.204-21 and NIST SP 800-171 were already required. Level 3's bar is small for the same reason and is the most misleading one to read alone: DoD prices the Level 3 engineering separately at $2.7 million one-off for a small entity and $490,000 a year to sustain it, and those are not plotted here. DoD also assumes a first-attempt pass.
Level 3 Government Assessment
The Level 3 assessment itself is conducted by DCMA DIBCAC, so no C3PAO fee attaches to that step — but reaching Level 3 is not C3PAO-free. 32 CFR 170.18(a) makes a Final Level 2 (C3PAO) status a prerequisite for undergoing a Level 3 certification assessment, and DoD's own model says so plainly: the total cost of a Level 3 certification assessment includes the cost of a Level 2 certification assessment. Budget the C3PAO fee above, then add Level 3 on top of it. The assessment step is the cheap part. DoD models the government-led Level 3 assessment at $9,050 for a small entity and $39,021 for an other-than-small entity, then prices the engineering to meet the 800-172 requirements on separate lines: $2.7 million and $21.1 million of nonrecurring engineering, plus $490,000 and $4.12 million a year to sustain it (89 FR 83188). Level 3 is the only level where DoD priced implementation at all, which is why it is the only level where the published figure resembles a real programme cost.
The Hidden Cost Drivers Most Contractors Miss
Recurring cost is real, but it is not where DoD's own model puts the weight. The Regulatory Impact Analysis budgets a Level 2 annual affirmation at $1,459 for a small entity and $2,712 otherwise (89 FR 83185-86) — modest, and filed each year between assessments. The recurring costs that actually surprise contractors are the ones DoD does not model at all: the tooling, monitoring and staff time standing behind the controls. Those vary too widely by environment for anyone to quote honestly, so the drivers below are described rather than priced. Treat any vendor who does put a number on them as quoting their own assumptions, not yours.
1. Gap Remediation Is the Biggest Line Item
This is the line item DoD's numbers do not contain. The Regulatory Impact Analysis prices assessment only at Levels 1 and 2, on the stated assumption that implementing FAR 52.204-21 and NIST SP 800-171 was already required — since 2016 and 2017 respectively — and so was not a new cost of the CMMC rule (89 FR 83178–83189). Whatever your gap analysis finds is additional to every figure on this page, and it is the reason lived experience runs above the rule's numbers. We deliberately publish no per-seat prices for EDR, SIEM, MFA or backup here: that pricing moves constantly, we have no primary source for it, and a stale number in someone's budget is worse than no number. Price those with your own vendors and date the quote.
2. System Security Plan (SSP) Development
Your SSP is the cornerstone document for assessment. It maps every NIST 800-171 control to your specific implementation. A poorly written SSP is the number-one reason assessments fail or require remediation rounds.
3. Ongoing Compliance Costs (Year Over Year)
DoD prices the recurring side separately, and it is the part contractors most often leave out of a budget: $560 a year for a small entity to file the Level 1 reaffirmation ($584 other-than-small); $1,459 a year for the Level 2 annual affirmation ($2,712 other-than-small); and at Level 3, $490,000 a year of recurring engineering for a small entity and $4.12 million for an other-than-small entity (89 FR 83185–86 and 83188). One arithmetic trap worth naming: DoD's published three-year Level 2 totals — $104,670 on the certification path and $37,196 on the self-assessment path, small entity — already contain the two intervening annual affirmations, so adding the affirmation on top of them double-counts it.
4. What Still Binds You After the Phase 2 Suspension
The suspension removed a deadline, not your obligations, and the distinction is where money gets wasted in both directions. Still in force: DFARS 252.204-7012, which requires you to implement NIST SP 800-171 on covered contractor information systems and to report a cyber incident within 72 hours; DFARS 252.204-7019, which conditions award on a current NIST SP 800-171 assessment — not more than three years old unless the solicitation says otherwise — posted in SPRS; and DFARS 252.204-7020, which governs DoD assessments and flowdown to subcontractors. The cost of letting any of those lapse is award eligibility, and none of it depends on what happens to CMMC.
