The Department of Defense’s cost analysis in the 2024 CMMC Program rule (32 CFR Part 170) estimates CMMC costs for a small business in 2023 dollars. It puts a Level 1 self-assessment and affirmation at $5,977 a year, a Level 2 self-assessment at $37,196 over three years, and Level 2 C3PAO certification at $104,670 over three years, including $31,234 for the C3PAO engagement. These estimates cover assessment effort only and exclude implementing the security requirements, which FAR 52.204-21 and DFARS 252.204-7012 already required. No regulation sets C3PAO prices: the rule leaves them to market forces of supply and demand. As of September 2026, the Department of War has suspended the move to CMMC Phase 2 and contracts may designate only Level 1 (Self) or Level 2 (Self), so a C3PAO fee is voluntary unless an existing contract or an unamended solicitation still carries a C3PAO requirement.
Published CMMC cost figures come from three kinds of sources, and they don’t measure the same thing. This page keeps them in separate tables.
- DoD’s estimates. The regulatory impact analysis in the CMMC Program final rule, 89 FR 83092 (October 15, 2024) prices each assessment path in 2023 dollars. The rule treats its figures as representative averages of assessment effort.
- Published market ranges. CMMC Third-Party Assessment Organizations (C3PAOs), consultancies and independent sites publish their own price ranges. Each appears here with its publisher, date and stated basis, and this page never averages them together.
- Deep Fathom planning estimates. These are our budgeting ranges for the implementation and operating work that DoD’s estimates leave out. They’re labeled wherever they appear.
The timing question changed on July 13, 2026, when the Department of War (DoW) suspended the move to CMMC Phase 2. As of September 2026, new designations may be only Level 1 (Self) or Level 2 (Self). C3PAO assessments remain available to contractors that choose them. The requirement to implement NIST SP 800-171 Rev 2 under DFARS 252.204-7012 still applies. To check what a specific solicitation or contract requires, see what to check during the CMMC pause.
What Does the DoD Estimate CMMC Costs by Level?
DoD’s cost analysis for 32 CFR Part 170 estimates each CMMC assessment path for two classes of business, small and other than small. SBA size standards define both. It assumes that “small entities are likely to outsource IT and cybersecurity to an External Service Provider (ESP),” and it states: “These costs include labor and consulting.” All figures are DoD estimates in 2023 dollars.
| Path and cadence | Small entity | Other than small | Source |
|---|---|---|---|
| Level 1 (Self): self-assessment and affirmation every year | $5,977 a year | $4,042 a year | 89 FR 83181 |
| Level 2 (Self): self-assessment every 3 years, affirmation every year | $34,277 in the first year; $37,196 over 3 years | $43,403 in the first year; $48,827 over 3 years | 89 FR 83182 to 83183 |
| Level 2 (C3PAO): certification assessment every 3 years, affirmation every year | $101,752 in the first year, including $31,234 for the C3PAO (3-person team, 120 hours); $104,670 over 3 years | $112,345 in the first year, including $52,056 for the C3PAO (5-person team, 200 hours); $117,768 over 3 years | 89 FR 83185 to 83186 |
| Level 3 (DIBCAC): requires Final Level 2 (C3PAO) status first; DoD assessors perform it free of cost | $9,050 for the assessment; $12,802 over 3 years; plus $2,700,000 nonrecurring and $490,000 a year recurring engineering to implement and maintain the Level 3 requirements | $39,021 for the assessment; $44,445 over 3 years; plus $21,100,000 nonrecurring and $4,120,000 a year recurring engineering | 89 FR 83151, 83187 to 83188 |
For Level 2, the three-year figures add two annual affirmations to the first year. Those run $1,459 a year for a small entity and $2,712 for an other-than-small entity. Level 3 is the only level where DoD priced implementation. The final rule kept these per-entity figures unchanged from the December 2023 proposed rule. DoD explained that they “are intended to be representative and to inform rulemaking.” No official cost analysis has replaced them since the suspension.
For scale, DoD modeled 221,286 entities, 74% of them small. By level, that’s 139,201 at Level 1, 4,000 at Level 2 (Self), 76,598 at Level 2 (C3PAO) and 1,487 at Level 3. It put the annualized public cost at about $3.99 billion, using a 7% discount rate over a 20-year horizon.
