Skip to main content
Compliance & ATO

What CMMC actually costs

We are not going to print a number we cannot source, and neither should anyone else. What we can do is show you the six buckets a real budget contains, name the one lever that moves the total by multiples, point at where the government published its own estimates, and give you a two-week method for producing a defensible figure for your company.

No invented figures This article deliberately contains no dollar estimate of our own. Every number you see attributed here comes from a public government source and is named as such. Assessment pricing is set by independent assessor organizations in a competitive market and moves; product pricing moves faster. Get quotes, read the rules, and treat anyone offering a firm price before seeing your boundary as offering a guess with a decimal point on it.

Why the numbers you have seen are not useful

Search for what CMMC costs and you will find figures spanning more than an order of magnitude, and almost none of them state a scope. That is not sloppiness on the writer's part so much as the nature of the thing being priced. The same one hundred and ten security requirements applied to twelve machines in a controlled enclave and applied to a two-hundred-seat corporate network are the same standard and two entirely different projects. A price quoted without a boundary is not a price. It is a range with a scope missing from the middle of it.

There are public figures worth knowing, and it is worth being precise about whose they are. In July 2026, announcing the suspension of the Phase 2 requirements, the Department of Defense Chief Information Officer Kirsten Davies pointed to a mismatch between more than 100,000 companies in the defense industrial base that would need third-party assessments and roughly 100 approved assessor organizations able to perform them, and estimated that moving into the later phases could cost small and medium businesses on the order of $7 billion a year to reach compliance. That is her estimate of an aggregate across an entire industrial base, publicly stated, and it tells you the program is expensive at national scale. It tells you nothing about your company.

For per-entity figures produced by the government itself, go to the source everyone skips: the regulatory impact analysis published in the preamble to the program rule at 32 CFR part 170, and the corresponding analysis in the DFARS acquisition rule. Federal rulemaking requires agencies to estimate the cost of compliance, broken out by entity size, by level, and by whether the assessment is a self-assessment or a third-party assessment, with the assumptions laid out. Those documents are free, they are the government's own arithmetic, and they are the only per-entity numbers in this whole area with a stated methodology behind them. Read the assumptions before you read the totals — that is where you find out whether the estimate describes a company like yours.

You are probably here because

  • You have to put a number in next year's budget and have nothing to base it on
  • Two consultants quoted you figures that differ by a factor of five
  • You are deciding whether the defense revenue is worth the compliance it carries
  • Somebody sold your board a platform and you are not sure what it replaces

The six-buckets section is the budget structure. The levers section explains the factor of five. The two-week method at the end produces a number you can defend in a board meeting.

The six buckets

Every honest CMMC budget has the same six lines. Firms get surprised because quotes usually cover two of them.

1. Scoping and gap assessment. Determining whether CUI is genuinely in play, drawing the boundary, and scoring honestly against the requirements. Small in money and decisive in effect — every other line in the budget is a function of what this one decides.

2. Remediation engineering. Building or fixing what is missing: identity and access, logging and retention, encryption in the right places, the enclave and its transfer paths, endpoint management, network separation, physical and media controls. This is where the variance lives, because it depends entirely on what you already have.

3. Licensing and tenancy. Additional platform tiers, a separate tenant if you need one, log retention, endpoint tooling, secure transfer. Recurring, not one-time, and frequently underestimated because the quote covers year one.

4. The assessment itself. For a self-assessment, this is internal time. For a third-party assessment, it is a fee set by an independent assessor organization in a competitive market, driven by the size and complexity of your boundary and the number of locations. Get three quotes against an identical written scope statement, and treat a wide spread as information about your scope statement rather than about the assessors.

5. Internal labor. The largest line in most real budgets and the one that appears on no quote. Your people writing procedures, gathering artifacts, sitting interviews, changing how they work. It is real money whether or not anyone tracks it, and a readiness plan that does not name who is doing this work is a plan that will slip.

6. Ongoing operation. The annual affirmation, the periodic reviews that have to actually happen, evidence that stays current, and the reassessment cycle. Level 2 statuses are valid for three years with an affirmation at assessment and annually thereafter, so the third-party fee is not a once-in-a-lifetime event. Budget it as a cycle, not a project.

BucketWhat drives itWho you buy it fromWhat makes it explode
Scoping and gap assessmentNumber of contracts, clarity of the CUI determinationInternal, or an outside reader for independenceSkipping it, then discovering the boundary halfway through remediation
Remediation engineeringDistance between what you run today and what the requirements askInternal IT, your managed service provider, or an engineering firmAssessing the whole corporate network instead of an enclave
Licensing and tenancySeat count inside the boundary, log volume, retention periodPlatform vendors, resellersBuying a second tenant before establishing whether you need one
Assessment feeBoundary size, system count, number of physical locationsAn authorized third-party assessor organizationA vague scope statement, which every assessor prices defensively
Internal laborHow much evidence is generated automatically versus by handYour own payrollManual evidence collection, which recurs forever
Ongoing operationAffirmation cycle, review cadence, reassessment intervalMostly internal, plus periodic reassessmentTreating the first assessment as the end of the spend

One lever moves the total by multiples

Everything else in this article is arithmetic around a single decision: how much of your company sits inside the assessment boundary.

