The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC Cost Calculator: DoD's Official Estimate vs. Your Real Cost

Estimate your first-cycle and three-year CMMC budget by level, CUI scope, environment, and readiness — then see the number DoD's official estimate leaves out.

The Defense Compliance Report Editorial TeamIndependent CMMC and DIB compliance research
Published: Last reviewed:
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Verify scope and applicability with a Registered Practitioner before acting.

Methodology · Editorial standards · Corrections policy

Last verified: June 3, 2026.The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. Built from 32 CFR Part 170, the DFARS final rule, DoD's Regulatory Impact Analysis, NIST SP 800-171 Rev. 2, and Cyber AB ecosystem rules. This page is an educational budgeting resource, not legal, contractual, compliance, or certification advice. Do not enter CUI, drawings, contract numbers, or vulnerability findings into any tool on this page. We may receive compensation for qualified introductions when disclosed; compensation does not control our regulatory analysis or which provider category we point you to.

This CMMC cost calculatorgives you a defensible budget range, not a sales quote. Here is the bottom line up front: DoD's own small-business estimates are $5,977 a year for a Level 1 self-assessment, $37,196 over three years for a Level 2 self-assessment, and $104,670 over three yearsfor a Level 2 certification assessment by a third party. Those figures come straight from DoD's Regulatory Impact Analysis for the CMMC rule. But here's the part almost no vendor tells you: for Levels 1 and 2, those numbers cover only the assessment — not the implementation, remediation, environment, and maintenance work it takes to become compliant in the first place. This tool reconciles the two.

Use the CMMC cost calculator

What this calculator does, in one line:it starts from DoD's official assessment estimate for your level, then adds the readiness, remediation, environment, evidence, and maintenance work DoD's estimate excludes — and returns a first-cycle range, a three-year range, your biggest cost driver, and the provider category to talk to first. It is an editorial budgeting tool, not a quote, and not legal or contractual advice.
Interactive estimator

Build your CMMC budget range

Company size (DoD cost model)

A proxy for the DoD cost split; true SBA size standards are NAICS-specific.

This lever moves cost more than total headcount.

A SPRS score of 88+ does notmean you're ready. 88 is only a minimum threshold for a conditionalLevel 2 (C3PAO) status with a limited POA&M; some high-weight requirements can't be deferred, and open items must close within 180 days. Treat 88+ as “in range,” not “done.”

Enter only non-sensitive planning details. Never enter CUI, export-controlled technical data, drawings, contract numbers, vulnerability findings, or customer names.

DoD official (3-yr)
$104,670
Assessment only
Your real 3-yr
$251,500 – $997,500
All-in planning range
Estimated first-cycle budget
$192,500 – $624,500
Likely: $320,500 · ranges, not quotes.
First-cycle line-item breakdown
DoD assessment anchor$101,752
Readiness$8,500 – $47,500
Remediation$26,500 – $178,500
Environment$10,000 – $65,000
GRC / evidence tooling$10,000 – $60,000
Annual operations$15,000 – $105,000
Contingency (12%)applied above
Confidence95/100

Lower when level, scope, or environment is unclear, because pretending otherwise would be dishonest.

Your biggest cost driver
Remediation and evidence readiness
Your recommended next step
Readiness / RPO / MSP / MSSP before C3PAO

Don't schedule the certification assessment yet. Close gaps and organize evidence first, then bring in an independent C3PAO.

Find readiness help before you schedule a C3PAO

We may receive compensation for qualified introductions when disclosed; it does not control our regulatory analysis or which provider category we point you to.

Assembles your inputs and results into a copyable summary to paste into an email or hand to a provider. No CUI, no network call, no PII.

  • This is a budgeting estimate, not a quote or a certification guarantee.
  • DoD's official Level 1 and Level 2 estimates do not include implementation, remediation, or maintenance.
  • Keep your readiness/remediation help separate from the firm that performs your certification assessment.

Pressure-test this estimate before you request quotes

Tell us your level, scope, and timeline, and we'll match you with source-checked provider options for the stage you're actually in. No CUI, contract numbers, drawings, or system details.

Get matched with source-checked provider options →

We may receive compensation for qualified introductions when disclosed; it does not control our regulatory analysis or which provider category we point you to.

