Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Cost, Grants and Exposure

What CMMC Level 2 Actually Costs

DFARS 252.204-7012 and NIST SP 800-171 Rev 2 apply to anyone handling Controlled Unclassified Information (CUI) for the Department of Defense. Although the CMMC Phase II third party certification requirement is suspended as of July 2026, Level 2 compliance costs still matter for your business. You are still required to complete self-assessments, participate in government-led assessments, and provide annual senior official affirmation. Misrepresenting your compliance now carries more financial risk than ever.

What are the main CMMC cost categories for Level 2?

CMMC Level 2 compliance costs break down into several main categories (CMMC Scoping and Assessment Guides L2 v2.13):

  • Gap assessment: This is the initial review of your current environment against all 110 NIST SP 800-171 Rev 2 controls. Most organizations spend between $10,000 and $50,000 for a thorough gap assessment.
  • Remediation (tools and configuration): Addressing the deficiencies found in your gap assessment means acquiring, configuring, and deploying security tools, as well as tightening configurations. This typically ranges from $30,000 to $200,000, depending on the size and complexity of your environment.
  • Documentation and policy writing: To be considered compliant, you must have policies, procedures, and evidence for all 110 controls. Documentation and policy writing often runs $15,000 to $60,000.
  • MSP or Registered Provider Organization (RPO) consulting: Ongoing support, monitoring, and compliance management from an MSP or RPO generally costs $20,000 to $120,000 per year.
  • C3PAO assessment fee: If and when third party certification resumes, expect a C3PAO assessment to cost between $30,000 and $150,000.
  • Personnel: Hiring or reallocating staff to manage your CMMC program can add $40,000 to $150,000 a year.

Most mid-sized defense contractors land between $200,000 and $500,000 in first year total spend for Level 2 readiness and compliance. These figures come directly from the CMMC Scoping and Assessment Guides and industry reporting.

How does scoping affect your CMMC cost?

The CMMC program allows you to limit the number of systems and assets that fall under the full set of 110 controls by defining your CUI environment. According to 32 CFR 170.19(c)(1) Table 3, there are five asset categories:

  • CUI Assets (assessed against all 110 controls)
  • Security Protection Assets (assessed only against relevant controls)
  • Contractor Risk Managed Assets (subject to SSP review and limited spot checks)
  • Specialized Assets (SSP review only)
  • Out of Scope Assets (no assessment, but separation must be justifiable)

The tighter you can scope your CUI environment, the fewer systems are subject to the full set of controls. This is where the enclave approach comes in: by isolating CUI processing and storage into a dedicated enclave, you can dramatically reduce remediation costs. Fewer assets to secure means less tooling, less configuration work, and less ongoing management.

What evidence is actually required for CMMC Level 2?

You must do more than just write policies. CMMC assessment follows a clear proof chain:

  • Policy defines intent.
  • Procedure describes how you implement the policy.
  • Evidence is the system-generated, timestamped proof that your controls are actually in effect.
  • Assessment validates that your controls are working as documented.

For each of the 110 controls, there are underlying assessment objectives. Every objective must be met for the control to be considered satisfied (NIST SP 800-171A). Documentation alone is not proof. You will need to provide actual artifacts, such as system logs, screenshots, and audit trails.

What happens if you overstate your CMMC self-assessment score?

With third party certification suspended, your senior official’s annual affirmation is the only assurance the government has that you are compliant. This increases your exposure under the False Claims Act for any inflated self-assessment score.

Recent cases have shown that liability for false claims can extend to primes, subcontractors, affiliates, and even private equity owners. For example, Health Net Federal Services falsely certified compliance and failed to scan and remediate known vulnerabilities. MORSECORP failed multiple NIST 800-171 controls, used non-FedRAMP email, and had no SSP on file. Aero Turbine failed controls and shared defense data with an unauthorized foreign entity, and the private equity owner was named in the settlement. Whistleblowers can file qui tam actions, leading to significant legal and financial risk.

How ready are most companies for CMMC Level 2 right now?

Readiness across the defense industrial base is low. As of the end of Phase I, only about 0.5 percent of companies had certified. The average SPRS score is around 60, well below the required 110. Fewer than half have completed their System Security Plan (SSP) or Plan of Action and Milestones (POA&M) documentation. For most, reaching full compliance is still a work in progress.

What do you need to provide in a CMMC Level 2 assessment?

Whether you are preparing for a self-assessment or a future C3PAO review, you will need to provide four primary scoping artifacts:

  • CUI Flow Diagram
  • Network Boundary Diagram
  • Physical Site Diagram
  • Authorized User List

These help define your assessment scope and demonstrate how CUI moves through your environment.

Does the enclave approach really reduce CMMC cost?

Yes, limiting the scope of your CUI environment through an enclave approach is one of the most effective ways to manage CMMC cost. By designating only the minimum required assets as in scope (CUI Assets and Security Protection Assets), you reduce the number of systems that must meet all 110 controls. This reduces your remediation, documentation, and ongoing management needs.

Common questions

What is the current status of CMMC Level 2 certification? The Department of War has suspended the requirement for third party certification as of July 2026, pending a 60 day strategic review. Self-assessments, SPRS posting, and annual senior official affirmation remain required.

How much does a gap assessment for CMMC Level 2 typically cost? A comprehensive gap assessment usually ranges from $10,000 to $50,000, depending on your organization’s size and complexity.

Is documentation alone enough for CMMC Level 2 compliance? No. You must provide evidence, system-generated, timestamped artifacts, that your controls are actually implemented, more than described in policy.

Final thoughts

CMMC cost is a strategic investment in revenue protection. With self-assessment and government oversight in force, the risks of non-compliance are real and rising. If you are a defense contractor and need to understand where you stand against all 110 NIST 800-171 Rev 2 controls, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services. This grant covers all required controls for qualifying companies. Learn more about the opportunity at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

For more details on the CMMC program and current requirements, see https://www.acquisition.gov/dfars.

At a glance

The proof chain from policy to assessmentDocumentation shows intent. Evidence proves execution.Policydefines intentProceduredescribes howEvidenceproves executionAssessmentvalidates realityA control is not met because you wrote it down. It is met because you can prove it happened.
The proof chain from policy to assessment
A 30 day starting plan
A 30 day starting plan

More on Cost and Grants