Status update — verified August 22, 2026: CMMC Phase II and later implementation milestones remain suspended. During the review, new designations are limited to Level 1 (Self) and Level 2 (Self). What changed →
By The Defense Compliance Report Editorial Team Independent CMMC and Defense Industrial Base compliance research Published: June 20, 2026 · Last reviewed: August 22, 2026 Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Confirm contract interpretation with your contracting officer or qualified federal-contracts counsel; confirm implementation questions with a current CMMC Registered Practitioner or Registered Provider Organization. The Defense Compliance Report is not affiliated with the Cyber AB, the U.S. Department of War (formerly Department of Defense), DCMA DIBCAC, NIST, or any U.S. government agency. This is educational research, not legal, contractual, procurement, cybersecurity, or compliance advice.
The bottom line, before you scroll
In-house vs outsourced CMMC compliance is almost never an either-or, and the number that settles it starts in the Department of Defense's own rulemaking. In the Regulatory Impact Analysis published with the CMMC final rule, DoD modeled an external service-provider or assessor hour at $260.28. The same table modeled a director hour at $190.52 and a senior IT hour at $81.96. Those in-house figures already include DoD's 30% fringe and general-and-administrative load; adding 30% again would double-count it.
Pair that $260.28 outside-hour model with current Bureau of Labor Statistics pay data and a clearly stated 30% employer-cost assumption, and the hiring break-even lands at roughly 650 outsourced expert hours a year. Under that modeled line, buying is cheaper. Over it, hiring is.
Here's the part that decides your budget. A standing-start Level 2 build can cross 650 hours once scope, remediation, documentation, evidence, and operating changes are counted. A mature steady state may not. No authoritative source publishes a universal Level 2 implementation-hour total, so the defensible answer for most Defense Industrial Base contractors is neither of the two things this market sells you — it's buy the spike, keep the steady state, and force every bidder to disclose the hours.
What changes that answer: your required CMMC level and assessment type, whether you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), whether you already have technical staff with real capacity, and whether outsourcing pulls a provider's services into your own assessment scope. We'll take each of those in turn, and we'll show you our arithmetic so you can check it against your own payroll instead of taking our word for it.
The 60-second version
| Model | Best fit | What you own | What a provider does | The failure mode nobody quotes you |
|---|---|---|---|---|
| In-house-led | Mature internal security and compliance capability, with redundancy | Governance and most execution | Specialist validation and surge support | Underestimated hours, one-person dependency, evidence that has never been tested |
| Hybrid (our default) | Most small and mid-sized DIB contractors | Scope, decisions, self-assessment result, and affirmation | Runs selected technical, documentation, or monitoring functions | A responsibility gap where neither side owns a requirement |
| Outsourced-heavy | Limited internal capacity, narrow CUI enclave, or a 24/7 monitoring gap | A named owner, approvals, and every representation you make | Operates most technical and evidence functions | Lock-in, provider-created assessment scope, weak evidence transfer |
Is this page for you?
Yes, if you're sizing a CMMC budget, writing a job requisition, weighing an MSP renewal, or trying to explain to a CFO why the quote looks like that.
No, if you haven't yet confirmed whether you actually receive FCI or CUI — start with the CMMC scoping guide, because everything on this page depends on that answer. If you do not yet know which level applies, use the CMMC Levels guide. Also no if you're already assessment-ready and just need to evaluate an assessor; go to our C3PAO selection framework instead. We'd rather lose you to the right page than sell you a decision you don't need to make yet.
In-house vs outsourced CMMC compliance: which model fits?
Answer capsule: Most contractors should not choose one extreme. An in-house-led CMMC program is workable when a company already has an accountable owner, NIST SP 800-171 fluency, continuous technical operations, and enough staff redundancy to survive turnover. An outsourced-heavy model fits when several of those capabilities are missing. A hybrid model — internal governance plus purchased execution — preserves the accountability the rule assigns to the contractor while buying the specialist capacity many small suppliers lack.
The reason this question is so hard to answer from the open web is that nearly every page ranking for it is published by a company that sells one of the two answers. Managed service providers conclude you should outsource. Consultants conclude you need a consultant. Software vendors conclude the platform closes the gap.
We provide none of those services. We are a trade publication that routes readers to provider categories, and we may earn referral compensation when a matched provider engages with a reader. We'll show you below exactly where that creates a conflict for us, because it does.
So here's the honest three-line version.
- Go in-house-led only if all six capability gates further down this page are genuinely satisfied. Not five. Six.
- Go hybrid if leadership and governance can stay internal but one to three execution capabilities are missing.
- Go outsourced-heavy if you're missing four or more operating capabilities — but appoint the internal owner before you sign anything, not after.
One clarification that saves people real money: outsourcing more work does not make you less accountable. Under 32 CFR Part 170, the CMMC Program Rule that took effect December 16, 2024, your organization owns the accuracy of the scope, SSP, self-assessment result where applicable, SPRS record, and annual affirmation. A provider can do a great deal of the work. It cannot make a false statement true.
Did the July 13, 2026 suspension change the answer?
Answer capsule: It changed the rollout timing and the contract designations the Department may newly impose during the review. It did not erase the work. The original Phase 1 window ran from November 10, 2025 through November 9, 2026. On July 13, 2026, the Department suspended the transition to Phase II and later implementation milestones, limiting new procurement designations during the review to CMMC Level 1 (Self) and Level 2 (Self). DFARS 252.204-7012 safeguarding and incident-reporting duties, the CMMC Program Rule, and the NIST SP 800-171 Revision 2 Level 2 baseline remain in force.
This is the first thing to get right, because a lot of pages on this topic were written before July 13 and still lead with a countdown to a November 10, 2026 third-party certification deadline. That transition date is exactly what got paused.
| What changed on July 13, 2026 | What did not change |
|---|---|
| New Level 2 (C3PAO) and Level 3 contract designations were suspended during the review | New Level 1 (Self) and Level 2 (Self) designations remain permitted |
| The transition to Phase II and later implementation milestones was suspended | Phase 1 remains active; its original schedule was November 10, 2025 through November 9, 2026 |
| Components were instructed to amend active solicitations containing affected designations and remove them from existing contracts at the next option or scheduled administrative modification | DFARS 252.204-7012 safeguarding and 72-hour cyber-incident reporting remain in force where the clause applies |
| A generic “book your assessor before Phase II” countdown is no longer defensible | NIST SP 800-171 Revision 2 remains the CMMC Level 2 baseline unless DoD amends 32 CFR Part 170 |
| Assessment timing became contract-specific and policy-sensitive | Truthful scope, an accurate SSP, real evidence, SPRS submissions, and annual affirmations remain required where the applicable clause and status require them |
Primary sources: the Department's July 13, 2026 release, “Forging the Arsenal of Freedom”; Implementing Procedures 26-P-1023; the acquisition final rule effective November 10, 2025; and 32 CFR Part 170.
The one thing that genuinely shifted your math
For work newly designated during the suspension, the permitted CMMC paths are self-assessment paths. That means there is no required C3PAO certification-assessment fee attached to those new designations.
Which means for most readers pricing a newly designated Phase 1 requirement today, the spend is overwhelmingly the build-versus-buy decision. There is no mandatory certification-assessment line item to hide behind, no scarcity story about assessor availability, and no way to point at a C3PAO invoice and say the government made you do it. It's labor allocation, tooling, remediation, and operating evidence now.
That's uncomfortable, and it's also the clearest the decision has ever been.
