You run a 15-person machine shop or a 40-person engineering firm. You make parts or design subsystems for a DoD prime. You handle Controlled Unclassified Information. And a CMMC quote just landed that made you wonder whether it is time to stop bidding government work.
Before you decide, check what the quote assumes. Here is what the DoD estimates CMMC Level 2 costs a small defense contractor, why a quote can run higher, and how to bring the preparation bill down without cutting corners on the assessment.
Status note, September 2026. On July 13, 2026 the Department of War suspended the November 2026 Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and Level 2 (C3PAO) requirements are to be removed from active solicitations and existing contracts (DoW CIO memorandum, Attachment 1, cleared for open publication July 13, 2026). This guide describes the Level 2 (C3PAO) path as written in 32 CFR Part 170. See what the suspension changed and what still applies.
The Honest Number for Small Defense Contractors
Start from what the DoD published rather than a vendor's worst case. The regulatory impact analysis in the CMMC final rule puts the three-year Level 2 certification cost for a small entity at $104,670, with the C3PAO engagement at $31,234 and the balance in planning, assessment-support and reporting labor, including outside help, plus annual affirmations. The estimate assumes the NIST SP 800-171 requirements are already implemented, so remediation is on top.
| Path (3-year cycle) | Small entity |
|---|---|
| Level 2 Certification (C3PAO) | $104,670 |
| C3PAO assessor engagement alone | $31,234 |
| Level 2 Self-Assessment | $37,196 |
Source: DoD regulatory impact analysis in the CMMC Program final rule, 89 FR 83092 (October 15, 2024), at 83183 and 83185 to 83186.
Treat those as a planning floor for the assessment itself. A major lever you have is being precise about which systems actually touch CUI.
Why a Small Contractor's Quote Can Run High
- The requirement count does not shrink with headcount. Level 2 is the 110 NIST SP 800-171 Rev 2 requirements (32 CFR 170.14(c)(3)) whether you have 15 employees or 1,500, so the documentation covers the same requirement set at any size.
- The quote may assume your entire network is in scope. If you have not enclaved CUI to a segmented environment, the assessment boundary is everything, and cost scales with the boundary.
- Per-seat tool licenses can add cost on top of consulting hours.
Each of these is worth checking before you sign.
The Five Line Items in a Small-Business CMMC Budget
Assessment fees
The fee paid to a CMMC Third-Party Assessment Organization (C3PAO) for the Level 2 certification assessment. The DoD estimate puts the small-entity C3PAO engagement at $31,234 for the assessment that covers each three-year cycle. Ask any C3PAO for its current scheduling lead time before you plan around a date.
Remediation and tooling
Multifactor authentication, FIPS-validated cryptography protecting CUI at rest and in transit, malicious code protection such as EDR, centralized logging, identity and access management, configuration management. What you already run changes this line; see GCC High cost for the cloud decision. Enclave AI’s connectors read commercial AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike; GCC High and GovCloud tenants cannot be connected today.
Documentation
The System Security Plan (SSP), Plan of Action and Milestones (POA&M), supporting policies, and an evidence library mapped to all 110 requirements. Much of this work is repetitive, which is where an AI-native platform can take labor out.
Ongoing monitoring
The annual affirmation that 32 CFR 170.17 requires, periodic evidence refresh, and scheduled re-checks of configuration. Skip it and your evidence goes stale before the next assessment.
Internal time
The cost contractors forget to budget: your team's hours across IT, operations, and executive review. The DoD estimate counts assessment-support labor, your director plus an outside service provider, at $45,509 for the small-entity certification assessment, the largest single component of the $104,670 total (89 FR 83092, at 83186).
Before you take any quote to your board, get a directional read on your gap to Level 2. The free gap check is a directional self-assessment, not an official SPRS score.
Run the free gap check →The Enclave Strategy: Cut the Scope, Cut the Cost
An enclave is a segmented environment that contains all CUI handling and processing. Email, file storage, engineering applications, ERP modules, anything that touches CUI lives inside the enclave. Everything else stays outside the audit boundary.
For a small contractor, an enclave can reduce the assessment scope from every endpoint and server in the company to a defined set of users and applications. Remediation can drop too, because you are securing a smaller surface area. Government cloud tenants such as Microsoft 365 GCC High and AWS GovCloud are one approach; any design needs careful identity and data-flow work. Enclave AI cannot connect to GCC High or GovCloud tenants today, so requirements inside such an enclave are answered from your own evidence rather than measured.
Why Spreadsheets Cost More Than They Look
A manual workflow looks like this: a consultant interviews your team, copies what they hear into a spreadsheet mapped to NIST 800-171, then transposes the spreadsheet into the SSP and POA&M. The bill is hours times rate.
An AI-native platform works from measurement instead. On a readiness subscription, Enclave AI reads the read-only configuration of the commercial cloud and identity sources you connect, keeps the relevant excerpt of the API response behind each measured finding on file with a SHA-256 hash, and drafts the SSP and POA&M from those findings plus your own attestations for what no connected source can show. Your Affirming Official reviews and decides; no consultant retypes screenshots. The labor it targets is documentation and ongoing monitoring, the work measured in hours. That is the same dynamic our small-business cost article explains.
An Example 90-Day Plan for a 25-Person Contractor
An illustration, not a benchmark: your starting posture and scope set the real calendar.
- Days 1 to 14: Scope CUI. Identify every system, application, and user that touches CUI. Decide enclave versus full-network. The free gap check is a quick directional read on ten requirements, not a scoping exercise.
- Days 15 to 45: Stand up the enclave if you chose one. Migrate CUI workloads in. Implement MFA, endpoint protection, logging, and FIPS-validated cryptography.
- Days 46 to 75: Generate the SSP and POA&M from measured findings where your sources can be connected and from your evidence where they cannot. Close priority gaps. Run an internal pre-assessment.
- Days 76 to 90: Engage a C3PAO if your contracts call for Level 2 (C3PAO), or complete the Level 2 self-assessment and affirmation if they call for Level 2 (Self). Put ongoing monitoring on a stated schedule.
This plan does not promise a passing score; no honest platform can. What it does is put your preparation on a stated schedule so your people spend more of their hours on decisions and less on paperwork. Readiness subscriptions are billed annually, with a month-to-month option on every tier. For the broader cost picture, see CMMC certification cost and the CMMC Level 2 certification cost breakdown.