Skip to main content
New InterSec is now ISO/IEC 42001 certified for AI management systems Read the announcement
cmmc

CMMC Level 2 Cost in 2026. DoD's $105,000 Is the Assessment, Not the Budget.

CMMC Level 2 cost in 2026. DoD prices the assessment near $105K and excludes implementation. See the real three-year math and how to sequence the spend.

InterSec Team Cybersecurity & Compliance August 7, 2026 Article
CMMC Level 2 Cost in 2026: DoD's $105,000 Is the Assessment, Not the Budget
Share

The compliance lead at a 120-person machine shop has three numbers on one desk. DoD’s rule prices the Level 2 assessment cycle near $105,000, a consultant’s proposal reads several times that, and the budget line the owner has to approve still says nothing. Nobody has explained to her why the numbers disagree.

They disagree because they measure different things. Read them against the rulemaking text and the number you take to the owner survives the first hard question.

How much does CMMC Level 2 cost?

DoD’s CMMC final rule estimates a Level 2 third-party assessment cycle at about $105,000 for a small business, covering the triennial assessment and annual affirmations. DoD’s own text excludes implementation from that figure, because it assumes the NIST SP 800-171 work is already done. Implementation and ongoing operations, not the assessment, set the real budget.

The precise figures sit in the regulatory impact analysis of the CMMC final rule, published at 89 FR 83185-86 on October 15, 2024. Here is DoD’s own math.

DoD’s Level 2 cost model (89 FR 83185-86)Amount
Assessment planning, small entity$20,699
Conducting the assessment$45,509
Reporting$2,851
C3PAO engagement (a 3-person team, 120 hours, $260.28 per hour)$31,234
Annual affirmation$1,459
Per-assessment total ($20,699 + $45,509 + $2,851 + $31,234 + $1,459)$101,752
Three-year cycle (adds two more annual affirmations of $1,459 each)$104,670
Other-than-small entity, certification path$112,345 per assessment, $117,768 over three years
Small entity, self-assessment path$34,277 per assessment, $37,196 over three years

For calibration, the same rule prices a Level 1 self-assessment at roughly $4,000 to $6,000 depending on entity size, plus an annual affirmation of about $560 to $584. That figure includes no control implementation either.

Those figures are real, primary-sourced, and current. They also price the assessment and affirmation, and nothing else. The rule’s fine print says so in one sentence.

What does the official estimate leave out?

Read that sentence verbatim. “There are no nonrecurring or recurring engineering costs associated with Level 2 certification assessment since it is assumed the contractor or subcontractor has implemented the NIST SP 800-171 R2 security requirements.”

In practice, DoD priced the exam and assumed the studying was already done. The rule assigns implementation cost to DFARS 252.204-7012, the clause that has obligated contractors handling CUI to implement NIST SP 800-171 since before CMMC existed.

The studying is not small. CMMC Level 2 is assessed against the 110 security requirements of NIST SP 800-171 Revision 2, the baseline DoD pinned with Class Deviation 2024-O0013.

Implementation money buys access controls, logging, multifactor authentication, incident response capability, and the documentation that proves each control operates. Assessment money buys an examination of that proof. The two budgets fund different work, and only one of them shows up in the figure everyone quotes.

None of this is a trick. It is scoping, stated openly in the rule. But a budget built on the $105,000 figure funds verification of work that the figure contains no money to perform.

The real three-year number for a small business

For a small business, the honest three-year picture lands near $488,000. That number is a composite of two rulemakings, and the derivation is short enough to show in full.

The implementation estimate lives in a different rulemaking. In the January 2025 FAR CUI proposed rule (90 FR 4284), the FAR Council modeled NIST SP 800-171 Revision 2 implementation for an average small business at roughly $148,200 in first-year labor, 1,560 hours at $95 per hour, plus $27,500 in hardware and software. Call it $175,700 combined.

Recurring years run near $98,800 in labor plus $5,000 in hardware and software, roughly $103,800 per year.

Three caveats travel with those figures. The totals are sums derived from components the rule prints, and the model describes a small business generally rather than a defense contractor specifically.

A June 2026 revision then superseded the proposal without printing new per-entity figures, which leaves these as the government’s most recent published estimates. That successor proposal also points implementation at Revision 3, while CMMC assessments stay on Revision 2 under the class deviation, so the estimates model the standard your assessment still runs on. The model also excludes system security plan maintenance, incident reporting, and assessment cooperation costs.

