HomeBlogCost Guides

CMMC Certification Cost: What Level 1 and Level 2 Cost in 2026

Pixel-art illustration of a robot on a pirate ship's deck holding up a glowing blue shield against red bug-shaped threats above stormy waves

CMMC certification cost has two parts: bringing your systems up to the security requirements, and the assessment itself. The Defense Department's own estimates for a small company are $37,196 over three years for a Level 2 self-assessment and $104,670 over three years for a Level 2 certification assessment by a C3PAO, and both assume the requirements are already in place. As of October 10, 2026, Phase II is suspended, so contracts may require only self-assessments.

Our CMMC compliance services cover the first part: scoping where controlled unclassified information (CUI) lives, building the controls and writing the System Security Plan. We are not a C3PAO, we certify no one, and we publish no prices. This guide sets out the cost lines, the Department's published estimates and a worksheet you can fill in with real quotes. It is general information, not legal advice.

How much does CMMC certification cost?

The only cost figures from a primary source are the Department's regulatory estimates in the CMMC program rule, 32 CFR part 170, published October 15, 2024. They cover planning for an assessment, conducting it, reporting the results in the Supplier Performance Risk System (SPRS) and the affirmations a senior official submits:

CMMC assessmentSmall business estimateLarger company estimateHow often
Level 1 self-assessment and affirmation$5,977$4,042Every year
Level 2 self-assessment, affirmation and two yearly reaffirmations$37,196 per three years$48,827 per three yearsAssessment every three years, affirmation every year
Level 2 certification assessment by a C3PAO, affirmation and two yearly reaffirmations$104,670 per three years$117,768 per three yearsAssessment every three years, affirmation every year

Read the table with three cautions. First, these are estimates built from assumed labor rates, including $260.28 an hour for an outside service provider or assessor, and they assume the company passes on the first attempt. Small businesses come out higher at Level 1 because the Department assumed they hire outside help instead of using in-house staff.

Second, the assessor's own fee is only part of the certification figure. For a small business, the Department priced the C3PAO engagement at $31,234, a three-person team working 120 hours; the rest is the company's preparation time and outside help. Third, the Department's CMMC FAQ says the real cost depends on the level required, the complexity of your network, your existing cybersecurity posture and market forces of supply and demand. That is why published figures and quotes vary by assessor.

What do the Department's estimates leave out?

The work of meeting the requirements. The rule's cost analysis assumes contractors already implemented the 15 requirements of FAR 52.204-21, in force since June 15, 2016, and the NIST SP 800-171 requirements that DFARS 252.204-7012 required by December 31, 2017. So it includes no cost to implement the requirements, to keep them running or to close items on a plan of action. The CMMC FAQ says the same thing: costs to implement existing safeguarding requirements are not counted as CMMC compliance costs.

For a company that starts with gaps, that excluded work is the part of the budget the estimates cannot tell you. It depends on what a gap assessment finds, which is why scoping comes before any quote.

What drives CMMC Level 2 cost for a small business?

  • Scope. Under 32 CFR 170.19, every asset that processes, stores or transmits CUI is assessed against all Level 2 requirements, which our guide to CMMC Level 2 requirements lists by family, and security tools that protect those assets are assessed against the requirements relevant to what they do. Fewer people, devices and systems touching CUI means less to build, document and assess.
  • An enclave or the whole company. Keeping CUI in a separate environment, used only by the people who need it, takes the rest of the company out of scope.
  • The cloud environment. A cloud service holding CUI must be FedRAMP Moderate authorized or meet equivalent requirements. Choosing between commercial Microsoft 365, GCC and GCC High changes licensing and migration cost, and the right choice depends on the data you hold.
  • Your starting point. Multifactor authentication, FIPS-validated encryption for CUI, central logging, configuration baselines and patching either exist already or become remediation projects.
  • Physical safeguards. Visitor escorts, physical access logs and managed physical access must be in place before an assessment, because the rule never allows them on a plan of action.
  • Documentation. The System Security Plan, policies, procedures and an evidence library take real hours, and the evidence must be kept for six years from the CMMC status date.
  • The assessment route. A self-assessment costs staff and provider time; a C3PAO assessment adds the assessor's fee and the time spent supporting it.

CMMC budget worksheet

Copy this into a spreadsheet and fill in the last column with quotes and internal estimates. We left it blank on purpose: no published figure can price your scope.

Budget lineWhat it coversWhat moves the costOne-time or recurringYour figure
Contract and CUI reviewReading clauses, asking primes in writing whether CUI is coming, mapping where it goesNumber of contracts and primesOne-time, repeated for new contracts
Gap assessmentScoring current controls against each requirement and its assessment objectivesScope size and existing documentationOne-time, then before each reassessment
EnvironmentEnclave design, cloud tenant, network segmentation, migration of CUIUser count and data typesSetup once, then licenses
Technical remediationMFA, encryption, logging, endpoint protection, patching, backupsStarting posture and tools already licensedProjects plus subscriptions
Physical safeguardsVisitor logs, escorts, access control for areas holding CUIOffice layoutMostly one-time
DocumentationSystem Security Plan, policies, procedures, POA&M, evidence libraryHow much exists todayOne-time, then upkeep
Self-assessment and SPRSAssessment labor, SPRS entry, the Affirming Official's reviewIn-house staff or outside helpEvery three years, affirmation yearly
C3PAO assessment, only if a contract requires itCertification assessment and any closeout assessmentScope and assessor ratesEvery three years
Ongoing operationMonitoring, patching, access reviews, evidence upkeepSize and toolingMonthly
Internal timeAffirming Official, process owners, interviews during assessmentNumber of people in scopeOngoing

What does the Phase II suspension change about the budget?