Do not treat the suspension as permission to stop. The implementing procedures directed a 60-day review and further guidance; they did not repeal 32 CFR Part 170, and they did not suspend DFARS 252.204-7012. Existing contracts, amendments, flow-downs, and the legacy DFARS assessment clauses still require contract-by-contract reading. For the full suspension analysis, see CMMC Phase II deadline and suspension update
No countdown on this page. The real dates are the ones in your solicitation, your contract, your option year, your remediation plan, and your affirmation cycle.
What does an in-house CMMC hour actually cost versus an outsourced one?
Answer capsule: In the Regulatory Impact Analysis published with the CMMC final rule at 89 FR 83092, the Department modeled external service-provider and assessor labor at $260.28 per hour. DoD states that rate includes labor, overhead, general and administrative expense, and profit. The in-house rates in the same table already include DoD's 30% fringe and G&A load. They are not base wages waiting to be loaded again.
This is the table nobody in this market shows you, and it exists because DoD had to price CMMC in order to publish the rule. The cost narrative sits at 89 FR 83178–83189, with the labor rates at 89 FR 83180–81.
What DoD assumed an hour costs
| Role | DoD's published fully burdened rate | External $260.28 hour divided by this rate | Difference versus the external hour |
|---|---|---|---|
| External service provider / C3PAO | $260.28 | — | — |
| Director | $190.52 | 1.37× | $69.76 |
| Staff IT | $97.49 | 2.67× | $162.79 |
| Manager | $95.96 | 2.71× | $164.32 |
| Staff IT (small business) | $86.24 | 3.02× | $174.04 |
| Senior IT | $81.96 | 3.18× | $178.32 |
| IT level 2 | $54.27 | 4.80× | $206.01 |
| IT level 1 | $36.32 | 7.17× | $223.96 |
Source: CMMC Program final rule Regulatory Impact Analysis, 89 FR 83180–81. The figures above are DoD's published fully burdened hourly rates. The ratio and difference columns are our arithmetic. Last verified August 22, 2026.
And what the labor market actually pays
DoD's rates were set for a 2024 rulemaking. Here's the current reality check from the Bureau of Labor Statistics Occupational Employment and Wage Statistics program, May 2025 national data — the most recent release available as of August 22, 2026.
| Occupation (SOC code) | U.S. employment | Mean hourly | Mean annual | Median hourly |
|---|---|---|---|---|
| Information security analysts (15-1212) | 190,650 | $63.71 | $132,510 | $62.11 |
| Computer and information systems managers (11-3021) | 670,570 | $92.39 | $192,160 | $84.20 |
| Network and computer systems administrators (15-1244) | 314,340 | $49.85 | $103,680 | $47.66 |
| Compliance officers (13-1041) | 417,070 | $42.50 | $88,400 | $38.81 |
| Computer user support specialists (15-1232) | 717,190 | $32.37 | $67,330 | $29.74 |
Source: BLS Occupational Employment and Wage Statistics, May 2025. National figures; your local market will differ.
Two DCR calculations fall out of those two tables.
First: “we'll just have the VP handle it” is still the most expensive version of doing it yourself. DoD's modeled director hour is $190.52, only $69.76 below its modeled external expert hour. The person you buy may already know what 32 CFR § 170.19 says about external service providers, while your director is reading it for the first time on a Tuesday night. If leadership is going to absorb this work, price the opportunity cost honestly. The hourly gap exists, but it is much smaller at the director level than it is for technical staff.
Second: the labor arbitrage is strongest when qualified technical staff can do the recurring work. DoD's senior IT hour is $81.96 against a modeled outside hour of $260.28 — a 3.18× gap, or $178.32 per hour. That is the economic case for keeping steady-state CMMC work in-house. It just requires that the work actually be done by capable technical staff, not by an executive squeezing it in around a customer escalation.
At what point does hiring beat paying a firm?
Answer capsule: Divide the fully loaded annual cost of the person you would hire by the outside hourly rate you would otherwise pay. Using BLS May 2025 national pay data for an information security analyst, a transparent 30% employer-cost assumption, and DoD's $260.28 external-hour model, the break-even falls between 645 and 662 outsourced hours per year — approximately 650 hours, or 12 to 13 hours per week. Below that modeled line, buying is cheaper. Above it, hiring is.
Here is the arithmetic, shown as arithmetic, because a number you can't check is just a claim.
At the BLS mean: $132,510 × 1.30 = $172,263 modeled fully loaded $172,263 ÷ $260.28 per outside hour = 661.8 hours
At the BLS median: $62.11 × 2,080 = $129,189 → × 1.30 = $167,945 modeled fully loaded $167,945 ÷ $260.28 = 645.2 hours
Call the line 650 outsourced expert hours a year. That's about a day and a half a week of somebody who actually knows this material.
The 30% applied here is our employer-cost modeling assumption for converting BLS cash compensation into a comparable annual cost. It is not a second load applied to DoD's already burdened in-house rates.
The damaging admission we owe you
This site routes readers to provider categories, and we may earn referral compensation when a matched provider engages with a reader. So here is the number that works directly against our business model:
Once your program needs more than roughly 650 outside expert hours a year at these inputs, a loaded information-security hire beats buying those hours. We're publishing the arithmetic so you can replace every input with your own payroll and quote data rather than trusting us.
Now the part that makes that admission useful instead of theatrical: the workload shape matters as much as the total.
A Level 2 build from a standing start can include CUI data-flow mapping, boundary design, remediation, SSP authoring, evidence assembly, operational change, and a mock run. That can be a spike. Evidence upkeep, recurring control operation, incident readiness, change management, and annual affirmation support continue after it. No authoritative source publishes a universal hour total for either stage.
A hire is a recurring cost. A fixed-scope engagement can absorb a spike.
So the arithmetic doesn't point automatically at “hire” or “outsource.” It points at a split — demand a year-one hour estimate and a steady-state hour estimate, buy the finite specialist work, and keep a named internal owner for the recurring state. That's the recommendation neither side of this market makes, because neither side gets paid for the split.
Two honest adjustments, because a model without them is a sales tool
A full-time hire is not 2,080 CMMC hours. If your new person is half on CMMC and half on general IT, only half the salary belongs in this comparison — but you've also bought general IT capacity you may have needed regardless. Run the number at your actual allocation.
A new hire starts at zero on CMMC specifically. Assume a real ramp. The $260.28 hour is a DoD modeling rate, not a guaranteed market price, but a specialist engagement may buy prior repetitions you do not have internally.
The cross-check that turns this into a verdict
Now put the break-even against DoD's own cost model for a small entity's Level 2 certification-assessment cycle.
DoD modeled the initial assessment and affirmation at $101,752 and the three-year total at $104,670. The line items include 176 external service-provider hours supporting the organization and a separate 120-hour C3PAO team. That is 296 modeled external hours, not 176. The C3PAO component alone is $31,234.
Two hundred ninety-six hours is still nowhere near 650.
So for the external assessment-and-support work DoD actually priced, DoD's own model says buy it — don't hire a permanent employee for that finite cycle.
But read DoD's fine print, because it's the whole ballgame: the Level 1 and Level 2 figures cover assessment and affirmation effort. DoD explicitly excluded the nonrecurring and recurring engineering costs of implementing and maintaining FAR 52.204-21 and NIST SP 800-171 on the reasoning that those obligations already applied. DoD also assumed a first-attempt pass and stated that its estimates do not represent actual C3PAO market prices. That excluded implementation and operating work is where a real environment can cross the 650-hour line.
The work DoD priced is a buy. The work DoD excluded is where a hire can pay for itself.
That single sentence is the honest answer to “in-house vs outsourced CMMC compliance,” and it took the government's own rulemaking to produce it.
Map the category before you price the hours
You now know where the line sits. The next question is which kind of help you'd be buying — readiness, managed operations, an enclave, evidence workflow, or assessment — because those are different markets with different price structures, and quoting them against each other is how budgets get wrecked.