The rule gives you the categories to work with. Systems that process, store or transmit CUI are assessed against the full requirement set. Systems providing security functions to that environment are assessed for what they do. Systems kept clear of CUI by policy and procedure are documented and risk-managed rather than fully assessed. Specialized assets that cannot be fully secured — operational technology, test equipment, government-furnished gear — are documented and risk-managed too. Systems that cannot hold CUI and provide no security function are out of scope entirely.

An enclave is the deliberate use of those categories. Controlled work happens in one small, well-instrumented environment; the rest of the company is documented as kept clear. The consequence for the budget is direct: fewer machines to secure, fewer artifacts to produce, a smaller assessment to pay for, and less of the business disrupted. A firm that skips the scoping exercise and assesses everything pays for a far larger program than its contract requires, and the decision is expensive to reverse once the system security plan has been written around it.

The boundary decision is made in the first two weeks, costs almost nothing, and sets the size of every invoice that follows. It is the only part of this program where a fortnight of thinking reliably outperforms a quarter of spending.

What moves the total most — our read, ordered by impact

How much of the company is inside the boundary
95
Maturity of identity, endpoint and logging today
80
Whether evidence is generated or collected by hand
72
Number of physical locations and specialized assets
58
Count of external service providers in the workflow
46
Self-assessment versus third-party assessment
30

Our ordering of the levers by how much each moves a total, not a survey and not a price. Note the bottom row: the assessor fee is real, and it is not the variable people think it is.

The costs nobody quotes

Four lines appear in real projects and almost never in proposals.

Time itself. Some assessment objectives can only be satisfied by records that have accumulated over a period. Turning on logging in the final month leaves you with no history, and history cannot be purchased at any price. This is the most common cause of a slipped date, and its cost shows up as a delayed award rather than an invoice.

The six requirements that can never be deferred. Two access-control requirements covering external connections and control of publicly posted information, the system security plan itself, and three physical-access requirements covering visitor escorting, physical access logs, and management of physical access. If any of them is unmet, no conditional path exists at any score. For a firm with a plant, the physical three are frequently the surprise line item, because a readiness program run out of the IT department does not walk the floor.

Chasing external providers. Responsibility matrices, cloud equivalency artifacts, and written answers from software vendors about what they store. Little of it costs money and all of it costs calendar time, and some providers take months.

The closeout. A conditional status with a plan of action carries a 180-day clock, and closing it out is a second engagement with its own cost. Firms budget for the assessment and not for the closeout, then discover that the cheaper path was fixing the gap before the assessment rather than after.

Two costs that are not real

It is worth naming the spending that does nothing, because both are actively sold.

There is no such thing as a product that makes you compliant. Vendors describe tools as CMMC compliant, and what that phrase can honestly mean is that the product itself is capable of being configured to support certain requirements. Compliance is a property of your environment, your procedures and your evidence — not of anything in a shopping cart. A governance platform bought before the boundary is drawn is a place to store confusion in a more expensive format.

And a second tenant, purchased before establishing whether the requirements actually demand it, is a recurring cost with a plausible story attached. The safeguarding clause requires a cloud service handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. It does not name a product. Sometimes a government community offering is the right answer, usually for reasons involving data residency, support personnel screening, or export control. Establish which of those reasons applies to you before signing a multi-year commitment.

Getting a real number in two weeks

This sequence produces a figure you can defend, and it costs almost nothing but attention.

Days 1–3. Settle the CUI question. Read the clauses, the data deliverables and their distribution statements, and the prime flowdowns on every active award. If there is genuinely no CUI, your obligation is fifteen requirements, self-assessed, and the budget conversation is over. Get ambiguity answered by the contracting officer in writing.

Days 3–6. Draw two boundaries and price both. One that assumes a small enclave, one that assumes the current estate. Write each as a scope statement an outsider could read: systems, users, locations, external providers. The gap between the two is the value of the scoping decision, in your own numbers.

Days 5–9. Score yourself honestly. Against the requirements, five-point items first, and check the six that can never sit on a plan of action before anything else. You do not need a consultant for a first pass and a first pass is enough to size the remediation bucket.

Days 8–12. Three assessor quotes on one scope statement. Send identical wording to three authorized assessor organizations. Where quotes diverge widely, the usual cause is ambiguity in the scope statement, and finding that out now is worth the whole exercise. Ask each one what would make the number go down.

Days 10–14. Price the other four buckets. A delta quote from your managed service provider, licensing from your reseller, an honest internal hours estimate by function, and a recurring annual figure. Add the closeout as a contingency line rather than pretending it will not happen.

