What a CMMC Level 2 self-assessment costs, what the suspended third-party certification path would have cost, what the official estimates leave out, and how a small defense contractor should budget for it now.
As of September 2026, a CMMC Level 2 self-assessment is the only CMMC assessment most defense contractors have to pay for, and the DoD cost analysis published with the CMMC program final rule estimates it at US$34,277 for a small entity, or US$37,196 across three years once two annual affirmations are added. The third-party certification path, estimated at US$101,752 per assessment for a small entity, was suspended on 13 July 2026. Both figures cover the assessment only. Neither includes the cost of implementing the 110 security requirements that CMMC Level 2 assesses.
The DoD estimated a CMMC Level 2 self-assessment at US$34,277 for a small entity, covering a three year cycle, with an annual affirmation of continuing compliance estimated at US$1,459 each. Across the full three years that comes to US$37,196. Almost all of that figure is internal labour: the hours your own people spend evidencing each of the 110 security requirements in NIST SP 800-171 Revision 2, writing up the result, and entering the score into the Supplier Performance Risk System. A CMMC Level 2 self-assessment carries no assessor fee, because no external party is involved. These estimates come from the regulatory analysis published with the CMMC program final rule, 32 CFR Part 170.
| Assessment path | What it covers | Estimated cost, small entity | Status in September 2026 |
|---|---|---|---|
| Level 1 self-assessment | 15 requirements in FAR clause 52.204-21, assessed annually | US$5,977 per year | Required for federal contract information |
| Level 2 self-assessment | 110 requirements in NIST SP 800-171 Rev 2, assessed every three years | US$34,277, plus US$1,459 per annual affirmation | Required for controlled unclassified information |
| Level 2 self-assessment, three year total | One assessment plus two annual affirmations | US$37,196 | Required in Phase 1 |
| Level 2 certification assessment | Same 110 requirements, assessed by a C3PAO | US$101,752 per assessment, of which US$31,234 is the C3PAO fee | Suspended since 13 July 2026 |
| Level 2 certification, three year total | One certification assessment plus two annual affirmations | US$104,670 | Suspended since 13 July 2026 |
| Level 2 certification, other than small entity | Same 110 requirements, larger organisation | US$112,345 per assessment, of which US$52,056 is the C3PAO fee | Suspended since 13 July 2026 |
On 13 July 2026 the Department of War, formerly the Department of Defense, suspended CMMC Phase 2. Phase 2 had been scheduled to begin on 10 November 2026 and would have made third-party certification a condition of award on contracts involving controlled unclassified information. The later phases were suspended with it, and a CMMC reform task force was established to review the program. What remains in force is Phase 1: Level 1 and Level 2 self-assessments, DFARS clause 252.204-7012, and NIST SP 800-171 Revision 2. The Department of War CIO CMMC page states that compliance will be enforced through self-assessments and select government-led assessments during the pause. For anyone building a budget this quarter, that is the single most important fact about CMMC Level 2 cost: the six figure C3PAO invoice that most cost guides lead with is not a bill you have to pay in 2026.
A CMMC Level 2 certification assessment, the kind performed by a certified third-party assessor organisation, was estimated by the DoD at US$101,752 per assessment for a small entity and US$112,345 for an other than small entity. Within those totals, the C3PAO's own fee was estimated at US$31,234 and US$52,056 respectively. The remainder is your own team's time preparing for and supporting the assessment. Over a three year cycle with two annual affirmations, the DoD put the small entity total at US$104,670. That path is suspended rather than cancelled, so treat it as a cost that may return.
The CMMC cost estimates cover assessment, not remediation. The DoD reasoned that contractors handling controlled unclassified information were already obliged to implement NIST SP 800-171 Revision 2 under DFARS clause 252.204-7012, so the cost of implementing those 110 requirements sits outside the CMMC rule's numbers entirely. For a contractor that has genuinely done that work, the assessment figures above are close to the real bill. For a contractor that has not, implementation is usually the largest line in the budget and none of the published estimates touch it.
| Cost component | In the DoD estimate? | What drives the number |
|---|---|---|
| C3PAO assessor fee | Yes, within the certification figure | US$31,234 for a small entity, US$52,056 for an other than small entity |
| Your team's assessment hours | Yes | Number of requirements, quality of existing documentation |
| Annual affirmation | Yes | US$1,459 per affirmation for a small entity |
| Implementing the 110 NIST SP 800-171 requirements | No | Treated as an existing DFARS 252.204-7012 obligation |
| Remediating gaps found during a gap analysis | No | How far your current environment sits from the requirements |
| Consultant, RPO or vCISO support | No | Day rates, and how much of the work you outsource |
| Enclave, licensing or infrastructure changes | No | Whether CUI has to be moved into a separate environment |
| Compliance software to track it | No | Published pricing where a vendor offers it, quoted pricing where it does not |
That last row is worth stating plainly, because it is the one line a buyer cannot easily research. Vanta, Drata and Secureframe do not publish list pricing for their compliance platforms, so a contractor comparing options has to book a sales call before seeing a number. CertAssist publishes its price: US$225 per month as a limited-time launch offer, normally US$375 per month, or US$3,999 per year, all in USD, with every framework including CMMC Level 2 included in the one plan.
