CMMC Level 2 · CUI · defense contractors
CMMC Level 2 timeline and cost: what defense contractors actually pay
Use DoD's published three-year estimates as an anchor. Then budget the work those estimates cannot know: your CUI boundary, remediation backlog, operating evidence, and assessment path.
Executive summary
The official number is a three-year anchor, not your project quote
The Department of Defense has published useful numbers. The CMMC Program Rule estimates three-year Level 2 costs of $37,196 for a small entity using self-assessment, $48,827 for an other-than-small entity using self-assessment, and $117,768 for an other-than-small entity on the certification-assessment path. They are not a universal price for a CUI environment, a migration, managed security, or a C3PAO engagement.
The practical planning number is usually higher because the certification event is the final checkpoint, not the work. A contractor still has to discover where CUI moves, narrow or defend the system boundary, assess all 110 Level 2 requirements, remediate real technical and procedural gaps, write an accurate System Security Plan (SSP), sustain a Plan of Action and Milestones (POA&M), and produce evidence that shows controls operate. For most organizations, 12 to 24 months is the reasonable planning window from initial scope to assessment readiness. A sprawling Microsoft 365 estate, weak logging, or undocumented shared services will take longer.
This page separates published facts from planning assumptions. The endpoint-size table is clearly labeled as an illustrative planning model, not a DoD estimate or vendor quote. See Cyberuptive's CMMC MSSP buyer guide and CMMC compliance services for operating context.
Official DoD cost estimates
What 32 CFR Part 170 actually says
The official source is the final CMMC Program Rule, published at 89 FR 83092, 32 CFR Part 170. It distinguishes a Level 2 self-assessment from a Level 2 certification assessment. It also states that Level 2 uses the 110 requirements derived from NIST SP 800-171 Revision 2.
| Assessment path | DoD's verbatim three-year statement |
|---|---|
| Level 2 self-assessment — small entity | “The three-year cost is $37,196 ... which includes the triennial assessment + affirmation, plus two additional annual affirmations.” |
| Level 2 self-assessment — other-than-small entity | “The three-year cost is $48,827 ... which includes the triennial assessment + affirmation, and two additional annual affirmations.” |
| Level 2 certification assessment — other-than-small entity | “The three-year cost is $117,768 ... and includes a triennial assessment + affirmation, plus two additional annual affirmations.” |
Read those estimates precisely. The final rule says the small-entity self-assessment estimate begins with $34,277 before adding two $1,459 annual affirmations. The other-than-small self-assessment estimate begins with $43,403 before adding two $2,712 affirmations. The certification-assessment estimate begins with $112,345 before those two $2,712 affirmations. None of that creates a fixed assessment fee, or proves that a particular C3PAO, RPO, or managed-services provider will charge the same amount.
The underlying compliance duty has a different source. DFARS 252.204-7012 requires adequate security on covered contractor information systems, directs contractors to NIST SP 800-171, requires cyber-incident reporting within 72 hours of discovery, and requires preservation of affected media and relevant monitoring or packet-capture data for at least 90 days. The rule's Level 2 mapping references the 110 Rev. 2 requirements; NIST's Rev. 2 publication remains the cited baseline for that program mapping even though NIST has subsequently published Rev. 3. Confirm the version incorporated by your current contract and solicitation.
The missing budget lines
What DoD's numbers do not settle for your environment
A published regulatory estimate cannot know the architecture you inherited. Budget internal labor for executives, IT, security, facilities, HR, legal, and program staff who must make the policy and evidence true. Budget remediation for identity hardening, MFA coverage, endpoint management, secure configuration, vulnerability management, backups, incident response, asset cleanup, and supplier controls. The effort rises when people discover CUI in email, shared drives, engineering systems, ticketing, source-code repositories, or unmanaged endpoints outside the intended enclave.
Include platform decisions explicitly. A GCC High tenant may be appropriate when the contract, data-flow, cloud requirements, and operating design justify it; it is not automatically required by CMMC. Include the migration, tenant configuration, identity integration, endpoint management, retention, and administrator effort if it is needed. Include EDR licensing and operations, whether you select Trellix, CrowdStrike, Microsoft, or another defensible option. Include centralized logging, alert triage, log retention, and response runbooks. A tool license without an owner, a response process, and evidence is not an operating control.
Finally, separate MSP or MSSP fees from the controls they operate. Ask which systems collect telemetry, who can access alerts, how CUI is treated in tickets, which work is subcontracted, what data stays after termination, and how evidence is delivered. Recurring services can reduce execution risk, but they become part of the boundary and responsibility model. Cyber AB explains that an RPO provides non-certified advisory services, while a C3PAO conducts certified assessments. Preserve the independence required for the official assessment.