Tell Find My CMMC Path your required level, FCI or CUI handling, assessment type, environment, and timeline. It maps your situation to a provider category, not a ranked provider, and it takes about two minutes.
Free. No obligation. Do not submit CUI, drawings, or sensitive contract details.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
What must your company still own no matter how much you outsource?
Answer capsule: Your company must own the truth of its scope, the accuracy of its SSP, the result it submits for a self-assessment, its SPRS records, its evidence continuity, and the annual affirmation. A required Level 2 certification assessment is the opposite: it must be performed independently by an authorized or accredited CMMC Third-Party Assessment Organization (C3PAO). Level 3 is assessed by DCMA DIBCAC. Outsourcing execution never transfers the contractor's accountability for what it represents.
A readiness provider can build the package. It cannot make your affirmation or certify its own preparation work.
The independent assessment. For a Level 2 (C3PAO) requirement, an authorized or accredited C3PAO performs the certification assessment. Level 3 is assessed by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Under 32 CFR § 170.8, a CMMC ecosystem member may not participate in your Level 2 certification assessment if it served as a consultant preparing you for a CMMC assessment within the previous three years.
The affirmation. 32 CFR § 170.22 defines the Affirming Official as the senior-level representative from within the organization with authority to affirm continuing compliance. That person affirms in SPRS after each assessment, annually after, and at POA&M closeout. No vendor can be your senior official.
The truth of it. The rule assigns the self-assessment result, status records, continuing-compliance obligation, and affirmation to the Organization Seeking Assessment. Providers support. You represent.
And one more that people forget until the wrong moment: you own the evidence continuity. Not the portal it lives in. For Level 1 and Level 2 self-assessments, the OSA must retain assessment evidence for six years from the CMMC Status Date. Certification assessments carry separate hashing, submission, and retention duties. If your provider's platform holds your only usable copy, you have a continuity problem dressed up as a subscription.
What can you actually outsource for CMMC compliance?
Answer capsule: A great deal. Contractors routinely outsource control implementation, identity and access administration, endpoint and patch operations, logging and monitoring, cloud or enclave operation, SSP and POA&M drafting, evidence organization, training delivery, and remediation project management. What the contractor cannot outsource is validating that the work was done, documenting the shared responsibilities, and ensuring the resulting statements are accurate. If you searched outsource CMMC compliance and landed here, this is the section you came for. The short version: the ceiling is higher than most people assume, and it is a real ceiling. Highly outsourceable — technical operations. Identity and access management, multifactor authentication rollout, secure configuration baselines, network segmentation, encryption, backup, vulnerability scanning, patch operations. This is squarely inside what a competent managed service provider does every day. Highly outsourceable — monitoring. Security information and event management, managed detection and response, alert triage, escalation, log preservation, incident investigation support. Most small contractors cannot staff this around the clock, and shouldn't try. Supportable, with your validation — documentation. A provider can interview your control owners, draft descriptions, map controls to evidence, and maintain version history for your SSP and Plan of Action and Milestones (POA&M). It should not invent a description, and it should never convert a planned capability into an implemented one on paper. Operable externally — the CUI environment. A managed enclave or government-community cloud tenancy can be run by someone else entirely. What you keep is the boundary decision, the user workflow, and whether people actually stay inside it. Buy independent validation when the stakes justify it — the mock assessment. A dry run is most valuable when the reviewer did not build the environment or write the evidence package being tested. That does not make a mock an official CMMC assessment, and the provider still must manage any future certification-assessment conflict. Here's the pull quote we'd put on a wall:
A provider can perform an enormous share of the work. It cannot know your contracts, your data, your people, and your exceptions better than you do — and it cannot make your affirmation for you.
The CMMC Work Allocation Matrix
Answer capsule: The operating model is decided workstream by workstream, not by picking one label for the whole program. Assign every activity as internal-led, co-managed, or externally operated, then document who does it, what evidence proves it, and which provider category is the right buyer. The matrix below maps eighteen CMMC workstreams against those columns, with the July 2026 suspension effect noted where it applies.
This is the asset we built for this page. Assembling it requires reading the implementation suspension, 32 CFR §§ 170.8, 170.9, 170.16, 170.19, 170.21 and 170.22, DFARS 252.204-7012/-7019/-7020/-7021, NIST SP 800-171 Revision 2, and the Cyber AB CMMC Assessment Process — and then making an editorial judgment on each row.
How to read the verdict column:
- Keep — outside help may advise, but your company must own the decision, the approval, or the representation.
- Split — a provider can execute most of it; you validate the output, retain the evidence, and oversee the relationship.
- Buy — a qualified provider can run the function; you remain responsible for selecting, documenting, and proving the service.
- Buy separately — must be performed by an independent party under the rule.
Relative effort is our editorial weighting of where year-one or recurring hours can concentrate. It is not a DoD figure and not an hour count. Use it to see which rows may move your 650-hour line.
A. Governance and scope
| # | Workstream | Verdict | Relative effort | What a provider can do | What you must retain | Evidence to demand | Category |
|---|---|---|---|---|---|---|---|
| 1 | Read the solicitation, contract, modification, and flow-down | Keep | Low | Extract clauses, explain terms, draft questions | Confirm the binding requirement with the contracting officer or counsel | Clause register, written applicability decision | RP/RPO; federal-contracts counsel |
| 2 | Determine whether you receive FCI or CUI | Keep | Medium | Facilitate discovery interviews and data mapping | The truth of what you receive, create, store, and transmit | CUI register, data inventory, sanitized examples | RP/RPO; internal contract owner |
| 3 | Define the assessment boundary and data flows | Split | High | Inventory assets, diagram flows, identify specialized assets | Approve the boundary and confirm it matches how work actually happens | Data-flow diagrams, asset inventory, categorization rationale | RP/RPO; MSP; enclave architect |
| 4 | Appoint the internal owner and Affirming Official | Keep | Low | Recommend governance structure and cadence | Appoint a senior representative from within the organization | Governance charter, responsibility matrix | Internal leadership |
| 5 | Author the System Security Plan | Split — buy the first, keep the upkeep | High | Draft, map requirements, capture technical descriptions, version-control | Validate that it describes the environment that exists | Version-controlled SSP, approval record, evidence links | RP/RPO; GRC platform |
| 6 | POA&M management and remediation decisions | Keep the decisions, split the tracking | Recurring | Track actions, coordinate fixes, assemble closure evidence | Fund it, prioritize it, validate closure, confirm POA&M eligibility | POA&M with eligibility basis, closure evidence, approvals | RP/RPO; GRC platform |
B. Technical and operational execution
| # | Workstream | Verdict | Relative effort | What a provider can do | What you must retain | Evidence to demand | Category |
|---|---|---|---|---|---|---|---|
| 7 | Identity, access, and configuration management | Split | High | Configure identity, MFA, permissions, baselines | Approve users, roles, exceptions, privileged access | Configurations, access reviews, change tickets | MSP/MSSP |
| 8 | Endpoint, patch, and vulnerability operations | Buy or split | Recurring | Operate tooling, deploy patches, scan and remediate | Confirm coverage, approve exceptions, monitor SLAs | Inventory reconciliation, scan results, exception register | MSP/MSSP |
| 9 | Logging, SIEM, and continuous monitoring | Buy | Recurring | Collect logs, monitor, investigate, escalate | Define escalation authority; verify every scoped asset is covered | Log-source list, alert records, SLA reports | MSSP |