The Hours Behind the Small-Entity Estimates
DoD built each estimate from hours multiplied by labor rates. Director time is priced at $190.52 an hour, a small entity’s staff IT specialist at $86.24, and an ESP or C3PAO cybersecurity expert at $260.28. The rule’s $260.28 estimate for outsourced labor “includes the labor rate, overhead expense, G&A expense, and profit.” In-house rates include a 30% factor for fringe and G&A expenses.
| Small-entity path (DoD estimate) | Director | ESP | IT specialist | C3PAO engagement |
|---|---|---|---|---|
| Level 1 (Self), each year | 14 hours | 12 hours | 2.16 hours | None |
| Level 2 (Self), first year | 56 hours | 88 hours | 8.16 hours | None |
| Level 2 (C3PAO), first year | 126 hours | 176 hours | 8.16 hours | 120 hours × $260.28 = $31,234 |
The C3PAO engagement is 31% of DoD’s $101,752 first-year small-entity certification estimate. That leaves $70,518 for the company’s own director and IT time, its ESP support and the affirmation.
What the DoD Estimate Leaves Out
- Implementation. “DoD did not consider the cost of implementing the security requirements themselves because implementation is already required by FAR clause 52.204-21, effective June 15, 2016, and by DFARS clause 252.204-7012, requiring implementation by Dec. 31, 2017” (89 FR 83179). The DoW CIO CMMC FAQ gives the same answer: costs to implement existing safeguarding requirements “are not considered part of the CMMC compliance cost.”
- Maintenance and remediation. No estimate is included for an entity to “maintain implementation of these existing security requirements, or remediate a plan of action for unimplemented requirements.”
- Failed or repeated assessments. “Assessment costs assume the OSA passes the assessment on the first attempt.”
Short of a first-attempt pass, a plan of action and milestones (POA&M) supports a Conditional Level 2 status only when the assessment score divided by the number of Level 2 requirements is at least 0.8. Every open requirement must also be one 32 CFR 170.21 permits on a POA&M. For a C3PAO status, the closeout assessment must happen within 180 days of the Conditional status date. According to the DoW CIO FAQ, the closeout can be finalized in CMMC eMASS one time. If requirements are still NOT MET, the FAQ says, the Conditional status ends and a new assessment is needed.
DoD’s figures also aren’t market prices. They “are representative of average assessment efforts not actual prices of C3PAO services available in the marketplace.” The rule adds: “The size and complexity of the network within the scope of the assessment impacts the costs as well.” This page reports them as published, in 2023 dollars, without an inflation adjustment.
How Much Does a C3PAO Assessment Cost for CMMC Level 2?
No regulation sets the price of a CMMC Level 2 C3PAO assessment. DoD’s cost analysis modeled the engagement at $31,234 for a small entity and $52,056 for an other-than-small one, both in 2023 dollars. The DoD table above shows the team and hours. In the rule’s words, “Market forces of supply and demand will determine C3PAO pricing for CMMC Level 2 certification assessments.” DoD also “declines to speculate about how OSCs and C3PAOs negotiate mutually acceptable terms and conditions for assessment agreements.”
As of September 2026, contracts may not designate Level 2 (C3PAO) during the DoW review. On July 15, 2026, the Cyber AB stated that “all CMMC program elements remain operational and available, to include C3PAO Level 2 certification assessments” (Cyber AB statement). A C3PAO fee is therefore a voluntary cost today. The exceptions are an existing contract or an unamended solicitation that still carries a C3PAO requirement (see the contract situations below).