At the end you have a number with a boundary attached, three market quotes, and an internal labor estimate. That is a defensible budget. It is also, in our experience, materially lower than the first figure the company was quoted, because the first figure was priced against the whole business.

Is the revenue worth it?

This is the question underneath the budget question, and it deserves a straight answer rather than an assumption.

For a firm with meaningful defense revenue and controlled data already in the building, the arithmetic is usually easy: the cost of compliance is smaller than the revenue that requires it, and a certification is a genuine commercial advantage with primes who prefer a supplier that holds one over a supplier who intends to. For a firm with one small defense contract, no controlled data today, and a general-purpose IT estate, it may not be. Two honest alternatives exist and neither is failure.

The first is to stay clear of CUI deliberately. Structure the work so controlled data never lands on your systems, keep the obligation at fifteen requirements, and be excellent at the part of the supply chain that does not require an enclave. The second is to sub under a prime who holds the data, doing work that does not require them to send it to you. Both are real positions taken by real firms, and both are better than a half-built program that supports an affirmation nobody can stand behind.

What is not a position is deciding by drift — taking the contract, receiving the data, and sorting out the compliance later. That is how a company ends up with controlled information on unmanaged machines and a signature already on file.

The mistakes we see most

  • Buying a price before drawing a boundary, which guarantees the price is for the wrong thing
  • Assessing the whole company when the contract required a fraction of it
  • Leaving internal labor out of the budget, then being surprised when the project stalls on capacity
  • Budgeting the assessment and not the closeout, or the annual affirmation, or the reassessment
  • Buying a governance platform first, before there is anything for it to govern
  • Purchasing a second tenant reflexively, without establishing which requirement demands it
  • Skipping the physical requirements because the readiness program lives in the IT department
  • Treating time as free, when the objectives that need history are the ones that slip the date

What a defensible budget contains

  • A written CUI determination, with the contracting officer's answer where it was ambiguous
  • A boundary described well enough that an outsider could price it
  • An honest self-score, five-point items and the never-deferrable six checked first
  • Three assessor quotes against identical wording
  • A remediation estimate itemized by requirement, not a lump sum
  • Internal hours by function, named and agreed by the people who will spend them
  • Recurring annual cost separated from one-time cost
  • A contingency line for closeout if a conditional status is likely
  • The government's own per-entity estimates read, with their assumptions checked against your company
  • An explicit decision that the revenue justifies the program

Bottom line

There is no CMMC price, only your CMMC price, and it is set almost entirely by a scoping decision most firms make late and by accident. Read the government's own regulatory impact analyses for per-entity estimates with stated assumptions, treat any figure quoted without a boundary as a guess, and spend the first fortnight on the determination and the boundary rather than on procurement. Then get three quotes on identical wording, add the four buckets nobody quotes, and put the recurring cost in the model. If the resulting number does not justify the revenue, say so out loud — deciding not to hold CUI is a legitimate business strategy, and it is a much better outcome than a program that stops halfway with an affirmation already signed.

Frequently asked questions

Why will nobody give us a price over the phone?

Because the price is a function of the boundary and the boundary is a function of decisions you have not made yet. An assessor pricing an undefined scope has to price defensively, which is why quotes against a vague scope statement come back high and far apart. Write the scope statement first — systems, users, locations, external providers — and the same assessors will quote a narrower range.

Is a self-assessment much cheaper than a third-party assessment?

The assessor fee goes away and almost nothing else does. The security requirements are identical, the evidence burden is the same, and a named official affirms the result in a government system either way. That affirmation carries the same weight regardless of who performed the assessment. Treat the fee as the smallest lever in the budget rather than the main one.

Where can we find the government's own cost estimates?

In the regulatory impact analysis published with the program rule at 32 CFR part 170 and in the corresponding analysis in the DFARS acquisition rule. Federal rulemaking requires cost estimates broken out by entity size and by assessment type, with the assumptions stated. Read the assumptions before the totals so you can judge whether the modeled entity resembles yours.

Does the July 2026 pause save us money?

It changed when a third-party certification becomes an automatic condition of award. It did not change the safeguarding clause, the underlying standard, the Phase 1 award conditions, or the annual affirmation, and Phase 1 already permits the Department to require a third-party assessment on a specific requirement at its discretion. Work spent implementing the requirements is not at risk from the review; only the paperwork wrapper around it is. Deferring the engineering to see what happens is the version of this that costs money.

Can we make our managed service provider carry the cost?

They can carry part of the work, and none of the accountability. Ask for a written responsibility matrix showing which requirements they cover, which are shared, and which stay with you, then price the remainder honestly. External service providers sit inside the scoping rules, so their gaps become yours at assessment time and their reports become part of your evidence.

1 business day response

Need a number you can put in a budget?

Send a description of your environment and one contract's clause list, and we will tell you plainly which buckets are likely to dominate and what a tighter boundary would remove. Email bo@precisionfederal.com.

Email an engineerCapabilitiesMore insights →
Boundary ScopingRemediationAssessment FeesRecurring Cost