Real CMMC cost and timeline numbers by level - Department of War 32 CFR estimates, market ranges, scope-driven cost drivers, and DIY vs software vs consultant.
CMMC certification cost depends almost entirely on your level and your scope. For Level 1, the Department of War (DoW) itself estimates roughly $4,000-$6,000 per year for a self-assessment; market all-in figures run $5,000-$20,000. For Level 2, the Department estimated roughly $105,000-$118,000 for a triennial third-party (C3PAO) assessment cycle, while market C3PAO assessment fees commonly land $30,000-$100,000+ and reach $145,000-$200,000+ for large, complex scopes - before remediation. The single biggest lever on that number is scope: an enclave costs a fraction of an enterprise-wide assessment. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect: contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS, and DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 security requirements. This guide breaks down the real numbers by level, the cost drivers that actually move the total, C3PAO market reality, and how DIY, software, and consultants compare.
There are two useful reference points for CMMC cost, and honest planning uses both. The first is the Department's own published estimates from the economic analysis behind the 32 CFR rule. The second is what the market actually charges in 2025-2026, which tends to run wider than the Department's representative-entity modeling.
| Level | DoW estimate (from the rule) | Market range (industry, all-in) | What it buys |
|---|---|---|---|
| Level 1 (Self) | ~$4,000-$6,000/yr | ~$5,000-$20,000 all-in | Annual self-assessment + prep for 15 FCI requirements |
| Level 2 (C3PAO) | ~$105,000-$118,000 per triennial cycle (assessment + affirmations) | ~$30,000-$100,000+ assessment fees; up to ~$145,000-$200,000+ for large/complex scope | Triennial third-party assessment of the 110 NIST 800-171 Rev 2 requirements |
| Level 2 (Self) | Lower than C3PAO (self-assessment, no third party) | Scope-driven; below C3PAO | Self-assessment every three years + annual affirmations |
| Level 3 (DIBCAC) | Not separately broken out here | Level 2 (C3PAO) cost + the 800-172 enhanced-requirement lift | Government assessment on top of Level 2 |
Sources: DoW 32 CFR rule economic analysis as reported by DefenseScoop and PreVeil (DoW estimates); Secureframe, PreVeil, and Cabrillo (market ranges). These are ranges, and actual cost is scope-driven.
Two caveats a practitioner should carry into any budget conversation:
If you take one thing from this post, take this: scope is the master variable. Two contractors at the same level can pay wildly different totals depending on how much environment they drag into the assessment. Here is what moves the number, roughly in order of impact.
This is the order-of-magnitude lever. An enterprise-wide approach, where CUI is allowed to touch every laptop, server, and cloud tenant, pulls your entire environment into the assessment boundary, multiplying the controls to implement, the evidence to produce, and the assessor's hours. An enclave approach, with CUI confined to a deliberately bounded, segmented environment, shrinks the boundary to a fraction of that.
The move that keeps CMMC affordable is scoping CUI into an enclave before you implement or assess. It depends on a clean CUI inventory, which is why we cover what counts as CUI and how to scope it as a prerequisite to costing.
If you already comply with DFARS 252.204-7012 and have a real NIST 800-171 implementation, your remediation bill is small. If you are starting from a bare Microsoft 365 tenant with no SSP, most of your spend is remediation and tooling, not the assessment. Your current SPRS score is a decent proxy for how far you have to go.
Handling CUI often pushes organizations toward compliant cloud environments (for example, government-community cloud offerings). Those carry higher licensing costs than commercial equivalents - a recurring line item, not a one-time fee.
Closing gaps (configuring logging, deploying MFA everywhere, writing and enforcing policy, standing up the enclave) is usually the largest single component of a first-time Level 2 effort, whether you do it in-house or pay a consultant.
The SSP and POA&M are not optional and not trivial. A thin SSP stalls an assessment; rebuilding one under time pressure is expensive. Keeping these records current is exactly where tooling earns its keep: Compli.ai holds the SSP implementation statement for each requirement, evidence tagged to requirements and objectives inside your own tenant, a live SPRS score, and POA&M items checked against the 32 CFR 170.21 eligibility rules.
With Phase 2 suspended, a Level 2 (C3PAO) assessment is not a standard award condition today, but the assessor market still matters for planning if third-party requirements return. For Level 2 (C3PAO), you cannot self-select your way around a third party - you need an authorized Certified Third-Party Assessment Organization. And the supply of them is a real constraint on both price and timeline.
The Cyber AB Marketplace (cyberab.org) lists the authorized C3PAOs, and the pool is small relative to the number of contractors that handle CUI. Check the live count on the Marketplace before you plan around a specific number.