Published C3PAO Fee Ranges
| Publisher (type) | Date | Company size | Published fee range | Stated basis |
|---|---|---|---|---|
| IBSS Corp (describes itself as an authorized C3PAO) | July 16, 2026 | 1 to 50 employees | $30,000 to $50,000 | Cost data from “over 200 defense industry sources and federal regulatory filings”; method not disclosed; the page does not mention the suspension |
| IBSS Corp | July 16, 2026 | 51 to 200 employees | $50,000 to $80,000 | Same |
| CMMCCost.com (independent site, Digital Signet) | Updated September 14, 2026 | Under 50 employees | $30,000 to $50,000 | Public C3PAO engagement reports, the Cyber AB registry, and practitioner posts on LinkedIn and Reddit |
| CMMCCost.com | Updated September 14, 2026 | 50 to 200 employees | $50,000 to $80,000 | Same |
| CMMCCost.com | Updated September 14, 2026 | 200 to 500+ employees | $80,000 to $200,000+ | Same |
Publisher type is listed because a C3PAO that publishes fee ranges also sells the assessment it prices.
To compare a quote with DoD’s model, divide it by the $260.28 hourly rate. At that rate, $50,000 buys about 192 assessor hours and $80,000 buys about 307, against the 120 and 200 hours DoD modeled. A quote well below DoD’s figure is worth a question about scope and team size. Aprio, which describes its own C3PAO team, wrote in April 2026 that heavily discounted bids can signal reduced scoping discipline, limited assessor experience or incomplete assessments.
What Changes the Fee
DoD names the drivers: “market forces that govern availability of C3PAOs and the size and complexity of the enterprise or enclave under assessment.” Of the major cost categories the rule names, it says all “except the market costs of a C3PAO are controlled by the organization seeking assessment.” Scope is the lever a contractor controls. 32 CFR 170.19 also limits one scoping cost: limited checks of Contractor Risk Managed Assets “shall not materially increase the assessment duration nor the assessment cost.” To shrink the assessed boundary, see reducing CMMC scope with a CUI enclave.
Two other rules affect what a contractor pays.
- The preparer can’t be the assessor. 32 CFR Part 170 requires the accreditation body’s code of professional conduct to prohibit CMMC Ecosystem members from participating in a Level 2 certification assessment where they “previously served as a consultant to prepare the organization for any CMMC assessment within 3 years.” Readiness support and the C3PAO assessment are two engagements and two budget lines. See the three-year consultant rule.
- Earlier DIBCAC High Assessments converted. The conversion covers a DCMA DIBCAC High Assessment aligned with CMMC Level 2 scoping and conducted before the rule took effect on December 16, 2024. A contractor that achieved a perfect score in one, with no open POA&M, received Final Level 2 (C3PAO) status for three years from the date of that assessment (32 CFR 170.20). The rule describes this as a way “to avoid duplication of efforts, thereby reducing the aggregate cost to industry and the Department.” The section makes no provision for later government assessments.
How Much Does CMMC Compliance Consulting Cost?
CMMC compliance consulting and professional support are priced by the hour or by the project. Two 2026 publishers put hourly rates at $250 to $400. DoD’s model gives two anchors for judging a quote. Its outsourced cybersecurity rate is $260.28 an hour. It also assumes that a small business buys 12 ESP hours a year for Level 1 (Self). For a small business, a Level 2 self-assessment is modeled at 88 ESP hours, and a Level 2 certification assessment at 176 hours. At that rate, those hours cost $3,123, $22,905 and $45,809. They cover support for the assessment itself. Remediating gaps isn’t in DoD’s estimate.
| Service | Published range | Publisher (type), date | Stated basis |
|---|---|---|---|
| Hourly consulting rate | $250 to $400 an hour | Kioptrix Labs (consultancy), September 16, 2026 | Presented as a planning assumption |
| Hourly consulting rate | $250 to $400 an hour | Secureframe (compliance software vendor), page modified July 22, 2026 | The page cites the 2023 proposed rule, Reddit, LinkedIn and vendors |
| Advisory review, 8 to 20 hours | $2,000 to $8,000 | Kioptrix Labs, September 16, 2026 | Hours multiplied by the hourly rate |
| Readiness diagnostic, 20 to 40 hours | $5,000 to $16,000 | Kioptrix Labs, September 16, 2026 | Hours multiplied by the hourly rate |
| Readiness review | $5,000 to $25,000 | CMMCCost.com (independent site), September 14, 2026 | Public engagement reports and practitioner posts |
| Remediation sprint, 60 to 120 hours | $15,000 to $48,000 | Kioptrix Labs, September 16, 2026 | Hours multiplied by the hourly rate |
| Broad program support, 150 to 300 hours | $37,500 to $120,000 | Kioptrix Labs, September 16, 2026 | Hours multiplied by the hourly rate |
Two kinds of support have no dated published range in our sources, so these figures are Deep Fathom planning estimates.