| 10 | CUI cloud hosting or enclave operation | Buy, with your governance | High then recurring | Host and operate the environment | Validate the assurance basis, contract terms, data flows, and boundary | FedRAMP evidence or documented equivalency, architecture, CRM | CSP; CUI enclave provider |
| 11 | ESP/CSP service description and Customer Responsibility Matrix | Split | Medium | Describe services, dependencies, inherited responsibilities | Ensure the SSP and CRM allocate every responsibility to somebody | Current CRM, service description, subcontractor list | MSP/MSSP; CSP; GRC platform |
| 12 | Training, personnel, and physical processes | Keep, with content support | Low then recurring | Supply training content, platforms, advisory | Enforce policy, manage personnel actions, run physical controls | Rosters, acknowledgments, visitor records | Training provider; RP/RPO |
| 13 | Incident response and DFARS reporting readiness | Split | Medium | Detect, investigate, preserve artifacts, draft reports | Reporting authority, contract knowledge, an escalation path that works at 2 a.m. | IR plan, exercise results, contact tree, preserved artifacts | MSSP; IR provider |
C. Evidence, assessment, and continuity
| # | Workstream | Verdict | Relative effort | What a provider can do | What you must retain | Evidence to demand | Category |
|---|---|---|---|---|---|---|---|
| 14 | Evidence collection and workflow | Split, trending to keep | High then recurring | Organize evidence, map requirements, automate reminders | Validate truth and completeness; retain export rights | Evidence index, source links, timestamps, export files | GRC platform; RP/RPO |
| 15 | Level 2 self-assessment | Keep the represented result | High | Readiness testing, evidence review, objective-level analysis | The result your OSA submits for its environment | Objective-level workpapers, findings, approvals, final score | RP/RPO for support |
| 16 | SPRS submission and annual affirmation | Keep | Low, recurring | Prepare data and provide authorized administrative support | Approve the submission; your Affirming Official affirms | Submission record, assessment identifier, affirmation record | Internal leadership |
| 17 | Independent certification assessment | Buy separately | Project | Perform the authorized assessment | Select the assessor; provide evidence; preserve separation | Marketplace status check with a date, engagement agreement, independence confirmation | C3PAO |
| 18 | Change management, retention, and provider offboarding | Keep control, split execution | Recurring | Monitor changes, export records, support transition | Credentials, keys, configurations, evidence copies, continuity plan | Exit plan, tested export, retention schedule, credential inventory | GRC platform; MSP/MSSP; internal owner |
How we built this matrix: The Defense Compliance Report reviewed the July 13, 2026 implementation suspension, 32 CFR Part 170, the applicable DFARS clauses, NIST SP 800-171 Revision 2, NIST SP 800-171A, and the Cyber AB assessment process. “Keep,” “split,” and “buy” are editorial work-allocation conclusions — not regulatory labels, provider rankings, or compliance determinations. Relative effort is our weighting, not a DoD figure. Last verified August 22, 2026.
The pattern, once you see it
Look down the verdict column and a shape emerges.
Buy finite build spikes. Keep recurring accountability.
Initial data-flow mapping, boundary design, the first SSP, discrete remediation projects, and independent validation are finite spikes. Scope review, evidence upkeep, control operation, provider oversight, change management, incident readiness, and affirmation support recur.
Put every recurring responsibility on an open-ended retainer without checking its hour load and you've converted a program into a permanent bill.
That's the whole strategy, and it's why “hybrid” isn't a hedge. It's the answer.
Before you price either path, find out how big your gap is
Every number on this page moves with one variable: how much of the 110 requirements your environment already satisfies. An organization with a small, evidence-ready gap has a different decision than one missing entire technical processes.
Our CMMC Readiness Checklist is 32 points mapped to the NIST SP 800-171 Revision 2 control families. Free, no sales call, and it takes about twenty minutes with your IT lead in the room.
Download the CMMC Readiness Checklist →
Do not upload contracts, CUI, system diagrams, vulnerabilities, or incident details. The checklist doesn't ask for any of it.
Can your current IT person actually carry CMMC?
Answer capsule: Usually they can carry part of it, and usually not the part leadership assumes. Operating multifactor authentication, logging, and endpoint tooling sits squarely inside a competent system administrator's skill set. Interpreting 32 CFR Part 170, mapping 110 security requirements to the 320 assessment objectives used for Level 2, and writing an SSP that another party can test is a different discipline with different vocabulary. The test is not intelligence. It is prior reps and free hours.
This is the question nobody wants to ask in front of the person it's about. So let's make it a checklist instead of a conversation.
The six capability gates
An in-house-led program is realistic only when all six of these are credibly true. Five is a hybrid. Four or fewer is an outsourced build with an internal owner.
- An accountable executive owner with authority, budget, and the standing to say no to a customer deadline.
- CMMC and NIST fluency — not “we read the standard,” but working familiarity with assessment objectives and what evidence satisfies them.
- Technical operations capacity to run identity, endpoint, logging, vulnerability, and patch processes continuously.
- Documentation and evidence discipline — someone who will maintain an evidence index nobody is asking to see.
- Incident detection and response capability, including the ability to meet a 72-hour reporting obligation under DFARS 252.204-7012 where that clause applies.
- Redundancy — the program survives if one person takes another job.
Gate six is the one that fails quietly. A one-person program can look fine right up until that person's LinkedIn profile changes.
The eight-question self-test
Ask these about the person you're considering. Be honest; nobody's watching.
- Can they explain the difference between a security requirement and an assessment objective?
- Have they read NIST SP 800-171A, not just NIST SP 800-171?
- Can they explain what a Customer Responsibility Matrix is and why an assessor cares?
- Do they know which requirements are POA&M-eligible under 32 CFR § 170.21 and which must be fully met at assessment?
- Have they ever authored an SSP that an outside party actually read and questioned?
- Do they have twelve genuinely free hours a week — not twelve hypothetical ones?
- Will they realistically still be here in eighteen months?
- Do they want this work?
Six to eight yes: in-house-led is real. Buy validation, not execution. Three to five: hybrid. Buy the build; keep the ownership. Zero to two: buy the build and start growing the owner underneath it. This is a normal starting point for a small supplier, and it is not a failure.
What the role actually has to own
Strip away the title and the role has eight operating responsibilities: contract and flow-down intake; FCI/CUI data-flow mapping; SSP and POA&M maintenance; coordination across the 110 Revision 2 requirements and 320 Level 2 assessment objectives; technical-control oversight; incident escalation under applicable DFARS terms; ESP/CSP and CRM oversight; and preparation of accurate SPRS and affirmation records for the people authorized to submit them.
That's the job. If it doesn't look like what your IT person does now, that's your answer.
For the implementation sequence and the line between advisory and hands-on work, see NIST SP 800-171 implementation services: what they include and who to hire first.
The middle option most people miss
If the honest score is three to five, the answer often isn't a full-time hire or a full outsource — it's a fractional or virtual chief information security officer providing governance while your existing staff run operations. We cover the fit and the limits in vCISO services for CMMC.
Does outsourcing put your provider inside your CMMC assessment?
Answer capsule: It can, and this is the cost nobody quotes. Under 32 CFR § 170.19, a non-cloud External Service Provider (ESP) that processes, stores, or transmits your CUI has its relevant services assessed within your scope. A provider that handles Security Protection Data (SPD) is treated through the Security Protection Asset path. A Cloud Service Provider (CSP) handling CUI must meet FedRAMP Moderate authorization or the DoD's documented equivalency requirements. The relationship and the split of responsibilities must be documented in your SSP, the provider's service description, and a Customer Responsibility Matrix.
