Nice To E-Meet You!



    What marketing services do you need for your project?

    How Much Does CMMC Certification Cost In 2026?

    Short answer: By the Department of Defense’s own estimates, a CMMC Level 1 self-assessment costs a small business about $6,000 a year, a Level 2 self-assessment about $34,000 to $43,000 per three-year cycle, and a Level 2 third-party (C3PAO) certification about $105,000 over three years. Those figures cover the assessment only. Fixing the gaps it finds (remediation) is usually the bigger bill, often $20,000 to well over $100,000 depending on how far your systems are from the NIST SP 800-171 standard.

    2026 status check (as of 27 September 2026): The Department of War suspended CMMC Phase 2 on 13 July 2026, and a class deviation issued on 3 September 2026 directs contracting officers to remove third-party assessment requirements from contracts. Level 1 and Level 2 self-assessments, SPRS scores and annual affirmations still apply. C3PAO certification is currently voluntary. The CMMC Reform Task Force delivered its recommendations to the Department of War CIO in September, but they have not been made public, so check the latest guidance before you budget.

    In This Guide

    CMMC Cost At A Glance

    The only official numbers come from the Regulatory Impact Analysis in the CMMC program final rule (32 CFR Part 170, published in the Federal Register on 15 October 2024). They estimate the cost of preparing for and completing an assessment, not the cost of becoming compliant.

    Level and assessment Small business (DoD estimate) Larger business (DoD estimate)
    Level 1 self-assessment, every year $5,977 per assessment, plus about $560 per affirmation $4,042 per assessment, plus about $584 per affirmation
    Level 2 self-assessment, every 3 years, affirmed yearly $34,277 per three-year cycle, plus about $1,459 per annual affirmation $43,403 per three-year cycle, plus about $2,712 per annual affirmation
    Level 2 C3PAO certification, every 3 years, affirmed yearly $101,752 per assessment (about $104,670 over three years with affirmations); the C3PAO fee itself is about $31,234 of that $112,345 per assessment; C3PAO fee about $52,056
    Level 3 DoD (DIBCAC) assessment, on top of Level 2 certification, every 3 years Assessment about $9,050, plus about $2.7 million one-time engineering and about $490,000 a year to maintain Assessment about $39,021, plus about $21.1 million one-time and about $4.12 million a year

    Two things to keep in mind when you read that table. First, the Level 1 and Level 2 figures assume you already meet the requirements, since the underlying rules (FAR 52.204-21 and DFARS 252.204-7012) have been in contracts for years. Second, they are averages built on labor-rate assumptions. Real quotes swing widely with company size, the number of locations and how much of your network handles controlled unclassified information (CUI).

    What The 2026 Phase 2 Suspension Means For Your Budget

    CMMC was being rolled out in four phases. Phase 1 began on 10 November 2025 and put Level 1 and Level 2 self-assessment requirements into new solicitations. Phase 2, due on 10 November 2026, would have required third-party Level 2 certification in applicable contracts.

    On 13 July 2026 the Department of War suspended Phase 2 and all later milestones, citing compliance costs, and set up a CMMC Reform Task Force with 60 days to report. On 3 September 2026 a class deviation made the pause binding, directing contracting officers to strip third-party assessment requirements out of contracts.

    For budgeting, that splits costs into two groups:

    Still required now Deferred or optional for now
    Meeting the 15 Level 1 requirements (if you handle FCI) or the 110 NIST SP 800-171 requirements (if you handle CUI) Mandatory C3PAO certification assessments
    Annual Level 1 self-assessment and affirmation Level 3 DIBCAC assessments under Phase 3
    Level 2 self-assessment, a current SPRS score and annual affirmation by a senior official Phase 2 contract clauses
    DFARS 252.204-7012 safeguarding and 72-hour incident reporting  

    The practical takeaway: the remediation money is not deferred, because the security requirements never went away. What moved is the third-party audit fee. Some contractors are still buying voluntary C3PAO certifications because primes ask for them and because a certificate is stronger evidence than a self-score if compliance is ever challenged. The Department of Justice continues to pursue False Claims Act cases over inflated self-assessment scores.

    CMMC Level 1 Cost

    Level 1 applies to companies that handle only federal contract information (FCI), meaning non-public information about the contract itself rather than technical or controlled data. It covers 15 basic safeguarding requirements from FAR 52.204-21: things like limiting system access to authorized users, using passwords, keeping antivirus current, controlling physical access and sanitizing media before disposal.

