If you handle Controlled Unclassified Information on a DoD contract, CMMC Level 2 is the level to plan for. Since July 13, 2026, with Phase 2 suspended, a DoW CIO memorandum allows requiring activities to designate only Level 1 (Self) or Level 2 (Self), not a C3PAO certification. The figures below are what the DoD modeled for a Level 2 certification assessment, for when a Level 2 (C3PAO) requirement applies, and they show how much of that cost you can control.
In the DoD's model, the C3PAO's fee is the smaller share. The larger share is your organization's own work to prepare for, support and report on the assessment, and to affirm.
What the DoD's own model says
The DoD's own published figures come from its Regulatory Impact Analysis for the CMMC program. They cover a full three-year certification cycle, and they are a sourced place for your budget to start.
| Level 2 Certification (C3PAO), 3-year cycle | Small entity | Larger entity |
|---|---|---|
| Plan and prepare (your side) | $20,699 | $26,264 |
| Conduct assessment (your side) | $45,509 | $28,600 |
| Report results | $2,851 | $2,712 |
| Annual affirmations (3-year) | $4,377 | $8,136 |
| C3PAO engagement (within the total) | $31,234 | $52,056 |
| Total per certification (3-year) | $104,670 | $117,768 |
Source: DoD CMMC Program Regulatory Impact Analysis (docket DoD-2023-OS-0063), pages 14 and 24 to 26; the same figures appear in the final rule, 89 FR 83092 (Oct. 15, 2024), at 83185 to 83186.
Read the bottom row carefully. The DoD estimated roughly $104,670 for a small contractor to support a Level 2 certification assessment and its affirmations over three years. The model assumes the 110 requirements are already implemented, so it does not include the cost of implementing or remediating them. The C3PAO engagement itself was $31,234 of that for a small entity. The rest, the majority, is your organization's own staff time plus, in the small-entity model, an external service provider's hours: to prepare for, support and report on the assessment, and to affirm.
Why the assessment fee is only part of the bill
Look at the table again and the pattern is clear: the third-party engagement is a minority of the total. Most of the modeled spend is your side of the work: preparing, supporting the assessment and reporting, and that is the work you have leverage over.
Preparation means scoping your environment, writing a System Security Plan that addresses all 110 NIST SP 800-171 controls, building Plans of Action and Milestones for any gaps, and collecting the evidence that each control is implemented. In the DoD's small-entity model, both the preparation and the assessment phases include external service provider hours (RIA p. 26).
Then there is the recertification clock. Level 2 certification is not one-and-done. The certification assessment is repeated every three years, with an affirmation of continuing compliance each year in between (32 CFR 170.17, 170.22), and each cycle carries reassessment effort, gap reviews, documentation updates, and remediation of anything that drifted. Plan for a recurring cost, not a one-time line item.
What drives your number up or down
- Scope. Every system, user, and location that touches CUI expands the assessment. Tight scoping, under the rules in 32 CFR 170.19, is a direct lever on cost.
- Environment readiness. Walking into the assessment with open gaps means remediation under time pressure.
- Documentation quality. Assessors credit what they can verify, so a weak SSP and stale evidence leave less for them to credit.
- Size. The DoD's estimate for a small entity ($104,670) is close to its estimate for a larger one ($117,768).
Where AaaS fits
The C3PAO's fee is set by the C3PAO. The rest of the bill is your side of the work, and the ai4cmmc.ai AaaS platform takes on part of it: reading configuration and keeping the readiness documents current.
On a readiness subscription, read-only connectors re-scan your connected cloud and identity sources about every seven days, and each tier cycle re-issues the posture estimate, SSP and POA&M against the 110 Level 2 controls: measured where a connected source can observe a control, answered from your recorded evidence where not. Documents ship on schedule; your designated executive can approve or disapprove each one before your organization presents it, and your Affirming Official makes the affirmation decision. That is operational leverage for your team, not a replacement for it.
Next step
Before you sign a consulting engagement, get a first read. The free gap check asks 10 questions and gives a directional Level 2 read; it is a self-assessment, not an official SPRS score. For a report that ranks your top control gaps, the $999 CMMC Level 2 Readiness Snapshot compares your connected configuration against all 110 controls, measuring the ones those sources can show, and returns a PDF within minutes of intake.