NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian, Arabic and Chinese.See what’s new →
CMMC Compliance Cost: What the DoD Estimated
Learn

CMMC Compliance Cost: What the DoD Estimated

·Alexander Sverdlov

The only official figures for CMMC cost are the Department of Defense's own, published in the regulatory impact analysis of the CMMC Program final rule (32 CFR part 170, 89 FR 83092, 15 October 2024). For a small entity, the DoD estimates a Level 2 certification assessment at $101,752 and puts the three year cost, with two annual affirmations, at $104,670. Of that, the notional fee for the assessor itself is $31,234; the rest is your own staff and consultant time. But those figures price only the assessment. In the rule's words, "DoD did not consider the cost of implementing the security requirements themselves", because they were already required by FAR 52.204-21 and DFARS 252.204-7012. Your real CMMC cost is the assessment plus whatever it takes to close the gap to the requirements, and for most firms the second number is the larger one.

This guide sets out what the DoD estimated, what it left out, and how to budget the rest. Every figure below is from the final rule, in 2023 dollars, and is stated "per assessment of each contractor information system, estimated at one per entity".

DoD estimateSmall entityOther than small
Level 1 self assessment, every year$5,977$4,042
Level 2 self assessment, three years with affirmations$37,196$48,827
Level 2 certification assessment by a C3PAO, three years with affirmations$104,670$117,768
Of which the notional C3PAO fee$31,234 (3 assessors, 120 hours)$52,056 (5 assessors, 200 hours)
Level 3 assessment, three years with affirmations$12,802$44,445
Level 3 implementation, one time, per entity$2,700,000$21,100,000
Level 3 implementation, recurring, per entity$490,000$4,120,000
What the DoD estimated for a small entity in the 32 CFR 170 cost analysis: $5,977 for a Level 1 self assessment each year, $37,196 for Level 2 self assessment over three years, $104,670 for the Level 2 C3PAO route over three years, and $2.7 million one time Level 3 implementation

What does CMMC cost, according to the DoD?

The rule builds each estimate from labour hours across planning, the assessment itself, reporting and, where allowed, closing out a plan of action. For a small entity's Level 2 certification, the C3PAO portion is "C3PAO engagement inclusive of Phases 1, 2, and 3 (3-person team) for 120 hours ($260.28/hr x 120hrs = $31,234)". For an organisation other than small it is a five person team for 200 hours, $52,056. The DoD is explicit that these "are representative of average assessment efforts not actual prices of C3PAO services available in the marketplace", and that "market forces of supply and demand will determine C3PAO pricing". Real quotes will vary with the size and complexity of the network in scope.

Level 1 is a yearly self assessment against the 15 security requirements of FAR 52.204-21, which NIST maps to 17 requirements in SP 800-171 Revision 2. Level 2 is a self assessment or a C3PAO assessment every three years against the 110 requirements of NIST SP 800-171 Revision 2, with an affirmation after every assessment and annually thereafter. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by DCMA DIBCAC, and the rule notes these assessments "are performed free of cost by DoD assessors". The Level 3 figures above are the contractor's cost of supporting that assessment, and the rule adds that the total cost of Level 3 "includes the cost of a Level 2 certification assessment as well as the costs to implement and assess the security requirements specific to Level 3".

Venvera CMMC 2.0 dashboard with the compliance roadmap, the SPRS score dial, open and overdue POA&M counts and practice implementation status

What do the DoD figures leave out?

Most of what you will actually spend. The analysis says plainly that "cost estimates are not included for an entity to implement the CMMC Level 1 or 2 security requirements, maintain implementation of these existing security requirements, or remediate a plan of action for unimplemented requirements". Implementation was priced only for Level 3. So the following sit outside every Level 1 and Level 2 number in the table.

Implementing the requirements. If you hold CUI under DFARS 252.204-7012 you have been required to implement NIST SP 800-171 since 31 December 2017. The DoD treats that cost as already sunk. If you have not done the work, it is your largest line: multifactor authentication, logging, encryption, configuration management, incident response and the System Security Plan that documents all of it.

Keeping them implemented. Staff time, tooling and evidence collection between assessments, so that each annual affirmation is true.

Closing gaps. Remediation of any plan of action items. Section 170.21 allows conditional Level 2 status only if your score is at least 0.8 of the 110 requirements, 88 points, and only for certain lower weighted requirements; open items must be closed out "within 180-days of the Conditional CMMC Status Date" or the status expires.

More than one assessed system. Every estimate assumes one contractor information system per entity. If your CUI sits in more than one assessed environment, budget for more than one assessment.

Cloud. Under DFARS 252.204-7012, a cloud service that stores CUI must meet security requirements "equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline". That is a constraint on which providers you can use, and it carries its own cost. Who needs FedRAMP explains the test.

What the DoD figures leave out: implementing NIST SP 800-171, maintaining the controls, fixing plan of action gaps, a second assessed CUI system, your C3PAO's actual quote, and FedRAMP Moderate equivalent cloud

When does each cost land?

The DFARS acquisition rule took effect on 10 November 2025, and that date started the four phase rollout in 32 CFR 170.3(e). In Phase 1, the DoD "intends to include the requirement for CMMC Statuses of Level 1 (Self) or Level 2 (Self)" as a condition of award, and may require Level 2 (C3PAO) instead. Phase 2 "begins one calendar year following the start date of Phase 1", which makes it 10 November 2026; from then the DoD intends to require Level 2 (C3PAO) for applicable contracts as a condition of award, though it may defer that to an option period. Phase 3 extends Level 2 (C3PAO) to option periods and Level 3 to award, and Phase 4 is full implementation.

CMMC also flows down. Section 170.23 applies the requirements "to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit any FCI or CUI", so a subcontractor's cost depends on the level its prime's contract sets.

When each cost lands under 32 CFR 170.3(e): Phase 1 from 10 November 2025 with self assessments, Phase 2 one year later with C3PAO assessment at award, Phase 3 with C3PAO for option periods and Level 3 at award, and Phase 4 full implementation

What do other cost guides get wrong?

Three mistakes appear again and again. The first is quoting $104,670 or $117,768 as "the cost of CMMC". Those are the DoD's assessment and affirmation estimates, and the rule itself excludes implementing, maintaining and remediating the requirements.

The second is treating the roughly $41,000 Level 3 figure in the rule's summary table for organisations other than small as an implementation cost. It is the cost of supporting the DIBCAC assessment. The rule's Level 3 implementation estimate is $2.7 million one time plus $490,000 recurring per small entity, and $21.1 million plus $4.12 million per entity other than small. Relatedly, guides that quote a C3PAO fee range for Level 3 have the wrong assessor: Level 3 is assessed by DIBCAC, free of charge.

The third is the requirement set. Level 2 is "identical to the requirements in NIST SP 800-171 R2". NIST published Revision 3 in May 2024, but the rule states that Revision 3 "is not currently applicable to this rule". Budgeting against Revision 3 prices the wrong control set.

How should you budget for CMMC?

Work from the contract outwards. Read the level the solicitation or your prime specifies. Draw the CUI boundary as tightly as you can, because every requirement applies to whatever sits inside it. Score yourself against the 110 requirements, which gives you both your gap and your score for the Supplier Performance Risk System. Price the remediation of every requirement not met, starting with those that cannot go on a plan of action: any requirement worth more than one point, apart from one encryption exception, and six named in section 170.21. Only then ask C3PAOs for quotes, with the boundary already fixed. The CMMC self assessment checklist is a free way to do the scoring step.

Budget in this order: read the level in the contract, draw the CUI boundary, score against NIST SP 800-171, price the remediation, then get C3PAO quotes
Venvera evidence library showing expired, renewing and current evidence artifacts, each linked to the controls it satisfies across frameworks
An illustrative view of where a CMMC budget is going: Level 2 requirements met, SPRS score, open POA&M items, and requirements barred from a POA&M that are not yet met

Check your own position

Fill in the middle column before you ask anyone for a quote.

QuestionYour answerWhy it matters
Which CMMC level and assessment type does the contract or your prime require?Level 2 (Self) and Level 2 (C3PAO) differ by roughly $67,000 over three years in the DoD's own small entity estimates.
Do you hold CUI, or only FCI?FCI only normally means Level 1: a yearly self assessment, with no plan of action allowed.
How many systems hold CUI?Each DoD estimate covers one contractor information system.
What is your score against the 110 requirements?Below 88 points, conditional status is not available.
Which requirements that cannot go on a plan of action are not met?Requirements worth more than one point, and six named ones, must be met before conditional Level 2 status.
Does every cloud service holding CUI meet FedRAMP Moderate or its equivalent?DFARS 252.204-7012 requires it, whatever the CMMC level.

If most rows are blank, the free compliance check gives you a starting position. CMMC 2.0 in Venvera tracks the 110 Level 2 practices with a live SPRS score and keeps the SSP and POA&M as living documents, and the CMMC software comparison sets out what to look for in any tool.

The bottom line on CMMC compliance cost: the DoD priced the assessment, and the controls are your bill

Frequently asked questions

How much does a CMMC Level 2 assessment cost?

The DoD's notional C3PAO fee is $31,234 for a small entity and $52,056 otherwise, inside total assessment estimates of $101,752 and $112,345. The rule says actual C3PAO prices are set by the market.

Who pays for the CMMC assessment?

The contractor must obtain a Level 2 certification assessment from an authorized or accredited C3PAO. Level 3 assessments are performed by DoD assessors free of cost.

Does the DoD estimate include implementing NIST SP 800-171?

No. For Levels 1 and 2 the rule excludes implementing, maintaining and remediating the requirements, because FAR 52.204-21 and DFARS 252.204-7012 already required them.

How often do the costs recur?

Level 1 is assessed every year. Level 2 is assessed every three years, with an affirmation after each assessment and annually thereafter. Level 3 recertification requires a new Level 2 certification assessment first.

Which revision of NIST SP 800-171 does CMMC use?

Revision 2. The rule states that Revision 3, published in May 2024, is not currently applicable.

Primary sources

Cost figures and quotations are from the regulatory impact analysis and preamble of the CMMC Program final rule, 89 FR 83092 of 15 October 2024, and from 32 CFR part 170, sections 170.3(e), 170.14, 170.15, 170.16, 170.18, 170.21, 170.22 and 170.23. Phase dates follow the effective date of the DFARS CMMC acquisition rule, 90 FR 43560. The cloud requirement is DFARS 252.204-7012(b)(2)(ii)(D); the Revision 3 date is from NIST. Figures are the DoD's estimates in 2023 dollars, not prices. Confirm current rules before relying on a reference.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING