The DoD’s Official Three-Year Estimate
The Department of Defense published its most comprehensive cost estimate in the January 2025 draft FAR CUI Rule (2024-30437). For a representative small business, the DoD projects a three-year total of approximately $487,970 to achieve and maintain CMMC Level 2 compliance.
| Cost Component | DoD Estimate |
|---|---|
| One-time implementation | $175,700 Internal labor to map controls, build documentation, and implement technical requirements (~$148,200) plus initial hardware and software purchases (~$27,500). |
| Recurring annual costs | $103,800 / year Ongoing compliance maintenance labor (~$98,800) plus recurring hardware and software (~$5,000). Over the three-year cycle this component totals ~$207,600. |
| Assessment & affirmations | ~$104,670 The formal C3PAO triennial assessment plus two annual affirmations required under 32 CFR Part 170. |
| Three-year total | ~$487,970 Annualized, this implies a compliance burden of roughly $160,000 per year for a small business. |
What Contractors Actually Spend
Industry-reported costs consistently exceed the DoD’s model. First-cycle costs for CMMC Level 2 — from gap assessment through C3PAO certification — range from $75,000 to $300,000+ depending on organization size and starting security posture.
A survey of over 2,000 defense contractors found that 70% had budgeted less than $100,000 for their CMMC program — well below the DoD’s own projections. That gap between planned spend and actual cost is one of the most reliable predictors of a difficult assessment experience.
| Organization Profile | Typical First-Cycle Cost |
|---|---|
| Small business — low maturity <50 employees, starting from scratch |
$150,000–$300,000+ Organizations at basic security maturity allocate roughly 82% of budget to preparation and remediation. Infrastructure modernization (particularly migrating to FedRAMP Moderate cloud) is often the single largest line item. |
| Small business — moderate maturity <50 employees, NIST 800-171 partially implemented |
$75,000–$150,000 Primary costs shift from remediation to documentation and gap closure. Organizations with existing security tooling spend less on implementation and more on evidence collection. |
| Mid-size organization 50–200 employees |
$150,000–$250,000 More systems in scope, more users to train, more access control complexity, and higher C3PAO fees. Assessment and labor costs scale with environment complexity. |
| Mature organization NIST 800-171 controls documented and operating |
40%–65% lower total cost vs. a low-maturity organization of the same size. Organizations that maintained accurate SPRS scores and SSPs prior to CMMC enforcement have a fundamentally different cost profile. |
C3PAO Assessment Fees
The formal C3PAO assessment is the most visible line item in any CMMC budget — but it is rarely the largest. The DoD projects the full triennial cycle at $105,000–$118,000. Actual fees vary significantly by organization size and assessor market conditions.
| Organization Size | Typical C3PAO Assessment Fee |
|---|---|
| Small <50 employees |
$30,000–$50,000 Assessment typically runs 2–3 days on-site or remote. Lead times to book a C3PAO slot are currently running 3–6 months in most markets. |
| Mid-size 50–200 employees |
$50,000–$80,000 More systems, more personnel interviews, and a larger evidence review scope drive the fee higher. Typical assessment duration: 3–5 days. |
| Large 200+ employees |
$80,000–$150,000+ Complex environments, multiple locations, and extensive system inventories extend scope substantially. Some large DIB assessments run multiple weeks. |
| DoD projected full cycle Assessment + 2 annual affirmations |
$105,000–$118,000 The DoD’s projected cost covers the triennial assessment plus both annual affirmations over the three-year certification period. |
The assessment fee does not include readiness preparation. A failed readiness review — where the C3PAO determines documentation is too incomplete to proceed — results in rescheduling costs on top of the original fee. Thorough preparation before engaging a C3PAO is the most reliable way to avoid that outcome.
Consultant and Implementation Costs
For most organizations, consultant and internal labor costs exceed the C3PAO assessment fee by a factor of three to four. This is the component the DoD’s estimate most significantly underestimates — and where organizations most commonly run over budget.
| Cost Item | Typical Range |
|---|---|
| Gap assessment (RPO) | $3,500–$20,000 A formal gap assessment evaluates your controls against NIST SP 800-171, produces an initial SPRS score, and identifies priority remediation areas. The required first step for any organization without an accurate current SPRS score. |
| RPO / vCISO hourly rate | $250–$400 per hour Consistent across the market. Total engagement costs for SSP development, policy writing, control implementation guidance, and evidence package preparation commonly run $50,000–$300,000 depending on org size and maturity. |
| SSP and policy development | $15,000–$60,000 with consultant support. Manual documentation without a compliance platform takes 50–200 hours of internal staff time. Generic or templated SSPs that don’t describe actual implementation fail assessor review. |
| Internal labor (staff time) | Dozens to hundreds of hours over the three-year cycle. Frequently omitted from compliance budgets because it doesn’t appear as an invoice. The DoD’s model attributes ~$148,200 of implementation cost to internal labor alone. |
A common budget mistake is planning for the gap assessment and C3PAO fee without adequately accounting for the consulting required to close the gaps between them. The gap assessment tells you where you are. Closing those gaps — and documenting the closure with evidence assessors will accept — is where the majority of consulting cost accumulates.
