All posts
Compliance Frameworks12 min readAug 16, 2026

CMMC certification cost

Ashish / CEO/Co-Founder
CMMC certification cost

How much does CMMC certification cost?

CMMC certification cost can mean three different budgets: the assessment itself, the work required to become ready for assessment, and the recurring cost of staying ready after the first submission or certification. For planning, keep those separate.

The most defensible public figures are DoD’s own regulatory estimates, not vendor market averages. In its 2024 CMMC rule, DoD estimated the following for modeled small entities: $5,977 for a Level 1 self-assessment and initial affirmation annually; $34,277 for a Level 2 self-assessment and initial affirmation; and $101,752 for a Level 2 C3PAO certification assessment and initial affirmation. DoD states that these are regulatory-model estimates in 2023 dollars, based on modeled assumptions, and are not marketplace quotes for every contractor’s all-in readiness program. Source: DoD CMMC Program rule.

That is why a single headline number is weak budgeting. A contractor with a narrow assessment scope, mature NIST SP 800-171 controls, clean documentation, and limited remediation may spend very differently from one with CUI spread across many systems, weak evidence, unmanaged endpoints, and heavy outside support needs.

For many contractors, Level 2 is the central budgeting problem because it applies NIST SP 800-171 Rev. 2 requirements to CUI and may require either a triennial self-assessment or a triennial C3PAO certification assessment, depending on the solicitation. Level 1 is usually simpler to model. Level 3 should be treated separately because it requires a current Final Level 2 C3PAO status and a DIBCAC assessment, not really a simple upgrade to a Level 2 budget.

Certification cost vs. compliance cost: what is actually included?

The assessment fee is only one line in a CMMC budget. Total cost depends on what the organization must do. Before, during, and after the assessment.

Use this vocabulary before comparing quotes:

  • Compliance implementation: Work to put required practices, processes, configurations, and operating routines in place.
  • Gap or readiness assessment: A pre-assessment review to find missing controls, weak evidence, unclear scope, or documentation gaps.
  • Remediation: Fixing deficiencies found during readiness work, such as access control, logging, asset management, encryption, incident response, or vendor-service issues.
  • Documentation and evidence: SSP, policies, procedures, control ownership, evidence collection, and assessor-ready records.
  • Security tools and platforms: Technology used to operate or evidence controls, such as endpoint, identity, logging, vulnerability, backup, ticketing, or evidence-management systems.
  • External support: Consultants, MSPs, MSSPs, or external service providers that help with scoping, operations, readiness, remediation, or evidence preparation.
  • Internal labor: Time from IT, security, compliance, contracts, engineering, operations, and executives.
  • Assessment-related fees: C3PAO or other assessment costs where the solicitation requires that assessment path.
  • Ongoing maintenance: Monitoring, evidence refresh, annual affirmation work, policy updates, control testing, vendor oversight, and issue remediation.
  • Reassessment: Triennial reassessment for Level 2 and Level 3 statuses where applicable.

This distinction matters because DoD’s Level 1 and Level 2 cost analysis excludes implementation, maintenance, and remediation of requirements already required by FAR 52.204-21 or DFARS 252.204-7012. A contractor’s real budget may therefore need separate lines for remediation, technology changes, documentation work, operating labor, and recurring maintenance. Source: DoD CMMC Program rule.

CMMC cost by level: Level 1, Level 2, and Level 3

The required CMMC level and assessment type are solicitation-specific and phased into DoD contracting. Budgeting should start with the expected contract requirement, then the systems and external-service-provider services that process, store, or transmit FCI or CUI for that contract. DoD states that the size and complexity of the in-scope network affect Level 2 certification-assessment costs. Source: DoD CMMC Program rule.

