Cost Guide

    What CMMC certification actually costs

    A line-by-line breakdown for Level 1 and Level 2 — assessment, documentation, remediation, licensing, C3PAO fees, and the recurring cost nobody budgets for.

    The cost lines for CMMC Level 2

    Ranges reflect what small and mid-sized defense suppliers typically encounter. Treat them as planning brackets, not quotes — scope is the variable that matters most.

    Gap assessment against NIST 800-171

    $8,000 – $25,000

    Scoping the CUI boundary, assessing all 110 controls, and producing a scored gap report and prioritized remediation plan. Cost scales with sites, systems, and enclave complexity.

    System Security Plan (SSP) & POA&M

    $10,000 – $30,000

    The documentation an assessor actually reads. Written once, then maintained — an SSP that does not match reality is the single most common assessment failure.

    Technical remediation

    $15,000 – $150,000+

    MFA, FIPS-validated encryption, logging and SIEM, endpoint protection, access control, network segmentation, and often a GCC High migration. The widest and least predictable line item.

    Enclave or GCC High licensing

    $35 – $85 per user / month

    Microsoft 365 GCC High or a dedicated CUI enclave, plus the security tooling layered on top. Recurring, not one-time.

    C3PAO assessment (Level 2)

    $35,000 – $110,000

    The third-party certification assessment itself, priced by scope and assessor. Required every three years, with annual affirmations in between.

    Ongoing managed compliance

    $2,500 – $12,000 / month

    Continuous monitoring, evidence collection, POA&M closure, policy upkeep, and annual affirmation support. Compliance decays without this.

    Level 1 is a different order of magnitude. It covers 15 basic safeguarding practices for Federal Contract Information, is self-assessed annually, and most organizations reach it for a few thousand dollars of documentation and configuration work plus internal time.

    What moves your number

    Scope size

    How many users, endpoints, and systems actually touch CUI. A tight enclave is dramatically cheaper to certify than a whole company.

    Current maturity

    Organizations already running MFA, EDR, logging, and documented policies often spend a fraction of what a from-scratch environment does.

    Level required

    Level 1 is an annual self-assessment against 15 practices. Level 2 requires all 110 NIST 800-171 controls and, for most contracts, a C3PAO assessment.

    Cloud posture

    Whether you need GCC High, and whether existing SaaS tools can meet the requirements or must be replaced.

    Manufacturing environment

    Shop-floor and OT systems that cannot be patched normally require segmentation and compensating controls.

    Internal capacity

    Evidence collection is labor. Someone pays for it — either your staff's time or an outside team's.

    Budget the timeline, not just the invoice

    Months 1–2

    Scope and gap assessment

    Define the CUI boundary, assess the 110 controls, and produce a scored SPRS baseline.

    Months 2–4

    Documentation

    SSP, POA&M, and the policy set built to match the environment you will actually run.

    Months 3–9

    Remediation

    Close technical gaps, migrate to an enclave if required, and stand up logging and monitoring.

    Months 9–12

    Evidence maturity

    Run the controls long enough to produce evidence an assessor will accept — this is what most schedules underestimate.

    Months 12–18

    C3PAO assessment

    Readiness review, assessor scheduling, and the certification assessment itself.

    Get a scoped number for your environment

    A 30-minute scoping call tells you which level your contracts require, how large your CUI boundary really is, and which of the lines above you can avoid entirely.

    Prefer to read first? Read the CMMC Level 2 guide

    Frequently Asked Questions

    Related reading

    CMMC Level 2 Guide

    The 110 controls and how the assessment runs.

    CMMC Compliance Services

    Gap assessment through audit readiness.

    NIST 800-171

    All 14 families and 110 requirements.

    ITAR Compliance

    Export-controlled data requirements.

    Managed IT + Compliance

    Compliance maintained as recurring service.

    Defense & DoD Suppliers

    How we work with the defense supply chain.

    Call Now