Why this matters for your budget and schedule:
Cost and timeline are linked: the phase-in schedule tells you when you need to spend, which shapes how you spend.
| Phase | Original start | Certification pressure |
|---|---|---|
| Phase 1 (in effect) | Nov 10, 2025 | Level 1 and Level 2 self-assessments with affirmations in SPRS on applicable contracts |
| Phase 2 (suspended) | Was scheduled for Nov 10, 2026 | Would have made Level 2 (C3PAO) a standard award condition; suspended July 13, 2026 while DoW reviews the program, with no new date announced |
| Phase 3 (on hold) | Was scheduled for Nov 10, 2027 | Would add Level 3 (DIBCAC) to applicable contracts |
| Phase 4 (on hold) | Was scheduled for Nov 10, 2028 | Full implementation across applicable contracts |
Source: 32 CFR 170.3(e) for the original schedule; DoW's July 13, 2026 suspension of Phase 2.
A realistic preparation timeline for a first-time Level 2 assessment, assuming a middling starting point:
The suspension does not change the underlying work. DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 requirements, and a Level 2 self-assessment covers the same requirements a C3PAO would assess, so the preparation above pays off whichever assessment your contracts end up requiring. Starting when a solicitation arrives is starting late.
There is no single right answer here - only trade-offs, and a practitioner will tell you the honest ones.
| Approach | What you pay for | Best when | The trade-off |
|---|---|---|---|
| DIY (in-house) | Internal labor + tooling + the C3PAO fee | You have real security/compliance staff and time | Cheapest on paper, but staff time is not free, and mistakes surface at assessment - the most expensive place to find them |
| Compliance software | Platform subscription + reduced internal labor + the C3PAO fee | You want to do the work yourself but not from scratch in Excel | Software structures the effort and generates artifacts, but you still own implementation decisions |
| Consultant | Consulting fees + the C3PAO fee (+ tooling) | You lack in-house expertise or need speed | Highest cash outlay; quality varies - vet for actual assessment experience |
| Software + consultant | Both, coordinated | Common in practice - the consultant runs the engagement on the platform | Highest tooling+services spend, lowest execution risk |
The honest framing: these are not mutually exclusive, and the strongest programs usually blend them. Software does not replace a good consultant, and a consultant running an engagement out of spreadsheets is leaving efficiency (and audit-readiness) on the table. Compli.ai is built for that blended approach. Your team, or a consultant working alongside you, records SSP implementation statements, manages the POA&M under the 32 CFR 170.21 rules, and tracks a live SPRS score in a SharePoint site inside your own Microsoft 365 tenant, so whichever assessment you face reviews work that is already documented. For help choosing a partner, read compliance automation vs consultants; to see the platform itself, see the Compli.ai overview.
It depends on level and scope. DoW estimates roughly $4,000-$6,000/yr for a Level 1 self-assessment and roughly $105,000-$118,000 for a Level 2 (C3PAO) triennial cycle. Market ranges are wider: Level 1 all-in around $5,000-$20,000, and Level 2 C3PAO assessment fees commonly $30,000-$100,000+, reaching $145,000-$200,000+ for large, complex scopes - all before remediation. Scope is the biggest driver.
There is no fixed price. C3PAO assessment fees for CMMC Level 2 commonly run $30,000-$100,000+ and can exceed $145,000-$200,000 for large or complex environments. The fee covers the assessment only, not the remediation, tooling, or internal labor needed to be ready for it. Fees are scoped and negotiated per environment, so a tight enclave lowers the quote.
Level 1 is a self-assessment of 15 basic requirements for FCI. Level 2 (C3PAO) is a triennial third-party assessment of all 110 NIST 800-171 Rev 2 requirements for CUI - which means more controls to implement, far more evidence, a full SSP, likely a compliant cloud environment, and an assessor's fee. The jump is a step change in both rigor and scope.
Yes. Level 1 is an annual self-assessment and affirmation. Level 2 (C3PAO) is a triennial assessment with annual affirmations in between, plus ongoing continuous-monitoring, tooling, and (often) compliant cloud licensing. Budget CMMC as a recurring program, not a one-time certification.
Yes - it is the single most effective lever. Confining CUI to a bounded enclave, rather than letting it spread enterprise-wide, shrinks the assessment boundary and can cut cost by an order of magnitude. Effective scoping starts with an accurate CUI inventory. Guessing high on scope is the most common way contractors overspend.
For a first-time Level 2 assessment, a realistic preparation-to-assessment timeline is roughly 9-12+ months from a middling starting point: CUI inventory and scoping (months 0-3), remediation and documentation (months 3-9), then the assessment itself, which for a C3PAO assessment depends on assessor availability. The Department has suspended Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program, but Level 1 and Level 2 self-assessments can still be required today, so most CUI contractors should already be underway.
The fastest way to blow a CMMC budget is to over-scope, under-document, and discover both at assessment time. Compli.ai addresses all three. Its CUI inventory and systems modules record what CUI you hold and where your boundary sits, the Controls Matrix holds the SSP implementation statement for each requirement, the POA&M module enforces the federal eligibility rules, and your SPRS score updates as you close gaps. Everything stays in your own Microsoft 365 tenant, whether your team or a consultant runs the engagement. See our CMMC compliance software, review the DFARS clause set that drives your obligations, and book a demo to get a real cost picture for your scope.