Level 1 is a 15-practice annual self-assessment that most suppliers reach for a few thousand dollars. Level 2 is the expensive one — 110 controls, documentation, remediation, and for most contracts a third-party C3PAO assessment.
Security & compliance gaps — plus the IT issues that create them
Not ready? Try the 10-min score · 14-Day IT Health Check
Last updated: September 2026
As of September 2026: For most small and mid-sized defense suppliers handling CUI, first-cycle CMMC Level 2 cost typically lands between $75,000 and $300,000+ once you include gap assessment, documentation, remediation, tooling/enclave licensing, and the C3PAO assessment. The C3PAO fee alone is usually $35,000–$110,000 — not the whole budget. DoD's published Level 2 C3PAO cycle estimate (~$104,670 over three years for a small entity) covers assessment/affirmation labor assumptions and excludes most implementation/remediation, which is why real-world totals run higher.
The two numbers most often quoted come from DoD's own rulemaking analysis. They model assessment labor, not the work of becoming assessable.
| Cost view | What it usually includes | Typical figure (small entity) |
|---|---|---|
| DoD Level 2 self-assessment cycle (3-year) | Assessment/affirmation model assumptions; implementation largely excluded | ~$37,196 (DoD model) |
| DoD Level 2 C3PAO cycle (3-year) | Assessment + affirmations in DoD model; implementation largely excluded | ~$104,670 (DoD model, small entity) |
| Real-world first-cycle program budget | Gap assessment, SSP/POA&M, remediation, enclave/tooling, C3PAO | $75,000–$300,000+ |
DoD figures are from the CMMC rule's regulatory impact analysis and should be read as assessment-oriented estimates, not turnkey program quotes.
Planning brackets we see across defense suppliers. Headcount is a proxy — the CUI boundary is the real driver.
| Size | Typical first-cycle total | C3PAO assessment band | What usually drives variance |
|---|---|---|---|
| Small (≈1–50 employees, tight CUI enclave) | $75,000–$130,000 | $30,000–$50,000 | Scope discipline + starting maturity |
| Mid (≈51–200) | $130,000–$220,000 | $50,000–$80,000 | Multi-site, tooling, documentation quality |
| Larger (≈201–500) | $220,000–$300,000+ | $80,000–$120,000 | Broad CUI boundary, OT/IT complexity |
Ranges reflect what small and mid-sized defense suppliers typically encounter. Treat them as planning brackets, not quotes — scope is the variable that matters most.
Scoping the CUI boundary, assessing all 110 controls, and producing a scored gap report and prioritized remediation plan. Cost scales with sites, systems, and enclave complexity.
The documentation an assessor actually reads. Written once, then maintained — an SSP that does not match reality is the single most common assessment failure.
MFA, FIPS-validated encryption, logging and SIEM, endpoint protection, access control, network segmentation, and often a GCC High migration. The widest and least predictable line item.
Microsoft 365 GCC High or a dedicated CUI enclave, plus the security tooling layered on top. Recurring, not one-time.
The third-party certification assessment itself, priced by scope and assessor. Required every three years, with annual affirmations in between.
Continuous monitoring, evidence collection, POA&M closure, policy upkeep, and annual affirmation support. Compliance decays without this.
Level 1 is a different order of magnitude. It covers 15 basic safeguarding practices for Federal Contract Information, is self-assessed annually, and most organizations reach it for a few thousand dollars of documentation and configuration work plus internal time.
How many users, endpoints, and systems actually touch CUI. A tight enclave is dramatically cheaper to certify than a whole company.
Organizations already running MFA, EDR, logging, and documented policies often spend a fraction of what a from-scratch environment does.
Level 1 is an annual self-assessment against 15 practices. Level 2 requires all 110 NIST 800-171 controls and, for most contracts, a C3PAO assessment.
Whether you need GCC High, and whether existing SaaS tools can meet the requirements or must be replaced.
Shop-floor and OT systems that cannot be patched normally require segmentation and compensating controls.
Evidence collection is labor. Someone pays for it — either your staff's time or an outside team's.
Ohio's defense supply base is heavy on multi-plant manufacturers, and that changes the math. A second or third site rarely doubles the cost, but it does add network segmentation, physical-security evidence, and local admin practices that an assessor will sample at each location. Shop-floor and OT equipment — CNC controllers, test benches, legacy Windows machines that cannot be patched — usually has to be segmented behind compensating controls rather than remediated, and that engineering work lands in the remediation line above.
Export-controlled work stacks on top. If your drawings or technical data fall under ITAR, the GCC High question stops being optional, and licensing plus a tenant migration becomes a recurring cost rather than a project. Suppliers in the Cleveland and Columbus corridors frequently discover this mid-program, after the budget was already set against a commercial Microsoft 365 assumption.
The most common local underestimate, though, is time — specifically months 9 through 12. Controls have to run long enough to generate the evidence an assessor accepts: log retention, review records, ticket history, training completion. Turning on MFA in March does not produce a year of proof by April. Budget the evidence-maturity window as a real phase and the C3PAO assessment stops being the risky part.
Define the CUI boundary, assess the 110 controls, and produce a scored SPRS baseline.
SSP, POA&M, and the policy set built to match the environment you will actually run.
Close technical gaps, migrate to an enclave if required, and stand up logging and monitoring.
Run the controls long enough to produce evidence an assessor will accept — this is what most schedules underestimate.
Readiness review, assessor scheduling, and the certification assessment itself.
A 30-minute scoping call tells you which level your contracts require, how large your CUI boundary really is, and which of the lines above you can avoid entirely.
Prefer to read first? Read the CMMC Level 2 guide
The 110 controls and how the assessment runs.
Gap assessment through audit readiness.
All 14 families and 110 requirements.
Export-controlled data requirements.
Compliance maintained as recurring service.
How we work with the defense supply chain.