How to Reduce Your CMMC Certification Cost
Every lever below works the same way: it shrinks what has to be assessed. DoD's model scales with entity size and assessment scope (89 FR 83185-86), so the least expensive assessment is the one with the smallest defensible CUI boundary. We are deliberately not quoting a savings figure — what you save depends entirely on where your CUI sits today, and a number invented here would be worth less than the exercise of finding out.
Minimize Your CUI Boundary
The single most effective cost-reduction strategy is shrinking the scope of your assessment. Every system that touches CUI must meet all 110 Level 2 controls. By consolidating CUI handling into a defined enclave — a limited set of systems, networks, and applications — you reduce the number of controls to implement across your broader IT environment.
Cabrillo Club's private AI platform is built around that principle: CUI processing, proposal automation and collaboration happen inside one defined boundary rather than spread across your IT estate, so the systems in scope for assessment are the ones you deliberately put there. To be explicit about our own status, since this is a page about compliance cost: we maintain a documented SSP and our self-assessment is in progress; we have never been assessed by a C3PAO. Nothing on this page should be read as a certification claim about us. See our security and deployment posture for the detail.
Leverage Existing FedRAMP-Authorized Tools
If your tools are already FedRAMP-authorized, some security requirements can be inherited from the cloud service provider's authorization — but inheritance narrows the work rather than removing it, and we are not going to put a number on how much. FedRAMP authorization removes one specific burden: you do not need to obtain the CSP's own SSP. What remains is documentation you still owe — 32 CFR 170.19(c)(2) and (d)(2) require the use of an external service provider, its relationship to you, and the services it provides to be documented in your SSP and described in the provider's customer responsibility matrix, and the CSP's assessment results and CRM are themselves in scope for the C3PAO assessment. Treat inheritance as redirected documentation work, not deleted documentation work. See our FedRAMP collaboration tools comparison for options.
Use a Phased Approach
Don't try to achieve full compliance in one sprint. A phased approach spreads costs across budget cycles:
- Phase 1 (Months 1–3): Gap analysis, SSP development, quick-win remediation
- Phase 2 (Months 4–8): Technology deployment, network segmentation, training
- Phase 3 (Months 9–12): Internal mock assessment, POA&M closure, C3PAO scheduling
For a complete step-by-step walkthrough, see our guide on how to get CMMC certified.
How ready are you for CMMC?
Take our free readiness assessment. 10 questions, instant results, no email required until you want your report.
Check Your CMMC Readinessor try our free CMMC Cost Estimator→
Consolidate Compliance Tools
Running many separate security tools multiplies licensing, administration and compliance documentation. Consolidating reduces all three.
Platforms like Cabrillo Club combine CUI-safe CRM, AI proposal automation, and secure collaboration within a single CUI boundary. Consolidating tools reduces the number of systems in your assessment boundary and the amount of SSP documentation that follows from it.
CMMC Cost by Industry Segment
Different types of contractors face different cost profiles based on their typical CUI exposure and existing security maturity.
Small Business Primes and Subcontractors
- Typical level: Level 1 or Level 2
- CUI scope: Limited (often just proposals and technical data)
- Key challenge: Limited IT staff; often need external consultant support
- Cost tip: use the no-cost readiness resources before buying consulting hours — Project Spectrum and the DoD Cyber Crime Center's DIB Cybersecurity Program both publish free material aimed at exactly this segment.
Mid-Market Defense Contractors
- Typical level: Level 2
- CUI scope: Moderate (engineering data, logistics, program management)
- Key challenge: Multiple CUI enclaves across business units
- Cost tip: Centralize CUI handling to reduce per-enclave assessment costs
Large Primes and Tier-1 Subcontractors
- Typical level: Level 2 or Level 3
- CUI scope: Extensive (classified-adjacent programs, CUI across all functions)
- Key challenge: Legacy systems, complex supply chains, multiple facility clearances
- Cost tip: Establish a CMMC Program Management Office (PMO) to coordinate across divisions
To learn more about meeting compliance requirements, explore our private AI versus cloud AI for proposal work.