LevelTypical cost categoryWhat it coversRecurrenceAssumptions to verifyBudgeting basis
Level 1Self-assessment and affirmationAnnual self-assessment for FCI and required affirmationAnnualConfirm the solicitation requires Level 1 and identify systems that process, store, or transmit FCIDoD defines Level 1 as an annual self-assessment for FCI
Level 1Readiness and documentationPolicies, procedures, evidence, basic control operation, and internal reviewOne-time setup, then annual upkeepCurrent state of basic security practices and quality of existing recordsOrganization-specific budget line; not just the DoD modeled assessment figure
Level 2 self-assessmentSelf-assessment, reporting, and affirmationAssessment against NIST SP 800-171 Rev. 2 requirements for CUI where the solicitation permits self-assessmentTriennial status, with annual affirmation of continuous complianceConfirm whether the solicitation permits Level 2 self-assessmentDoD rule and DFARS recurrence requirements
Level 2 C3PAOThird-party certification assessmentC3PAO certification assessment where required by the solicitationTriennial status, with annual affirmation of continuous complianceConfirm C3PAO requirement, assessment boundary, CUI flows, external services, and evidence readinessDoD rule distinguishes Level 2 self-assessment from C3PAO assessment
Level 2Implementation and remediationClosing NIST SP 800-171 control gaps, improving configurations, updating workflows, and preparing evidenceMostly one-time, with recurring maintenanceCurrent NIST SP 800-171 posture, SSP quality, POA&M position, technical debt, and internal capacityOrganization-specific; DoD estimates do not equal all-in remediation budgets
Level 2Tools, consultants, MSP/MSSP, and internal laborTechnology, advisory help, managed operations, evidence handling, and staff timeOne-time and annual, depending on the service or toolWhether existing systems can support required control operation and evidenceOrganization-specific; model separately from assessment fees
Level 3Level 2 prerequisite plus Level 3 assessment planningRequires current Final Level 2 C3PAO status before Level 3; DIBCAC assessment appliesTriennial status, with annual affirmation of continuous complianceConfirm the solicitation and whether Level 3 is actually requiredDoD states Level 3 affects a small subset of the DIB
Level 3Additional engineering and operations24 selected NIST SP 800-172 requirements beyond Level 2One-time implementation and recurring engineering/operationsDo not extrapolate from Level 2; validate architecture, staffing, and engineering assumptionsDoD treats Level 3 separately because requirements go beyond prior obligations

Level 1 costs are usually easiest to separate: annual self-assessment and affirmation, plus any internal work needed to maintain the required practices and evidence.

Level 2 requires more careful modeling because CUI scope drives the assessment boundary, evidence burden, technical controls, external-service-provider review, and and potential C3PAO involvement. Level 2 statuses can be current for three years, but annual affirmation of continuous compliance still creates recurring work. Source: DFARS Subpart 204.75.

Level 3 should not be budgeted by taking a Level 2 estimate and adding a simple percentage. DoD states that Level 3 adds 24 selected NIST SP 800-172 requirements, requires Final Level 2 C3PAO status first, and is expected to affect only a small subset of the defense industrial base. Source: DoD CMMC Program rule.

Why official estimates can be lower than real-world CMMC budgets

Official estimates are useful, they answer a narrower question than “What will our company spend to become ready?”

DoD’s modeled Level 2 C3PAO estimate includes contractor labor, external-service-provider support, and C3PAO engagement under modeled assumptions. It does not mean a contractor with poor control maturity, unclear CUI flows, missing documentation, or significant remediation can treat that number as an all-in project budget.

The gap usually comes from five places:

  1. Starting maturity: A contractor with a current SSP, operating controls, and recent evidence has less readiness work than one building the program during the assessment window.
  2. Assessment scope: More systems, users, locations, cloud services, and CUI workflows usually mean more evidence and more coordination.
  3. Remediation depth: Fixing control gaps can require configuration changes, process changes, vendor changes, new tooling, or managed services.
  4. Documentation quality: Existing policies are not enough if they do not match the real environment or cannot support assessment evidence.
  5. Internal labor: Staff time is still a cost even when no invoice is issued.

For CUI environments, NIST SP 800-171 posture and the supporting SSP affect readiness planning. Level 2 assessments and affirmations also have required reporting paths, and permitted POA&Ms must be closed through a follow-up assessment within 180 days for Final status. Source: DoD CMMC Program rule.

Level 2 budget model for a small contractor handling CUI

Use this as an editorial worksheet, not an official DoD calculator. The point is to surface assumptions before you ask for quotes or commit to remediation spend.

Step 1: Define the baseline

InputPlanning questionBudget effect
UsersHow many users access systems that process, store, or transmit CUI?More users can increase identity, endpoint, training, support, and evidence effort
SystemsWhich endpoints, servers, SaaS tools, cloud services, networks, and external services are in scope?More systems expand evidence collection and control operation
CUI flowsWhere is CUI received, stored, processed, transmitted, and archived?Unclear flows create scoping and remediation risk
Assessment typeDoes the solicitation require Level 2 self-assessment or Level 2 C3PAO certification assessment?C3PAO assessment adds third-party assessment planning and fees
Current NIST SP 800-171 postureWhich requirements are already implemented and evidenced?Weak posture shifts budget toward remediation and advisory support
SSP and documentationIs the SSP current, accurate, and aligned to the environment?Poor documentation adds readiness and evidence-preparation work
Remediation depthAre gaps mostly procedural, configuration-based, architectural, or operational?Deeper technical gaps create larger one-time and recurring cost lines
Internal capacityCan internal IT and security staff own implementation, evidence, and maintenance?Limited capacity may increase consultant, MSP, or MSSP reliance
Tooling gapsCan existing tools support required control operation and evidence?Gaps may require new tooling, configuration work, or service changes
Recurring obligationsWho will maintain evidence, monitor controls, support annual affirmation, and prepare for reassessment?Recurring work should be budgeted separately from the first assessment