The whole derivation in one place

Put the two rulemakings side by side and the three-year picture for a small business adds up in five lines.

Three-year all-in, small businessAmount
Implementation, year one (FAR CUI proposed rule, 90 FR 4284)$175,700
Operations, year two, recurring (FAR CUI proposed rule)$103,800
Operations, year three, recurring (FAR CUI proposed rule)$103,800
Certification assessment cycle (CMMC final rule, 89 FR 83185-86)$104,670
Total ($175,700 + $103,800 + $103,800 + $104,670)$487,970

Any page that attributes that $487,970 to a single document is repeating a secondary-source error. The FAR Council priced the implementation, DoD priced the assessment cycle, and neither priced the other’s half.

Here is the detail that explains the confusion. Both rulemakings assume the implementation work is already done. DoD’s assessment estimate excludes it as pre-existing DFARS 252.204-7012 work, and the FAR Council’s model covers non-defense contractors for the same reason.

The result is that no single government document prices a small DIB contractor’s real all-in bill. That is why the quotes on your desk refuse to match, and why the honest answer is a derivation rather than a citation.

One honesty note applies to the derivation itself. The Phase II suspension makes the assessment-cycle line of that composite conditional on third-party verification returning after the current review.

Why market quotes run higher than the rulemaking math

Government models are one thing. The quotes in your inbox are another, and the spread between them turns rational once you see which slice each vendor is pricing.

Start with the assessment itself. DoD models the C3PAO engagement at $31,234, a 3-person team working 120 hours at a blended $260.28 per hour, and the rule concedes that market forces set actual pricing. Observed C3PAO fees in 2026 run $20,000 to $100,000 and up, because team size, hours, and scoping complexity vary with every environment.

The other slices spread the same way. In the 2026 market, readiness and gap assessments run $3,500 to $20,000, and remediation work runs $35,000 to $115,000 and up depending on how much of the 110-requirement baseline is actually in place.

So read every proposal against one question. Which slice of the stack does this quote price? A proposal that lands at three or four times DoD’s figure is usually pricing implementation plus assessment, the two things the government deliberately priced apart.

Two follow-ups strip most of the remaining mystery. Ask how many systems and users the price assumes, and ask whether remediation labor sits inside or outside the number. A vendor with a defensible quote answers both in a sentence.

A 300-person avionics supplier took the lowest of three quotes, an engagement that turned out to price assessment preparation alone. The remediation surfaced by that preparation cost a multiple of the original engagement, and part of the early work was redone because nobody had scoped where CUI actually lived. The supplier paid for the cheap slice twice.

Then July arrived, and the deadline everyone was budgeting against moved.

What changes while the verification clock is paused?

On July 13, 2026, the Department of Defense suspended CMMC Phase II, the phase that makes third-party C3PAO certification a condition of contract award, pending a 60-day review. Phase I self-assessment requirements remain in effect, and the DFARS obligations underneath them never moved. For what still applies day to day, read the companion piece CMMC Phase II Is Paused. Here Is What Still Applies to Defense Contractors.

The review reports around mid-September 2026, with public release expected roughly 15 days later, and the public RFI on reforming the program closes August 14, 2026. During the review, new solicitations may carry only self-assessment requirements, and Level 2 C3PAO requirements are coming out of active solicitations and existing contracts.

For the budget, the consequence is a matter of timing. The assessment slice of the stack now waits on what the review recommends, while the implementation and operations slices stay live through the pause. Treat the mid-September report as a scheduled checkpoint for this line item.

That reframing helps with the owner too. The line item stops being a race to a date and becomes a staged spend, and each stage produces evidence a prime contractor can ask to see during the pause.

The pause also does nothing to soften the cost of misstating where you stand. In June 2026, the Department of Justice settled a False Claims Act case with LOGZONE, Inc. for $507,144.

The company had reported a perfect NIST SP 800-171 self-assessment score of 110 in SPRS, and a later assessment by DIBCAC, the government’s own assessment arm, scored the environment at -170. LOGZONE did not admit guilt, and the settlement still cost more than DoD’s entire modeled three-year assessment cycle.

Self-assessment scores age out as well. DFARS 252.204-7019 defines a current assessment as one not more than three years old, unless the solicitation specifies less.

The $100,000 grant is not a line item yet

Section 1626 of the Senate’s FY2027 NDAA (S. 4784) would create CMMC assessment grants of up to $100,000 per award for small businesses and nontraditional defense contractors. The grants are capped at $50 million total, usable only for the direct costs of a Level 2 C3PAO assessment, with the program to be established by July 1, 2027. It is a bill, not a program.