On July 13, 2026 the Department of War suspended Phase II, which was due to start on November 10, 2026. The implementing memo lets program offices include only CMMC Level 1 (Self) or Level 2 (Self) in procurement requests, bars them from designating Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, and tells contracting officers to remove those requirements from existing contracts before the next option period or at the next scheduled administrative modification. It also keeps DFARS 252.204-7012 in effect and says the Department will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments.

In budget terms: no new contract can make you buy a C3PAO assessment during the suspension, but the work to meet the requirements is still owed under clauses you have already signed. The CIO's own memo explains the pause in cost terms, citing prohibitive compliance costs and severe shortages in third-party assessment capacity, and it names no-cost help that continues: the Office of Small Business Programs' Project Spectrum, Cyber Crime Center services and the NSA Cybersecurity Collaboration Center. The memo promised further guidance after a 60-day review. When we checked the Department of War CIO's CMMC pages on October 10, 2026, Phase II was still suspended and no review results were posted. Our post on the CMMC Phase II suspension tracks what changes next.

How can a small contractor keep CMMC costs down?

  1. Confirm the data first. Ask the prime in writing whether you will receive CUI. Federal contract information alone means Level 1: 15 requirements and a yearly self-assessment, with no plan of action allowed.
  2. Shrink the scope with an enclave before buying tools for the whole company.
  3. Fix the heavy requirements first. The scoring rule in 32 CFR 170.24 subtracts 5, 3 or 1 points for each requirement not met, and only 1-point items, plus non-FIPS encryption, can sit on a plan of action.
  4. Use what you already license. If you already pay for Microsoft 365 identity, device management and endpoint protection, configure those before buying new tools.
  5. Collect evidence as you build. Final, dated exports made at the time are cheaper than reconstructing proof before an assessment.
  6. Use the free resources the Department points to before paying for training.

Does NetSys provide CMMC certification?

No. Only an authorized C3PAO can perform a Level 2 certification assessment, and the CMMC rule requires everyone in the assessment ecosystem to avoid actual or perceived conflicts of interest, so the firm that builds your environment should not be the one that assesses it. Our work sits before the assessment: contract and flow-down review, CUI data mapping and an enclave boundary, a gap assessment with a prioritized remediation plan, implementation of the NIST SP 800-171 requirements, a System Security Plan written from the configuration we deployed, a plan of action kept within the limits the rule allows, and an evidence library organized by requirement. After that we run monitoring and patching inside the enclave, hold quarterly control reviews and prepare an annual affirmation package for leadership. Agreements run month to month, and you can start with a free remote external penetration test within an agreed scope.

Not sure whether your contracts call for Level 1 or Level 2? Book a call and we will look at the clauses and your CUI flow with you before you budget anything.

Frequently asked questions

What does the CMMC budget worksheet cover?

Every line between today and a CMMC status in SPRS: contract review, gap assessment, the environment that will hold CUI, technical remediation, physical safeguards, documentation, the assessment and affirmations, and ongoing operation. It separates one-time from recurring costs, because Level 2 repeats every three years and affirmations every year.

Who should maintain the CMMC budget and evidence?

The Affirming Official, the senior person who affirms compliance in SPRS, should own both, with a security lead or outside provider keeping the evidence library current. Evidence used for an assessment must be retained for six years from the CMMC status date, so treat it as a records job, not a project folder.

How do we validate that the spending achieved compliance?

Score a self-assessment against every requirement with the 32 CFR 170.24 method, using final evidence: configuration exports, logs, signed policies and screenshots with dates. A score of 110 with every requirement met is the target; a lower score shows exactly which requirements still need money or time.

How much does a C3PAO assessment cost?

C3PAOs set their own prices, and the Department's FAQ says supply and demand affect them. The 2024 rule estimated the assessor's own engagement at $31,234 for a small business and $52,056 for a larger company, before the company's preparation time. During the Phase II suspension no new contract can require one.

How much does CMMC Level 1 cost?

The Department estimated $5,977 a year for a small business to complete and affirm a Level 1 self-assessment with outside help, and $4,042 for a larger company using in-house staff. Level 1 has 15 requirements; if they are not already met, the cost of meeting them comes on top.

Can a plan of action spread the cost over time?

Only a little. A Level 2 plan of action needs a score of at least 88 out of 110, may include only 1-point requirements plus encryption that is not FIPS-validated, and must be closed within 180 days. Six requirements, including the System Security Plan, can never be on it. Level 1 allows no plan of action at all.

Sources and further reading

CMMC 2.0 Compliance Services

Discuss cmmc 2.0 compliance services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore CMMC 2.0 Compliance Services 845-203-3914