    • Assessment: an annual self-assessment, entered in SPRS, with an affirmation from a senior company official. DoD estimates about $6,000 a year for a small business.
    • No POA&Ms: every requirement must be fully met. There is no option to list open items and fix them later.
    • Typical remediation: for a small company with modern IT, often little more than documentation and a few configuration changes. Budget $2,000 to $15,000 if you need outside help with policies, endpoint protection or access controls.

    Most of Level 1 is ordinary IT hygiene. If a managed IT provider already runs your network well, the main cost is staff time to document it. Our CMMC compliance checklist lists all 15 requirements with a check item for each.

    CMMC Level 2 Cost: Self-Assessment Vs C3PAO Certification

    Level 2 applies to companies that handle controlled unclassified information (CUI), such as technical drawings, specifications and export-controlled data. It requires all 110 security requirements in NIST SP 800-171 Rev. 2, covered in detail in our CMMC Level 2 requirements guide. This is where most of the cost, and most of the confusion, sits.

    Level 2 Self-Assessment

    You score yourself against all 110 requirements using the DoD assessment methodology, post the score in SPRS and have a senior official affirm it every year. DoD estimates $34,277 per three-year cycle for a small business. In practice, the assessment itself is cheap if you do it in-house and costs more if you hire a consultant to run it, which many contractors do because a score that later proves inflated carries legal risk.

    Level 2 C3PAO Certification Cost

    An accredited CMMC Third-Party Assessment Organization (C3PAO) verifies all 110 requirements and their 320 assessment objectives, reviewing documents, interviewing staff and testing systems. DoD estimates about $31,000 to $52,000 for the C3PAO’s fee alone and about $102,000 to $112,000 for the whole assessment effort including your own preparation time.

    Market quotes vary with scope. A small company with a tightly scoped CUI environment may see C3PAO fees in the $30,000 to $60,000 range, while larger or multi-site organizations routinely pay more. The single biggest driver is how many systems, people and locations are in scope.

    What Pushes Level 2 Costs Up

    • Scope: every system that stores, processes or transmits CUI, plus the systems that protect them, is assessed.
    • Cloud choices: cloud services holding CUI must meet FedRAMP Moderate or an equivalent standard, which can force migration to a government cloud tenant.
    • Multifactor authentication and FIPS-validated encryption: two of the most common and most expensive gaps.
    • Documentation: a System Security Plan (SSP) is mandatory, and assessors test that it matches reality.
    • Logging and monitoring: audit logging requirements often mean buying a SIEM or managed detection service.

    CMMC Level 3 Cost

    Level 3 is for a small number of contractors handling the most sensitive CUI. It adds 24 requirements from NIST SP 800-172, assessed by the government’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), and you must hold a final Level 2 C3PAO certification first. DoD’s own estimates put the one-time engineering cost in the millions, with hundreds of thousands to millions a year to sustain. If you are asking whether you need Level 3, you will usually be told by the contracting office.

    Remediation: The Cost The Estimates Leave Out

    DoD’s figures deliberately exclude the cost of meeting the requirements. For most small and mid-sized contractors, remediation is the largest line item in total CMMC compliance cost.

    Remediation area Typical cost range Notes
    Gap assessment $5,000 to $25,000 Usually the first paid step; tells you your real score
    Policies, procedures and SSP $5,000 to $30,000 Lower with templates, higher for complex environments
    Multifactor authentication $2,000 to $20,000 Depends on user count and legacy systems
    Government cloud migration (for example GCC High) $10,000 to $100,000+ one-time, plus higher per-user licensing Often the biggest single cost for Microsoft 365 users
    Endpoint protection and patching $20 to $60 per device per month Often bundled by an MSP
    Logging, SIEM or managed detection $1,000 to $10,000+ per month Scales with log volume and staff
    Security awareness training $20 to $100 per user per year Required for all users
    Physical security Varies Badge access, visitor logs and escorts where CUI is handled

    These are typical market ranges rather than official figures, and a well-run IT environment may already cover several rows. The only way to know your number is a gap assessment against the 110 requirements.

    Consultant, RPO And C3PAO Fees

    Three kinds of outside firms show up in most CMMC budgets, and they do different jobs:

    • CMMC consultants and Registered Provider Organizations (RPOs): help you prepare. They run gap assessments, write the SSP and policies, and manage remediation. Pricing ranges from fixed-fee readiness packages to monthly retainers.
    • Managed service providers (MSPs and MSSPs): run the technical controls day to day. Some specialize in defense contractors and include CMMC-aligned tooling in their monthly fee.
    • C3PAOs: perform the certification assessment. A C3PAO cannot also have consulted on your preparation, so you will need separate firms for readiness and assessment.