Outsourcing feels like it moves the problem off your desk. Structured badly, it moves services onto your assessment.
| If your provider… | Scope consequence | Document to demand |
|---|---|---|
| Stores, processes, or transmits your CUI as a non-CSP ESP | The relevant services are assessed within your scope | Service description plus Customer Responsibility Matrix |
| Offers a cloud service that handles your CUI | CSP; must meet FedRAMP Moderate authorization or documented equivalency | Authorization evidence or equivalency package, architecture, contract |
| Processes, stores, or transmits only log, configuration, or other Security Protection Data | The relevant assets/services are assessed as Security Protection Assets | Shared-responsibility matrix describing the split |
| Has administrative access but neither CUI nor SPD touches the provider's systems | Do not assume the provider is automatically assessed as a CUI-handling ESP; document access, dependencies, and responsibilities in the SSP | CRM plus access, role, and architecture documentation |
The document that decides all of this is the Customer Responsibility Matrix — the mapping of which security responsibilities belong to the provider and which belong to you. Assessors use it to determine whether each requirement has a responsible party and real evidence behind it. If the CRM assigns a requirement to your provider and the provider cannot produce evidence, the requirement is scored against you.
Our full mechanics on boundary and scope live in the CMMC scoping guide. The cost consequence is the part that belongs here: more in-scope services and assets mean more evidence, and more evidence means more hours — whichever way you resource it. A poorly designed outsourcing arrangement can push you over the 650-hour line rather than under it.
The other cost: your future assessor pool
Here's a connection we haven't seen anyone else make on this topic.
Under 32 CFR § 170.8, a CMMC ecosystem member may not participate in a Level 2 certification assessment for an organization it served as a consultant preparing for a CMMC assessment within the previous three years. The Cyber AB CMMC Assessment Process adds the operating procedure around assessment teams and conflicts; it does not replace the rule.
Run it forward. Every CMMC ecosystem member you use for readiness is unavailable to participate in your Level 2 certification assessment for three years. Practically, using a C3PAO, CCA, or other assessment-side ecosystem member for readiness can narrow your future assessor pool.
That's a forward-looking consideration right now, not a reason to book an assessor during the suspension. New Level 2 (C3PAO) designations are suspended as of July 13, 2026. But if you're signing a multi-year readiness relationship this quarter, ask any prospective provider, in writing, whether the engagement would conflict the organization or named personnel out of a later certification assessment. A good one will answer immediately.
Related: CMMC mock assessments and the independence boundary.
What does each model actually cost over three years?
Answer capsule: There is no credible universal price for any of the three models, because cost is driven by your starting maturity, CUI boundary, existing tooling, remediation debt, and operating evidence — not by headcount alone. The defensible comparison is three-year total cost using identical categories across every option. DoD's own published figures cover assessment and affirmation burden; the rule explicitly excludes Level 1 and Level 2 implementation and maintenance engineering cost.
We're going to do something here that costs us traffic: we are not publishing a universal market price range.
The public ranges on this topic are not methodologically comparable. We'd rather hand you an architecture you can fill in than a number you'd have to trust.
The three-year comparison formula
Three-year CMMC operating cost = internal loaded labor + recruiting and turnover + security tooling + GRC tooling + cloud or enclave cost + external advisory + managed operations + remediation projects + evidence management + assessment administration + incident-response readiness + transition and exit cost.
Run that same list against all three models. Most quote-shock conversations end the moment a buyer sees that one bucket is eating seventy percent of the total.
What DoD published, and exactly what it means
| DoD modeled figure — small entity | Amount | What it covers |
|---|---|---|
| Level 1 initial self-assessment and affirmation | $5,977 | Initial assessment and affirmation activity |
| Level 1 annual affirmation | $560 | Reaffirmation activity |
| Level 2 self-assessment and initial affirmation | $34,277 | Initial assessment and affirmation activity |
| Level 2 annual affirmation | $1,459 | Reaffirmation activity |
| Level 2 certification assessment and initial affirmation | $101,752 | OSA preparation/support, C3PAO assessment, and initial affirmation |
| Level 2 certification path over three years | $104,670 | Initial cycle plus two annual affirmations |
| C3PAO engagement inside the initial total | $31,234 | Modeled 3-person, 120-hour assessment team |
Source: CMMC Program final rule Regulatory Impact Analysis, 89 FR 83180–86. Other-than-small entities are modeled with different labor mixes and a 5-person, 200-hour assessment team.
Read the fine print, because it's most of the story. DoD's Level 1 and Level 2 figures are assessment-and-affirmation cost models. The Department excluded the cost of implementing and maintaining FAR 52.204-21 and NIST SP 800-171 on the reasoning that those obligations already applied. DoD assumed the assessed organization passes on the first attempt. And DoD said its estimates do not reflect actual C3PAO market prices.
These are regulatory burden estimates. They are not a turnkey budget.
The variable that moves your number more than any other
Not headcount. Not your provider's rate card. Scope.
The rule's scoping mechanics determine which assets and external services are assessed, which responsibilities must appear in the SSP and CRM, and where evidence has to come from. That creates a direct chain:
More CUI pathways → more in-scope assets and services → more responsibility mappings → more evidence → more hours.
That chain is our synthesis of 32 CFR § 170.19 and the Level 2 assessment process, not a government price formula. But it is the reason two companies with the same employee count can receive radically different quotes.
The Small Business Administration's July 13, 2026 release estimated total compliance cost at approximately $593,800 for a small firm on a third-party-certification path and $388,600 for a small firm eligible for self-assessment. SBA also said more than 120,000 small DIB businesses would have faced Phase II demand supported by about 100 approved assessors. Those are SBA advocacy estimates, not the CMMC final rule's assessment-only burden figures and not a quote for your environment. Do not mix the two datasets as though they measure the same thing.
Before you resource this decision, be certain you're resourcing the right-sized problem. Start with the CMMC scoping guide, then compare dollar-level components in the CMMC Level 2 cost guide and CMMC consulting cost guide.
How do you compare proposals without buying ambiguity?
Answer capsule: Require every bidder to state which workstreams it performs, which security requirements it supports, what evidence it delivers and how often, which responsibilities remain with you, and every material exclusion. Then require one number almost nobody asks for: total labor hours. Without hours, you cannot compare a proposal to an internal hire, and you cannot use any break-even analysis at all.
That last point deserves its own line, because it's the single most useful thing on this page and it costs nothing to implement.
Ask every bidder to state the total labor hours in the proposal, broken into year one and steady state.
Vendors quote dollars. Dollars hide everything. Hours let you compare a $90,000 engagement against your modeled loaded hire, test both against the 650-hour line, and see that $90,000 equals about 346 hours at DoD's $260.28 outside-hour assumption.
Ask anyway. A provider that refuses has told you something.
Fifteen questions that make proposals comparable
- Which specific workstreams from your scope are included — by name, not by category?
- Which are advisory, which are co-managed, and which do you fully operate?
- What is the total labor-hour estimate, split into year one and ongoing?
- Which systems, users, and locations are assumed in this price?
- Will you receive our CUI or Security Protection Data?
- Do your services enter our CMMC assessment scope?
- What Customer Responsibility Matrix will you provide, and when?
- What evidence do you deliver for each supported requirement, and on what cadence?
- Who owns the tenant, the configurations, the documents, the encryption keys, and the logs?
- Can we export all evidence in a usable format without your platform?
- Which subcontractors or downstream cloud services do you use?
- What is expressly excluded from this price?
- What happens to price and scope when our environment changes?
- What are the termination, transition-assistance, and data-return terms?
- Would this engagement conflict your organization or named personnel out of a future independent assessment of our environment?
Ask for redacted samples, too: an evidence package, a CRM, a monthly operating report, an incident escalation record, and an offboarding export. A serious provider has these ready. A risky one gets defensive.
Proposal red flags
- “We handle everything” or “100% outsourced — nothing required from your team.”