- Managed compliance services from an MSP or compliance partner: $1,500 to $6,000 a month, depending on scope. These services usually cover monitoring, evidence management, documentation upkeep and advisory support.
- Documentation written in-house (system security plan, policies, procedures and evidence): 200 to 500 hours of internal labor for a full package. For comparison, DoD’s model assigns 56 to 126 director hours to the Level 2 assessment activity alone.
Before signing a consulting engagement:
- Ask for hours and an hourly rate along with the total. Convert a fixed fee to hours at DoD’s $260.28 rate and compare it with the 88 or 176 ESP hours DoD modeled.
- Which systems and which requirements does the quote cover? Scope drives a consultant’s effort just as it drives an assessor’s.
- Confirm that the system security plan, policies and evidence stay in your own records when the engagement ends. Work product held only in a consultant’s system has to be rebuilt or bought again at reassessment.
For who does what, see what RPOs, MSPs and C3PAOs each do. To decide how much outside help to buy, see choosing between internal work, software and professional review.
Worked Example: CMMC Level 1 Cost for a 10-Person Company
Assume a 10-person company that handles Federal Contract Information (FCI) and no Controlled Unclassified Information (CUI). The company is small under its SBA size standard, has already implemented the FAR 52.204-21 safeguarding requirements, and uses an ESP for support. These assumptions match DoD’s small-entity Level 1 model.
| DoD estimate, small entity, 2023 dollars | Hours | Cost |
|---|---|---|
| Director time at $190.52 an hour | 14 | $2,667 |
| ESP support at $260.28 an hour | 12 | $3,123 |
| IT specialist time at $86.24 an hour | 2.16 | $186 |
| Total per year, including the affirmation | $5,977 | |
| Three years, at one self-assessment a year | $17,931 |
Line items are rounded to the dollar, so they sum to $5,976. DoD’s rule states the total as $5,977, split into $1,803, $2,705 and $909 across the assessment phases plus $560 for the affirmation. About $3,123 of it is paid ESP support. The rest prices the company’s own time.
What changes the figure:
- Doing it without an ESP. DoD’s other-than-small Level 1 estimate uses an in-house director, manager and IT specialist and no ESP: $4,042 a year. Its staffing assumptions describe a larger firm, so treat it as a reference point.
- No POA&M. A POA&M isn’t allowed: “No POA&Ms are permitted for CMMC Level 1.” Every requirement must be MET when the company records its self-assessment in the Supplier Performance Risk System (SPRS) and affirms.
Published Level 1 figures follow in their own table.
| Publisher (type), date | Figure | Scenario or basis |
|---|---|---|
| The Defense Compliance Report (independent trade site), June 3, 2026 | $0 to $2,000 plus internal time | Editorial band for a 1 to 10 person company with FCI only and modern IT already in place |
| The Defense Compliance Report, June 3, 2026 | $2,000 to $10,000 | Editorial band for 10 to 50 people with weak documentation or access controls |
| The Defense Compliance Report, May 27, 2026, verified September 14, 2026 | $5,000 to $20,000 in the first year | Editorial band attributed to public 2026 industry pricing data |
As of September 2026, Phase 1 self-assessment requirements remain in place.
Worked Example: CMMC Level 2 Certification Cost for a 100-Person Engineering Firm
This example assumes an engineering firm with 100 employees that handles CUI under DFARS 252.204-7012. It has implemented the NIST SP 800-171 Rev 2 requirements. As DoD’s model assumes, it passes its assessment on the first attempt.
Step 1: Apply the size test. DoD’s small and other-than-small columns follow the SBA size standards in 13 CFR 121.201. For NAICS 541330, Engineering Services, the size standard is $25.5 million in average annual receipts. Under Exception 1, Military and Aerospace Equipment and Military Weapons, it is $47.0 million. Headcount doesn’t decide the column. A 100-person firm within the receipts standard for its code uses the small-entity figures, and one above it uses the other-than-small figures.
