In this article:

What Does CMMC Certification Cost?

Compliance
/
July 11, 2026
What Does CMMC Certification Cost?

CMMC certification costs most defense contractors between $40,000 and $250,000 to reach Level 2, and the assessment itself is rarely the biggest line. Level 1, which covers 15 basic requirements for companies handling only Federal Contract Information, is a self-assessment with no assessor fee: budget $5,000 to $25,000 for the readiness work behind it. Level 2 covers all 110 requirements of NIST SP 800-171 and normally requires a third party. Expect $15,000 to $45,000 for a readiness and gap assessment, $20,000 to $150,000 or more for remediation, and $40,000 to $110,000 for the C3PAO certification assessment, followed by annual affirmations and a recertification every three years. How you scope the environment moves every one of those numbers more than any other decision.

Level 1 and Level 2 are different purchases

The cost conversation splits at the line between self-assessment and third party certification. Level 1 applies to contractors that handle Federal Contract Information and no Controlled Unclassified Information. It covers 15 requirements taken from FAR 52.204-21 and is affirmed annually in SPRS by a senior company official, with no assessment invoice attached. What you pay for is arriving at an answer you can sign: someone has to confirm that access control, media handling, physical protection, and basic system maintenance are real rather than assumed. A company under 50 people running cloud-first infrastructure usually spends $5,000 to $15,000 there. A machine shop with legacy Windows controllers, no written policies, and a shared administrator password is closer to $15,000 to $25,000, and the remediation that follows often costs more than the assessment did.

Level 2 applies once CUI is stored, processed, or transmitted, and it covers all 110 requirements of NIST SP 800-171. Most Level 2 contracts require certification by a C3PAO, a CMMC Third Party Assessment Organization authorized by the Cyber AB. A narrow band of Level 2 contracts still permits self-assessment, but budgeting around that exception means betting on which DFARS clause your contracting officer selects. Going from 15 requirements to 110 also means going from about 60 assessment objectives to roughly 320, each scored MET or NOT MET by an independent party with no partial credit.

Line one: readiness and gap assessment

A gap assessment tells you where you stand against all 110 requirements and what your SPRS score defensibly is today, before anyone from outside is looking. Priced work runs $15,000 to $45,000 for most small and mid-sized contractors. The spread comes from asset count, number of physical locations, and how many external providers touch in-scope systems. A 25-person engineering firm with one office and a government cloud tenant sits near the bottom. A 300-person manufacturer with three plants, an ERP system, and a managed service provider running the network sits at the top, because each of those adds interviews, sampling, and shared responsibility to untangle.

What justifies the spend is the artifact set: a scoping and boundary document, a control by control assessment against the NIST SP 800-171A objectives, a System Security Plan, and a Plan of Action and Milestones with named owners and dates. Skipping this line to save money is the most expensive choice on the list, because remediation without a scope decision means paying to harden systems that never needed to be in scope. What happens in a CMMC audit covers what the assessment team does with those documents once you get there.

Line two: remediation, the number nobody can quote blind

Remediation is the largest and least predictable line in a CMMC budget. Ranges of $20,000 to $150,000 are common, and contractors starting from a standard commercial IT setup with no federal history land above that. The variability is not evasion. Remediation cost is a function of the gap, and the gap is not knowable until it is measured.

The drivers are consistent. Identity and access work, including FIPS validated multifactor authentication on every path into the CUI environment, typically runs $10,000 to $40,000 in licensing and engineering. Moving to a government community cloud tenant carries a licensing premium of roughly $10 to $35 per user per month over commercial equivalents, plus $15,000 to $60,000 in migration labor. Centralized logging with the retention and review the audit family requires costs $10,000 to $40,000 a year once you count the platform and the person who reads it. Endpoint hardening to a documented baseline, vulnerability scanning, validated encryption, and configuration management tooling add $15,000 to $50,000. The rest is labor: a policy set that describes your company rather than a template, an incident response capability that has been exercised, and training with records behind it.

Two items surprise contractors more than the rest. External service providers come first: if your MSP administers in-scope systems, its practices come into your assessment, and restructuring that relationship is its own project. Cloud services come second, because anything handling CUI needs FedRAMP Moderate authorization or documented equivalency, which can force a platform migration that no security tool purchase would have avoided.