- Any guarantee of a certification outcome. No one can sell you a CMMC status.
- Readiness and independent assessment bundled together with no conflict-of-interest explanation.
- No Customer Responsibility Matrix and no data-handling answer.
- A readiness package built around NIST SP 800-171 Revision 3 as though it were the current CMMC Level 2 assessment basis. It is not. 32 CFR § 170.14 still incorporates Revision 2 — 110 requirements across 14 families — unless and until DoD amends the rule.
- No client administrative access to your own tenant.
- A quote priced only on employee count, with no scoping analysis behind it.
- Urgency built on a November 10, 2026 Phase II deadline that was suspended on July 13, 2026.
- A claim that DFARS 252.204-7019 or -7020 disappeared merely because the CMMC acquisition rule became effective. Acquisition.gov still publishes both clauses; read the solicitation, contract, and any applicable deviation instead of letting a vendor erase them.
- A claimed Cyber AB ecosystem role with no verification and no date. Verify status yourself in the Cyber AB Marketplace and record the date you checked. In January 2025, DoD OIG found that the Department had not effectively implemented its C3PAO authorization process and made ten recommendations. Your own verification is the backstop.
Now shop for the hours, not for “CMMC”
You know which workstreams you're buying, what evidence to demand, and which fifteen questions make proposals comparable. The remaining step is making sure the right categories respond — because a managed security provider and a readiness practitioner will price the same request completely differently, and you can't normalize what you can't compare.
Send us a non-sensitive scope summary and we'll help you request scoped quotes from matched provider categories, so every response comes back against the same defined scope.
Request scoped quotes from matched provider categories →
Do not submit CUI, drawings, credentials, or contract documents. This intake is for provider-category routing only.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
What actually goes wrong — in both directions
Answer capsule: Enforcement records show failures on both sides of this decision. A contractor has settled after using a third-party service without ensuring the required protections were in place. Another settled after a government assessment contradicted a perfect NIST SP 800-171 Basic Assessment score by 280 points. Neither model is safe without evidence. What the government examines is not who did the work but whether the representation was true.
We looked for the fairest illustrations we could source, and deliberately picked one from each direction.
When outsourcing goes wrong: MORSECORP
In March 2025, the Department of Justice announced that defense contractor MORSECORP agreed to pay $4.6 million to resolve False Claims Act allegations. The resolution described a third-party email host that MORSE did not ensure provided the required protections, plus the absence of a consolidated SSP. As part of the settlement, MORSE admitted, acknowledged, and accepted responsibility for the facts described by DOJ.
The lesson isn't “don't outsource.” It's that the existence of a provider is not evidence that the provider's controls, cloud assurance status, reporting terms, or documentation are correct. Buying the service does not buy you the proof.
When in-house goes wrong: LOGZONE
In June 2026, the Department of Justice announced that Alabama defense contractor LOGZONE Inc. agreed to pay $507,144 to resolve allegations involving Navy contracts. The settlement materials state that LOGZONE posted a 110 NIST SP 800-171 Basic Assessment score in SPRS in October 2021. A later DIBCAC Medium Assessment scored the environment at negative 170, against a possible range of –203 to 110. The settlement resolved allegations and was not a determination of liability.
That 2021 score was a DFARS 252.204-7019/-7020 Basic Assessment score, not a CMMC Level 2 self-assessment status. The distinction matters. The lesson doesn't change.
The lesson isn't “don't self-assess.” Level 2 (Self) is an active CMMC path when the contract specifies it. The lesson is that a self-generated, Low-confidence score can be far from what a government review finds — and the 280-point gap between 110 and –170 is the proof.
The synthesis
Put those two side by side and the actual risk stops being a model choice.
Outsourcing fails when you trust a provider's assurance instead of evidence. In-house fails when you trust your own read instead of validation. Both failure modes are the same failure: a representation nobody independently checked.
That's the strongest argument for hybrid we can make, and it isn't an economic argument at all.
The verification table to run against any claim
| Someone tells you… | Evidence to demand | Who reviews it internally |
|---|---|---|
| “Our cloud is compliant” | Authorization or documented equivalency package, service boundary, contract terms | Security owner; counsel if needed |
| “We cover that requirement” | Configuration, logs, tickets, test results, CRM mapping | Control owner |
| “Your SSP is complete” | Reconciliation against actual assets, services, and data flows | Scope owner |
| “Your score is X” | Objective-level workpapers and supporting evidence | Assessment owner |
| “We handle incident response” | Exercise results, escalation tree, preservation procedure, reporting roles | Executive and incident owner |
| “You can leave any time” | Tested export, credential list, transition assistance, deletion terms | Executive, IT, procurement |
Which provider category fits which gap?
Answer capsule: Provider categories solve different problems and are not interchangeable. Registered Provider Organizations and Registered Practitioners support readiness and implementation planning. Managed service and managed security providers operate technical controls. GRC platforms organize evidence. CUI enclaves constrain a data environment. CMMC Third-Party Assessment Organizations conduct independent Level 2 certification assessments when the contract requires one, and any CMMC ecosystem member that prepared you is barred from participating in that assessment for three years.
We don't publish named provider rankings on this page, and that's deliberate. A category decision made well makes the vendor shortlist obvious; a vendor shortlist offered first makes the category decision for you. We'd rather be useful than convenient.
| Category | Use it for | Do not treat it as | Verify before you sign |
|---|---|---|---|
| RPO / RP (Registered Provider Organization / Registered Practitioner) | Scoping, readiness, SSP and POA&M support, remediation planning | A certifying assessor or legal authority | Marketplace status with a date, named practitioners, deliverables with completion criteria, written assessment-conflict boundary |
| MSP (Managed Service Provider) | IT operations, identity, endpoint, configuration, patching, support | Proof that requirements are met | Scope, whether it touches CUI or SPD, CRM, evidence output, your admin rights |
| MSSP (Managed Security Service Provider) | Monitoring, logging, detection and response, vulnerability and incident support | Your Affirming Official or contract owner | Log-source coverage, SLA, escalation path, evidence retention, subcontractors |
| GRC platform | Evidence workflow, requirement mapping, ownership, version control | A substitute for implementing or testing anything | Export rights, integrations, accurate Revision 2 mapping, data ownership |
| CUI enclave | Constraining a genuinely narrow CUI workflow to shrink your boundary | Automatic scope reduction regardless of how people actually work | Boundary diagram, user workflow, shared-service dependencies, leakage controls, CSP assurance evidence |
| C3PAO (CMMC Third-Party Assessment Organization) | Independent Level 2 certification assessment when the contract requires it | Your readiness or remediation provider for an assessment within the three-year conflict window | Current authorization/accreditation with the date checked, scope experience, independence confirmation, and whether your contract currently requires one |
| Federal-contracts counsel | Ambiguous clause, flow-down, disclosure, or contractual interpretation | A technical implementation provider | Relevant DIB experience and engagement scope |
A current qualifier: as of August 22, 2026, new Level 2 (C3PAO) and Level 3 designations are suspended under the July 13 implementation instructions. Confirm what your actual solicitation or contract says — including any post-July 13 amendment — before booking assessment work. Our fuller category reference is at CMMC provider categories.
What if neither option fits your budget?
Answer capsule: For contractors where defense work is a small share of revenue, the right answer may be neither a hire nor a six-figure engagement. Reducing scope, asking sharper questions about what is genuinely CUI, using a state Manufacturing Extension Partnership center, or declining low-margin CUI work are legitimate business decisions.
This is the section a vendor page will never write, so we will.
Option one: shrink the problem. Scope is the highest-leverage lever in a CMMC program. Before you resource anything, confirm what's actually FCI, what's CUI, what systems and external services touch it, and what the contract requires. Our scoping guide and subcontractor flow-down guide both start there.
