Small defense contractors are stuck between two walls: CMMC Level 1 and Level 2 self-assessment requirements can appear in the DoD contracts they bid on, and the budget can look prohibitive for a 12-person shop. This guide sets out the DoD's own cost estimates at small-business scale and where you can control cost.
Short version: CMMC recurs, with annual affirmations and, for Level 2, a three-year assessment cycle (32 CFR 170.22), so treat it like a system rather than a one-time project, and scope it correctly from day one.
Step zero: figure out which level applies to you
Cost depends first on whether your contracts have you handling Federal Contract Information (FCI) only or Controlled Unclassified Information (CUI). Contracts that involve FCI only are expected to call for Level 1; contracts that involve CUI call for Level 2 or, for a small subset of contractors, Level 3 (DoD Regulatory Impact Analysis, page 16). The solicitation names the level. Check your DFARS clauses and ask your primes what is flowing down.
Mis-scoping in either direction is expensive. Over-scope and you pay to assess and protect assets that did not need to be in scope. Under-scope and assets that do handle CUI are left out of your preparation. See Level 1 vs. Level 2 for the dividing line.
Level 1 cost reality for small business
Level 1 is an annual self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21, with a senior official affirmation. There is no C3PAO fee. The real costs are documentation, the basic safeguards the clause lists (limiting access to authorized users, identifying and authenticating users, timely flaw remediation, malicious code protection), and the time of whoever owns IT.
The DoD Regulatory Impact Analysis estimates a small entity's cost for each annual Level 1 self-assessment and affirmation at $5,977 (RIA page 20). That estimate assumes the 15 requirements are already implemented, so any remediation you still need comes on top (RIA pages 15 to 16).
Level 2 cost reality for small business
Level 2 is where small businesses see sticker shock. You are now working against the full set of 110 NIST SP 800-171 controls and substantially more documentation. The DoD estimates for a small entity, across the three-year cycle:
| Path | Small entity (3-yr) |
|---|---|
| Level 2 self-assessment | $37,196 |
| Level 2 Certification (C3PAO) | $104,670 |
Source: DoD CMMC Program Regulatory Impact Analysis (docket DoD-2023-OS-0063), page 14. The estimates cover assessment, reporting and affirmation; they exclude the cost of implementing or remediating the requirements (pages 15 to 16).
Scope drives the rest: under 32 CFR 170.19, the Level 2 assessment scope includes the assets that process, store or transmit CUI, the assets that protect them, assets that can handle CUI but are kept from it by policy, and specialized assets such as OT and test equipment, so whether CUI sits in a defined enclave or sprawls across your whole environment decides how much gets assessed.
Where small businesses actually waste money
- Treating compliance as an IT project. CMMC touches HR, legal, contracts, IT, and the executive. If only IT owns it, work outside IT can be missed and then redone.
- Buying tools before scoping. Map the data flow first, pick tools second. A tool stack bought before the CUI flow is known may not cover the assets that matter.
- Skipping the gap assessment. Booking an assessor without a real readiness pass is an expensive way to learn what is missing.
- No system for maintaining evidence. Re-collecting screenshots and logs every year is a hidden tax.
The enclave-first strategy
Carve out a small, deliberate environment where CUI lives, with a separate identity boundary, device pool, and file storage. Assets that cannot process, store or transmit CUI and do not protect the enclave fall outside the Level 2 assessment scope (32 CFR 170.19). Confirm the scoping interpretation with your assessor or counsel before you build.
What an AaaS platform actually changes
ai4cmmc.ai provides Agent-as-a-Service (AaaS) compliance agents, not a productivity dashboard you have to learn. The agents check the read-only configuration of the commercial cloud and identity systems you connect, re-scanning about every seven days to flag drift, draft the SSP and POA&M, map evidence to controls, and re-issue the package on your tier's cycle. Requirements no connected source can show are answered from your own evidence. This is operational leverage, not headcount reduction. Your IT person can stay focused on actual security work, and your Affirming Official reviews the output and makes every decision.
Programs that may reduce your cost
Check with your local APEX Accelerator, the SBA, and any state-level cyber readiness programs for small defense suppliers. Availability and eligibility change, so confirm current status.