DoD's official estimate vs. budget reality

The single most expensive mistake in CMMC budgeting is treating four different numbers as one. DoD's official estimate, a C3PAO's assessment fee, a readiness firm's quote, and your true all-in budget are not the same number. The table below is our reconciliation of DoD's published per-level estimates against what the same effort tends to cost once you add the work DoD's estimate leaves out.
CMMC pathDoD's official estimate (small entity)What that figure actually buysWhat it does not settleRealistic all-in, Year 1*
Level 1 self-assessment (FCI only)$5,977 / yearThe annual self-assessment, reporting, and affirmationWhether your FCI environment already meets the 15 basic safeguardsUsually light if scope is truly FCI-only
Level 2 self-assessment (CUI, self-assessed)$37,196 / 3 yrsThe triennial self-assessment plus three annual affirmationsImplementation, remediation, evidence, environment, upkeep~$60K–$200K+ (higher with broad scope or a cloud move)
Level 2 (C3PAO) (CUI, third-party assessed)$104,670 / 3 yrsThe certification assessment, reporting, affirmations, and your labor to support itEverything needed to become ready before the assessor arrives~$90K–$350K+ (mid-six figures starting from scratch)
Level 3 (DIBCAC, high-sensitivity CUI)$12,802 / 3 yrs assessment + affirmationThe government assessment and affirmations only (no C3PAO fee)DoD also budgets $2.7M one-time + $490K/yr to implement NIST SP 800-172, on top of a Level 2 (C3PAO) statusProgram-level (DoD models ~$4.3M over 3 yrs); validate against contract

*Realistic all-in ranges are The Defense Compliance Report's editorial planning estimates, informed by publicly published provider pricing and our own reporting — not DoD figures, and not a substitute for a scoped quote. The Level 3 figures above are DoD's own model.

Look closer at that $104,670, because the breakdown is the whole lesson. The accredited assessor's own engagement fee is just $31,234 of it. The rest is your side of the table: $45,509for your team's and your IT provider's labor to conduct and sit through the assessment, $20,699 to plan and prepare, $2,851 to report, and $4,377 for three years of affirmations. Add it up and you get $104,670 — and not one dollar of it fixes a single security gap. It is the cost of proving readiness, not achieving it.

Is that a proving cost or an achieving cost?

Not sure whether the number you're staring at is a proving cost or an achieving cost? Get matched with source-checked provider options for your level and scope.

Get matched with source-checked provider options →

How much does CMMC cost in 2026?

CMMC cost depends on four things: your level, your assessment type, how much of your business touches CUI, and whether you're budgeting only for the assessment or for the full path to readiness. DoD's official small-entity estimates are roughly $6,000 a year for Level 1, $37,000 over three years for Level 2 self-assessment, and $105,000 over three years for a Level 2 certification assessment by a third party. Those are assessment costs only.

CMMC(Cybersecurity Maturity Model Certification) is the Department of Defense's program for verifying that defense contractors and subcontractors actually protect the sensitive information they handle. It exists for a blunt reason: between January 2020 and February 2022, the FBI, NSA, and CISA reported sustained Russian state-sponsored targeting of U.S. cleared defense contractors, and a DoD Inspector General audit (DODIG-2019-105) found contractors were not consistently implementing the security controls they had already agreed to.

Here's the honest range by path, with DoD's anchor on one side and the budget reality on the other:

To put scale on it: DoD estimates roughly 8,350 medium and large entities will need a Level 2 certification assessment as the rule fully rolls out, and its Regulatory Impact Analysis projects about 56,689 small-entity Level 2 certification assessmentsacross the phase-in. This is not a niche compliance chore; it's a market-wide budgeting event, and the contractors who price it correctly now will have a scheduling and cash-flow advantage over the ones who wait.

What DoD's official CMMC cost estimates include — and deliberately leave out

Here is the damaging admission this calculator is built around: DoD's official Level 1 and Level 2 cost estimates are not your all-in budget, and DoD says so plainly. For Levels 1 and 2, those estimates cover only assessment, reporting, and affirmation — the cost to proveyou're compliant. They exclude implementation, remediation, and maintenance, because DoD assumes you already implemented the underlying security controls years ago.

This is the most important section on the page, so we'll be precise. In its Regulatory Impact Analysis, DoD states that for Levels 1 and 2, “cost estimates are not included for an entity to implement the CMMC Level 1 or 2 security requirements, maintain compliance with current security requirements, or remediate a Plan of Action for unimplemented requirements.” Why not? Because those controls were already mandated: FAR 52.204-21 (the basic safeguarding clause, effective June 15, 2016) requires the 15 Level 1 safeguards, and DFARS 252.204-7012 required implementation of NIST SP 800-171 Rev. 2 by December 31, 2017.

