Planning & Cost

How Much Does CMMC Level 2 Compliance Cost? (2026)

Last updated: 2026-03-17

DoD Estimate Actual Costs C3PAO Fees Consultant Costs Technology Costs The Baseline Problem Reducing Costs

The DoD’s Official Three-Year Estimate

The Department of Defense published its most comprehensive cost estimate in the January 2025 draft FAR CUI Rule (2024-30437). For a representative small business, the DoD projects a three-year total of approximately $487,970 to achieve and maintain CMMC Level 2 compliance.

Cost ComponentDoD Estimate
One-time implementation $175,700
Internal labor to map controls, build documentation, and implement technical requirements (~$148,200) plus initial hardware and software purchases (~$27,500).
Recurring annual costs $103,800 / year
Ongoing compliance maintenance labor (~$98,800) plus recurring hardware and software (~$5,000). Over the three-year cycle this component totals ~$207,600.
Assessment & affirmations ~$104,670
The formal C3PAO triennial assessment plus two annual affirmations required under 32 CFR Part 170.
Three-year total ~$487,970
Annualized, this implies a compliance burden of roughly $160,000 per year for a small business.
The Hidden Assumption in the DoD’s Numbers
The DoD’s estimate assumes contractors were already operating in conformance with NIST SP 800-171 before CMMC — treating certification as a marginal cost rather than a ground-up implementation. A 2020 DoD review found this was not warranted: contractors had submitted Plans of Action with remediation dates extending as far as 2099. For organizations starting from a low baseline, $487,970 is a floor, not a ceiling.

What Contractors Actually Spend

Industry-reported costs consistently exceed the DoD’s model. First-cycle costs for CMMC Level 2 — from gap assessment through C3PAO certification — range from $75,000 to $300,000+ depending on organization size and starting security posture.

A survey of over 2,000 defense contractors found that 70% had budgeted less than $100,000 for their CMMC program — well below the DoD’s own projections. That gap between planned spend and actual cost is one of the most reliable predictors of a difficult assessment experience.

Organization ProfileTypical First-Cycle Cost
Small business — low maturity
<50 employees, starting from scratch
$150,000–$300,000+
Organizations at basic security maturity allocate roughly 82% of budget to preparation and remediation. Infrastructure modernization (particularly migrating to FedRAMP Moderate cloud) is often the single largest line item.
Small business — moderate maturity
<50 employees, NIST 800-171 partially implemented
$75,000–$150,000
Primary costs shift from remediation to documentation and gap closure. Organizations with existing security tooling spend less on implementation and more on evidence collection.
Mid-size organization
50–200 employees
$150,000–$250,000
More systems in scope, more users to train, more access control complexity, and higher C3PAO fees. Assessment and labor costs scale with environment complexity.
Mature organization
NIST 800-171 controls documented and operating
40%–65% lower total cost vs. a low-maturity organization of the same size. Organizations that maintained accurate SPRS scores and SSPs prior to CMMC enforcement have a fundamentally different cost profile.

C3PAO Assessment Fees

The formal C3PAO assessment is the most visible line item in any CMMC budget — but it is rarely the largest. The DoD projects the full triennial cycle at $105,000–$118,000. Actual fees vary significantly by organization size and assessor market conditions.

Organization SizeTypical C3PAO Assessment Fee
Small
<50 employees
$30,000–$50,000
Assessment typically runs 2–3 days on-site or remote. Lead times to book a C3PAO slot are currently running 3–6 months in most markets.
Mid-size
50–200 employees
$50,000–$80,000
More systems, more personnel interviews, and a larger evidence review scope drive the fee higher. Typical assessment duration: 3–5 days.
Large
200+ employees
$80,000–$150,000+
Complex environments, multiple locations, and extensive system inventories extend scope substantially. Some large DIB assessments run multiple weeks.
DoD projected full cycle
Assessment + 2 annual affirmations
$105,000–$118,000
The DoD’s projected cost covers the triennial assessment plus both annual affirmations over the three-year certification period.
Assessment Fees May Rise
C3PAOs set their own fees. With Phase 2 enforcement beginning November 2026 and a limited number of authorized C3PAOs relative to the size of the DIB, demand for assessment slots is expected to outpace supply through 2027. Organizations that delay booking risk both longer lead times and higher fees as the enforcement window approaches.

The assessment fee does not include readiness preparation. A failed readiness review — where the C3PAO determines documentation is too incomplete to proceed — results in rescheduling costs on top of the original fee. Thorough preparation before engaging a C3PAO is the most reliable way to avoid that outcome.

Consultant and Implementation Costs

For most organizations, consultant and internal labor costs exceed the C3PAO assessment fee by a factor of three to four. This is the component the DoD’s estimate most significantly underestimates — and where organizations most commonly run over budget.

Cost ItemTypical Range
Gap assessment (RPO) $3,500–$20,000
A formal gap assessment evaluates your controls against NIST SP 800-171, produces an initial SPRS score, and identifies priority remediation areas. The required first step for any organization without an accurate current SPRS score.
RPO / vCISO hourly rate $250–$400 per hour
Consistent across the market. Total engagement costs for SSP development, policy writing, control implementation guidance, and evidence package preparation commonly run $50,000–$300,000 depending on org size and maturity.
SSP and policy development $15,000–$60,000 with consultant support. Manual documentation without a compliance platform takes 50–200 hours of internal staff time. Generic or templated SSPs that don’t describe actual implementation fail assessor review.
Internal labor (staff time) Dozens to hundreds of hours over the three-year cycle. Frequently omitted from compliance budgets because it doesn’t appear as an invoice. The DoD’s model attributes ~$148,200 of implementation cost to internal labor alone.