Your contract sets your CMMC level, not your own judgement about risk. CMMC Level 1 applies when you only handle federal contract information and covers the 15 basic safeguarding requirements in FAR clause 52.204-21, self-assessed annually, with no plans of action and milestones permitted. CMMC Level 2 applies when you handle controlled unclassified information and covers the 110 requirements in NIST SP 800-171 Revision 2, assessed every three years, with plans of action and milestones permitted and a 180 day closeout. CMMC Level 3 applies to a small number of the highest priority programs and adds selected requirements from NIST SP 800-172 on top of Level 2. If you are unsure which applies, the clause in the solicitation is the answer, and your contracting officer is the person to ask.
The largest lever on CMMC Level 2 cost is scope. Every system that stores, processes or transmits controlled unclassified information is in scope, and every system that does not is out. Moving CUI into a defined enclave, rather than leaving it spread across a general corporate network, shrinks the estate you assess and cuts both the implementation work and the assessment hours. The second lever is evidence discipline. A self-assessment is expensive mostly because people reconstruct months of evidence in a hurry. Recording it against each requirement as the work happens turns the assessment into a review rather than an excavation. The third is honesty about plans of action and milestones. CMMC Level 2 permits them, but they must be closed within 180 days, so a POA&M is a scheduling tool and not a way to avoid a requirement.
CertAssist supports the third lever directly. CertAssist lays out all 110 CMMC Level 2 practices across the 14 control families, gives each one an editable policy and evidence template, and keeps the evidence and the activity history in one place for a read-only assessor login. CertAssist requires no integrations and no access to your systems, which matters more than usual in a defense context where every additional vendor with cloud admin is a question you will be asked to answer.
CertAssist is not a C3PAO, does not perform your assessment, does not submit your score to the Supplier Performance Risk System, and does not replace an assessor or a certification body. CertAssist has no integrations by design, so it will not pull configuration evidence out of your cloud or identity provider. If your requirement is continuous automated monitoring across a large estate, a platform with integrations is a better fit and worth its higher price. If you need someone to write your system security plan for you, that is consulting work, and CertAssist is not a substitute for it.
As of September 2026, a CMMC Level 2 self-assessment is estimated by the DoD at US$34,277 for a small entity, or US$37,196 across three years once two annual affirmations are added. The third-party certification path was estimated at US$101,752 per assessment for a small entity, but the Department of War suspended CMMC Phase 2 on 13 July 2026, so that cost is not currently triggered.
A CMMC Level 2 self-assessment costs whatever your own team's hours cost, which the DoD estimated at US$34,277 for a small entity across a three year cycle. A CMMC Level 2 certification assessment performed by a C3PAO was estimated at US$101,752 for a small entity, of which US$31,234 is the C3PAO fee. Neither figure includes implementing the 110 security requirements.
Your contract sets the level. CMMC Level 1 applies when you only handle federal contract information and covers the 15 requirements in FAR clause 52.204-21. CMMC Level 2 applies when you handle controlled unclassified information and covers the 110 requirements in NIST SP 800-171 Revision 2. CMMC Level 3 applies to a small number of the highest priority programs.
The DoD estimated a CMMC Level 1 self-assessment and affirmation at US$5,977 per year for a small entity. CMMC Level 1 is an annual self-assessment against the 15 basic safeguarding requirements in FAR clause 52.204-21, with the result entered into the Supplier Performance Risk System. Plans of action and milestones are not permitted at Level 1, so every requirement has to be met before you affirm.
CMMC Phase 1 began on 10 November 2025, and Level 2 self-assessment requirements apply now to solicitations that carry the CMMC clause. Phase 2, which would have required third-party certification from 10 November 2026, was suspended on 13 July 2026 along with the later phases. No replacement date has been published, so the CMMC Level 2 self-assessment is the current requirement.
CMMC Level 1 covers the 15 basic safeguarding requirements in FAR clause 52.204-21, protects federal contract information, and is self-assessed every year. CMMC Level 2 covers the 110 requirements in NIST SP 800-171 Revision 2, protects controlled unclassified information, and is assessed every three years. CMMC Level 2 permits plans of action and milestones with a 180 day closeout, and CMMC Level 1 does not.
CertAssist lays out every CMMC Level 2 practice with editable policy and evidence templates and read-only assessor access, with no integrations and no access to your systems. Launch price US$225 a month, normally US$375, all frameworks included.
See pricing FrameworksFlat US$225 a month launch price (normally US$375), or US$3,999 a year (12 months for the price of 11). All prices in USD.