Read that again, because it's the whole game. DoD's $104,670 is the cost to verify work it assumes you finished in 2017. If you did finish it, that figure is roughly your number. If you didn't, your real budget includes everything DoD left out.

How do we know many contractors didn't? DoD knows too, and it built the rule around the gap. The same analysis cites the DoD Inspector General's finding that contractors “did not consistently implement” the required safeguards. And buried in the analysis is the detail that explains every sticker-shock story in the Defense Industrial Base. DoD writes, in plain language, that under the existing self-attestation model “a contractor is compliant with the NIST SP 800-171 Rev 2 standard if 10% of NIST SP 800-171 Rev 2 requirements are implemented and the other 90% are listed in a Plan of Action.” A Plan of Action and Milestones, or POA&M, is a document listing security gaps and your plan to fix them. For years, contractors marked themselves “compliant” in SPRS(the Supplier Performance Risk System, DoD's official supplier database) while most of their controls lived on that list. CMMC is the moment the list comes due — especially at the Level 2 certification assessment, where a third party verifies what you've actually built, not what you've promised.

So why does this raise your odds of doing CMMC well, rather than scaring you off? Because it tells you exactly where your money goes, and in what order. The contractors who blow their budgets are the ones who schedule an assessment before fixing anything, then pay for a failed assessment and a remediation scramble. The contractors who do it cleanly figure out their real gap first, close it, organize evidence, and thenbring in an assessor. The calculator above separates these costs precisely so you can sequence them. There's good news in the structure, too: at Level 2, the most powerful cost lever isn't the assessment fee — it's how much of your business touches CUI, which you can often shrink. That's the next question.

Your budget just changed — now sequence it.

If your budget just changed after separating 'proving' from 'achieving,' that's the point of this page. Get matched with source-checked provider options that fit your stage — readiness first, assessment later.

Get matched with source-checked provider options →

Why do two Level 2 companies get completely different CMMC quotes?

Two companies can both need Level 2 and still receive wildly different quotes because cost is driven by scope, maturity, environment, and timeline — not company size. DoD's own analysis says Level 2 cost is “driven by multiple factors, including market forces … and the size and complexity of the enterprise or enclave under assessment.” A 12-user enclave with organized evidence is a different budgeting problem than an enterprise-wide mix of cloud and on-prem systems with unmapped CUI.

If you've collected quotes and felt like you were comparing apples to anvils, you weren't imagining it. Here's the same calculator run on two real-world small-business profiles — same level, very different invoice:

Company ACompany B
Profile12 CUI users, narrow enclave, SSP written, near-ready, 12-month runway75 CUI users, CUI spread across M365 + file shares + endpoints, no SSP, 0–3 months
First-cycle estimate~$140K–$295K (likely ~$185K)~$535K–$2.8M (likely ~$1.2M)
Three-year estimate~$170K–$490K (likely ~$260K)~$685K–$3.8M (likely ~$1.6M)
Biggest cost driverThe assessment itselfCUI scope and remediation
First provider categoryC3PAO comparison (evidence is ready)Readiness / RPO / MSP / MSSP (fix first)

Ranges are illustrative outputs of this calculator's editorial planning model; your scoped quote is the binding number.

Four drivers move the number far more than your employee count does.

Scope is usually the first cost driver. The single biggest variable is how much of your organization is in the assessment boundary— the set of systems, people, and workflows that store, process, or transmit CUI. Fifteen users handling CUI inside one controlled environment is a small, knowable assessment. The same company with CUI flowing through email, three SaaS apps, a file server, and everyone's laptop is a far larger one.

Maturity changes cost more than size. A near-ready company with a written System Security Plan (an SSP — the document describing how you meet each requirement), organized evidence, and a SPRS score in the 90s is mostly buying an assessment. A company with no SSP and a low score is buying months of remediation first. Same level, same headcount, very different invoice.

Environment complexity can dominate the budget. Where CUI lives determines how hard it is to control and prove. Commercial Microsoft 365 or Google Workspace, government cloud such as Microsoft GCC High or AWS GovCloud, on-prem servers, endpoints, identity, and logging each carry different remediation and evidence costs. The wrong architecture can quietly expand your scope and your bill.

