compli.ai
From the blog

CMMC Certification Cost and Timeline: Real Numbers

Real CMMC cost and timeline numbers by level - Department of War 32 CFR estimates, market ranges, scope-driven cost drivers, and DIY vs software vs consultant.

CMMC certification cost depends almost entirely on your level and your scope. For Level 1, the Department of War (DoW) itself estimates roughly $4,000-$6,000 per year for a self-assessment; market all-in figures run $5,000-$20,000. For Level 2, the Department estimated roughly $105,000-$118,000 for a triennial third-party (C3PAO) assessment cycle, while market C3PAO assessment fees commonly land $30,000-$100,000+ and reach $145,000-$200,000+ for large, complex scopes - before remediation. The single biggest lever on that number is scope: an enclave costs a fraction of an enterprise-wide assessment. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect: contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS, and DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 security requirements. This guide breaks down the real numbers by level, the cost drivers that actually move the total, C3PAO market reality, and how DIY, software, and consultants compare.

Cost by level: DoW estimates vs market ranges

There are two useful reference points for CMMC cost, and honest planning uses both. The first is the Department's own published estimates from the economic analysis behind the 32 CFR rule. The second is what the market actually charges in 2025-2026, which tends to run wider than the Department's representative-entity modeling.

LevelDoW estimate (from the rule)Market range (industry, all-in)What it buys
Level 1 (Self)~$4,000-$6,000/yr~$5,000-$20,000 all-inAnnual self-assessment + prep for 15 FCI requirements
Level 2 (C3PAO)~$105,000-$118,000 per triennial cycle (assessment + affirmations)~$30,000-$100,000+ assessment fees; up to ~$145,000-$200,000+ for large/complex scopeTriennial third-party assessment of the 110 NIST 800-171 Rev 2 requirements
Level 2 (Self)Lower than C3PAO (self-assessment, no third party)Scope-driven; below C3PAOSelf-assessment every three years + annual affirmations
Level 3 (DIBCAC)Not separately broken out hereLevel 2 (C3PAO) cost + the 800-172 enhanced-requirement liftGovernment assessment on top of Level 2

Sources: DoW 32 CFR rule economic analysis as reported by DefenseScoop and PreVeil (DoW estimates); Secureframe, PreVeil, and Cabrillo (market ranges). These are ranges, and actual cost is scope-driven.

Two caveats a practitioner should carry into any budget conversation:

  • The Department's figures cover the assessment cycle. The DoW estimates in the table are for assessment and affirmation activity, as the table notes. Budget implementation, remediation, tooling, and internal labor as separate lines.
  • Assessment fee is not the whole bill. The C3PAO's fee buys the assessment. It does not buy the remediation, tooling, or internal labor needed to be ready for that assessment - which for most organizations dwarfs the assessment fee itself.

The cost drivers that actually matter

If you take one thing from this post, take this: scope is the master variable. Two contractors at the same level can pay wildly different totals depending on how much environment they drag into the assessment. Here is what moves the number, roughly in order of impact.

1. Scope: enclave vs enterprise

This is the order-of-magnitude lever. An enterprise-wide approach, where CUI is allowed to touch every laptop, server, and cloud tenant, pulls your entire environment into the assessment boundary, multiplying the controls to implement, the evidence to produce, and the assessor's hours. An enclave approach, with CUI confined to a deliberately bounded, segmented environment, shrinks the boundary to a fraction of that.

The move that keeps CMMC affordable is scoping CUI into an enclave before you implement or assess. It depends on a clean CUI inventory, which is why we cover what counts as CUI and how to scope it as a prerequisite to costing.

2. Your starting maturity

If you already comply with DFARS 252.204-7012 and have a real NIST 800-171 implementation, your remediation bill is small. If you are starting from a bare Microsoft 365 tenant with no SSP, most of your spend is remediation and tooling, not the assessment. Your current SPRS score is a decent proxy for how far you have to go.