The Senate has not passed it. A procedural vote failed 50-46 on July 14, 2026, the House-passed NDAA carries no counterpart provision, and an enacted program would still need separate appropriations. Build the budget as if the grant never arrives, and treat it as upside if it does.

How should you sequence the spend?

The pause window is not a reason to stop spending. It is room to sequence the spend on your own clock, because scoping decides every downstream number in the stack. The six steps below run in the order that protects the eventual assessment fee.

  1. Map where CUI actually lives. Trace every system, share, and data flow that touches CUI before you price anything. The pitfall is buying tools for an environment you have not yet drawn.
  2. Score yourself against the 110 requirements. Run an honest self-assessment against NIST SP 800-171 Revision 2 and record the score you can defend. An optimistic score is how a $507,144 settlement starts.
  3. Close the high-weight gaps first. Remediate the requirements that deduct 5 points under the DoD Assessment Methodology before touching the 1-point items, because that is the cheapest score recovery per dollar spent.
  4. Decide the architecture from the CUI map. Choose between an enclave and a full-environment build only after scoping. The pitfall is letting a vendor pitch make an architecture decision that belongs to your data flows.
  5. Build the evidence while you remediate. Write system security plan entries and collect artifacts as each gap closes, because documentation is the easiest line to underprice.
  6. Time the C3PAO engagement to the review outcome. Hold the assessment contract until the task-force report lands around mid-September 2026, then book against whatever timeline it sets.

Work the list in that order and every downstream bucket shrinks. Scoping trims implementation, honest scoring targets remediation, and early evidence cuts assessment hours.

The order also survives the review. If third-party verification returns on schedule, you are ahead of the C3PAO queue. If it returns changed, nothing you funded above the assessment line is wasted.

You now walk into the owner’s office with what the conversation needed. A number with its derivation shown, from two named rulemakings, and an order of operations for the pause window.

The assessment fee was never the budget. Implementation and operations are.

One disclosure belongs next to the ask. InterSec is a Registered Provider Organization under The Cyber AB, with no software in the cost stack it just priced, and it prepares contractors for CMMC assessment rather than conducting one. If the budget line still refuses to hold together, bring the three numbers on your desk and we will map each one to the slice it actually prices.

Frequently asked questions

How much does CMMC Level 2 cost a small business?

DoD’s final rule prices the third-party path at $101,752 per certification assessment and $104,670 over the three-year cycle for a small entity. The self-assessment path runs $34,277 per assessment and $37,196 over three years. Both figures cover assessment activity alone. Implementation of the underlying NIST SP 800-171 requirements is extra, and it is usually the larger spend.

Is CMMC still required after the Phase II pause?

Yes. The Department of Defense suspended Phase II on July 13, 2026, which paused third-party certification as a condition of award while a review runs. Phase I self-assessment requirements remain in effect, and the DFARS obligation to implement NIST SP 800-171 predates CMMC entirely. Budget as if verification returns on the review’s schedule. The companion pause article linked above walks through what still applies.

What does DoD’s cost estimate not include?

Implementation. The final rule states there are no engineering costs in its Level 2 assessment estimate because it assumes the contractor has already implemented the NIST SP 800-171 R2 security requirements. That means the $104,670 cycle figure carries none of the technology, labor, or process work that closes gaps, and none of the recurring operations after them. For most small contractors those excluded categories run several times the assessment fee.

Is CMMC cost one-time or recurring?

Recurring. The certification assessment renews on a three-year cycle, with an affirmation of continuing compliance filed every year in between, priced by DoD at $1,459 per affirmation for a small entity. On top of that cycle, the FAR Council’s implementation model carries roughly $103,800 per year in recurring operations for an average small business. Budget CMMC as a permanent operating line, not a one-time project.

Will the government pay for CMMC assessments?

Not today. Section 1626 of the Senate’s FY2027 NDAA would create grants of up to $100,000 per award for the direct costs of a Level 2 C3PAO assessment, capped at $50 million total. It is proposed, not law. The Senate has not passed the bill, the House version has no counterpart, and the program would still need appropriations. Even if enacted, it funds the assessment slice only, never implementation.

Book a CMMC readiness and cost-scoping gap review

Bring the three numbers on your desk and we will map each one to the slice it actually prices. InterSec is a Cyber AB RPO. We prepare you for the assessment; a C3PAO conducts it.