Timeline pressure raises the price.A 12-month runway lets you remediate methodically. A 60-day scramble means premium consulting rates, rework, and competing for scarce assessor calendar slots. Urgency is itself a cost driver — the unglamorous reason to start before you're forced to.

Your quote spread is a scope-and-readiness story.

See which provider category fits your scope before you collect another bid. Get matched with source-checked provider options for your level and scope.

See which provider category fits →

What's the difference between assessment, readiness, remediation, environment, and maintenance costs?

A credible CMMC budget separates five buckets instead of hiding them inside one number. Assessment is the cost to evaluate and report your status. Readiness is preparing for it. Remediation is fixing the gaps. Environment is the cloud or enclave work to control CUI. Maintenanceis keeping it all current year after year. For Levels 1 and 2, DoD's official estimate covers only the first bucket.

This is the framework that prevents the most expensive budgeting error. When a vendor hands you a single CMMC number, the first question is always: which buckets are in this, and which are missing?

Cost bucketWhat it includesWho usually provides itThe common mistake
AssessmentSelf-assessment, certification assessment by a C3PAO, or DIBCAC assessment; reporting; affirmationsYour team, a C3PAO, or DCMA DIBCACTreating the assessment fee as the all-in cost
ReadinessGap assessment, SSP and POA&M support, evidence preparationRPO, consultant, MSP, MSSP, virtual CISOScheduling an assessment before evidence exists
RemediationTechnical fixes — identity, logging, endpoints, encryption, policyMSP, MSSP, internal IT, cloud integratorBuying tools before the scope is defined
EnvironmentCUI enclave, GCC High / GovCloud migration, secure collaborationMSP/MSSP, enclave provider, cloud integratorMoving everything instead of shrinking scope
Evidence / GRCGovernance-risk-compliance software, evidence tracking, control ownershipGRC platform, internal GRC leadMistaking a tool for actual implementation
MaintenanceAnnual affirmations, monitoring, evidence refresh, POA&M managementInternal team, MSP/MSSP, virtual CISOBudgeting only for Year 1

A few definitions, since these provider categories get used loosely. An RPO (Registered Provider Organization) is a Cyber AB–registered firm that provides CMMC consulting and readiness — note, readiness, not certification. An MSP (Managed Service Provider) runs your IT; an MSSP (Managed Security Service Provider) runs your security operations. DCMA DIBCACis the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center — the government body that conducts Level 3 assessments. Knowing which category owns which bucket is half the battle; the order you engage them in is the other half.

Most of the budget hides outside the assessment.

Most of the budget hides in readiness, remediation, and environment — not the assessment. If you're not sure which bucket is yours, get matched with source-checked provider options for that exact stage.

Get matched for your stage →

Which NIST SP 800-171 control families usually drive CMMC cost?

Level 2 maps to NIST SP 800-171 Rev. 2: 110 security requirements organized into 14 control families. Not all 14 cost the same to implement and prove. In our experience reviewing readiness work, a handful of families — audit logging, access control, identity, and system/communications protection — account for most of the remediation spend, because they usually require new tooling and architecture rather than just a written policy. The table below is our editorial cost-driver mapping, not a DoD cost allocation; DoD does not publish cost by family.
NIST SP 800-171 Rev. 2 familyTypical cost-driver weightWhy
Access ControlHighLeast-privilege, MFA, remote-access control, and CUI flow restrictions often force real change
Audit & AccountabilityHighCentralized logging, retention, and log review usually mean new tooling and managed effort
Identification & AuthenticationHighMFA everywhere and identity hygiene are common, expensive gaps
System & Communications ProtectionHighEncryption, boundary protection, and FIPS-validated cryptography can drive cloud/architecture cost
Configuration ManagementMediumBaselines, change control, and inventory take process and tooling
System & Information IntegrityMediumEndpoint protection, patching, and monitoring — moderate if you already run an MSP/MSSP
Incident ResponseMediumPlan, testing, and the existing DFARS 72-hour reporting workflow
Security AssessmentMediumSSP and POA&M development and upkeep — heavy on labor, light on tooling
MaintenanceLower–MediumControlled maintenance and tooling, depending on environment
Media ProtectionLower–MediumMedia marking, sanitization, and encryption of removable media
Awareness & TrainingLowerMostly program and documentation effort
Personnel SecurityLowerScreening and access-on-departure processes
Physical ProtectionLowerFacility controls, often already in place
Risk AssessmentLower–MediumPeriodic risk and vulnerability assessment cadence

If your environment is light on logging, identity, and encryption today, expect those four high-weight families to dominate your remediation budget — which is exactly why the calculator weights environment and maturity so heavily.