Choosing a C3PAO: Price vs. Value
Not all C3PAOs are created equal. The Cyber AB Marketplace lists accredited assessors, but choosing solely on price can backfire.
What to evaluate:
- Assessment methodology: Do they provide a clear assessment plan upfront?
- Remediation guidance: Some C3PAOs offer advisory services pre-assessment (though they cannot assess organizations they've consulted for)
- Industry experience: C3PAOs with defense contractor experience understand CUI boundaries
- Timeline: ask for their current scheduling lead time and the length of the assessment window, in writing. Both vary by assessor and with demand, and we have no published figure for either — treat any range you are quoted, including ranges you find online, as that firm's capacity rather than a market fact.
- Scope negotiation: Experienced C3PAOs help you define the most efficient assessment boundary
Red flags:
- Guaranteeing certification before the assessment
- Pricing significantly below market (may indicate corner-cutting)
- No references from similar-sized organizations
- Unwillingness to share their assessment methodology
CMMC Certification Cost: Planning Your Budget
Here's a practical budgeting framework for 2026:
How ready are you for CMMC?
Take our free readiness assessment. 10 questions, instant results, no email required until you want your report.
Check Your CMMC Readinessor try our free CMMC Cost Estimator→
Step 1: Determine Your Required Level
Review your current and target contracts on SAM.gov. DFARS 252.204-7012 tells you whether you handle covered defense information at all; 252.204-7019 and 252.204-7020 tell you what assessment and SPRS obligations attach and what flows down to your subcontractors. 252.204-7021 is the CMMC clause and names the level a contract requires — read it as the destination rather than today's gate, since Phase 2 is suspended. If your contracts involve CUI, plan for Level 2.
Step 2: Conduct a Gap Assessment
Hire an experienced consultant or use internal resources to assess your current NIST 800-171 posture against all 110 controls. This determines your remediation scope.
Step 3: Build a 12-Month Budget
Start from DoD's published assessment cost for your path and entity size — the figures above — then add the two things its model leaves out: the remediation your gap assessment found, and the affirmation cost in the years between assessments. At Level 2 the right planning horizon is three years rather than twelve months, because the certification assessment is triennial and DoD publishes the three-year totals directly: $104,670 for a small entity on the certification path and $37,196 on the self-assessment path (89 FR 83185–86).
Step 4: Keep Your SPRS Assessment Current
Budgeting once is not enough. DFARS 252.204-7019 conditions award on a NIST SP 800-171 assessment in SPRS that is not more than three years old, unless the solicitation specifies otherwise. Put that expiry in the same calendar as your annual affirmation: an assessment that ages out costs you eligibility silently, without any notice from the buying activity, and the cost of re-establishing it lands in whichever quarter you discover it.
Frequently Asked Questions
How much does CMMC Level 2 certification cost for a small business?
DoD models a Level 2 certification assessment for a small entity at $101,752, with $104,670 over three years once the annual affirmation is included, and the C3PAO's share of that at $31,234 (89 FR 83185-86). Read it as an assessment cost, not an all-in programme cost: DoD excluded NIST SP 800-171 implementation from the Level 1 and Level 2 figures on the basis that it was already required, so whatever remediation your gap analysis finds is additional.
Is CMMC certification a one-time cost?
No. DoD prices Level 2 as a three-year cycle with an annual affirmation in between, and publishes three-year totals accordingly: $104,670 for a small entity on the certification path and $37,196 on the self-assessment path, against $101,752 and $34,277 for the assessment alone (89 FR 83185–86). The affirmation itself is $1,459 a year for a small entity. At Level 3 the recurring side is a different order of magnitude — DoD models $490,000 a year for a small entity to sustain the NIST SP 800-172 requirements, on top of the one-time engineering to build them (89 FR 83188).