Option two: the Manufacturing Extension Partnership. NIST's MEP National Network has centers serving every state and Puerto Rico. Services and pricing vary by center. A current NIST-published case study describes Nelson Engineering, an Arizona aerospace manufacturer with limited internal resources, using Arizona MEP for a fixed-price CMMC/NIST SP 800-171 gap assessment, an SSP, and a draft POA&M. NIST reported $2 million in retained sales and six retained jobs. Check your state center directly rather than assuming a service or price.
Option three: walk away from the work. If defense revenue is a thin slice, margins are tight, and CUI exposure can't be contained, the cheapest CMMC program is a smaller one — or none. That's a business decision, not a compliance failure, and we'd rather say it than sell you a program you don't need.
If you're in this bucket, stop here. Start with the CMMC Level 1 path if FCI is all you handle, and come back when the contract picture changes.
How do you keep this working after year one?
Answer capsule: A sustainable arrangement leaves the contractor better evidenced over time, not more dependent on a portal it cannot leave. Retain administrative control, exportable evidence, a current SSP and Customer Responsibility Matrix, a tested incident process, and a written transition plan — then revisit scope and shared responsibilities whenever the environment, the provider, or the contract changes.
Year one gets all the attention. Year three is where programs quietly fail.
Review quarterly. Scope changes, new contracts and flow-downs, new systems and providers, open remediation, SLA performance, evidence gaps, personnel changes, and current program policy.
Test your evidence export, for real. Export the index. Open the files outside the provider's platform. Reconcile against source systems. Confirm version history. Confirm you'd still understand it if the provider vanished tomorrow. For Level 1 and Level 2 self-assessments, 32 CFR Part 170 requires the OSA to retain assessment evidence for six years from the CMMC Status Date. Certification assessment records have separate retention and artifact-hashing rules. Make sure the copy you'd rely on is one you control.
Keep the SSP and CRM current. Update after architecture changes, provider changes, new cloud services, new subcontractors, new CUI workflows, and control-owner changes. A stale SSP is not evidence of the environment you actually operate.
Hold the continuity assets internally. Provider contact tree, emergency access credentials, encryption-key ownership or documented custody, configuration backups, evidence copies, current contracts, and a transition runbook.
Expect the model to change. Companies move from outsourced-heavy to hybrid as they build capacity, and back again after turnover or a major environment change. That's not indecision. That's a program responding to its own hour count — which is exactly what the break-even on this page is for.
What we actually verified
We'd want the receipts, so here they are. Last verified: August 22, 2026.
Primary and authoritative sources we read for this report:
- The CMMC Program final rule and its Regulatory Impact Analysis — 89 FR 83092, with the cost narrative at 89 FR 83178–83189, labor rates at 89 FR 83180–81, and per-level cost figures at 89 FR 83182–86
- 32 CFR Part 170 at eCFR, including § 170.8 (ethics and the three-year consultant bar), § 170.9 (C3PAOs), § 170.14 (Level 2 and Revision 2), § 170.16 (Level 2 self-assessment), § 170.17 (Level 2 certification assessment), § 170.18 (Level 3), § 170.19 (scoping, ESPs, CSPs, and SPD), § 170.21 (POA&M), and § 170.22 (affirmation)
- The CMMC acquisition final rule, effective November 10, 2025; and DFARS 252.204-7012, DFARS 252.204-7019, DFARS 252.204-7020, and DFARS 252.204-7021 at Acquisition.gov
- NIST SP 800-171 Revision 2, NIST SP 800-171A Revision 2, and the DoD CMMC Level 2 Assessment Guide v2.13
- NIST SP 800-172, February 2021, the edition incorporated for the selected Level 3 requirements in 32 CFR Part 170. NIST later withdrew that publication in favor of Revision 3, but the CMMC rule does not silently update when NIST publishes a replacement.
- Cyber AB resource downloads, including the CMMC Assessment Process (CAP) and Code of Professional Conduct; and the Cyber AB Marketplace for dated ecosystem-status checks
- Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 national data
- The Department's July 13, 2026 release, Implementing Procedures 26-P-1023, and the current DoW CMMC overview
- Department of Justice materials in the MORSECORP and LOGZONE matters, including the LOGZONE settlement agreement
- DoD Office of Inspector General, DODIG-2025-056
- The Small Business Administration's July 13, 2026 release
- NIST MEP's Nelson Engineering case study
What is regulatory or source-stated fact on this page: the assessment cycles, the affirmation requirement and who may make it, ESP/CSP/SPD scoping, POA&M limits, the Revision 2 mapping, the functions of the four DFARS clauses described above, the DoD cost-model figures, the DOJ settlement facts, the original Phase 1 timing, and the July 2026 implementation suspension.
What is our editorial judgment: the hybrid default, the 650-hour decision model, the “buy the spike, keep the steady state” verdict, the keep/split/buy matrix, the relative-effort weighting, the six capability gates, the eight-question self-test, the scope-to-hours chain, the category-fit guidance, and the proposal red flags. Each is a conclusion drawn from verified inputs, not a regulatory label or compliance determination.
What we could not establish, stated plainly:
- There is no authoritative universal hour count for implementing or sustaining CMMC Level 2.
- There is no official national market rate card for CMMC readiness, managed operations, enclaves, software, or C3PAO services.
- DoD's labor rates are rulemaking assumptions, not current market quotes.
- The 30% employer-cost assumption used in our 650-hour model is an editorial input applied to BLS compensation, not a second load on DoD's already burdened in-house rates.
- SBA's $593,800 and $388,600 figures are advocacy estimates of broader compliance cost; the Federal Register figures on this page are assessment-and-affirmation burden estimates. They are not interchangeable.
Found an error? Our corrections policy is published in full, and we'd genuinely rather hear it from you than not.
Frequently asked questions
Can CMMC compliance be fully outsourced? No. Implementation, monitoring, documentation support, evidence management, and substantial portions of assessment preparation can be heavily outsourced. Your organization still owns the truth of its scope, SSP, submitted self-assessment result where applicable, SPRS record, evidence continuity, and annual affirmation. A readiness provider can prepare the package. It cannot be your Affirming Official or certify its own preparation work.
Is it cheaper to do CMMC in-house or hire a firm? It depends on hours, workload shape, and capability. Using DoD's $260.28 external-hour model, BLS May 2025 information-security pay data, and a 30% employer-cost assumption, the modeled break-even lands near 650 outside expert hours a year. Below that, buying is cheaper at those inputs. Above it, hiring is. Replace the inputs with your actual salary, allocation, quote, and expected hours.
How many hours does CMMC Level 2 actually take? No authoritative implementation total exists. DoD's small-entity Level 2 certification model includes 176 external service-provider support hours and a separate 120-hour C3PAO team — 296 modeled external hours — but the model explicitly excludes implementation and maintenance engineering. Ask every bidder to state total labor hours split into year one and steady state.
What does a CMMC compliance manager cost? BLS May 2025 national data puts information security analysts at a mean annual wage of $132,510 and a median hourly wage of $62.11. Computer and information systems managers averaged $192,160. Add the benefits, payroll costs, tools, recruiting, management time, and overhead that actually apply to your company rather than treating cash wage as fully loaded cost.
Can one person handle CMMC compliance? Sometimes, in a small and tightly scoped environment. But a single-person program has no redundancy, and evidence quality is often the first thing to degrade when that person is pulled onto something else. If one departure would stall your program, treat that as a capability gap, not a staffing preference.