Step 2: Price the path a contract can require today. As of September 2026, a contract may designate Level 2 (Self). Its DoD estimates are the first two rows below.
Step 3: Price certification, if the firm pursues it voluntarily. The table’s remaining rows price it.
| DoD estimate, 2023 dollars | Small firm | Other-than-small firm |
|---|---|---|
| Level 2 (Self), first year | $34,277 | $43,403 |
| Level 2 (Self), 3 years | $37,196 | $48,827 |
| Level 2 (C3PAO), first year | $101,752 | $112,345 |
| Level 2 (C3PAO), 3 years | $104,670 | $117,768 |
| C3PAO engagement inside the certification figure | $31,234 | $52,056 |
| Added cost of certification over 3 years | $67,474 | $68,941 |
Step 4: Add preparation and remediation. DoD’s figures stop at the assessment. What the firm spends to close gaps depends on what its gap assessment finds. Here are published 2026 figures. IBSS’s rows cover 51 to 200 employees, and The Defense Compliance Report’s bands state no company size.
| Publisher (type), date | Item | Published range | Stated basis |
|---|---|---|---|
| IBSS Corp (describes itself as an authorized C3PAO), July 16, 2026 | Preparation and technology, 51 to 200 employees | $65,000 to $120,000 | Cost data from “over 200 defense industry sources and federal regulatory filings”; method not disclosed |
| IBSS Corp, July 16, 2026 | First-year total, 51 to 200 employees | $130,000 to $220,000 | Same |
| The Defense Compliance Report (independent trade site), May 27, 2026 | First year, Level 2 (Self) | $50,000 to $200,000 | Editorial band attributed to public 2026 industry pricing data |
| The Defense Compliance Report, May 27, 2026 | First year, Level 2 (C3PAO) | $75,000 to $300,000 | Same |
For the C3PAO fee itself at this size, IBSS Corp and CMMCCost.com each publish $50,000 to $80,000 (see the fee table above). On the path contracts can require today, a 100-person engineering firm therefore budgets DoD’s $37,196 or $48,827 three-year assessment estimate. Any remediation its gap assessment finds comes on top, along with its annual operating cost. Certification adds about $67,000 to $69,000 in DoD’s model.
Total Cost Ranges by Starting Point
The ranges below are Deep Fathom planning estimates for a first year of CMMC Level 2 work. They include the implementation and operating costs that DoD’s estimates leave out. Use them for a first budget conversation. Then replace them with figures from a gap assessment of your own scope.
| Starting point (Deep Fathom planning estimate) | Preparation and remediation | Ongoing annual operation | C3PAO fee, only if certification is pursued | First-year total with a C3PAO fee |
|---|---|---|---|---|
| Strong existing program (high SPRS score, current documentation) | $20,000 to $50,000 | $18,000 to $48,000 | $31,000 to $60,000 | $70,000 to $160,000 |
| Moderate program (some controls, partial documentation) | $50,000 to $150,000 | $24,000 to $60,000 | $40,000 to $80,000 | $115,000 to $290,000 |
| Minimal program (low SPRS score, limited controls) | $100,000 to $250,000 | $30,000 to $72,000 | $50,000 to $100,000 | $180,000 to $420,000 |
On the Level 2 (Self) path, leave out the fee column. Actual costs depend on the CUI scope, the number of locations, the architecture and the providers you choose.
Annual Cost of Maintaining CMMC Level 2 Compliance
Spread evenly, DoD’s three-year estimates come to about $12,399 a year for a small entity on the self-assessment path. On the C3PAO path, it’s about $34,890 a year. Neither figure covers operating and maintaining the controls.
| DoD estimate, 2023 dollars | Small entity | Other than small |
|---|---|---|
| Annual affirmation, years 2 and 3 | $1,459 | $2,712 |
| Level 2 (Self), three-year estimate divided by 3 | About $12,399 a year | About $16,276 a year |
| Level 2 (C3PAO), three-year estimate divided by 3 | About $34,890 a year | About $39,256 a year |
32 CFR Part 170 sets the cadence. A Level 2 (Self) status needs a new self-assessment every three years. A Level 2 (C3PAO) status needs a new certification assessment within three years of the CMMC Status Date. Affirmations follow every assessment, including a POA&M closeout, and recur annually.
