CMMC Cost Estimator — DoD’s own numbers

Every figure below is priced by the Department of Defense in the CMMC final rule’s Regulatory Impact Analysis, quotable line by line back to the Federal Register. Nothing here is a vendor estimate; the few figures we compute from DoD’s line items are marked Derived.

Note: third-party (C3PAO) certification was suspended as a condition of award on July 13, 2026 pending review, so these figures are planning numbers rather than a bill you owe today. NIST 800-171 implementation, SPRS scoring, and annual affirmations remain in force — and DoD’s Level 1 and Level 2 figures below cover only the assessment, so the implementation work is real spend they do not price.

Inputs

Entity size

These are the only two brackets DoD’s analysis uses, and they follow the SBA size standard for your NAICS code rather than a headcount. DoD counted 337,968 affected entities, of which 229,818 are small.

Source: DFARS CMMC Acquisition Final Rule RIA, 90 FR 43573

Assessment path

These four rows are DoD’s own, not our categories.

How many contractors are on this path

DoD projects 118,289 entities (35% of the defense industrial base) on level 2 certification, of which 80,436 are small.

Source: DFARS CMMC Acquisition Final Rule RIA, 90 FR 43573

DoD’s modeled cost

Level 2 certification assessment · every 3 years

$101,752

Small entity · Level 2 — certification assessment (C3PAO)

Source: DoD CMMC Final Rule RIA, 89 FR 83185–86

Three-year cycle

$104,670

DoD prints this three-year total itself.

Recurring, per year

$1,459

What DoD models you keep paying after the assessment.

RIA line items

Level 2 certification assessment

$101,752 every 3 years

Assessment

One triennial certification assessment performed by a C3PAO. Still assessment cost only: DoD did not include the cost of implementing the 110 requirements at this level.

C3PAO assessor fee (inside the total above)

$31,234

DoD modeled a 3-person / 120-hour assessment team for a small entity and a 5-person / 200-hour team otherwise, at the $260.28 external rate.

Source: DoD CMMC Final Rule RIA, 89 FR 83185–86

Source: DoD CMMC Final Rule RIA, 89 FR 83185–86

Level 2 annual affirmation

$1,459 per year

Recurring

Filed each year between assessments to affirm continued compliance.

Source: DoD CMMC Final Rule RIA, 89 FR 83185–86

Outside-provider share

Derived

DoD itemizes this path by labor category, so the portion it assumes you buy from an external service provider separates out exactly:

$45,809

External provider (derived)

$31,234

C3PAO assessor (DoD)

$24,709

Your own staff (derived)

Separated from DoD’s labor-category itemization; the share works out to about 176 external-provider hours at $260.28/hr. The three shares add back to DoD’s published $101,752 exactly.

The rule bars CMMC ecosystem members from assessing an organization they consulted for within the previous 3 years, so certification assessment and readiness work must be bought from different firms.

Source: Derived from DoD CMMC Final Rule RIA, 89 FR 83185–86; CMMC Final Rule, 89 FR 83221 (32 CFR 170.8(b)(17)(ii)(G))

Across the 80,436 small entities DoD projects on this path, that share annualizes to roughly $1,228,230,908 a year of outside-provider work.

About these numbers

Source document: Cybersecurity Maturity Model Certification (CMMC) Program, final rule, 89 FR 83092 (Oct. 15, 2024), cost narrative at 89 FR 83178–83189; entity counts from the companion DFARS acquisition rule, 90 FR 43560 (Sept. 10, 2025). DoD priced external-provider work at $260.28/hr — a rate set by the government, not by us.

DoD’s own caveats

  • The Level 1 and Level 2 figures are assessment cost only. DoD excluded the cost of actually implementing FAR 52.204-21 and NIST SP 800-171 R2, because it assumed those had been required since 2016 and 2017. Only Level 3 carries an implementation line.Source: DoD CMMC Final Rule RIA, 89 FR 83178–83189
  • DoD’s estimates assume the assessed organization passes on the first attempt.Source: DoD CMMC Final Rule RIA, 89 FR 83178–83189
  • DoD, verbatim: “Some public comments received reflect a misinterpretation of the cost estimates that accompany this rule, which are representative of average assessment efforts, and do not include actual prices of C3PAO services available in the marketplace. Market forces of supply and demand will determine C3PAO pricing.”Source: DoD CMMC Final Rule RIA, 89 FR 83178–83189
  • The external-provider hours are DoD’s assumption about how much of the work an average organization outsources, priced at a single blended $260.28/hr that DoD says “includes the labor rate, overhead expense, G&A expense, and profit.” In-house hours instead carry a 30% fringe and G&A factor.Source: DoD CMMC Final Rule RIA, 89 FR 83180–81
  • The rule is designated major — “expected to have annual effect on the economy of $100M dollars or more.”Source: DoD CMMC Final Rule RIA, 89 FR 83178–83189
  • DoD’s 20-year aggregate cost tables are published in the Federal Register as images and are not machine-readable, so no 20-year CMMC total appears in this tool. Anyone quoting one is not quoting the public text.Source: DoD CMMC Final Rule RIA, 89 FR 83178–83189

The hourly rates DoD assumed

  • External service provider / C3PAO assessor$260.28
  • Director$190.52
  • Manager$95.96
  • Staff IT$97.49
  • Staff IT (small business)$86.24
  • Senior IT$81.96
  • IT level 2$54.27
  • IT level 1$36.32

Source: DoD CMMC Final Rule RIA, 89 FR 83180–81

Figures marked Derivedare our arithmetic on DoD’s published line items, not DoD-published totals.

Save Estimate

Create a free account to save and revisit your estimates

Create a free account to save your cost estimates and revisit them anytime.

Join free →

Where These Numbers Come From

Every figure in this estimator is one DoD published itself. To issue the CMMC final rule, DoD had to price it, so the rule carries a Regulatory Impact Analysis with per-entity cost estimates broken out by labor category, hour count, and hourly rate — Cybersecurity Maturity Model Certification (CMMC) Program, 89 FR 83092 (Oct. 15, 2024), cost narrative at 89 FR 83178–83189. The entity counts come from the companion DFARS acquisition rule, 90 FR 43560 (Sept. 10, 2025).

That matters for two reasons. Any number here is quotable straight back to the government’s own rulemaking rather than to a vendor’s “typical cost” claim — and DoD’s model prices the work above what an independent firm charges, so the honest number is also the useful one.

DoD’s brackets are its own: small entity versus other than small, by SBA size standard rather than headcount, across the four assessment paths the rule defines. Read the caveats in the tool before quoting anything — in particular, DoD’s Level 1 and Level 2 estimates cover assessment effort only and exclude the cost of implementing NIST SP 800-171, which it assumed had been required since 2017. Where this tool computes something from DoD’s line items rather than reporting one directly, it is labeled derived.

Turn this gap analysis into a remediation plan

The CMMC Cost Estimator is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.

Book a 25-min assessment

Related: how much CMMC certification costs — DoD’s own priced figures