If you supply the Department of Defense and you handle Controlled Unclassified Information, CMMC Level 2 is the level your contracts can call for. The question is what it costs. The honest answer: it depends on how much CUI you touch, how clean your current environment is, and how much you do yourself versus pay someone else to do. This guide gives you the figures you can actually cite, the line items behind them, and one cost that is easy to leave out of the budget.
The short answer: the DoD's cost estimates by level
The figures with a named primary source come from the DoD CMMC Program Regulatory Impact Analysis. Per entity, per assessment, at each level's required frequency (Level 1 is annual; the Level 2 figures are three-year totals including annual affirmations):
| Path | Small entity | Larger entity |
|---|---|---|
| Level 1 self-assessment | $5,977 | $4,042 |
| Level 2 self-assessment | $37,196 | $48,827 |
| Level 2 Certification (C3PAO) | $104,670 | $117,768 |
Source: DoD CMMC Program Regulatory Impact Analysis (docket DoD-2023-OS-0063), pages 13 and 14. The estimates cover assessment, reporting and affirmation, not the cost of implementing or remediating the requirements (pages 15 to 16).
Within Level 2 Certification, the C3PAO assessor engagement alone is estimated at $31,234 for a small entity and $52,056 for a larger one. The rest is your own staff time and outside service-provider support to prepare for and support the assessment, plus affirmations (pages 25 to 26).
While the July 13, 2026 suspension of CMMC Phase 2 is in effect, solicitations may require only CMMC Level 1 (Self) or Level 2 (Self) assessments, not Level 2 (C3PAO) or Level 3 (DIBCAC) (Department of War memorandum, July 13, 2026, Attachment 1).
What actually drives CMMC compliance cost
Five variables move the number. Understand these and the quotes you get stop looking random.
1. CUI scope and network segmentation
Every system, application, person, and location that processes, stores, or transmits CUI is in scope, and each one raises assessment hours, evidence collection, and remediation. Segmenting CUI into a defined enclave keeps the scope small. Letting CUI live in shared email, shared drives, and general-purpose laptops makes the scope the whole company (32 CFR 170.19).
2. Existing maturity vs. NIST SP 800-171
CMMC Level 2 is built on the 110 controls in NIST SP 800-171. If your environment was already implementing 800-171 with a current SSP, POA&M, and evidence, your gap-to-Level-2 cost is mostly proof and process. If your SSP is two years old or your POA&M has stale open items, you are paying to build foundation work, not just to certify it.
3. Internal staffing vs. outside help
A senior IT or security person who can own the SSP, POA&M, and audit prep reduces the outside hours you buy. The opposite is also true: every gap in your internal capability becomes billable hours. Documentation is part of that outside work, and it is the part agents can draft for your team to review.
4. C3PAO assessment fees
Third-party assessment for Level 2 is a separate line from remediation and preparation. The DoD estimates the assessor engagement at $31,234 for a small entity and $52,056 for a larger one, and the actual fee is set by the C3PAO you engage.
5. Ongoing maintenance and POA&M closure
CMMC is not a one-time event. You re-affirm annually and re-assess every three years for Level 2. Any control gap that returns during ongoing monitoring becomes a re-work item, so budget for a recurring run-rate, not just the event.
Level 1 cost breakdown
Level 1 applies to contractors handling Federal Contract Information only, no CUI. It is an annual self-assessment against the 15 basic safeguarding requirements drawn from FAR 52.204-21, affirmed by a senior official (32 CFR 170.22). The DoD estimates each annual self-assessment and affirmation at $5,977 for a small entity (RIA page 20). Do not treat Level 1 as free: it is annual, it is affirmed, and a false affirmation carries real legal exposure; the DoD's final rule notes that the False Claims Act imposes liability for knowingly submitting false claims to the government (89 FR 83092).
Level 2 cost breakdown
Level 2 is where the real money sits. The 110 NIST SP 800-171 controls span access control, audit and accountability, configuration management, identification and authentication, incident response, and more. The DoD's three-year Level 2 Certification estimate is $104,670 for a small entity and $117,768 for a larger one. Because the 110 requirements are fixed, scope is the variable you control most directly. See our small-business guide for the enclave-first approach.
Level 3 cost
Level 3 adds a subset of NIST SP 800-172 enhanced controls on top of Level 2 and is assessed by DIBCAC, not a C3PAO. It is expected to apply only to a small subset of contractors, and unlike the Level 1 and Level 2 figures, the DoD's Level 3 estimate includes the cost of implementing and maintaining the added requirements (RIA page 16). A Final Level 2 (C3PAO) status for the same scope is a prerequisite (32 CFR 170.18). Level 3 applies only where a contract requires it, and during the July 13, 2026 suspension no solicitation may designate it.
The hidden cost that is easy to miss
Lost time. Not outside hours, lost time. Compliance work pulls senior engineers, IT leadership, and the owner away from delivery and sales. A CMMC budget can hold on consulting and still be blown by a delay that pushes a contract decision into the next fiscal year. A realistic program plan protects revenue-generating capacity.
How Agent-as-a-Service changes the math
When CMMC preparation is bought as consulting hours, every SSP paragraph, every POA&M item, every evidence task is billable. Agent-as-a-Service (AaaS) inverts that. An agent that works from the 110 requirements and their assessment objectives can draft your SSP, generate your POA&M, map your existing controls, and index your evidence against the objectives without billing by the hour. Your Affirming Official still makes every decision. ai4cmmc.ai is AaaS for exactly this work: not software you have to learn, not a consultant you have to manage, but a system that produces the artifacts and re-issues them on your tier's cycle while your team reviews them and operates the controls.