Should you budget for an RPO, MSP/MSSP, CUI enclave, GRC tool, or C3PAO first?

The right first spend depends entirely on your stage. If your CUI scope is unclear, start with scoping. If your controls are weak, start with readiness and remediation. If CUI is spread everywhere, evaluate an enclave before buying tools. If your evidence is organized and your contract requires certification, compare C3PAOs — and never let the firm that prepared you also be the firm that assesses you.

Use this as a sequencing guide. Spending out of order is how budgets balloon.

Your situationFirst provider categoryWhy this order
You don't know where CUI actually livesScoping / readiness advisorCost can't be estimated until the boundary is defined
You handle CUI but controls are weakRPO / MSP / MSSP / virtual CISOYou need implementation before an assessment is worth scheduling
CUI is spread across email, files, endpoints, SaaSEnclave / secure-collaboration / architecture helpShrinking scope can cut the whole budget
Your evidence is mostly organized and readyC3PAO comparisonThe certification assessment is now your bottleneck
You need ongoing evidence operationsGRC software + managed complianceMaintenance is a Year-2-and-beyond reality, not a one-time buy
You're a Level 3 candidateSpecialized Level 3 / DIBCAC planningLevel 3 is a program-level path, not a standard SMB budget

One rule overrides all of the above, and it's not optional. The firm that helps you get ready generally cannot be the firm that certifies you. CMMC's ecosystem rules — administered by the Cyber AB(the Cyber Accreditation Body, DoD's authorized accreditation body for the program) and reflected in 32 CFR 170.8 — require assessor independence. A C3PAO that consulted on your readiness has an organizational conflict of interest and generally can't perform your Level 2 certification assessment. Practically, that means budgeting for two relationships: a readiness partner to get you ready, and an independent assessor to certify you.

Decision resolution points — placed by branch:

Weak controls or no SSP? Find readiness help before you schedule an assessment.

CUI scattered across systems? Compare CUI enclave and managed-cloud options.

Evidence organized and certification required? Check current C3PAO availability on the Cyber AB Marketplace, then compare scoped C3PAO options.

How much should a small business budget for CMMC Level 2?

A small business should treat DoD's ~$104,670 figure as the floor for provingcompliance, then add the buckets DoD excludes: readiness, remediation, environment, evidence tooling, internal labor, and ongoing maintenance. The biggest swing factor is rarely employee count — it's how much of the business touches CUI and how mature your existing NIST SP 800-171 program is. Realistic Year-1 all-in budgets for small contractors commonly run from the high five figures into the low-to-mid six figures.

DoD's own data is built for small business, which is useful. Across the phase-in, its Regulatory Impact Analysis projects about 56,689 small-entity Level 2 certification assessments, and it cites a Federal Procurement Data System annual average of 30,145 unique small-business DoD contractors(FY2019–2022). This is your peer group. Here's how the budget tends to split by situation.

Narrow CUI enclave, organized evidence

Lower scope, fewer CUI users, a smaller remediation surface. You're closer to “just the assessment,” though you still need disciplined evidence and operations. This is the cheapest credible path to a Level 2 (C3PAO) status, and it's often reachable on purpose by containing CUI.

CUI spread across email, file shares, endpoints, and SaaS

Broad scope, higher architecture cost, a heavier evidence burden, and the highest risk of underbudgeting. This is where Year-1 numbers climb toward and past six figures, mostly from environment and remediation work — not the assessment.

No SSP or a low SPRS score

Remediation dominates. You need readiness and implementation before an assessment is even worth scheduling, and treating a C3PAO quote as your first budget number guarantees a painful surprise.

Near-ready for a certification assessment

The assessment cost finally becomes the main event. Evidence quality and assessor scheduling matter most here, and you're the rare contractor for whom DoD's $104,670 is close to your real number.

One more piece of context worth budgeting around: DoD's cost model assumes an experienced in-house IT specialist at about $86/hour and an external service provider or assessor at about $260/hour, and industry practitioners commonly put Level 2 preparation at six to twelve months. This calculator treats that as the default runway unless a scoped quote says otherwise. The longer your runway, the more of this you can do at sane rates instead of emergency ones.

