If you handle Controlled Unclassified Information (CUI) on a DoD contract, CMMC Level 2 is no longer optional. The cost question is the one most contractors get wrong, usually because the figures floating around online are vendor estimates with no source behind them. There is a better number to plan against: the Department of Defense published its own per-entity cost estimates in the CMMC Program Regulatory Impact Analysis. Those are the figures we use here.
What the DoD's Own Estimates Say
In its Regulatory Impact Analysis, the DoD modeled the three-year cost of a Level 2 Certification assessment (the path that requires a third-party assessor) at $104,670 for a small entity and $117,768 for a larger entity. The self-assessment path, where eligible, is modeled lower at $37,196 small and $48,827 larger over three years.
These are estimates, not quotes, and your actual spend depends heavily on scope and starting posture. But they are sourced, defensible numbers you can take to your board, which is more than can be said for most of the ranges you will find.
Source: DoD CMMC Program Regulatory Impact Analysis (DOD-2023-OS-0063-0003), page 14.
Where the Money Goes
The DoD's small-entity breakdown for the Level 2 Certification path is the most useful map of where your budget actually lands:
| Cost component | Small entity (3-yr) |
|---|---|
| Plan & Prepare | $20,699 |
| Conduct Assessment (your labor) | $45,509 |
| Report Results | $2,851 |
| Annual Affirmations (3-yr) | $4,377 |
The C3PAO assessor engagement itself is modeled separately at $31,234 for a small entity and $52,056 for a larger one. Notice what dominates: the assessor fee is real, but your own internal labor to prepare, document, and produce evidence is the larger share. That is the part most cost articles miss, and it is the part that determines whether your project runs lean or runs long.
Source: DoD CMMC Program Regulatory Impact Analysis, pages 25-26.
Want a directional read on where you stand against the 110 controls before you commit a budget? The free 2-minute gap check gives you a starting picture before you commit a budget.
Run the free gap check →Why Scope Drives Everything
CMMC Level 2 covers all 110 NIST SP 800-171 controls. The single biggest lever on your cost is how much of your environment those controls have to cover. A flat network where CUI can land anywhere puts the whole organization in scope. An enclave that isolates CUI keeps the boundary, and the bill, narrow. The scoping decision is made early and it sets the ceiling on everything that follows. For the full sequence, see our CMMC certification process walkthrough.
The Cost Nobody Itemizes: Time to Award
Dollar line items are not the whole story. Once third-party Level 2 certification is required on the contracts you bid, every month you are not certifiable is a month of work you cannot pursue. For many contractors the opportunity cost of delay outweighs the assessment fee. Treating CMMC as a revenue-enablement project, rather than a compliance tax, is what keeps a contractor bidding.
How AI Changes the Math
Look back at where the money goes: preparation, documentation, and evidence are the labor-heavy buckets. That is exactly the work an AI-as-a-Service (AaaS) platform can compress. Instead of consultants billing hours to copy configuration screenshots into a Word document, an AaaS platform maps your live environment to the 110 controls, drafts SSP and POA&M sections from observed state, and assembles evidence with provenance as a byproduct of normal operations.
The point is operational leverage, not headcount cuts. Your authorizing official stays the human-in-the-loop who reviews and approves every output. The platform does the assembly; the executive owns the affirmation. The savings show up in the documentation and continuous-monitoring buckets, which are the ones that consume the most labor under the consultant model.
Building Your Budget
Start from the DoD's sourced figures, adjust for your scope and starting posture, and decide early whether an enclave shrinks your boundary. Then get an honest read on where you are today. You can compare paths in our self-assessment vs. C3PAO guide, or see how AI-native tooling stacks up against legacy GRC in compliance software vs. AI compliance platform.