Short answer: By the Department of Defense’s own estimates, a CMMC Level 1 self-assessment costs a small business about $6,000 a year, a Level 2 self-assessment about $34,000 to $43,000 per three-year cycle, and a Level 2 third-party (C3PAO) certification about $105,000 over three years. Those figures cover the assessment only. Fixing the gaps it finds (remediation) is usually the bigger bill, often $20,000 to well over $100,000 depending on how far your systems are from the NIST SP 800-171 standard.
2026 status check (as of 27 September 2026): The Department of War suspended CMMC Phase 2 on 13 July 2026, and a class deviation issued on 3 September 2026 directs contracting officers to remove third-party assessment requirements from contracts. Level 1 and Level 2 self-assessments, SPRS scores and annual affirmations still apply. C3PAO certification is currently voluntary. The CMMC Reform Task Force delivered its recommendations to the Department of War CIO in September, but they have not been made public, so check the latest guidance before you budget.
The only official numbers come from the Regulatory Impact Analysis in the CMMC program final rule (32 CFR Part 170, published in the Federal Register on 15 October 2024). They estimate the cost of preparing for and completing an assessment, not the cost of becoming compliant.
| Level and assessment | Small business (DoD estimate) | Larger business (DoD estimate) |
| Level 1 self-assessment, every year | $5,977 per assessment, plus about $560 per affirmation | $4,042 per assessment, plus about $584 per affirmation |
| Level 2 self-assessment, every 3 years, affirmed yearly | $34,277 per three-year cycle, plus about $1,459 per annual affirmation | $43,403 per three-year cycle, plus about $2,712 per annual affirmation |
| Level 2 C3PAO certification, every 3 years, affirmed yearly | $101,752 per assessment (about $104,670 over three years with affirmations); the C3PAO fee itself is about $31,234 of that | $112,345 per assessment; C3PAO fee about $52,056 |
| Level 3 DoD (DIBCAC) assessment, on top of Level 2 certification, every 3 years | Assessment about $9,050, plus about $2.7 million one-time engineering and about $490,000 a year to maintain | Assessment about $39,021, plus about $21.1 million one-time and about $4.12 million a year |
Two things to keep in mind when you read that table. First, the Level 1 and Level 2 figures assume you already meet the requirements, since the underlying rules (FAR 52.204-21 and DFARS 252.204-7012) have been in contracts for years. Second, they are averages built on labor-rate assumptions. Real quotes swing widely with company size, the number of locations and how much of your network handles controlled unclassified information (CUI).
CMMC was being rolled out in four phases. Phase 1 began on 10 November 2025 and put Level 1 and Level 2 self-assessment requirements into new solicitations. Phase 2, due on 10 November 2026, would have required third-party Level 2 certification in applicable contracts.
On 13 July 2026 the Department of War suspended Phase 2 and all later milestones, citing compliance costs, and set up a CMMC Reform Task Force with 60 days to report. On 3 September 2026 a class deviation made the pause binding, directing contracting officers to strip third-party assessment requirements out of contracts.
For budgeting, that splits costs into two groups:
| Still required now | Deferred or optional for now |
| Meeting the 15 Level 1 requirements (if you handle FCI) or the 110 NIST SP 800-171 requirements (if you handle CUI) | Mandatory C3PAO certification assessments |
| Annual Level 1 self-assessment and affirmation | Level 3 DIBCAC assessments under Phase 3 |
| Level 2 self-assessment, a current SPRS score and annual affirmation by a senior official | Phase 2 contract clauses |
| DFARS 252.204-7012 safeguarding and 72-hour incident reporting |
The practical takeaway: the remediation money is not deferred, because the security requirements never went away. What moved is the third-party audit fee. Some contractors are still buying voluntary C3PAO certifications because primes ask for them and because a certificate is stronger evidence than a self-score if compliance is ever challenged. The Department of Justice continues to pursue False Claims Act cases over inflated self-assessment scores.
Level 1 applies to companies that handle only federal contract information (FCI), meaning non-public information about the contract itself rather than technical or controlled data. It covers 15 basic safeguarding requirements from FAR 52.204-21: things like limiting system access to authorized users, using passwords, keeping antivirus current, controlling physical access and sanitizing media before disposal.
Most of Level 1 is ordinary IT hygiene. If a managed IT provider already runs your network well, the main cost is staff time to document it. Our CMMC compliance checklist lists all 15 requirements with a check item for each.
Level 2 applies to companies that handle controlled unclassified information (CUI), such as technical drawings, specifications and export-controlled data. It requires all 110 security requirements in NIST SP 800-171 Rev. 2, covered in detail in our CMMC Level 2 requirements guide. This is where most of the cost, and most of the confusion, sits.