Line three: the C3PAO assessment fee

C3PAOs price on assessor days, usually a lead assessor plus one or two others with a quality reviewer behind them, across one to two weeks of fieldwork. A small, tightly scoped enclave commonly runs $40,000 to $60,000. A contractor with 100 to 300 people on a single site sees $60,000 to $110,000. Multi-site scopes with heavy external provider involvement run past $150,000. Travel is usually billed separately, and if you finish with conditional status, the POA&M closeout assessment adds $8,000 to $20,000 inside the 180 day window.

One boundary matters for both budgeting and reading proposals: the C3PAO fee is paid to the assessment organization, not to BD Emerson. BD Emerson is not a C3PAO and does not certify anyone. We work the readiness side, which means scoping, gap assessment, remediation, System Security Plan development, and mock assessment. That separation is required, and it also means we can be blunt about what is broken without holding a stake in how it gets scored.

Line four: annual affirmations and triennial recertification

Certification is a three year cycle with obligations in every year of it. A senior company official affirms continuing compliance in SPRS annually, which reads like an administrative step and is in fact a signed statement the government can hold you to. Keeping that affirmation honest costs money: plan on $15,000 to $50,000 a year for the tooling, monitoring, and oversight that keep 110 requirements operating rather than decaying. Recertification at the three year mark costs 80 to 100 percent of the initial assessment fee, and it is a full assessment rather than a review of the last one. Contractors who treat the certificate as an endpoint pay twice, because controls drift and the next assessment finds exactly where.

Enclave versus enterprise: the single biggest lever

Every number above scales with the size of the assessment boundary, which makes scoping the decision that moves the most money. An enclave is a contained environment where CUI lives, separated from the rest of the corporate network by identity, network, and data flow controls. Certifying an enclave rather than the whole company commonly removes 60 to 90 percent of assets from scope, and every asset removed is one fewer laptop to harden, one fewer configuration to defend, and one fewer sample an assessor can pull.

The arithmetic is stark. Take a 150-person manufacturer with 400 endpoints, an ERP system, and CUI spread across file shares and email. Certifying the enterprise means remediating all of it, roughly $150,000 to $200,000 in remediation and $90,000 to $130,000 in assessment fees. Building an enclave for the 20 people who actually handle CUI costs $25,000 to $75,000 up front, brings in-scope assets down to about 25, and cuts remediation to $50,000 to $70,000 with an assessment near $45,000 to $60,000. The enclave path is usually more than $100,000 cheaper on the first cycle and cheaper again at recertification. The tradeoff is operational: some employees work in two environments, data movement becomes deliberate, and someone has to police the boundary.

What to budget, by company size

  • Under 25 people, Level 1 only. $5,000 to $15,000 for readiness and documentation, plus remediation that is usually under $20,000. No assessor fee, and the annual affirmation is internal effort.
  • Under 50 people, Level 2 with an enclave. $15,000 to $25,000 gap assessment, $30,000 to $70,000 remediation, $40,000 to $60,000 C3PAO assessment. First cycle commonly totals $90,000 to $160,000.
  • 50 to 250 people, Level 2. $25,000 to $40,000 gap assessment, $60,000 to $150,000 remediation, $60,000 to $110,000 assessment. First cycle commonly totals $150,000 to $300,000, with scoping deciding where inside that band you land.
  • 250 people and up, or multi-site. $40,000 to $75,000 gap assessment, $150,000 and up remediation, $110,000 to $250,000 assessment. Programs this size usually run 18 to 24 months from start to certificate.

The costs that never appear in a proposal

Internal hours are the quiet line. Expect 200 to 600 hours across IT, engineering, HR, and facilities in the first year, spent on evidence collection, interviews, and rework. Time is another. Assessors can tell a program from a sprint, so plan on at least a quarter of operating history before assessment day so that logs, tickets, reviews, and training records exist to sample. The sequencing is uneven too: gap assessment spend starts in month one, remediation spreads across six to twelve months, and the assessment fee arrives as one large invoice at the end.

Where to start

Every number in this article narrows once scope is real, which makes scoping the first conversation rather than the second. A CMMC gap assessment produces the boundary decision, the control by control position against all 110 requirements, and a defensible SPRS score, which together turn a range into a budget. Our CMMC consulting practice carries the rest: enclave design, remediation, System Security Plan development, POA&M management, and a mock assessment that samples the way a C3PAO will. The certificate comes from the assessor. Everything that decides what it costs happens before they arrive.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director