Published operating figures get their own table.
| Publisher (type), date | Figure | Stated basis |
|---|---|---|
| IBSS Corp (describes itself as an authorized C3PAO), July 16, 2026 | $30,000 to $50,000 a year in annual maintenance, 51 to 200 employees | Method not disclosed |
| CyberSheath (managed service provider), August 18, 2026 | $155,204 average annual cybersecurity spending | Survey of 302 U.S. defense contractors, conducted by Merrill Research for CyberSheath; covers all cybersecurity spending, so it is not a CMMC-only figure |
Deep Fathom’s planning estimate for ongoing annual operation is $18,000 to $72,000, depending on the starting point (see the table above). That estimate covers security awareness training and its records, the annual affirmation and evidence refresh. It also covers system security plan updates, policy reviews, vulnerability scanning and remediation, and access reviews. Managed compliance services, if outsourced, add the $1,500 to $6,000 a month estimated in the consulting section.
Costs Required Today and Optional Costs (as of September 2026)
| Cost item | Required today? | Basis |
|---|---|---|
| Implementing NIST SP 800-171 Rev 2 where DFARS 252.204-7012 applies | Yes. DoD doesn’t count it as a CMMC cost | DFARS 252.204-7012; 89 FR 83179; DoW CIO FAQ |
| Level 1 (Self) self-assessment and annual affirmation | Yes, where a contract designates Level 1 (Self) | USW(A&S) memo; 32 CFR 170.15 and 170.22 |
| Level 2 (Self) self-assessment every three years and annual affirmation | Yes, where a contract designates Level 2 (Self) | USW(A&S) memo; 32 CFR 170.16 and 170.22 |
| Level 2 (C3PAO) assessment fee | Not for new designations. Contracts may not designate it during the review, but an existing contract can carry it until its next option or modification (see below). C3PAO assessments remain available voluntarily | USW(A&S) memo; Cyber AB statement |
| Level 3 (DIBCAC) assessment | No. Contracts may not designate it during the review | USW(A&S) memo |
Three contract situations change the answer.
- Self-assessment results and affirmations. DFARS 252.204-7021, as carried in class deviation 2026-O0025 Rev 3, requires the results of a current self-assessment in SPRS for each CMMC unique identifier not covered by a C3PAO or DIBCAC assessment. It also requires an annual affirmation in SPRS. The deviation no longer prescribes 252.204-7019 or 252.204-7020 for new solicitations and prescribes 252.240-7997 for government-led Medium and High Assessments. Existing contracts may still carry 7019 and 7020.
- An existing contract that still designates Level 2 (C3PAO). The implementing memo from the Under Secretary of War for Acquisition and Sustainment, USW(A&S), directs removal of C3PAO requirements at the next option or administrative modification and grants no waivers. Before exercising an option, a contracting officer checks SPRS for a current status at the required level “or higher.” Confirm the order of those two steps with the contracting officer before paying for an assessment.
- A solicitation that still shows Level 2 (C3PAO). The fill-in text of 252.204-7021 and 252.204-7025 wasn’t amended, so an unamended solicitation can still show it. The Self-only limit comes from the July 13 memos and the deviation’s cover memo. Ask the contracting officer before budgeting a C3PAO fee for a bid.
Timing Scenarios After the July 2026 Suspension
The DoW CIO memo of July 13, 2026 set up a CMMC Reform Task Force for a 60-day review. That review ended around September 11, 2026. As of September 24, 2026, no report or decision had been published. The memo ties the suspension to cost. It says the program “imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses.” It also cites “prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines.” The task force’s mandate is to recommend a reformed framework that “replaces prohibitive, third-party compliance models with scalable, realistic security measures.”
In an August 14, 2026 comment letter, the SBA Office of Advocacy states: “Dozens of small businesses have reported that the assessment itself can be prohibitively expensive. Assessor scarcity contributes to this high cost.” It recommended “either a safe harbor or appropriate grandfathering” for organizations that have completed or substantially completed assessments. That recommendation isn’t policy.