If remediation or environment is your driver, that's a readiness conversation

If your situation above points to remediation or environment as the driver, that's a readiness conversation, not an assessment one. Get matched with source-checked provider options for your stage.

Get matched with source-checked provider options →

How does a CUI enclave change CMMC cost?

A CUI enclave can lower cost when it genuinely narrows the systems, users, and workflows in scope — but it can raise cost when it adds duplicate operations or creates a false sense of scope reduction while CUI still moves elsewhere. The decision hinges on whether you can truly contain CUI to the enclave.

A CUI enclaveis a separated, tightly controlled environment where you confine all CUI handling, so the rest of your business stays out of the assessment boundary. Done right, it's the most reliable way to cut Level 2 cost. Done wrong, it's a second environment you pay for and a scope problem you still have.

When an enclave lowers cost: a small number of CUI users, clear and containable workflows, and an existing enterprise environment that would be expensive to bring fully into scope. If you can route all CUI through the enclave and keep it there, you shrink everything downstream — remediation, evidence, and the assessment itself.

When an enclave raises cost:users still export, download, or email CUI outside the enclave; multiple programs need conflicting workflows; identity, device, and logging integration is poor; or you treat the enclave as a substitute for evidence discipline it doesn't actually provide. An enclave controls whereCUI lives — it doesn't erase your obligation to prove control.

A quick enclave-fit check. An enclave is usually worth it when most of these are true: you have a small count of true CUI users; CUI touches a limited set of systems; external collaboration is predictable; users can realistically keep CUI inside the enclave; and your broader environment would otherwise be expensive to bring into scope. The more of those that are false, the more an enclave adds cost instead of cutting it.

Came back high because CUI is everywhere?

If your estimate came back high because CUI is everywhere, the move is architecture, not more tooling.

Compare CUI enclave and managed-cloud options →

Do you need a C3PAO, or can you self-assess?

Whether you can self-assess or must hire a C3PAO is set by your contract, not your preference. Level 1 is always self-assessed. Level 2 can be either self-assessed or third-party assessed, depending on the solicitation — and starting in Phase 2 (November 10, 2026), a Level 2 certification assessment by a C3PAO becomes a condition of award in applicable solicitations. Level 3 is assessed by the government.

This distinction drives a roughly threefold difference in assessment cost, so it's worth getting right. The rule never lets you choose the cheaper path on your own — the solicitation tells you which applies. (For the full breakdown of how the levels map to data types and requirements, see our CMMC levels guide.)

The timing matters for cash flow. Through most of 2026, many contracts still accept a Level 2 self-assessment under Phase 1. But the planning reality is fixed: a certification assessment takes months to prepare and schedule, and Phase 2's requirement lands in November 2026. If your work involves CUI, plan for the C3PAO path even if your current contract hasn't demanded it yet.

If your contract requires a certification assessment and your evidence is ready, compare scoped C3PAO options.

If you're certain you're FCI-only and self-assessing at Level 1, you likely don't need any of the heavier stack — start with the readiness checklist instead.

What about Level 1 and Level 3 costs?

Level 1 is the cheapest path — about $5,977 per year for FCI-only contractors, with no POA&M allowed. Level 3 is the most specialized and the most expensive: the government assessment itself is small (~$12,802 over three years, no C3PAO fee), but DoD's small-entity Level 3 model also budgets $2.7 million one-time plus $490,000 per year to implement the NIST SP 800-172 controls — and Level 3 requires a Final Level 2 (C3PAO) status first.

Level 1exists for contractors who handle only FCI and no CUI. The budget is the annual self-assessment, reporting, and affirmation — DoD's small-entity figure is $5,977 per year. The one trap is misjudging scope: if any CUI is actually in your environment, you're not a Level 1 company, and budgeting as one will fail you at the worst possible moment. Confirm FCI-only status before you bank on the low number.

Level 3is a different animal, and most readers of this page are not Level 3 candidates. The government (DCMA DIBCAC) conducts the assessment, so there's no C3PAO fee, and the assessment and affirmation run only ~$12,802 over three years. But unlike Levels 1 and 2, Level 3 adds a defined subset of NIST SP 800-172 enhanced controls that are notrequired under any prior rule — so DoD's model does include the implementation cost it omits elsewhere: $2.7 million in non-recurring engineering plus $490,000 a year in recurring engineeringper small entity. Stack on the Level 2 (C3PAO) status you must hold first, and DoD's own small-entity Level 3 model runs to roughly $4.3 million over three years.If you're a Level 3 candidate, treat it as a program-level budget and validate the requirement directly against your contract.

Level 3 is a program-level decision, not a checklist item

Plan the Level 3 path with specialized support and confirm the requirement against your contract before you budget.

Plan the Level 3 path with specialized support →

The CMMC cost timeline: why the budget clock is already running

CMMC rolls out in four phases through 2028, and the deadlines are fixed in the DFARS final rule. Phase 1 began November 10, 2025. Phase 2 — a Level 2 certification assessment by a C3PAO as a condition of award in applicable contracts — begins November 10, 2026. Because Level 2 preparation typically takes six to twelve months, the budgeting and remediation window for many contractors is now, not later.

This is the one place scarcity is real rather than manufactured, because the dates come from federal regulation. The contracting rule (DFARS clause 252.204-7021, with the solicitation provision at 252.204-7025) took effect November 10, 2025 and set this schedule:

Two practical notes that affect timing and cost. First, many prime contractors are already requiring subcontractors to be Level 2–ready ahead of the formal schedule, so your effective deadline may be a prime's flowdown date, not DoD's. Second, the rule revised CMMC's cost estimates upwardfrom the 2020 version after more than 750 public comments said the original numbers were too low. Even the official estimates already reflect the reality that contractors don't do this alone.

The cheapest version of this is the one you start early

If Phase 2 affects you, the cheapest version of this is the one you start early. Get matched with source-checked provider options and turn your runway into an advantage.

Get matched with source-checked provider options →

How we built this CMMC cost calculator

This calculator starts from official DoD assessment estimates, adds clearly labeled editorial planning bands for the real-world costs DoD excludes, and returns a range rather than a single number — because false precision would be dishonest where scope is the dominant variable. We separate what's official, what's our editorial estimate, and what only a scoped quote can settle.

What's official.The DoD anchors in the tool — $5,977 for Level 1, $37,196 for Level 2 self-assessment, $104,670 for a Level 2 certification assessment, and the Level 3 model ($12,802 assessment plus $2.7M non-recurring and $490K recurring engineering) — are taken directly from DoD's Initial Regulatory Flexibility Analysis for the CMMC rule (32 CFR Part 170, RIN 0790-AL49). The level structure, assessment types, affirmation cadence, SPRS and eMASS reporting, POA&M limits and the 180-day closeout, and the phase timing all come from 32 CFR Part 170 and the DFARS final rule.

What's editorial.The readiness, remediation, environment, evidence-tooling, annual-operations, and contingency bands are The Defense Compliance Report's own planning estimates, informed by publicly published provider pricing and our reporting. They are not DoD figures, and we re-verify them quarterly. The way your inputs scale those bands is summarized below.

Calculator inputHow it moves your costStatusWhat to verify
Level / assessment typeSets the official anchor and the whole cost structureOfficialYour solicitation or contract
CUI / FCI usersScales nearly every bucket; the strongest single leverEditorialWho actually touches CUI
CUI footprint / scopeDrives remediation and evidence breadthEditorialWhere CUI flows and lives
EnvironmentDrives one-time architecture and enclave/cloud costEditorialWhether your stack is assessment-ready
Readiness / SPRS maturityDrives remediation; near-ready ≈ assessment-onlyEditorialYour real SSP and evidence quality
Timeline pressureAdds a rush premium under tight runwaysEditorialYour true deadline (and any prime flowdown)

What requires a quote. Named-provider pricing, your actual C3PAO fee, your specific cloud or enclave costs, your true remediation scope, your internal labor capacity, and whether any cost is allowable or reimbursable under your contract. The calculator estimates exposure; only a scoped engagement produces a binding number.

One accuracy note we won't skip: CMMC Level 2 currently maps to NIST SP 800-171 Rev. 2, not Rev. 3. NIST published Revision 3 in 2024, but the CMMC rule remains pinned to Rev. 2 unless and until DoD amends it through future rulemaking.

What we actually verified

We're a trade publication, not a vendor, so we'll tell you exactly what we checked and what we didn't.

Verified on June 3, 2026, against primary sources:

What you still need to verify yourself:

Primary sources

CMMC cost calculator FAQ

Regulatory answers below are sourced to 32 CFR Part 170, the DFARS final rule, DoD's Regulatory Impact Analysis, and NIST CSRC — see Primary sources above.