Illustrative three-year TCO model
Budget by endpoint count, but scope by CUI flow
Illustrative planning ranges only — not DoD estimates, not a quote, and not a substitute for a C3PAO proposal. These ranges assume a U.S. contractor pursuing a defensible Level 2 path with varying complexity. Each includes the categories buyers routinely omit. Replace every range with a scoped statement of work, platform quote, and internal-labor estimate.
| Illustrative contractor profile | Gap assessment | Remediation | GCC High, if needed | SSP / POA&M | C3PAO path | Affirmation / evidence | Managed services | Illustrative 3-year total |
|---|---|---|---|---|---|---|---|---|
| 25 endpoints | $15–30K | $35–100K | $0–60K | $15–35K | $25–60K | $5–15K | $55–110K | $150–350K |
| 100 endpoints | $25–50K | $75–200K | $0–140K | $25–60K | $40–90K | $10–25K | $120–260K | $295–700K |
| 500 endpoints | $50–100K | $200–650K | $0–350K | $60–140K | $75–160K | $25–60K | $400–950K | $810K–2.4M |
| 2,000 endpoints | $100–225K | $750K–2.5M | $0–1.2M | $150–350K | $125–275K | $60–150K | $1.5–4.0M | $2.7M–8.7M |
The rows are deliberately broad. A 25-endpoint team with a clean enclave and managed identity may need less than a 100-endpoint contractor with CUI dispersed through legacy systems. Conversely, a 2,000-endpoint contractor may limit cost by proving a tight enclave rather than treating every corporate system as in scope. Make the TCO table a decision record: list assumptions, exclusions, owner, sourcing status, and the evidence each recurring service must produce.
CMMC Level 2 timeline
A phase-by-phase 12–24 month plan
The schedule below is a planning pattern, not a promise. Workstreams overlap, and the actual critical path is usually the slowest technical change, not the document template. Start the assessment clock only after the organization can show operating evidence.
- Months 1–2: scope, boundary, and CUI flow. Inventory contracts, prime requirements, systems, endpoints, cloud tenants, admin paths, backups, and external providers. Trace how CUI enters, moves, and leaves. Decide what is deliberately out of scope and prove it.
- Months 3–4: gap analysis against 110 controls. Test implementation and evidence against the Level 2 requirements. Separate a missing control from a missing proof. Assign a business owner, technical owner, due date, and acceptance evidence to every gap.
- Months 5–8: remediation. Complete technical, procedural, and documentation changes. Typical time consumers are identity cleanup, administrative access, endpoint coverage, centralized logging, secure baselines, media handling, backups, incident procedures, and vendor access.
- Months 9–10: SSP finalization and POA&M. Document the real implementation, shared responsibilities, inherited services, and residual items. An SSP should be precise enough that a new administrator can locate the system, owner, procedure, and evidence without guessing.
- Month 11: RPO pre-assessment. Use a qualified advisor for an evidence-led readiness review. An RPO can prepare an organization, but it is not the independent C3PAO assessment. Resolve ambiguities before scheduling.
- Months 12–14: C3PAO scheduling and assessment. Confirm the required assessment path from the contract, select an authorized C3PAO where applicable, lock the scope, stage evidence, and make accountable owners available. Scheduling capacity can be a real dependency.
- Months 15–16: findings remediation. Address findings with configuration changes, procedural fixes, evidence, and owner signoff. Do not respond to a technical finding solely by changing the SSP wording.
- Ongoing: annual affirmation and continuous compliance. Keep access reviews, log coverage, vulnerability actions, policy updates, incident exercises, supplier checks, and evidence collection on an operating cadence. Certification readiness decays when the environment changes faster than the records.
Costly mistakes
The five decisions that create unnecessary spend and delay
- Over-scoping the CUI enclave. Pulling every corporate system into scope can multiply remediation and evidence work. Minimize scope only where the data-flow analysis supports it; arbitrary exclusion creates an assessment risk.
- Choosing the wrong platform. Commercial Microsoft 365 and GCC High are not interchangeable checkboxes. Select the tenant and services that match the contract, CUI flow, cloud obligations, and support model, then fund the migration and operations if a change is justified.
- Inadequate logging. Logging that is incomplete, unavailable, or not reviewed undermines detection, response, and evidence. Define sources, retention, alert ownership, escalation, and testing before the assessment window.
- A weak SSP. Generic language fails when it cannot be traced to the boundary, a configuration, a person, and an artifact. The SSP is an implementation record, not a marketing document.
- No evidence discipline. A control that operates but leaves no reviewable record is hard to defend. Build evidence collection into normal operations: tickets, access reviews, change records, reports, tabletop outputs, and management approvals.
The fastest savings come from avoiding rework. Use the CMMC readiness checklist to structure discovery, and use the managed SOC pricing guide to ask sharper questions about recurring operating costs.
Small-business fast track
A practical 25–100 endpoint playbook
For a 25–100 endpoint contractor, plan an illustrative $150–350K over three years for the smallest environments, increasing with CUI sprawl, platform migration, and managed-services requirements. That is a planning range, not a DoD estimate. The fast track is not skipping requirements; it is making the boundary small enough to operate and making each workstream visible enough to fund.
First, appoint an executive owner and one accountable technical lead. Second, map CUI and isolate it from general collaboration, personal storage, unmanaged devices, and ambiguous shared services. Third, choose the minimum technology stack that can provide managed identity, endpoints, backups, vulnerability coverage, logging, and incident response. Fourth, build the SSP and evidence index while remediation happens, not after. Fifth, obtain an independent readiness review before committing to the certification assessment path.
Keep the budget honest by placing every item in one of four buckets: one-time scope and remediation; platform and license cost; independent assessment and annual affirmation; and recurring operating services. Require a monthly owner review of the POA&M and the evidence calendar. This turns a large, vague compliance project into a sequence of funded decisions.
Program context and cost mitigation
Do not treat a Phase II pause as a reason to stop preparing
If the CMMC certification rollout is paused or its dates change, confirm the current requirements in your solicitation and contract. Do not confuse a rollout change with the removal of base safeguards. DFARS 252.204-7012 remains a contractual obligation where incorporated, and the current CMMC context keeps self-assessment requirements relevant. The pause is a chance to correct costly structural weaknesses before the next externally driven deadline. Cyberuptive's CMMC Phase 2 pause analysis explains the operational steps to keep moving.
Mitigate cost with eligible public programs, not magical thinking. The DoD Defense Industrial Base Cybersecurity Strategy describes the DIB Cybersecurity Program as a public-private cybersecurity cooperative and points to threat information, cyber resilience analysis, and scalable cybersecurity-service offerings for eligible participants. Review eligibility and current availability directly with the program; these resources do not certify your company or replace required controls.
Also check state and local cybersecurity grants, manufacturing-extension programs, and defense-industry assistance offered in the places you operate. Funding changes often, and eligibility may depend on entity size, location, contract status, or a specific project. Treat grants as a possible offset, not a dependency on the assessment critical path. Spend the first dollars on scope, identity, endpoints, logs, and evidence—the work that makes every later dollar more defensible.
FAQ
CMMC Level 2 cost and timeline questions
How much does CMMC Level 2 cost?
Use DoD’s $37,196, $48,827, and $117,768 three-year anchors, then add scope-specific remediation, tools, internal labor, and operations.
How long does CMMC Level 2 take?
Plan for 12–24 months to establish scope, remediate gaps, build evidence, and complete the required assessment path.
What are DoD’s official CMMC cost estimates?
The final rule publishes $37,196 for small-entity self-assessment, $48,827 for other-than-small self-assessment, and $117,768 for other-than-small certification assessment over three years.
Is CMMC cheaper for small businesses?
The small-entity self-assessment estimate is lower, but fixed remediation, documentation, assessment, and operating costs can still be significant.
Do I need GCC High for CMMC Level 2?
Not automatically; choose the platform based on contract terms, CUI flows, cloud requirements, and the operating model.
Can we self-assess at Level 2?
Some contracts use self-assessment and others require a C3PAO certification assessment; the solicitation and contract determine the path.
What is the cost of a C3PAO assessment?
DoD’s $117,768 is a three-year other-than-small certification-path estimate, not a fixed C3PAO fee; obtain a scope-specific proposal.
How much do MSPs charge for CMMC support?
There is no set rate. Compare readiness, licensing, onboarding, remediation, managed operations, evidence, and incident-response scope over three years.
What is the annual maintenance cost?
Budget recurring affirmations, access reviews, vulnerability actions, logging, exercises, evidence, policy updates, and managed services.
Can we spread CMMC costs over multiple years?
Yes. Sequence scope, high-risk remediation, documentation, evidence, readiness review, and assessment without deferring critical prerequisites.
Are there grants for CMMC compliance?
Check state and local programs, manufacturing-extension resources, and current DIB Cybersecurity Program services; availability and eligibility vary.
Do subcontractors need Level 2?
Subcontractors handling CUI may need the required Level 2 status, while DFARS 252.204-7012 flowdown applies as the contract specifies.
What if we fail our C3PAO assessment?
Confirm the observation, preserve evidence, fund and assign the corrective action, and follow the applicable assessment and contract process.
How does the CMMC Phase 2 pause affect our timeline?
Confirm current solicitation requirements, but continue base safeguarding, self-assessment, and slow-moving remediation work.
What is the cheapest path to Level 2?
Use an accurate minimal boundary, controls that operate, evidence discipline, and a phased plan instead of under-scoping or buying unsupported tools.
For program details, use the current contract documents and official sources: 32 CFR Part 170 final rule, DFARS 252.204-7012, NIST SP 800-171 Rev. 2, and Cyber AB ecosystem roles.
Start with the boundary
Turn your CMMC cost estimate into an accountable plan
Bring your contract context, CUI data flow, current tools, and known gaps. We will help you separate published anchors from the work your environment actually requires.