This page does not predict the outcome. It sets out three scenarios and the cost consequence of each.
| Scenario | What holds | Effect on costs |
|---|---|---|
| The codified Phase 2 requirement returns | 32 CFR Part 170 as written, with Level 2 (C3PAO) designations resuming on dates the implementing documents set | The C3PAO fee and three-year reassessment become contract costs again, and DoD’s estimates above describe them |
| A reformed framework replaces third-party certification in some form | The task force mandate targets “prohibitive, third-party compliance models” | Assessment costs follow the new model; implementation under DFARS 252.204-7012 is a separate obligation |
| Self-assessment continues, with government-led assessments for selected contractors | Level 1 (Self) and Level 2 (Self), plus government Medium and High Assessments under DFARS 252.240-7997 | Self-assessment and affirmation costs continue, and a C3PAO fee stays optional |
Implementation cost sits outside the scenarios. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 apply today, and the DoW CIO FAQ treats that cost as separate from CMMC.
The voluntary certificate question. Under 32 CFR Part 170 as written, a Final Level 2 (C3PAO) status stays current for up to three years. Those years run from its CMMC Status Date, which is the Conditional date if the status began as Conditional. Keeping it current also requires the annual affirmations. Whether a status earned during the suspension would count under a reformed model hasn’t been decided. Deferring postpones the fee. There’s no official data on how long C3PAO scheduling would take if demand returned.
Market signals. The Cyber AB reported 110 authorized C3PAOs and nearly 2,000 contractors at Level 2 (Final) on July 15, 2026. Trade press reported cancelled C3PAO assessments and C3PAO layoffs after the pause (National Defense, August 17, 2026). No official data exists on current C3PAO lead times or on the direction of fees. C3PAOs set their own schedules and prices.
Reading Published CMMC Cost Figures
- $104,670 is a three-year total, and the assessor’s share of it is $31,234. Figures of $105,000 to $118,000 labeled as the “third-party assessment” cost are DoD’s three-year totals for small and other-than-small entities.
- “2023 DoD estimates” are the final rule’s numbers.
- A published “Level 1 C3PAO fee” has no basis in the rule. Under 32 CFR 170.15, Level 1 status comes from an annual self-assessment.
The SBA’s $593,800 has no published method or source document. A July 13, 2026 SBA news release said “total compliance costs can reach approximately $593,800 per CMMC certification for small firms requiring third-party assessment, and about $388,600 for firms eligible for self-assessment.” A CSIS analysis of July 29, 2026 cites it right after listing remediation and recurring costs, which DoD’s estimates exclude.
Two figures credited to DoD’s CMMC model appear in neither the CMMC final rule nor its proposed rule. “$98,800 per year in recurring compliance labor” comes from the January 2025 proposed FAR rule on CUI, 90 FR 4278. That proposal hasn’t been finalized. It estimated recurring yearly labor for a small non-defense contractor to comply with NIST SP 800-171 Rev 2. After the first year, the proposal put that labor at 1,040 hours at $95. The “$487,970” three-year small-contractor cost on vendor pages starts from DoD’s $104,670 assessment estimate and adds that proposal’s implementation estimates. Those are $148,200 in labor and $27,500 in hardware and software in the first year, then $103,800 a year.
The 2025 DFARS CMMC rule, 90 FR 43560 has its own, narrower analysis. It estimates only the cost of SPRS entries, affirmations and CMMC unique identifiers, at 5 minutes each per system, for 337,968 entities. Technical costs stay in the 32 CFR 170 analysis.
How to Reduce CMMC Costs Without Cutting Corners
Scope first. Buy second. Define the CUI boundary before you buy a SIEM, deploy endpoint tools on every device or migrate to GCC High. Otherwise you can end up securing systems that are out of scope. DoD names the size and complexity of the enterprise or enclave under assessment as a cost driver. A smaller boundary lowers tool, documentation and assessment effort together. Before a Microsoft 365 migration, compare GCC High versus commercial Microsoft 365 against your actual CUI flows.