How accurate is a CMMC cost calculator?

A CMMC cost calculator is reliable for budgeting, not for replacing a scoped quote. Its accuracy improves once you know your level, CUI scope, assessment type, environment, SPRS score, and timeline. Treat the output as a defensible range and confirm it with a provider once scope is defined.

How much does CMMC Level 2 cost?

DoD's official small-entity estimate is $37,196 over three years for a Level 2 self-assessment and $104,670 over three years for a Level 2 certification assessment by a C3PAO. For Levels 1 and 2 both figures exclude implementation, remediation, and maintenance. Realistic all-in Year-1 budgets for the certification path commonly run from the high five figures into the low-to-mid six figures.

How much does a C3PAO assessment cost?

Within DoD's $104,670 three-year figure, the accredited assessor's own engagement fee is about $31,234. The rest is your side of the table, including roughly $45,509 in your team's and your IT provider's labor to conduct the assessment, plus planning, reporting, and affirmations. Your actual C3PAO fee varies with scope, complexity, readiness, and scheduling.

Does DoD's official estimate include remediation?

For Levels 1 and 2, no — DoD's cost model excludes implementation, remediation, and maintenance because it assumes contractors already implemented NIST SP 800-171 Rev. 2 under DFARS 252.204-7012 by December 31, 2017. Level 3 is the exception: DoD's Level 3 model includes about $2.7M one-time plus $490K per year to implement the new NIST SP 800-172 controls.

Can I pass CMMC with a POA&M?

Not at Level 1, where POA&Ms aren't permitted. At Levels 2 and 3, a limited POA&M is allowed only if you meet a minimum assessment score, certain high-weight requirements aren't deferred, and open items are closed within 180 days. A conditional status is not a final status.

Do I need GCC High for CMMC?

Not automatically, but any cloud service handling covered defense information must be evaluated against DFARS and CMMC requirements, including FedRAMP Moderate equivalency where applicable. Environment is a major cost driver because the wrong architecture can expand scope and remediation cost.

Can a C3PAO help me fix gaps before assessing me?

Generally not for the same engagement. CMMC's ecosystem rules require assessor independence, so a firm that provided readiness or remediation typically can't perform your certification assessment. Plan for a separate readiness partner and independent assessor.

Is CMMC Level 2 based on NIST SP 800-171 Rev. 2 or Rev. 3?

Revision 2. CMMC Level 2 currently maps to NIST SP 800-171 Rev. 2 — 110 requirements across 14 families — even though NIST published Revision 3 in 2024. Budget and prepare against Rev. 2 until DoD amends the CMMC rule through future rulemaking.

How often do I reassess or affirm for CMMC?

Level 1 requires annual self-assessment and affirmation. Level 2, whether self-assessed or assessed by a C3PAO, runs on a three-year assessment cycle with annual affirmations. Level 3 uses a government DIBCAC assessment after a Final Level 2 (C3PAO) status.

Do subcontractors need CMMC?

Often yes. CMMC requirements flow down to subcontractors at all tiers that store, process, or transmit FCI or CUI in performance of the contract. A subcontractor's obligation depends on the data it handles, not on company size.

Will DoD reimburse CMMC costs?

Don't assume so. Whether a CMMC cost is allowable, allocable, or reimbursable under your contract is a question for qualified counsel or a contracts professional. A calculator estimates budget exposure, not reimbursement.

You came for a number. Now turn it into a plan.

You now have a defensible range, the buckets behind it, and the order to spend in. Tell us your level, scope, and timeline, and we'll match you with source-checked provider options that fit your stage — readiness first, assessment when you're ready. No CUI, contract numbers, or system details.

Get matched with source-checked provider options →

Or: work the CMMC readiness checklist at your own pace first.

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with the Department of Defense, the Cyber AB, DCMA DIBCAC, NIST, SPRS, eMASS, or any U.S. government agency. This page is an educational budgeting resource and is not legal, contractual, compliance, or certification advice. We label DoD figures as government estimates and market ranges as editorial planning estimates — neither is a quote for your specific environment. Read our editorial standards and corrections policy.

Last verified: June 3, 2026. Next scheduled review: September 2026, or sooner if DoD, NIST, Cyber AB, or DFARS implementation guidance changes.