If you supply the Department of Defense and you handle Controlled Unclassified Information, the question is no longer whether CMMC applies to you. It is what it costs. The honest answer: it depends on how much CUI you touch, how clean your current environment is, and how much you do yourself versus pay someone else to do. This guide gives you the figures you can actually cite, the line items behind them, and the one cost most contractors do not budget for until it bites.
The short answer: verified cost by level
Industry guides quote wildly different ranges, most of them unsourced. The figures you can stand behind come from the DoD CMMC Program Regulatory Impact Analysis. Per entity, across the three-year cycle:
| Path | Small entity | Larger entity |
|---|---|---|
| Level 1 self-assessment | $5,977 | $4,042 |
| Level 2 self-assessment | $37,196 | $48,827 |
| Level 2 Certification (C3PAO) | $104,670 | $117,768 |
Source: DoD CMMC Program Regulatory Impact Analysis (DOD-2023-OS-0063-0003), pages 12 and 14.
Within Level 2 Certification, the C3PAO assessor engagement alone is estimated at $31,234 for a small entity and $52,056 for a larger one. The rest is preparation, documentation, your own assessment labor, and affirmations.
What actually drives CMMC compliance cost
Five variables move the number more than anything else. Understand these and the quotes you get stop looking random.
1. CUI scope and network segmentation
Every system, application, person, and location that processes, stores, or transmits CUI is in scope, and each one raises assessment hours, evidence collection, and remediation. Contractors who segment CUI into a defined enclave pay materially less. Contractors who let CUI live in shared email, shared drives, and general-purpose laptops pay materially more, because the scope is the whole company.
2. Existing maturity vs. NIST SP 800-171
CMMC Level 2 is built on the 110 controls in NIST SP 800-171. If your environment was already implementing 800-171 with a current SSP, POA&M, and evidence, your gap-to-Level-2 cost is mostly proof and process. If your SSP is two years old or your POA&M has stale open items, you are paying to build foundation work, not just to certify it.
3. Internal staffing vs. outside help
A senior IT or security person who can own the SSP, POA&M, and audit prep cuts outside cost dramatically. The opposite is also true: every gap in your internal capability becomes billable hours. Most of that outside cost is the systematic documentation work, which is the work AI can compress.
4. C3PAO assessment fees
Third-party assessment for Level 2 is a separate line from remediation and preparation. The DoD estimates the assessor engagement at $31,234 for a small entity and $52,056 for a larger one, and actual fees vary with scope and asset count.
5. Ongoing maintenance and POA&M closure
CMMC is not a one-time event. You re-affirm annually and re-assess every three years for Level 2. Any control gap that returns during ongoing monitoring becomes a re-work item, so budget for a recurring run-rate, not just the event.
Level 1 cost breakdown
Level 1 applies to contractors handling Federal Contract Information only, no CUI. It is an annual self-assessment against the 15 basic safeguarding requirements drawn from FAR 52.204-21, attested by a senior official. The DoD estimates the three-year cost at $5,977 for a small entity. The biggest mistake is treating Level 1 as free: it is annual, it is attested to, and a false attestation carries real legal exposure.
Level 2 cost breakdown
Level 2 is where the real money sits. The 110 NIST SP 800-171 controls span access control, audit and accountability, configuration management, identification and authentication, incident response, and more. The DoD's three-year Level 2 Certification estimate is $104,670 for a small entity and $117,768 for a larger one. The driver of where you land inside the program is almost always scope, not control complexity. See our small-business guide for the enclave-first approach.
Level 3 cost
Level 3 adds a subset of NIST SP 800-172 enhanced controls on top of Level 2 and is assessed by DIBCAC, not a C3PAO. It applies to the highest-priority CUI on the most sensitive programs, and cost is significantly higher because the control set is harder and evidence requirements are deeper. Most contractors should not aim for Level 3 unless a specific contract requires it.
The hidden cost most contractors miss
Lost time. Not outside hours, lost time. Compliance work pulls senior engineers, IT leadership, and the owner away from delivery and sales. The contractors who blow through their CMMC budget usually do not blow through it on consulting. They blow through it on a delay that pushes contract decisions into the next fiscal year. A realistic program plan protects revenue-generating capacity.
How AI-as-a-Service changes the math
Traditional CMMC consulting was built on hours. Every SSP paragraph, every POA&M item, every evidence task was billable. AI-as-a-Service (AaaS) inverts that. An agent that already knows the 110 controls, the assessment objectives, and the evidence patterns assessors ask for can draft your SSP, generate your POA&M, map your existing controls, and produce the evidence checklist in a fraction of the time. The human stays the authorizing official on every decision. ai4cmmc.ai is AaaS for exactly this work: not software you have to learn, not a consultant you have to manage, but a system that produces the artifacts and tracks the program while your team approves and operates it.