If you are asking how much does CMMC certification cost, you have probably already discovered that most answers online are either a vague shrug or a sales pitch dressed up as a number. Neither helps you build a budget. The honest answer is that the Department of Defense has published its own cost estimates in the regulatory analysis behind the CMMC Program final rule (32 CFR Part 170, 89 FR 83092, October 15, 2024), and those figures are the only government-sourced baseline that exists. This article walks through DoD's numbers level by level, explains what those numbers deliberately leave out, and shows you how to translate them into a real budget for your company.
I am Craig Petronella, a CMMC Registered Practitioner, and my team at Petronella Technology Group, Inc. spends every week inside defense contractors' environments scoping exactly this question. What follows is the same framework we use when a contractor calls us and asks for a straight answer.
The Short Answer: DoD Published Its Own Cost Estimates
When the CMMC Program final rule was published in the Federal Register in October 2024, DoD included a detailed regulatory cost analysis. That analysis estimates what an assessment costs at each CMMC level, broken out separately for small entities and other-than-small entities. These are DoD's numbers, not a vendor's, which makes them the right starting point for any budget conversation.
Here is the summary, straight from the final rule's cost analysis:
- Level 1 self-assessment and affirmation: an estimated $5,977 per year for a small entity, or $4,042 per year for an other-than-small entity. Level 1 self-assessments recur annually.
- Level 2 self-assessment and affirmation: an estimated $37,196 over three years for a small entity ($34,277 for the triennial self-assessment plus two annual affirmations), or $48,827 over three years for an other-than-small entity.
- Level 2 certification assessment (C3PAO): an estimated $104,670 over three years for a small entity ($101,752 for the triennial assessment and initial affirmation, plus two annual affirmations at $1,459 each), or $117,768 over three years for an other-than-small entity.
- Level 3 certification assessment (DIBCAC): an estimated $12,802 over three years for a small entity for the assessment itself, plus DoD-estimated nonrecurring engineering costs of $2,700,000 and recurring engineering costs of $490,000 for the underlying NIST SP 800-172 security requirements. For other-than-small entities, the assessment estimate is $44,445 over three years with $21,100,000 nonrecurring and $4,120,000 recurring engineering costs.
Every figure above comes from the cost tables and per-entity breakdowns in the CMMC Program final rule. If a consultant quotes you numbers wildly out of line with these without explaining why, ask questions.
How Much Does CMMC Certification Cost by Level?
The right budget depends entirely on which CMMC level your contracts require. That, in turn, depends on what kind of information you handle. If you only touch Federal Contract Information, Level 1 applies. If you handle Controlled Unclassified Information, Level 2 applies, and a subset of contractors supporting the most sensitive programs will need Level 3. If you are not sure which category your data falls into, start with our CUI vs FCI guide for defense contractors, because misclassifying your data is the single most expensive scoping mistake you can make.
Level 1: Annual Self-Assessment
Level 1 covers the 15 basic safeguarding requirements from FAR clause 52.204-21. There is no third-party assessor involved. You self-assess annually, enter your results into the Supplier Performance Risk System (SPRS), and a senior official affirms compliance. DoD's cost analysis estimates the annual self-assessment and affirmation at $5,977 for a small entity and $4,042 for an other-than-small entity. The small-entity figure is higher because DoD assumes smaller companies lean on an external service provider for part of the work, billed in the analysis at $260.28 per hour, while larger companies use internal staff.
Note what that estimate assumes: DoD's analysis explicitly assumes you have already implemented the 15 safeguarding requirements, because they have been contractually required under FAR 52.204-21 for years. If you have not actually implemented them, your real cost includes remediation on top of the assessment.
Level 2 Self-Assessment: For a Limited Set of Contracts
Some Level 2 contracts will allow a self-assessment rather than a third-party certification. DoD estimates the triennial Level 2 self-assessment and affirmation at $34,277 for a small entity, with a three-year total of $37,196 once you add two annual affirmations at $1,459 each. For other-than-small entities the three-year total is $48,827. Do not build your strategy around self-assessment eligibility, though. The applicable level and assessment type are set by the contract, not by your preference, and most contractors handling CUI should plan for the certification track.
Level 2 Certification Assessment: The Number Most Contractors Actually Need
This is the figure most people mean when they ask about CMMC certification cost. A Level 2 certification assessment is conducted by a CMMC Third-Party Assessment Organization, a C3PAO, against all 110 security requirements of NIST SP 800-171. DoD's cost analysis estimates the full triennial cycle at $104,670 for a small entity and $117,768 for an other-than-small entity.
Inside the small-entity number, the C3PAO engagement itself is estimated at $31,234, based on a three-person assessment team working 120 hours at $260.28 per hour. For larger entities, DoD models a five-person team for 200 hours, or $52,056. The rest of the estimate is your own cost: planning and preparing for the assessment, supporting the assessors during the assessment window, reporting results, and the annual affirmations your Affirming Official must submit in between assessments.
Two practical takeaways from those numbers. First, the assessor's invoice is only about a third of the total; your internal effort is the majority of the cost. Second, these are recurring costs. Certification is valid for three years, so the triennial figure is best understood as roughly $35,000 to $39,000 per year of budget for the assessment cycle alone, using DoD's own math.
What DoD's Estimates Leave Out: Implementation
Here is the part that surprises contractors, and it is written plainly into the rule itself. DoD's Level 2 assessment estimates assume the contractor has already implemented all NIST SP 800-171 security requirements. The final rule states there are no nonrecurring or recurring engineering costs in the Level 2 estimate for exactly that reason: those requirements have been contractually required under DFARS clause 252.204-7012 since 2017, so DoD treats implementation as a sunk cost you were already obligated to pay.
In the real world, most small and mid-sized defense contractors are not at full implementation when they start. That gap between where your environment is today and where 110 requirements say it must be is the largest and most variable component of your true cost, and no government table can estimate it for you, because it depends on your specific environment. This is why credible providers quote implementation work with "From" pricing after a gap assessment rather than a flat rate off a price sheet.
The implementation gap is driven by things like whether you have multi-factor authentication everywhere it is required, whether your logging and monitoring actually satisfy the audit and accountability family, whether CUI is encrypted with FIPS-validated cryptography, whether you have a real System Security Plan rather than a template with your logo on it, and whether your incident response capability exists anywhere other than on paper. Every one of those is a cost driver that varies by orders of magnitude between companies of identical headcount.
The Cost Drivers That Actually Move Your Number
When we scope a CMMC engagement, five variables move the budget more than everything else combined:
- Assessment scope. The number of assets that store, process, or transmit CUI, plus the security protection assets around them, determines assessment effort. A 200-person company with CUI confined to a 12-user enclave can have a smaller assessment scope than a 40-person company where CUI flows through everyone's inbox.
- Enclave versus full environment. The single biggest lever you control. Consolidating CUI into a purpose-built enclave shrinks scope, shrinks the requirement footprint you must evidence, and shrinks both implementation and assessment cost. Scoping the entire corporate network into the assessment is almost always the expensive path.
- Your CUI footprint. How much CUI you receive, where it lives, and how many business processes touch it. Contractors are frequently storing CUI in places they have forgotten about, and every discovered location expands scope.
- Current maturity. A contractor with a truthful SPRS score in the negative range has a fundamentally different budget than one that has been operating under DFARS 252.204-7012 in good faith for years.
- Internal capacity. DoD's own models assume dozens to hundreds of internal labor hours across planning, assessment support, and reporting. If your team cannot absorb those hours, you are buying them from an external service provider, which DoD's analysis prices at $260.28 per hour.
A useful exercise: before you talk to any vendor, write one paragraph describing where CUI enters your company, where it is stored, and who touches it. If you cannot write that paragraph, your first dollar should go to scoping, not to tools. Our CMMC compliance guide walks through the full program structure if you need the foundation first.
How Much Does CMMC Certification Cost for a Small Business?
Small defense contractors carry the heaviest relative burden, and DoD's analysis acknowledges it by modeling small entities separately. For a small business, the government's own planning figures are $5,977 per year at Level 1, $37,196 over three years for a Level 2 self-assessment, and $104,670 over three years for a Level 2 certification assessment. Those numbers assume your NIST SP 800-171 implementation is already done.
For budgeting purposes, a small contractor pursuing Level 2 certification should think in three buckets: first, a gap assessment to establish the truth about your current state; second, remediation and implementation, which varies with the five drivers above and is the bucket no honest provider will flat-quote before discovery; third, the assessment cycle itself, for which DoD's $104,670 triennial small-entity estimate is the best public baseline. Sequencing matters: money spent on the wrong tools before scoping is money you will spend again.
The most effective cost-control decision a small business can make is enclave architecture. Concentrating CUI into a hardened enclave, rather than certifying your whole network, converts an unbounded problem into a bounded one. It is the difference between securing one room and securing the entire building.
Want a number for your actual environment? Book a CMMC scoping consultation. We will map your CUI footprint, identify your assessment boundary, and give you a defensible budget before you commit a dollar to tools or assessors.
CMMC Level 3 Certification Cost
Level 3 applies to a small subset of the Defense Industrial Base supporting the most sensitive programs. It requires a final Level 2 certification first, plus implementation of selected requirements from NIST SP 800-172, and the assessment is conducted by the Defense Contract Management Agency's DIBCAC rather than a commercial C3PAO.
DoD's cost analysis is blunt about the magnitude. Because the NIST SP 800-172 requirements are new obligations rather than pre-existing ones, the analysis includes engineering costs: an estimated $2,700,000 in nonrecurring engineering and $490,000 in recurring engineering for a small entity, and $21,100,000 nonrecurring with $4,120,000 recurring for an other-than-small entity. The assessment itself is comparatively modest, at an estimated $12,802 over three years for a small entity and $44,445 for an other-than-small entity, but the engineering burden dominates the total.
Those engineering estimates assume you are building advanced persistent threat resistance into a conventional environment from scratch. There are alternatives to that build-it-yourself path. Petronella Technology Group, Inc. offers the ComplianceArmor® CMMC Level 3 Sovereign License starting From $44,995 per year, an appliance-based approach designed to deliver the Level 3 technical stack without the multi-million dollar engineering program DoD's analysis models. The details, including what the license covers and how the sovereign appliance model works, are on our CMMC Level 3 page.
The Cost of Getting It Wrong
Whatever CMMC certification costs, the cost of a false compliance posture is worse, and it is no longer hypothetical. The Department of Justice has been using the False Claims Act against contractors whose SPRS scores did not match reality. We documented a case where a defense contractor paid $507,144 to settle allegations tied to a false SPRS score, a self-reported perfect 110 that an honest assessment would have placed deep in negative territory.
That settlement reframes the budget question. An artificially cheap path to a compliance claim, a template SSP, a generously self-scored SPRS entry, a vendor promising certification readiness in a week, is not a discount. It is deferred liability with treble damages attached. When you compare quotes, compare what is actually being delivered: evidence that survives an assessor, or paperwork that survives until someone looks.
There is also the quieter cost of doing nothing. CMMC requirements flow into contracts through the acquisition process, and primes are already asking subcontractors for their status. A contractor who waits until a solicitation demands certification has no schedule leverage: C3PAO capacity is finite, remediation takes months, and the contract will not wait. Budgeting now, even if you phase the spend, is cheaper than buying the same work on an emergency timeline.
How to Budget: A Practical Sequence
Here is the sequence we recommend to every defense contractor building a CMMC budget, in order:
- Classify your data. Determine whether you handle FCI only or CUI, and therefore whether Level 1 or Level 2 applies. Get this wrong and every downstream dollar is misallocated.
- Define your boundary. Decide, deliberately, whether CUI will live in an enclave or across your environment. This decision sets the scale of everything that follows.
- Run a gap assessment. Establish your honest score against all 110 requirements. This produces the remediation list that turns "somewhere between five and six figures" into an actual number.
- Price remediation from the gap list. Expect "From" pricing keyed to your node count and topology, because that is how honest scoping works. Flat quotes issued before discovery are guesses.
- Reserve the assessment cycle. Use DoD's triennial figures, $104,670 for a small entity or $117,768 for a larger one at Level 2, as your planning baseline for the assessment itself, and remember the annual affirmations in between.
- Budget for sustainment. Compliance is a standing operational posture, not a certificate. Monitoring, log review, patching discipline, and evidence maintenance continue every month between assessments.
Contractors who follow this sequence spend less in total than contractors who buy tools first and scope later. We see the receipts from both approaches every month.
FAQ
How much does CMMC Level 2 certification cost for a small business?
DoD's regulatory cost analysis for the CMMC final rule estimates $104,670 over three years for a small entity, covering the triennial C3PAO assessment, the initial affirmation, and two annual affirmations. That figure assumes NIST SP 800-171 is already fully implemented; remediation to close any gaps is additional and varies with your environment.
How much of the cost is the C3PAO assessor's fee?
In DoD's model, the C3PAO engagement is $31,234 of the small-entity estimate, based on a three-person team for 120 hours at $260.28 per hour. For larger entities the model is a five-person team for 200 hours, or $52,056. The majority of the total cost is your own preparation, assessment support, and reporting effort.
How often do CMMC costs recur?
Level 1 self-assessments are annual. Level 2 and Level 3 assessments are triennial, with an affirmation of continued compliance required every year in between. DoD estimates each annual affirmation at $1,459 for a small entity and $2,712 for an other-than-small entity, but the real recurring cost is maintaining the security posture those affirmations attest to.
Does the DoD estimate include implementing NIST SP 800-171?
No. The final rule states there are no engineering costs in the Level 1 and Level 2 estimates because those security requirements were already contractually required under FAR 52.204-21 and DFARS 252.204-7012. If your implementation is incomplete, remediation is a separate, and usually larger, budget line.
What is the cheapest legitimate way to reduce CMMC certification cost?
Shrink your assessment scope. Consolidating CUI into a dedicated enclave reduces the number of in-scope assets, which reduces implementation effort, assessment hours, and sustainment cost simultaneously. It is the one lever that cuts all three buckets at once, and it is far cheaper to design early than to retrofit late.
Can I just self-assess instead of paying for certification?
Only if your contracts allow it. The assessment type is specified by the contract requirement, not chosen by the contractor. And a self-assessment carries the same False Claims Act exposure if the score you affirm does not reflect reality, as the $507,144 settlement we covered demonstrates.
The bottom line: CMMC certification cost in 2026 has a public, government-published floor, and everything above that floor is determined by your scope, your CUI footprint, and your current maturity. Get those three things measured before you spend. If you want that measurement done by a team that lives in these assessments, contact Petronella Technology Group, Inc. for a CMMC scoping consultation and get a budget you can defend to your CFO and, later, to an assessor.
Free, practical, and specific to regulated environments. We will email it to you.
No spam. Unsubscribe anytime.