Step 2: Choose the scenario that most resembles your environment

ScenarioAssumptionsBudget shape
Narrower CUI scope, stronger controlsCUI is limited to a defined set of systems; existing controls are mostly operating; SSP and evidence are current; internal team can support readinessBudget is weighted toward assessment preparation, evidence validation, limited remediation, annual maintenance, and eventual reassessment
Broader CUI scope, moderate remediationCUI appears in multiple systems or workflows; some NIST SP 800-171 practices are implemented but not consistently evidenced; documentation needs cleanup; outside readiness help is likelyBudget includes readiness assessment, documentation rebuild, targeted remediation, possible tooling or service changes, internal labor, assessment fees, and recurring evidence maintenance
Weak starting posture, significant remediationCUI scope is unclear or broad; SSP is incomplete or stale; many controls are not operating or evidenced; internal staff lack capacityBudget is driven by scoping work, program buildout, technical remediation, external advisory or managed support, documentation, assessment preparation, recurring operations, and reassessment planning

Do not assume that changing the assessment boundary automatically lowers cost. Boundary design can change the cost model, but it has to be technically accurate and contractually appropriate. Validate it before building a budget around it.

Step 3: Separate first-year and recurring costs

A small Level 2 contractor should normally model at least four buckets:

  1. First-year readiness: scoping, gap assessment, SSP cleanup, policies, procedures, evidence preparation, and remediation planning.
  2. One-time remediation: technical fixes, configuration changes, workflow changes, vendor-service changes, or tooling deployment.
  3. Assessment path: self-assessment effort or C3PAO assessment preparation and fees, depending on the solicitation.
  4. Recurring operations: annual affirmation support, control monitoring, evidence refresh, issue tracking, documentation maintenance, and triennial reassessment preparation.

This structure is more useful than asking for “the average Level 2 cost,” because it shows which assumptions are driving the budget.

How to build a defensible CMMC budget

A defensible budget should let leadership see what is known, what is assumed, and what still needs validation.

  1. Identify the required CMMC level. Tie the budget to a real or expected solicitation rather than a generic maturity target.
  2. Confirm whether CUI is in scope. If CUI is involved, map where it is received, stored, processed, transmitted, and archived.
  3. Define the assessment boundary. Include relevant systems and external-service-provider services that process, store, or transmit FCI or CUI.
  4. Assess current NIST SP 800-171 posture. For Level 2, separate implemented controls from controls that are only documented or planned.
  5. Review SSP and evidence quality. Budget for rewriting or validating documentation if it does not match the actual environment.
  6. Separate one-time remediation from recurring operations. A firewall change, identity cleanup, or logging rollout is different from the labor to monitor and maintain it.
  7. Estimate internal labor separately from external spend. Internal work still consumes budget capacity, even when it does not appear as a vendor invoice.
  8. Include assessment and reassessment. Level 1 status is current for one year. Final Level 2 self-assessment, Level 2 C3PAO, and Level 3 DIBCAC statuses are current for three years, subject to annual affirmation of continuous compliance. Source: DFARS Subpart 204.75.
  9. Add contingency for readiness findings. Use a separate contingency line for gaps discovered during scoping, evidence review, or pre-assessment work.

The output should be a budget with named assumptions, not just a quote total.

Where tools, consultants, and managed services fit into CMMC cost

Tools, consultants, MSPs, and MSSPs can all be legitimate parts of a CMMC budget, but they solve different problems.

Tools may help organize control ownership, evidence, documentation workflows, monitoring, and recurring maintenance. Consultants may help with scoping, readiness assessment, documentation, remediation planning, and assessment preparation. MSPs or MSSPs may be relevant when the organization lacks internal capacity to operate security controls consistently.

None of these replaces ownership of the environment, implementation of required practices, or an assessment where the solicitation requires one. Choose support based on the actual gap: messy evidence, technical remediation, limited staff capacity, unclear scope, or ongoing operations.

Ciphrix’s operational view is that compliance cost is easier to manage when evidence, control ownership, documentation, and maintenance are treated as living operations rather than a last-minute document project. That perspective can help structure the work before selecting assessors, tools, or managed services, but it does not replace professional judgment or required assessment activity.

Final budgeting takeaway

The useful question is not “What is the average CMMC cost?” It is: What do our required level, CUI scope, assessment type, current maturity, evidence posture, remediation needs, labor capacity, and recurring obligations make likely?

Before committing to an assessor, tool, or major remediation project, run a scoped readiness review and build the budget in separate lines for assessment, implementation, remediation, documentation, tooling, internal labor, maintenance, and reassessment. That is usually how you get to a budget leadership can defend.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents