If you sell to the Department of Defense, CMMC is no longer a someday problem. The program is a final rule (32 CFR Part 170), and the question worth asking is what it actually costs.
Status note, September 2026. On July 13, 2026 the Department of War suspended the November 2026 Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and Level 2 (C3PAO) requirements are to be removed from active solicitations and existing contracts (DoW CIO memorandum, Attachment 1, cleared for open publication July 13, 2026). This guide describes the Level 2 (C3PAO) path as written in 32 CFR Part 170. See what the suspension changed and what still applies.
Here is the answer from the DoD’s own figures, with the numbers broken out, the line items a quote can leave off, and the levers that bring the total down.
The Four Cost Buckets
Every CMMC Level 2 certification budget breaks into the same four buckets:
- Readiness and gap assessment. Figuring out where you stand against the 110 NIST SP 800-171 Rev 2 requirements that define Level 2 (32 CFR 170.14(c)(3)). Done by hand, this is a labor line item that scales with how complex your environment is.
- Remediation and technology. Closing the gaps: access controls, logging, encryption, CUI handling. This bucket varies widely, from minimal spend for a mature shop to a large investment for a contractor starting from scratch.
- Documentation. Your System Security Plan (SSP), policies, procedures, and evidence, measured in staff or consultant hours.
- The C3PAO assessment itself. The fee paid to a CMMC Third-Party Assessment Organization (C3PAO) to conduct the certification assessment.
What the DoD Itself Published
You do not have to rely on vendor quotes to anchor a budget. The regulatory impact analysis in the CMMC final rule put figures on the cost of each path. They assume the requirements are already implemented, so remediation is on top; treat them as a planning floor.
| Path | Small entity | Larger entity |
|---|---|---|
| Level 2 Certification (C3PAO), 3-year cycle | $104,670 | $117,768 |
| C3PAO assessor engagement alone, per assessment | $31,234 | $52,056 |
| Level 2 Self-Assessment, 3-year cycle | $37,196 | $48,827 |
| Level 1 Self-Assessment, each annual assessment | $5,977 | $4,042 |
Source: DoD regulatory impact analysis in the CMMC Program final rule, 89 FR 83092 (October 15, 2024), at 83181 to 83186.
Notice the shape of the small-entity certification number. Of the $104,670 three-year total, the assessor engagement is $31,234. The published breakdown puts planning and preparing at $20,699, the organization’s labor during the assessment (a director plus an outside service provider) at $45,509, reporting at $2,851, and three years of annual affirmations at $4,377. The assessment fee is real, but the preparation and support labor is the larger share. That is the part you can compress.
Get a directional read before you write a check to anyone. The free gap check is a first read: ten questions on ten NIST SP 800-171 requirements, a directional self-assessment, not an official SPRS score.
Run the free gap check →The Line Items a Quote Can Leave Off
- Scoping mistakes. Assess your whole network when a CUI enclave would do, and you pay to certify systems that never needed it.
- Consultant hour creep. Readiness work billed hourly can expand, and documentation rework adds hours.
- Conditional assessments. A Conditional status means remediation plus a POA&M closeout assessment within 180 days (32 CFR 170.17 and 170.21).
- The scheduling tax. C3PAO capacity is finite, and a solicitation that requires a status you do not yet hold is one you cannot win.
How to Cut the Cost Without Cutting Corners
1. Shrink the scope
Scoping is a major cost lever. If CUI only touches a defined enclave, the Level 2 assessment scope is built around that enclave and the assets that provide its security functions or can reach CUI, rather than the whole company (32 CFR 170.19(c) sets which asset categories are in scope). Get the scoping decision right before you spend a dollar on remediation. Our small-business cost breakdown walks through why this matters most when you are small.
2. Take the labor out of documentation and evidence
This is where Agent-as-a-Service (AaaS) changes the math. Much of the preparation cost is human hours spent on gap analysis, SSP drafting, policy writing, and evidence collection, work that is systematic and repetitive. Enclave AI on ai4cmmc.ai does that work on a schedule: it re-scans the read-only configuration of the sources you connect about every seven days, measures the requirements those sources can show, takes the rest from your attestations and evidence, drafts and re-issues your SSP and POA&M on your tier’s cycle, and hands your team the package for review. Your Affirming Official decides what is affirmed.
3. Stay audit-ready, not audit-panicked
Certification is not a one-time event. Annual affirmations and a three-year reassessment cycle (32 CFR 170.17) mean readiness has to be maintained between assessments, not rebuilt from scratch before each one.
The Bottom Line
Budget against the published figures, not a vendor's worst-case quote. The assessment fee is the part you cannot automate. The preparation cost is the part you can reduce. For the certification path specifically, see our CMMC Level 2 certification cost breakdown, and if you want to know how 2026 market conditions shift the picture, read what changed in 2026.