Technology and Infrastructure Costs
Technology implementation is the third major cost component. Unlike labor and consulting, technology costs produce durable assets that continue to serve your security posture after certification. The initial investment is substantial for organizations not previously running a tool stack aligned to NIST SP 800-171.
| Technology Item | Typical Cost |
|---|---|
| SIEM and log management | 35%–40% of total tech spend the largest single category. AU domain requirements mandate creating, protecting, and retaining audit logs for CUI systems. Annual SIEM licensing runs $5,000–$30,000+ depending on data volume and platform. |
| Endpoint protection & vulnerability scanning | $3,000–$15,000 annually SI domain requirements include malware protection and vulnerability remediation. Many organizations have endpoint protection but lack formal scanning programs, which consistently surface as assessment findings. |
| Cloud migration to FedRAMP Moderate | $4–$12 per user per month in additional licensing, plus migration labor. Standard commercial Microsoft 365, Google Workspace, or similar cannot be used for CUI. Migration to GCC or equivalent is a bright-line requirement. MORSECORP paid $4.6M for using non-compliant email. |
| CUI enclave (if applicable) | $300–$400 per user per month, or $3,000–$4,000+ per month for a managed enclave. Containing CUI to an isolated environment limits scope and reduces compliance costs across every other category, but requires a defensible boundary design. |
| MFA, encryption, access control | $5,000–$20,000 annually MFA (IA domain), FIPS-validated encryption (SC.L2-3.13.11, the only 5-point SPRS requirement), and privileged access management are required for organizations that haven’t previously implemented them. |
| Annual tech maintenance | 20%–25% of initial implementation cost per year. Licensing renewals, platform updates, and tool reconfiguration as your environment changes. Must be budgeted beyond year one. |
The Baseline Problem: Why Official Estimates Undercount
The DoD’s $487,970 estimate carries a structural flaw: it treats CMMC as a marginal compliance cost for organizations already operating to NIST SP 800-171 standards. The data shows that assumption is wrong for most of the DIB.
DFARS 252.204-7012 has required NIST SP 800-171 compliance since 2017. A 2020 DoD review found widespread non-compliance — contractors had submitted Plans of Action with remediation dates extending decades into the future. In one documented case, a contractor’s plan did not project full compliance until 2099. Despite nine years of contractual obligation, most small contractors are not starting CMMC from a position of existing compliance.
The other consistently underestimated factor is ongoing labor. The DoD’s model projects ~$98,800 per year in recurring compliance labor. For organizations without a dedicated compliance function, this represents real internal staff time or ongoing consultant engagement that must be sustained between assessments to support annual affirmation.
How to Reduce Total Compliance Cost
Cost reduction in CMMC compliance is not primarily about finding cheaper vendors. It is about eliminating rework — the remediation cycles, documentation rewrites, and failed readiness reviews that drive budgets well above initial estimates. The organizations with the lowest total cost are those that did the work right once.
| Strategy | Why It Works |
|---|---|
| Reduce scope | The single most impactful lever. Every system, user, and location removed from your CUI boundary reduces assessment surface, lowers tool licensing needs, reduces documentation scope, and shortens the C3PAO engagement. Organizations that contain CUI to a well-defined enclave realize lower costs in every subsequent compliance phase. |
| Start with an accurate SPRS score | A realistic gap assessment against your actual environment prevents the most common budget failure: underestimating remediation costs because the initial assessment was optimistic. An accurate SPRS score gives you a prioritized roadmap before spending a dollar on consulting. |
| Prioritize by SPRS point weight | Remediate high-point requirements first. SC.L2-3.13.11 (CUI encryption) is the only 5-point requirement. The 57 three-point requirements account for over half of potential SPRS deductions. Closing this tier produces the most visible score improvement per dollar spent. |
| Use a compliance platform | Organizations using spreadsheet-driven processes pay more in labor over the compliance lifecycle. Duplicate documentation effort, evidence that cannot be traced to controls, and SSPs requiring complete rewrites for re-assessment are the dominant cost drivers in manual programs. A platform that maps evidence to controls once and maintains it continuously avoids most of this rework. |
| Avoid late-stage compression | Compressing a 12–18 month program into 3–6 months means premium consultant rates, expedited C3PAO fees, and remediation gaps that are expensive to close under time pressure. Phase 2 enforcement begins November 2026; organizations starting now should plan for a standard timeline, not an accelerated one. |