3. Cloud environment choices

Handling CUI often pushes organizations toward compliant cloud environments (for example, government-community cloud offerings). Those carry higher licensing costs than commercial equivalents - a recurring line item, not a one-time fee.

4. Remediation labor

Closing gaps (configuring logging, deploying MFA everywhere, writing and enforcing policy, standing up the enclave) is usually the largest single component of a first-time Level 2 effort, whether you do it in-house or pay a consultant.

5. Documentation

The SSP and POA&M are not optional and not trivial. A thin SSP stalls an assessment; rebuilding one under time pressure is expensive. Keeping these records current is exactly where tooling earns its keep: Compli.ai holds the SSP implementation statement for each requirement, evidence tagged to requirements and objectives inside your own tenant, a live SPRS score, and POA&M items checked against the 32 CFR 170.21 eligibility rules.

C3PAO market reality

With Phase 2 suspended, a Level 2 (C3PAO) assessment is not a standard award condition today, but the assessor market still matters for planning if third-party requirements return. For Level 2 (C3PAO), you cannot self-select your way around a third party - you need an authorized Certified Third-Party Assessment Organization. And the supply of them is a real constraint on both price and timeline.

The Cyber AB Marketplace (cyberab.org) lists the authorized C3PAOs, and the pool is small relative to the number of contractors that handle CUI. Check the live count on the Marketplace before you plan around a specific number.

Why this matters for your budget and schedule:

  • Demand can outstrip supply. If third-party requirements return (see the timeline below), a limited pool of assessors will face pent-up demand, which pressures both price and lead times.
  • Plan for lead time. If third-party assessments return, assessor availability can become the binding constraint on when you get certified, even when your own readiness is not. Contractors who wait until a contract requires it may find the calendar is the problem.
  • Fees are scope-driven and negotiated. There is no fixed price list; a C3PAO scopes your environment and quotes accordingly - another reason a tight enclave pays off.

Timeline by phase

Cost and timeline are linked: the phase-in schedule tells you when you need to spend, which shapes how you spend.

PhaseOriginal startCertification pressure
Phase 1 (in effect)Nov 10, 2025Level 1 and Level 2 self-assessments with affirmations in SPRS on applicable contracts
Phase 2 (suspended)Was scheduled for Nov 10, 2026Would have made Level 2 (C3PAO) a standard award condition; suspended July 13, 2026 while DoW reviews the program, with no new date announced
Phase 3 (on hold)Was scheduled for Nov 10, 2027Would add Level 3 (DIBCAC) to applicable contracts
Phase 4 (on hold)Was scheduled for Nov 10, 2028Full implementation across applicable contracts

Source: 32 CFR 170.3(e) for the original schedule; DoW's July 13, 2026 suspension of Phase 2.

A realistic preparation timeline for a first-time Level 2 assessment, assuming a middling starting point:

  • Months 0-3: CUI inventory, scoping, enclave design, gap assessment.
  • Months 3-9: Remediation - implement controls, stand up the enclave, write the SSP, build the POA&M.
  • Months 6-9: Get your SPRS score current; close high-weight gaps.
  • Months 9-12+: Complete the assessment your contracts require: a self-assessment with an affirmation in SPRS today, or a C3PAO assessment if third-party requirements return (subject to assessor availability).

The suspension does not change the underlying work. DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 requirements, and a Level 2 self-assessment covers the same requirements a C3PAO would assess, so the preparation above pays off whichever assessment your contracts end up requiring. Starting when a solicitation arrives is starting late.

DIY vs software vs consultant: how the money compares

There is no single right answer here - only trade-offs, and a practitioner will tell you the honest ones.

