What the DoD estimated CMMC Level 2 certification costs, and what it left out
The C3PAO assessment fee is the visible part of a CMMC Level 2 bill, and in the DoD's own estimate it is the smaller part. The estimate also leaves out a cost entirely: implementing the 110 NIST 800-171 controls in the first place. What that costs you depends on how far your current environment sits from them.
The DoD's own cost estimates
The Department of Defense published per-assessment cost estimates in its regulatory impact analysis for the CMMC program. These are the Department's own figures. The Level 2 figures cover a three-year cycle; the Level 1 figure is for one annual self-assessment.
| CMMC path | Small entity | Larger entity |
|---|---|---|
| Level 1 Self-Assessment (per year) | $5,977 | $4,042 |
| Level 2 Self-Assessment (3 years) | $37,196 | $48,827 |
| Level 2 Certification (C3PAO) (3 years) | $104,670 | $117,768 |
Source: DoD CMMC Program Regulatory Impact Analysis, pages 13 to 14 (Tables 1 and 2) and 25 to 26.
Since July 13, 2026, while Phase 2 is suspended, DoW requiring activities may designate only Level 1 (Self) or Level 2 (Self) assessments; they may not designate Level 2 (C3PAO) (DoW CIO memorandum 26-P-1023, Attachment 1). The certification row is the cost the rule was written to impose, not one a new solicitation can require today.
Read that bottom row carefully. The DoD estimated $104,670 for a small contractor to go through a Level 2 certification assessment and keep up the affirmations over three years. Within that total, the C3PAO engagement itself was estimated at $31,234 for a small contractor and $52,056 for a larger one. The rest is the contractor's own staff time and outside consultant or service-provider support to plan, prepare for and support the assessment, plus the affirmations. What the estimate leaves out: DoD did not count the cost of implementing the NIST SP 800-171 requirements, maintaining them, or remediating unimplemented ones, because DFARS 252.204-7012 already required them (RIA pages 15 to 16).
Where the money actually goes
The certification fee is the visible line. The full bill has these parts, and the DoD estimate counts all of them except remediation:
- Plan and prepare. Scoping your environment, mapping in-scope assets, assigning control ownership.
- Remediation. Closing the gap between what you have today and all 110 controls. The DoD estimate does not include this cost; what it comes to depends on where you start.
- Documentation. A System Security Plan and a POA&M that an assessor will accept, plus the evidence behind every claim.
- The C3PAO engagement. The assessment itself, performed by an authorized third party.
- Annual affirmations. Yearly attestations across the three-year cycle.
How to spend less on CMMC
A costly mistake is paying for a C3PAO assessment before the environment is ready. A failed or stalled assessment burns the fee and the calendar. Three steps keep the spend down, in order:
- Measure the gap first, against all 110 controls, before committing to remediation budget.
- Remediate by point-recovery impact, closing the controls that move the score most, first.
- Walk into the C3PAO assessment prepared, with the evidence already assembled, so the engagement is a confirmation rather than a discovery.
Know your starting cost before you spend a dollar on remediation
The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-control baseline; it measures only the controls a connected source can show, and returns a PDF of your top control gaps within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.
Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. The free gap check is a directional self-assessment and is not an official SPRS score. Cost figures cite the DoD CMMC Program Regulatory Impact Analysis. Patent Pending. ElasticD3M, LLC, Texas.