You run a 25-person machine shop, a small engineering firm, or a specialty supplier two tiers down from a prime. You handle Controlled Unclassified Information (CUI), which puts you at CMMC Level 2 (Level 3 is expected to apply only to a small subset of contractors, DoD Regulatory Impact Analysis, page 16). While the July 13, 2026 suspension of CMMC Phase 2 is in effect, solicitations may require only a Level 2 self-assessment, not a C3PAO certification (Department of War memorandum, July 13, 2026, Attachment 1). Either way, the question is what it costs and how much of that cost you can avoid.
The uncomfortable part is that CMMC costs weigh more per employee on a small business. Here is what the bill looks like, why, and what actually brings it down.
The DoD's headline estimate
The figures with a named primary source come from the DoD CMMC Program Regulatory Impact Analysis. For a small entity, the DoD estimates a Level 2 Certification (C3PAO) total of $104,670 across the three-year cycle. The C3PAO assessor engagement alone is estimated at $31,234 for a small entity. The rest is planning, supporting the assessment, reporting and affirmation work by your staff and outside service providers.
For a business doing a few million in annual revenue, that is a serious line item. It is also not evenly distributed, and that is the good news, because most of it is staff and outside-support time, not the assessor's fee.
Source: DoD CMMC Program Regulatory Impact Analysis (docket DoD-2023-OS-0063), pages 14 and 26. The estimate excludes the cost of implementing or remediating the requirements (pages 15 to 16).
Why small businesses pay disproportionately
- No internal security staff. The DoD's own estimate assumes small entities are likely to outsource IT and cybersecurity to an External Service Provider (RIA page 15). In its model, most of a small entity's assessment hours are External Service Provider time at $260.28 an hour, where a larger entity's are internal staff time (RIA pages 24 to 26).
- The requirement set does not scale with size. The same 110 NIST SP 800-171 requirements, including a System Security Plan (3.12.4), apply whether you have 25 employees or 25,000.
- Follow-up cost. Requirements left NOT MET at assessment go on a POA&M that must be closed and confirmed by a POA&M closeout assessment within 180 days, or the conditional status expires (32 CFR 170.21). On a small budget, that is remediation plus a return engagement.
Where the money actually goes
The DoD breakdown for a small entity at Level 2 Certification splits the cost into a few buckets:
| Line item | Small entity (3-yr) |
|---|---|
| Plan and prepare | $20,699 |
| Conduct assessment (your staff and outside support) | $45,509 |
| Report results | $2,851 |
| Annual affirmations (3-yr) | $4,377 |
| C3PAO assessor engagement | $31,234 |
Notice that planning and your side of the assessment together ($66,208) come to more than twice the assessor's fee. That labor, not the assessor's fee, is the larger share of the DoD estimate.
Three moves that cut the bill
1. Scope a CUI enclave
If CUI lives only in a defined enclave, a separate environment for the systems that touch it, then assets outside it that are physically or logically separated from CUI and provide no security protection for it fall outside the Level 2 assessment scope (32 CFR 170.19). Decide scope before spending on remediation. See our level-by-level cost guide for the enclave-first approach.
2. Replace preparation hours with AI work, keep human judgment
The preparation includes the systematic work of mapping controls, drafting the SSP, writing policies, and assembling evidence. That is the work an Agent-as-a-Service (AaaS) provider takes on. ai4cmmc.ai runs the gap analysis from your intake and the read-only configuration of the clouds you connect, drafts your SSP and POA&M, and re-issues them with an evidence package on your tier's cycle. It delivers every output to you; your Affirming Official reviews it and makes the decisions.
3. Treat compliance as an operating system, not a project
Certification recurs: annual affirmations and a three-year reassessment cycle (32 CFR 170.17 and 170.22). Keeping evidence current between assessments means you are not rebuilding it from scratch each cycle. For a sense of where the recurring spend lands, see our full cost breakdown by level.
The real question
If the DoD contracts you want carry a CMMC requirement, the question is how you pay for the work: in outside hours, or with agents doing the systematic preparation while your team makes the decisions.
Find out what your actual gap is before you budget. Start with the free directional self-assessment, not an official SPRS score, and you will have a first read on ten controls.