Skip to content

DoD's Own CMMC Cost Estimate Assumes Building the Controls Costs Nothing

By Donovan Brown
August 26, 2026
10 sections
US flag for federal compliance — CMMC, NIST, ITAR
Photo: Pang Yuhao on Unsplash

The $101,752 CMMC Level 2 figure from the DoD final rule is real, but it prices the assessment only. The rule assumes you have already implemented all 110 NIST SP 800-171 requirements, and with Phase 2 suspended the live estimate for most small CUI contractors is $34,277.

01

Introduction

The number most defense contractors carry in their head for CMMC Level 2 is $101,752. It comes from the Department of Defense itself, in the regulatory impact analysis attached to the CMMC final rule (32 CFR Part 170, 89 FR 83092, published 15 October 2024). It is real, correctly calculated and published in the Federal Register. It also assumes you have already built every one of the 110 security requirements the assessor is coming to check.

That assumption is stated in the rule in plain English. Most of the quoting that happens downstream drops it.

02

What the DoD figure actually covers

The small-entity estimates from the final rule, for assessment and initial affirmation only:

PathDoD small-entity estimateBasis
Level 2 certification assessment (C3PAO)$101,752 (three-year total $104,670)Per triennial cycle
Level 2 self-assessment$34,277 (three-year total $37,196)Per triennial cycle
Level 1 self-assessment$5,977Annual

The rule states there are "no nonrecurring or recurring engineering costs associated with Level 2 certification assessment since it is assumed the contractor or subcontractor has implemented the NIST SP 800-171 R2 security requirements."

Read that with a purchasing hat on. The published figure is the audit invoice for a company that is already compliant: assessor fees, staff time to gather evidence, documentation prep, the affirmation. Zero dollars for building the controls.

03

Why that assumption is defensible

It would be easy, and wrong, to call this a cover-up. The analysis is costing the new obligation this rule creates: the assessment and affirmation machinery. The obligation to implement NIST SP 800-171 came earlier, through DFARS 252.204-7012, and has applied to contractors handling controlled unclassified information for years. Counting it again here would double-count a burden that already exists on paper.

The modelling is sound. The problem is what happens when the number leaves the document. It gets pasted into a board slide or a vendor proposal and the qualifier stays behind. A company that has never touched 800-171 budgets $101,752, then discovers the figure buys the inspection, not the building.

If your last 800-171 self-assessment produced a low or negative SPRS score, the gap between the published estimate and your real cost is the remediation that score represents.

04

The live number today is not $101,752

CMMC Phase 2 was suspended on 13 July 2026 pending a 60-day program review, per the DoD CIO memorandum Implementing the Suspension of CMMC Phase II (13 July 2026). During the suspension, that memorandum directs that program managers "must only include the need for CMMC Level 1 (Self) or Level 2 (Self) assessments" and "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments."

So as of today, 26 August 2026, the third-party certification path is not being placed on new solicitations. For a small contractor handling CUI, the live DoD estimate is $34,277 for a Level 2 self-assessment, not $101,752 for a C3PAO certification. If you are arguing over a six-figure assessment line for the coming fiscal year, you are arguing about a path that cannot currently be assigned to you.

Treat that as timing, not a reprieve. The review window was announced as 60 days, so confirm current status before committing a number.

05

What did not get suspended

These all remain in effect:

  • NIST SP 800-171 Rev. 2 compliance
  • Level 1 and Level 2 self-assessments
  • SPRS score posting
  • Annual affirmations
  • DFARS 252.204-7012

The part that costs real money was never paused. Only the third-party audit layer was. Reading "CMMC suspended" as "stand down" accrues the same gap with less time left to close it.

06

110, 97, or 15: get the standard right before you price it

110 is the binding count. The contractual standard is NIST SP 800-171 Rev. 2, with 110 requirements across 14 families. DoD issued a class deviation to keep contractors on Rev. 2. The wrinkle that trips people up: NIST formally withdrew Rev. 2 on 14 May 2024, and it remains contractually binding anyway. A withdrawn publication is still your requirement set.