Can our existing IT person or MSP do CMMC? Partly, and usually not the part people assume. Operating controls is squarely inside a competent administrator's skill set. Interpreting the rule, mapping 110 requirements to the 320 Level 2 assessment objectives, and producing defensible evidence is a different discipline. Run the six capability gates and the eight-question self-test on this page before deciding.
Does my MSP need to be CMMC certified? There is no universal yes or no. Evaluate the service delivered, whether the provider handles CUI or SPD, what your contract requires, and what evidence it can produce. Under 32 CFR § 170.19, a non-CSP ESP's relevant services may be assessed within your scope when the provider processes, stores, or transmits CUI. We cover the full decision in CMMC requirements for MSPs.
Does outsourcing put my MSP inside my assessment? It can. A non-CSP provider that processes, stores, or transmits CUI has its relevant services assessed within scope; a provider handling SPD is treated through the Security Protection Asset path; and a CSP handling CUI must satisfy the applicable FedRAMP Moderate authorization or equivalency requirement. Document the relationship in the SSP, service description, and CRM.
Who makes the SPRS affirmation if we outsource everything? Your Affirming Official — a senior-level representative from within your organization with authority to affirm continuing compliance, as defined at 32 CFR § 170.22. A provider can prepare supporting materials and may provide authorized administrative help. It cannot be your senior official.
Can a consultant conduct our Level 2 self-assessment? A consultant can support evidence review, readiness testing, and objective-level analysis. The OSA owns the Level 2 (Self) result it submits for its environment and the affirmation supporting that status. Do not confuse consultant assistance with transfer of the representation.
Can the same firm prepare us and assess us? Not within the rule's three-year conflict window. Under 32 CFR § 170.8, a CMMC ecosystem member may not participate in a Level 2 certification assessment for an organization it served as a consultant preparing for a CMMC assessment during the previous three years. Ask how the firm handles organizational and named-personnel conflicts before signing readiness work.
Is a GRC platform a substitute for a person? No. A governance, risk, and compliance platform organizes evidence, maps requirements, and tracks ownership. It does not implement controls, produce evidence that doesn't exist, validate every technical assertion, or make the annual affirmation.
Does CMMC Level 2 use NIST SP 800-171 Revision 2 or Revision 3? Revision 2, currently. 32 CFR § 170.14 incorporates Revision 2 — 110 security requirements across 14 families — and that remains the CMMC Level 2 basis unless and until DoD amends the rule. NIST publishing Revision 3 does not silently rewrite CMMC.
What about NIST SP 800-172? Level 3 adds 24 selected requirements from NIST SP 800-172, February 2021, on top of the Level 2 baseline. NIST withdrew that publication in favor of Revision 3 in May 2026, but 32 CFR Part 170 still incorporates the February 2021 edition unless DoD amends the rule.
Does the July 13, 2026 suspension mean we can stop paying for this? No. The suspension paused the Phase II transition and new Level 2 (C3PAO) and Level 3 designations during the review. It did not suspend DFARS 252.204-7012 or repeal 32 CFR Part 170. Read your actual solicitation, contract, amendment, option, and flow-down. For the current implementation timeline, see CMMC Phase II deadline and suspension update.
What are DFARS 252.204-7019 and -7020 doing now? Acquisition.gov still publishes both clauses. -7019 addresses notice and the requirement for a current NIST SP 800-171 DoD Assessment score in SPRS; -7020 addresses DoD assessment access, cooperation, score posting, and flow-down. Read the exact solicitation, contract, and any applicable deviation. Do not assume the CMMC acquisition rule erased the legacy assessment clauses.
What should be in a CMMC job description? Contract and flow-down intake; FCI/CUI data-flow mapping; SSP and POA&M maintenance; coordination across 110 Revision 2 requirements and 320 Level 2 assessment objectives; technical-control oversight; incident escalation; provider and CRM oversight; evidence continuity; and support for accurate SPRS and affirmation records.
What should be in an RFQ so quotes are comparable? A named workstream list, the systems and users assumed, whether the provider will touch CUI or SPD, the evidence deliverables and cadence, the CRM commitment, ownership of tenants and keys, exclusions, termination and export terms — and total labor hours split into year one and steady state.
How long must we keep CMMC assessment artifacts? For Level 1 and Level 2 self-assessments, the OSA must retain assessment evidence for six years from the CMMC Status Date. Level 2 certification assessments have separate artifact hashing, submission, and record-retention requirements. Keep provider-independent copies and an evidence index you can still read without your vendor's platform.
We can't afford either option. What now? Reduce scope first, check whether your state NIST Manufacturing Extension Partnership center supports this work, and measure defense revenue against the real three-year operating cost. Declining low-margin CUI work is a legitimate business decision when the economics do not support the program.
The bottom line
In-house versus outsourced CMMC compliance is a resourcing decision that the market has turned into an identity question, and it shouldn't be either.
DoD's model prices an external expert hour at $260.28 and a senior in-house IT hour at $81.96; those published in-house rates already include DoD's 30% load. The separate 650-hour break-even comes from combining the $260.28 outside-hour model with BLS information-security pay and a disclosed 30% employer-cost assumption. A standing-start build can cross it. A mature steady state may not. So the defensible answer for most Defense Industrial Base contractors is to buy the spike, keep the steady state, and demand the hours — a fixed-scope outside build where specialist work is finite, a named internal owner for what recurs, and evidence you control on the way out as surely as on the way in.
Everything else is detail: which workstreams to split, whether your provider's services land inside your assessment scope, and whether you asked for hours before you asked for a price.
One last thing. Whichever way you resource this, the failure mode is identical on both sides — a representation nobody independently checked. Fix that, and the model matters a lot less than the market wants you to believe.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
Free. No obligation. “Source-checked” means we check a claimed Cyber AB ecosystem role and status against the Cyber AB Marketplace or the applicable Cyber AB source before routing; it does not mean the DoD, the Cyber AB, or DIBCAC endorses the provider.
Do not submit CUI, drawings, export-controlled content, or sensitive contract details. This intake is for provider-category routing only. Provider matching may generate referral or lead-routing compensation, disclosed at the point of recommendation.
Or, if you'd rather self-scope first: Download the CMMC Readiness Checklist — 32 points mapped to the NIST SP 800-171 Revision 2 control families.
About The Defense Compliance Report
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We do not sell consulting. We do not perform assessments. We do not accept editorial-approval rights from sponsors. We do operate a provider-matching form that may generate referral or lead-routing compensation when a matched provider engages with a reader — and we disclose that every time, including here.
We are not affiliated with the Cyber AB, the CAICO, the U.S. Department of War (formerly Department of Defense), DCMA DIBCAC, NIST, or any U.S. government agency. Our Methodology, Editorial Standards, Editorial Review Process, Corrections policy, and Editorial & Advertising Policy are published in full.
This article is educational research, not legal, contractual, procurement, cybersecurity, or compliance advice. Confirm contract interpretation with your contracting officer or qualified federal-contracts counsel; confirm implementation questions with a current RP/RPO. The solicitation, contract clause, flow-down, and your actual FCI/CUI handling control what applies.
Last reviewed: August 22, 2026.
Keep reading
- CMMC Level 1 vs Level 2 vs Level 3
- CMMC provider categories overview
- NIST SP 800-171 implementation services: who to hire first
- CMMC consulting services: what to buy and how to vet
- vCISO services for CMMC: fit, cost, and limits
- CMMC MSSP providers: scope, evidence, and cost
- CMMC requirements for MSPs
- Is my MSP actually CMMC compliant?
- CUI enclave vs. enterprise compliance
- CMMC scoping guide
- CMMC Level 2 cost guide
- CMMC Phase II deadline and suspension update
- Self-assessment vs C3PAO assessment
- SPRS score: what it is and how to post one