ApproachWhat you pay forBest whenThe trade-off
DIY (in-house)Internal labor + tooling + the C3PAO feeYou have real security/compliance staff and timeCheapest on paper, but staff time is not free, and mistakes surface at assessment - the most expensive place to find them
Compliance softwarePlatform subscription + reduced internal labor + the C3PAO feeYou want to do the work yourself but not from scratch in ExcelSoftware structures the effort and generates artifacts, but you still own implementation decisions
ConsultantConsulting fees + the C3PAO fee (+ tooling)You lack in-house expertise or need speedHighest cash outlay; quality varies - vet for actual assessment experience
Software + consultantBoth, coordinatedCommon in practice - the consultant runs the engagement on the platformHighest tooling+services spend, lowest execution risk

The honest framing: these are not mutually exclusive, and the strongest programs usually blend them. Software does not replace a good consultant, and a consultant running an engagement out of spreadsheets is leaving efficiency (and audit-readiness) on the table. Compli.ai is built for that blended approach. Your team, or a consultant working alongside you, records SSP implementation statements, manages the POA&M under the 32 CFR 170.21 rules, and tracks a live SPRS score in a SharePoint site inside your own Microsoft 365 tenant, so whichever assessment you face reviews work that is already documented. For help choosing a partner, read compliance automation vs consultants; to see the platform itself, see the Compli.ai overview.

FAQ

How much does CMMC certification cost?

It depends on level and scope. DoW estimates roughly $4,000-$6,000/yr for a Level 1 self-assessment and roughly $105,000-$118,000 for a Level 2 (C3PAO) triennial cycle. Market ranges are wider: Level 1 all-in around $5,000-$20,000, and Level 2 C3PAO assessment fees commonly $30,000-$100,000+, reaching $145,000-$200,000+ for large, complex scopes - all before remediation. Scope is the biggest driver.

How much does a C3PAO assessment cost?

There is no fixed price. C3PAO assessment fees for CMMC Level 2 commonly run $30,000-$100,000+ and can exceed $145,000-$200,000 for large or complex environments. The fee covers the assessment only, not the remediation, tooling, or internal labor needed to be ready for it. Fees are scoped and negotiated per environment, so a tight enclave lowers the quote.

Why is CMMC Level 2 so much more expensive than Level 1?

Level 1 is a self-assessment of 15 basic requirements for FCI. Level 2 (C3PAO) is a triennial third-party assessment of all 110 NIST 800-171 Rev 2 requirements for CUI - which means more controls to implement, far more evidence, a full SSP, likely a compliant cloud environment, and an assessor's fee. The jump is a step change in both rigor and scope.

Does CMMC certification have an ongoing cost?

Yes. Level 1 is an annual self-assessment and affirmation. Level 2 (C3PAO) is a triennial assessment with annual affirmations in between, plus ongoing continuous-monitoring, tooling, and (often) compliant cloud licensing. Budget CMMC as a recurring program, not a one-time certification.

Can I reduce CMMC cost by limiting scope?

Yes - it is the single most effective lever. Confining CUI to a bounded enclave, rather than letting it spread enterprise-wide, shrinks the assessment boundary and can cut cost by an order of magnitude. Effective scoping starts with an accurate CUI inventory. Guessing high on scope is the most common way contractors overspend.

How long does CMMC certification take?

For a first-time Level 2 assessment, a realistic preparation-to-assessment timeline is roughly 9-12+ months from a middling starting point: CUI inventory and scoping (months 0-3), remediation and documentation (months 3-9), then the assessment itself, which for a C3PAO assessment depends on assessor availability. The Department has suspended Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program, but Level 1 and Level 2 self-assessments can still be required today, so most CUI contractors should already be underway.

The fastest way to blow a CMMC budget is to over-scope, under-document, and discover both at assessment time. Compli.ai addresses all three. Its CUI inventory and systems modules record what CUI you hold and where your boundary sits, the Controls Matrix holds the SSP implementation statement for each requirement, the POA&M module enforces the federal eligibility rules, and your SPRS score updates as you close gaps. Everything stays in your own Microsoft 365 tenant, whether your team or a consultant runs the engagement. See our CMMC compliance software, review the DFARS clause set that drives your obligations, and book a demo to get a real cost picture for your scope.