How much does CMMC Level 2 cost?

Short answer

DoD's regulatory cost analysis in the 32 CFR Part 170 final rule estimates, for a small entity over three years, $37,196 for a Level 2 self-assessment and $104,670 for a Level 2 C3PAO certification assessment, including annual affirmations. Those figures assume the 110 requirements are already implemented. Remediation, tooling and any GCC High migration are separate and usually the larger cost.

What DoD estimated

The final rule's regulatory impact analysis gives per-entity estimates for small businesses. They cover planning, conducting and reporting the assessment and the senior-official affirmation, priced from labor rates for an internal director and an external service provider.

  • Level 1 self-assessment and affirmation: $5,977, repeated annually.
  • Level 2 self-assessment: $34,277 in the assessment year; $37,196 over three years with two annual affirmations.
  • Level 2 C3PAO certification assessment: $101,752 in the assessment year; $104,670 over three years with two annual affirmations.

What those numbers leave out

DoD states that its Level 2 estimates assume the contractor has already implemented the NIST SP 800-171 Rev 2 requirements, because DFARS 252.204-7012 has required them for years. So the estimates exclude the cost of actually getting compliant: new security tools, licensing, a cloud migration, consulting, policy writing and staff time.

For most small and mid-size companies, that implementation work is the larger share of the budget.

The same analysis prices external service provider time at $260.28 per hour, a useful reminder that DoD expects most small contractors to use outside help for preparation even when they run the assessment themselves.

What drives your price

  • Scope: how many people, devices, sites and systems touch CUI. A tight enclave costs less than an enterprise-wide boundary.
  • Starting point: an existing SSP and accurate SPRS score versus starting from nothing.
  • Cloud platform: staying where you are versus migrating email and files to Microsoft 365 GCC High.
  • Operational technology: CNC machines, test equipment and legacy systems that are hard to secure.
  • Ongoing operations: logging, vulnerability management and evidence upkeep needed to affirm every year.

How providers price the work

Expect three common models: a fixed-fee project for gap assessment, SSP and POA&M; time-and-materials or hourly for remediation; and a monthly retainer or per-user managed service to operate the controls afterward. Ask any provider to separate one-time readiness costs from recurring operating costs so you can compare quotes on the same basis, and to state which of the 110 requirements each line item addresses.

While the Phase 2 suspension is in place, new solicitations call only for self-assessments, which shifts near-term spending from assessor fees toward implementation.

Common follow-up questions

Is the DoD cost estimate what I will actually pay?

Treat it as a floor for the assessment itself. DoD's figures assume the 110 requirements are already in place, so remediation, licensing, migration and ongoing operations are additional and vary with your scope and starting point.

Do I have to pay for a C3PAO right now?

Not for new DoD solicitations while Phase 2 is suspended. The July 13, 2026 memo limits requirements to Level 1 (Self) or Level 2 (Self), and directs removal of C3PAO requirements from active solicitations and contracts.

Does a smaller CUI scope reduce cost?

Usually, yes. Assessment scope follows where CUI is processed, stored or transmitted, so isolating CUI in a defined enclave limits the systems, users and service providers you must secure, document and assess.

Need help with this?

LAN Service Group scopes CMMC programs, builds SSP and POA&M documentation, and carries out remediation through its ISSO-led compliance practice, with project, hourly or managed-service engagement models for small and mid-size businesses.

Talk to LAN Service Group (888) 281-7243

Sources