    A useful sanity check on quotes: ask each firm to break its price into assessment, documentation and remediation work, and ask how it defines your CUI scope. Differences in scope explain most of the gap between cheap and expensive proposals.

    Ongoing Costs Over The Three-Year Cycle

    CMMC is not a one-time purchase. Budget for:

    • An annual affirmation by a senior official at every level
    • Reassessment every three years for Level 2 and Level 3 (every year for Level 1)
    • Recurring licensing for security tools and government cloud
    • Staff time to keep policies, the SSP and asset inventories current
    • Annual security training
    • Closing any open POA&M items within 180 days of a conditional Level 2 result

    As a rough rule, many small contractors find the recurring cost of staying compliant runs to a meaningful share of their initial remediation spend every year after.

    How To Reduce CMMC Costs

    1. Shrink your CUI scope. Keep CUI in one well-defined environment instead of across the whole company. A CUI enclave, a segmented environment that only some staff use, can cut the number of in-scope systems dramatically.
    2. Confirm your level before buying anything. If you only handle FCI, you need Level 1, not Level 2. Your contract and the data you receive decide this.
    3. Start with a gap assessment. It turns an open-ended project into a priced list.
    4. Use what you already pay for. Many Microsoft and Google enterprise plans include security features that meet several requirements once configured.
    5. Pick providers who work with defense contractors. Firms that do this every week price more accurately and waste less time.
    6. Keep your SPRS score honest. Fixing an inflated score after a dispute costs far more than reporting accurately from the start.

    Is CMMC Worth The Cost?

    If defense contracts are a meaningful part of your revenue, yes. The underlying NIST SP 800-171 requirements already apply to any contract carrying DFARS 252.204-7012, so most of the spend is overdue compliance rather than a new cost. Contractors that are ready also win work from primes that need compliant suppliers. If defense work is a small, occasional slice of your business, weigh the cost against the revenue and consider whether you can stay at Level 1 by not accepting CUI.

    If you need help, REVERB’s lists of the top cybersecurity companies and top penetration testing companies are a good starting point for firms that can assess and harden your environment, and our guide to penetration testing cost covers the testing side of the budget.

    Frequently Asked Questions

    How much does CMMC certification cost?

    DoD estimates about $6,000 a year for a Level 1 self-assessment, about $34,000 to $43,000 per three-year cycle for a Level 2 self-assessment, and about $105,000 over three years for a Level 2 C3PAO certification for a small business. Remediation is extra and often larger.

    How much does CMMC Level 2 certification cost?

    DoD’s estimate for a small business is about $101,752 per C3PAO assessment, of which about $31,234 is the assessor’s fee. Larger businesses are estimated at about $112,345. Remediation to meet the 110 requirements is not included.

    How much does CMMC Level 1 cost?

    About $5,977 a year per DoD’s estimate for a small business, plus a small cost for the annual affirmation. Many small companies spend little beyond that if their basic IT security is already in place.

    Is CMMC certification still required in 2026?

    Partly. Phase 2, which would have required third-party Level 2 certification, was suspended in July 2026 and the requirement was removed from contracts by a September 2026 class deviation. Level 1 and Level 2 self-assessments, SPRS scores and annual affirmations are still required, as are the underlying security requirements.

    Who pays for CMMC certification?

    The contractor. There is no direct government reimbursement, though some companies recover part of the cost through overhead rates on cost-type contracts.

    How long does CMMC certification take?

    For a company starting from scratch, preparation for Level 2 commonly takes six to eighteen months. The C3PAO assessment itself usually takes days to a few weeks once scheduled.

    Can a small business afford CMMC?

    Many can by keeping CUI scope small, using an enclave or government cloud tenant for CUI work only, and staying at Level 1 where the contract allows. The cost that sinks small firms is usually remediating a whole network that did not need to be in scope.

    How often do you pay for CMMC assessments?

    Level 1 self-assessments are annual. Level 2 and Level 3 assessments are every three years, with an annual affirmation in between.

    The Short Version

    • DoD estimates: about $6,000 a year for Level 1, about $34,000 to $43,000 per cycle for a Level 2 self-assessment, and about $105,000 over three years for Level 2 C3PAO certification (small business).
    • Remediation is excluded from those figures and is usually the larger cost.
    • Since July 2026, mandatory third-party certification is suspended, but self-assessments, SPRS scores and the security requirements still apply.
    • Scope is the biggest cost lever: keep CUI in as few systems as possible.

      Once a week you will get the latest articles delivered right to your inbox