If you run a small defense business, CMMC math hits differently. A six-figure first-cycle compliance bill is not a line item on your P&L. It is a wall. This guide is for small contractors who need to know whether CMMC is survivable, and how to make the number work without leaving the DoD market. DoD’s “small entity” figures below follow the SBA small business size standards, not a fixed headcount.
Why small business CMMC cost is different
Three structural reasons. First, fixed costs hit harder. An assessor fee that is a rounding error for a prime is a real percentage of revenue for a 10-person shop. Second, you have fewer people to absorb the work. The owner and one engineer are often doing what a large enterprise has a dedicated GRC team for. Third, you do not have a large slack budget, so you have to be surgical about scope, automation, and what you spend on.
The cost estimate for small entities
Skip the industry guesswork and anchor to the DoD CMMC Program Regulatory Impact Analysis. Its per-entity estimates for a small entity, across the three-year cycle:
| Path | Small entity (3-yr) |
|---|---|
| Level 1 self-assessment | $5,977 |
| Level 2 self-assessment | $37,196 |
| Level 2 Certification (C3PAO) | $104,670 |
Source: DoD CMMC Program Regulatory Impact Analysis (docket DoD-2023-OS-0063), Table 2 (Small Entities), page 14; cost assumptions, page 15.
As of September 23, 2026: on July 13, 2026 the Department of War suspended the CMMC Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and C3PAO or DIBCAC requirements already in solicitations and contracts are to be removed by amendment or modification (DoW CMMC procedures memorandum, cleared for open publication July 13, 2026). The Level 2 Certification figure applies when a C3PAO assessment is required. See the Phase 2 timeline.
These are assessment and affirmation costs only. DoD’s estimates do not include the cost to implement or maintain the security requirements, so if NIST SP 800-171 is not yet implemented, that work comes on top. Three things move where you land: whether CUI is segmented into an enclave, whether you have already implemented NIST SP 800-171, and how much of the preparation you can automate.
Level 1 vs. Level 2 for small business
Look at your contracts. If you only handle Federal Contract Information, information not intended for public release that is provided by or generated for the Government under a contract (FAR 52.204-21), and no CUI, you may be a Level 1 contractor. Level 1 is an annual self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21, with an annual affirmation by your Affirming Official (32 CFR 170.15 and 170.22). Real, but comparatively cheap.
If you handle CUI, controlled technical information, ITAR-controlled drawings, export-controlled data, expect a Level 2 requirement and its 110 NIST SP 800-171 Rev 2 requirements. During the Phase 2 suspension that requirement is a Level 2 self-assessment; C3PAO and Level 3 assessments cannot be designated while it lasts. There is no way to wish your way out of Level 2 if your prime is flowing down CUI. For the line-item view, see our full cost breakdown by level.
Scope reduction: keep CUI in an enclave
Put CUI in an enclave. That is the most important sentence in this article. An enclave is a defined, segmented portion of your environment, virtual desktops in a cloud service approved to hold CUI, a dedicated workstation cluster, or a managed CUI environment, where CUI lives and only authorized users go.
Scope is the multiplier. If CUI is everywhere, your whole business is in scope: every laptop, every email, every drive, every printer. If CUI lives in a small enclave, the assessment scope is that enclave plus the assets that protect it or connect to it (32 CFR 170.19(c)), not your whole business. Fewer assets in scope means fewer to assess, collect evidence for, and remediate.
What you can do yourself, what you should not
Do yourself: scope diagramming, asset inventory, policy approval, evidence collection, user training, internal control monitoring, and POA&M tracking. These are management activities that benefit from your direct involvement.
Buy surgically: cryptographic configuration validation, audit logging architecture, segmentation design, advanced incident response procedures, and the final pre-assessment review. These are technical areas where mistakes are expensive. If you do not have the in-house skill, buy it by the task, not by the month.
How Agent-as-a-Service levels the field
Under traditional consulting, the small contractor’s disadvantage is hours: preparation a prime can absorb is a real cost to a 10-person shop. Agent-as-a-Service (AaaS) is built for that constraint. The agents draft the SSP, map controls, generate the POA&M and build the Evidence Library Index each cycle, and your team reviews and approves rather than authors. Your Affirming Official still decides what to affirm. This is operational leverage, not headcount reduction.
Government resources worth knowing about
Some DoD and SBA programs provide cybersecurity guidance or technical assistance to small businesses in the defense industrial base. Program names, eligibility, and funding status change, so confirm what is active before you rely on it. None of these do the work for you.