A line-by-line breakdown for Level 1 and Level 2 — assessment, documentation, remediation, licensing, C3PAO fees, and the recurring cost nobody budgets for.
Ranges reflect what small and mid-sized defense suppliers typically encounter. Treat them as planning brackets, not quotes — scope is the variable that matters most.
Scoping the CUI boundary, assessing all 110 controls, and producing a scored gap report and prioritized remediation plan. Cost scales with sites, systems, and enclave complexity.
The documentation an assessor actually reads. Written once, then maintained — an SSP that does not match reality is the single most common assessment failure.
MFA, FIPS-validated encryption, logging and SIEM, endpoint protection, access control, network segmentation, and often a GCC High migration. The widest and least predictable line item.
Microsoft 365 GCC High or a dedicated CUI enclave, plus the security tooling layered on top. Recurring, not one-time.
The third-party certification assessment itself, priced by scope and assessor. Required every three years, with annual affirmations in between.
Continuous monitoring, evidence collection, POA&M closure, policy upkeep, and annual affirmation support. Compliance decays without this.
Level 1 is a different order of magnitude. It covers 15 basic safeguarding practices for Federal Contract Information, is self-assessed annually, and most organizations reach it for a few thousand dollars of documentation and configuration work plus internal time.
How many users, endpoints, and systems actually touch CUI. A tight enclave is dramatically cheaper to certify than a whole company.
Organizations already running MFA, EDR, logging, and documented policies often spend a fraction of what a from-scratch environment does.
Level 1 is an annual self-assessment against 15 practices. Level 2 requires all 110 NIST 800-171 controls and, for most contracts, a C3PAO assessment.
Whether you need GCC High, and whether existing SaaS tools can meet the requirements or must be replaced.
Shop-floor and OT systems that cannot be patched normally require segmentation and compensating controls.
Evidence collection is labor. Someone pays for it — either your staff's time or an outside team's.
Define the CUI boundary, assess the 110 controls, and produce a scored SPRS baseline.
SSP, POA&M, and the policy set built to match the environment you will actually run.
Close technical gaps, migrate to an enclave if required, and stand up logging and monitoring.
Run the controls long enough to produce evidence an assessor will accept — this is what most schedules underestimate.
Readiness review, assessor scheduling, and the certification assessment itself.
A 30-minute scoping call tells you which level your contracts require, how large your CUI boundary really is, and which of the lines above you can avoid entirely.
Prefer to read first? Read the CMMC Level 2 guide
The 110 controls and how the assessment runs.
Gap assessment through audit readiness.
All 14 families and 110 requirements.
Export-controlled data requirements.
Compliance maintained as recurring service.
How we work with the defense supply chain.