You score yourself against all 110 requirements using the DoD assessment methodology, post the score in SPRS and have a senior official affirm it every year. DoD estimates $34,277 per three-year cycle for a small business. In practice, the assessment itself is cheap if you do it in-house and costs more if you hire a consultant to run it, which many contractors do because a score that later proves inflated carries legal risk.
An accredited CMMC Third-Party Assessment Organization (C3PAO) verifies all 110 requirements and their 320 assessment objectives, reviewing documents, interviewing staff and testing systems. DoD estimates about $31,000 to $52,000 for the C3PAO’s fee alone and about $102,000 to $112,000 for the whole assessment effort including your own preparation time.
Market quotes vary with scope. A small company with a tightly scoped CUI environment may see C3PAO fees in the $30,000 to $60,000 range, while larger or multi-site organizations routinely pay more. The single biggest driver is how many systems, people and locations are in scope.
Level 3 is for a small number of contractors handling the most sensitive CUI. It adds 24 requirements from NIST SP 800-172, assessed by the government’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), and you must hold a final Level 2 C3PAO certification first. DoD’s own estimates put the one-time engineering cost in the millions, with hundreds of thousands to millions a year to sustain. If you are asking whether you need Level 3, you will usually be told by the contracting office.
DoD’s figures deliberately exclude the cost of meeting the requirements. For most small and mid-sized contractors, remediation is the largest line item in total CMMC compliance cost.
| Remediation area | Typical cost range | Notes |
| Gap assessment | $5,000 to $25,000 | Usually the first paid step; tells you your real score |
| Policies, procedures and SSP | $5,000 to $30,000 | Lower with templates, higher for complex environments |
| Multifactor authentication | $2,000 to $20,000 | Depends on user count and legacy systems |
| Government cloud migration (for example GCC High) | $10,000 to $100,000+ one-time, plus higher per-user licensing | Often the biggest single cost for Microsoft 365 users |
| Endpoint protection and patching | $20 to $60 per device per month | Often bundled by an MSP |
| Logging, SIEM or managed detection | $1,000 to $10,000+ per month | Scales with log volume and staff |
| Security awareness training | $20 to $100 per user per year | Required for all users |
| Physical security | Varies | Badge access, visitor logs and escorts where CUI is handled |
These are typical market ranges rather than official figures, and a well-run IT environment may already cover several rows. The only way to know your number is a gap assessment against the 110 requirements.
Three kinds of outside firms show up in most CMMC budgets, and they do different jobs:
A useful sanity check on quotes: ask each firm to break its price into assessment, documentation and remediation work, and ask how it defines your CUI scope. Differences in scope explain most of the gap between cheap and expensive proposals.
CMMC is not a one-time purchase. Budget for:
As a rough rule, many small contractors find the recurring cost of staying compliant runs to a meaningful share of their initial remediation spend every year after.
If defense contracts are a meaningful part of your revenue, yes. The underlying NIST SP 800-171 requirements already apply to any contract carrying DFARS 252.204-7012, so most of the spend is overdue compliance rather than a new cost. Contractors that are ready also win work from primes that need compliant suppliers. If defense work is a small, occasional slice of your business, weigh the cost against the revenue and consider whether you can stay at Level 1 by not accepting CUI.
If you need help, REVERB’s lists of the top cybersecurity companies and top penetration testing companies are a good starting point for firms that can assess and harden your environment, and our guide to penetration testing cost covers the testing side of the budget.
DoD estimates about $6,000 a year for a Level 1 self-assessment, about $34,000 to $43,000 per three-year cycle for a Level 2 self-assessment, and about $105,000 over three years for a Level 2 C3PAO certification for a small business. Remediation is extra and often larger.
DoD’s estimate for a small business is about $101,752 per C3PAO assessment, of which about $31,234 is the assessor’s fee. Larger businesses are estimated at about $112,345. Remediation to meet the 110 requirements is not included.
About $5,977 a year per DoD’s estimate for a small business, plus a small cost for the annual affirmation. Many small companies spend little beyond that if their basic IT security is already in place.
Partly. Phase 2, which would have required third-party Level 2 certification, was suspended in July 2026 and the requirement was removed from contracts by a September 2026 class deviation. Level 1 and Level 2 self-assessments, SPRS scores and annual affirmations are still required, as are the underlying security requirements.
The contractor. There is no direct government reimbursement, though some companies recover part of the cost through overhead rates on cost-type contracts.
For a company starting from scratch, preparation for Level 2 commonly takes six to eighteen months. The C3PAO assessment itself usually takes days to a few weeks once scheduled.
Many can by keeping CUI scope small, using an enclave or government cloud tenant for CUI work only, and staying at Level 1 where the contract allows. The cost that sinks small firms is usually remediating a whole network that did not need to be in scope.
Level 1 self-assessments are annual. Level 2 and Level 3 assessments are every three years, with an annual affirmation in between.