A common budget mistake is planning for the gap assessment and C3PAO fee without adequately accounting for the consulting required to close the gaps between them. The gap assessment tells you where you are. Closing those gaps — and documenting the closure with evidence assessors will accept — is where the majority of consulting cost accumulates.

Technology and Infrastructure Costs

Technology implementation is the third major cost component. Unlike labor and consulting, technology costs produce durable assets that continue to serve your security posture after certification. The initial investment is substantial for organizations not previously running a tool stack aligned to NIST SP 800-171.

Technology ItemTypical Cost
SIEM and log management 35%–40% of total tech spend
the largest single category. AU domain requirements mandate creating, protecting, and retaining audit logs for CUI systems. Annual SIEM licensing runs $5,000–$30,000+ depending on data volume and platform.
Endpoint protection & vulnerability scanning $3,000–$15,000 annually
SI domain requirements include malware protection and vulnerability remediation. Many organizations have endpoint protection but lack formal scanning programs, which consistently surface as assessment findings.
Cloud migration to FedRAMP Moderate $4–$12 per user per month in additional licensing, plus migration labor. Standard commercial Microsoft 365, Google Workspace, or similar cannot be used for CUI. Migration to GCC or equivalent is a bright-line requirement. MORSECORP paid $4.6M for using non-compliant email.
CUI enclave (if applicable) $300–$400 per user per month, or $3,000–$4,000+ per month for a managed enclave. Containing CUI to an isolated environment limits scope and reduces compliance costs across every other category, but requires a defensible boundary design.
MFA, encryption, access control $5,000–$20,000 annually
MFA (IA domain), FIPS-validated encryption (SC.L2-3.13.11, the only 5-point SPRS requirement), and privileged access management are required for organizations that haven’t previously implemented them.
Annual tech maintenance 20%–25% of initial implementation cost per year.
Licensing renewals, platform updates, and tool reconfiguration as your environment changes. Must be budgeted beyond year one.

The Baseline Problem: Why Official Estimates Undercount

The DoD’s $487,970 estimate carries a structural flaw: it treats CMMC as a marginal compliance cost for organizations already operating to NIST SP 800-171 standards. The data shows that assumption is wrong for most of the DIB.

DFARS 252.204-7012 has required NIST SP 800-171 compliance since 2017. A 2020 DoD review found widespread non-compliance — contractors had submitted Plans of Action with remediation dates extending decades into the future. In one documented case, a contractor’s plan did not project full compliance until 2099. Despite nine years of contractual obligation, most small contractors are not starting CMMC from a position of existing compliance.

What This Means for Your Budget
If your organization has not previously scored itself against NIST SP 800-171 with an honest, documented assessment, do not use the DoD’s three-year figure as your budget. Use it as the cost for the assessment and maintenance phases — and build your implementation budget separately based on a genuine gap assessment against your actual environment. The difference between those two numbers is your real compliance investment.

The other consistently underestimated factor is ongoing labor. The DoD’s model projects ~$98,800 per year in recurring compliance labor. For organizations without a dedicated compliance function, this represents real internal staff time or ongoing consultant engagement that must be sustained between assessments to support annual affirmation.

How to Reduce Total Compliance Cost

Cost reduction in CMMC compliance is not primarily about finding cheaper vendors. It is about eliminating rework — the remediation cycles, documentation rewrites, and failed readiness reviews that drive budgets well above initial estimates. The organizations with the lowest total cost are those that did the work right once.

StrategyWhy It Works
Reduce scope The single most impactful lever. Every system, user, and location removed from your CUI boundary reduces assessment surface, lowers tool licensing needs, reduces documentation scope, and shortens the C3PAO engagement. Organizations that contain CUI to a well-defined enclave realize lower costs in every subsequent compliance phase.
Start with an accurate SPRS score A realistic gap assessment against your actual environment prevents the most common budget failure: underestimating remediation costs because the initial assessment was optimistic. An accurate SPRS score gives you a prioritized roadmap before spending a dollar on consulting.
Prioritize by SPRS point weight Remediate high-point requirements first. SC.L2-3.13.11 (CUI encryption) is the only 5-point requirement. The 57 three-point requirements account for over half of potential SPRS deductions. Closing this tier produces the most visible score improvement per dollar spent.
Use a compliance platform Organizations using spreadsheet-driven processes pay more in labor over the compliance lifecycle. Duplicate documentation effort, evidence that cannot be traced to controls, and SSPs requiring complete rewrites for re-assessment are the dominant cost drivers in manual programs. A platform that maps evidence to controls once and maintains it continuously avoids most of this rework.
Avoid late-stage compression Compressing a 12–18 month program into 3–6 months means premium consultant rates, expedited C3PAO fees, and remediation gaps that are expensive to close under time pressure. Phase 2 enforcement begins November 2026; organizations starting now should plan for a standard timeline, not an accelerated one.

Your SSP. Not a template.

1TEN generates your System Security Plan from your actual documented control implementations. C3PAO-ready.

Request a Demo