Start with what you already pay for. A properly configured Microsoft 365 tenant, endpoint protection, backup and vulnerability scanning may already address several requirements. Review what you own before buying.
Check encryption purchases against the FIPS 140-2 transition. FIPS 140-2 modules stay active for 5 years after validation or “until September 21, 2026, when the FIPS 140-2 validations will be moved to the historical list,” according to NIST’s transition page. NIST’s CMVP timeline places all FIPS 140-2 certificates on the Historical List on September 22, 2026. NIST adds: “Even on the historical list, CMVP supports the purchase and use of these modules for existing systems.” No DoW or Cyber AB guidance yet says how assessors treat Historical modules under SC.L2-3.13.11. The DoW CIO FAQ treats replacing a FIPS 140-2 solution with a FIPS 140-3 one as a routine change. That swap doesn’t count as a significant change that requires reassessment. In Deep Fathom’s view, choosing FIPS 140-3 validated modules for new deployments avoids the open question. Still, CMVP notes that FIPS 140-3 module choice may be limited for several years.
Use the no-cost DoW resources. The DoW CIO memo names DoW Cyber Crime Center (DC3) services, the NSA Cybersecurity Collaboration Center and Project Spectrum from the Office of Small Business Programs (OSBP), which “will continue to serve as no-cost resources to ensure companies are supported.”
Fund the annual work at the start. Some programs get a first-year budget and no maintenance budget. Evidence then goes stale and documentation drifts from practice, so the three-year reassessment arrives with much of the preparation to redo. The same risk follows an MSP chosen without CMMC capability, for example one that can’t produce a customer responsibility matrix.
Building the Budget Case for Leadership
Present the budget in three parts.
- The requirement. List what current contracts carry: FAR 52.204-21 (new solicitations may show it as FAR 52.240-93), DFARS 252.204-7012, any CMMC Level 1 (Self) or Level 2 (Self) designation, and any Level 2 (C3PAO) designation an existing contract still carries until it’s modified. Where a contract carries DFARS 252.240-7997, the contractor must also give access for government-led Medium and High Assessments.
- The cost. Separate DoD’s assessment estimate, the implementation cost from your gap assessment, the annual operating cost and the optional C3PAO fee. Mark which lines are required today. The CMMC rule “does not make any change to cost allowability as defined in the FAR 31.201-2 Determining Allowability.”
- The revenue at stake. Total the annual revenue from contracts that carry DFARS 252.204-7012 or a CMMC designation, and set it beside the annual cost.
Next Step
Send us three things: which contracts you hold (FAR 52.204-21 or 52.240-93 only, or DFARS 252.204-7012 with CUI), which systems handle CUI, and your current self-assessment status in SPRS. Our team will review that scope and reply within one business day. Our reply sets out the cost drivers in your environment and what the clauses you list require today. The review covers scope and cost. A self-assessment or a C3PAO assessment determines compliance. Send your CMMC scope to our team or see how Deep Fathom organizes CMMC work.
References · 6 official sources
| Source | What it supports on this page | Type |
|---|---|---|
| CMMC Program final rule and cost analysis, 89 FR 83092 (October 15, 2024) | DoD’s per-entity estimates for every path, the labor rates and hours behind them, the exclusions, the entity counts, the statement that market forces set C3PAO pricing, and cost allowability | Regulation |
| 32 CFR Part 170 (CMMC Program Rule) | Assessment cadence by level, affirmations, POA&M limits, the three-year consultant rule, scoping limits and DIBCAC High conversion | Regulation |
| USW(A&S) memo implementing the CMMC Phase II suspension (July 13, 2026) | The designations contracts may use during the review, and removal of C3PAO requirements from solicitations and contracts | Guidance |
| DoW CIO memo on CMMC reform and the Phase II suspension (July 13, 2026) | The suspension, the cost reasons it gives, the task force mandate and the no-cost DoW resources | Guidance |
| DoW CIO CMMC Frequently Asked Questions (July 2026) | DoW’s answer on what counts as CMMC compliance cost, and the one-time POA&M closeout | Guidance |
| 13 CFR 121.201 (SBA size standards by NAICS code) | The receipts thresholds that decide which DoD cost column applies | Regulation |