Can I self-assess for CMMC Level 2?
Both paths exist at Level 2, and DoD's own sizing shows how lopsided it expected the split to be: of the entities it modelled at Level 2, 118,289 sit on the certification path against 6,759 on self-assessment (90 FR 43573). Which path applies to you is set by the contract, not by preference. Note that CMMC Phase 2 — the phase that would have made C3PAO certification a condition of award — was suspended on 13 July 2026 pending programme review, so read the clauses in your actual solicitations rather than planning against the original schedule.
What is the biggest cost driver in CMMC certification?
For the assessment itself, DoD's model is unambiguous: at Level 2 certification the C3PAO fee is $31,234 of a $101,752 total for a small entity — roughly a third — and the remainder is your own organisation's labour (89 FR 83185–86). For the programme as a whole, the honest answer is that the biggest driver is remediation and that nobody has published a defensible figure for it. DoD excluded implementation from its Level 1 and Level 2 estimates on the basis that FAR 52.204-21 and NIST SP 800-171 were already required, so the largest line item is the one line item the government did not price. Any percentage attached to remediation — including ones this page previously carried — is an estimate, not a measurement.
Does the DoD offer financial assistance for CMMC compliance?
The DoD has acknowledged the cost burden on small businesses and has explored mechanisms through programs like Project Spectrum and the Defense Industrial Base Cybersecurity Program. Some states also offer cybersecurity grants for small defense contractors. Monitor federal and state procurement assistance programs for updates.
How long does the CMMC certification process take?
We have no source for an end-to-end duration, so we no longer publish one. The honest answer is that it is governed almost entirely by how much remediation your gap assessment finds — the one quantity DoD deliberately did not model, because it assumed NIST SP 800-171 was already implemented. What is fixed is the cadence on the far side: the Level 2 certification assessment is performed every three years (32 CFR 170.8), with an annual affirmation in between. The variable you can actually measure early is your prospective assessor's scheduling lead time — ask for it before you build a schedule around it.
Should I hire a CMMC consultant or do it in-house?
One rule constrains the choice before cost does, and it is in the regulation: 32 CFR 170.8(b)(17)(ii)(G) prohibits CMMC ecosystem members from taking part in a Level 2 certification assessment for an organisation they served as a consultant to prepare for any CMMC assessment within the previous 3 years. Readiness work and the certification assessment therefore have to be bought from different firms — the C3PAO that assesses you cannot be the firm that got you ready. On the build-versus-buy question itself, DoD's model assumes a mix and prices the two differently: $260.28 an hour for an external provider, inclusive of overhead, G&A and profit, against in-house hours carrying a 30% fringe and G&A factor (89 FR 83180–81). We publish no saving figure for doing it in-house, because we have no source for one.
CMMC Readiness Checklist
110-control checklist mapped to NIST 800-171. Track your compliance status across all 14 security families.
No spam. Unsubscribe anytime. Privacy Policy
How ready are you for CMMC?
Take our free readiness assessment. 10 questions, instant results, no email required until you want your report.
Check Your CMMC Readinessor try our free CMMC Cost Estimator→

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.
Related Articles

CMMC 2.0 Level 2 in 2026: Timeline, Requirements, and a 4-Step Plan
A practical playbook for achieving CMMC 2.0 Level 2 in 2026: key requirements, realistic timelines, and the steps to prepare for a smooth assessment.

CRM Compliance Checklist for Defense Contractors: Is Yours CMMC Ready?
A practical CRM compliance checklist for defense contractors pursuing CMMC. Validate controls, data flows, and vendor terms before an assessment.

CMMC 2.0 Level 2 in 2026: Timeline, Requirements, and a Real-World Path
An anonymized case study of a defense supplier preparing for CMMC 2.0 Level 2 by 2026—requirements, timeline, decision points, and measurable outcomes.