97 is Rev. 3, and it is not your target. Rev. 3 restructured the requirements down to 97. Building to it because it is the current NIST document means building to a standard your contract does not reference and your assessor will not score.

15 is Level 1. Level 1 is 15 requirements drawn from FAR 52.204-21, and it applies to federal contract information, not CUI. Quoting 110 requirements to a Level 1 company oversells the work by a factor of seven.

07

Scoping is the biggest lever, and it is usually pulled by accident

Here is the decision that moves your total more than any other, including which assessor you pick: do the 110 requirements apply to your entire company, or to a bounded enclave where CUI actually lives?

Whole-company scope pulls in every laptop, server, account and network segment. Enclave scope means a defined environment holds the CUI and the rest of the business stays outside the assessment boundary. The difference is not a percentage. It is a different project.

Most organizations never make this decision deliberately. CUI arrives by email, lands on a general file share, gets opened on a personal laptop, and the scope becomes everything by default. An enclave only works if the data genuinely stays inside it: controlling how CUI enters, where it is stored, who touches it, and what happens when someone drags a file out. That last part is a process problem, and it is where enclave plans usually fail.

Deciding scope on purpose, early, is the highest-return hour in a CMMC program. Our cybersecurity practice starts there for that reason.

08

The honest limitation

We cannot give you a number without looking at your environment. Neither can anyone else, and a firm quoting a flat CMMC price before seeing your systems is quoting a guess with a decimal point on it.

A mature Microsoft 365 tenant with conditional access enforced, managed and encrypted devices, MFA everywhere and central log collection may have a modest, documentation-heavy gap. Most technical controls already run. The work is evidence, policy, a system security plan and some configuration changes.

A flat network with shared administrator accounts, unmanaged endpoints and no central logging is not a compliance project. It is an infrastructure project with a compliance deliverable attached, and the honest sequence is rebuild first, assess second. Saying otherwise to win the engagement sets up a failed assessment eighteen months later.

One note on monitoring: automated log collection and alerting can run 24/7, and should. The people who triage those alerts work business hours with after-hours emergency response. Assuming constant human eyes on a console budgets for something most organizations this size do not buy.

09

What to put in the budget instead

Build the line item in four parts rather than one. A scoping decision, written down, with the CUI data flow mapped. A gap assessment against all 110 Rev. 2 requirements that produces a real SPRS score. Remediation, the part DoD's estimate excludes and the part that varies most. Then assessment and affirmation, which today means the $34,277 self-assessment path for most small CUI contractors.

For a starting read on where your environment sits before you spend on a formal gap assessment, our free IT assessment takes a few minutes, and there is more background in our resource guides.

10

Frequently Asked Questions

Does the DoD's $101,752 estimate include fixing the gaps an assessment finds?

No. The rule states there are no nonrecurring or recurring engineering costs in that figure because it assumes the contractor has already implemented the NIST SP 800-171 Rev. 2 requirements. It covers assessment and initial affirmation. Everything required to build the 110 controls sits outside it.

Is CMMC cancelled?

No. Phase 2 was suspended on 13 July 2026 pending a 60-day program review, per the DoD CIO memorandum Implementing the Suspension of CMMC Phase II, so program managers may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during the suspension. NIST SP 800-171 Rev. 2 compliance, Level 1 and Level 2 self-assessments, SPRS score posting, annual affirmations and DFARS 252.204-7012 all remain in effect. Verify current status before relying on this.

Should we implement NIST SP 800-171 Rev. 3 instead of Rev. 2?

Not for contract compliance. DoD issued a class deviation keeping contractors on Rev. 2 and its 110 requirements. Rev. 3 has 97 requirements and a different structure. NIST withdrew Rev. 2 on 14 May 2024, yet it remains the contractually binding standard. Build to what your contract references.

Does CMMC Level 1 require all 110 controls?

No. Level 1 is 15 requirements from FAR 52.204-21 and applies to federal contract information rather than CUI. If a proposal quotes 110 requirements for a Level 1 obligation, it is scoping work you do not owe.

Can a CUI enclave really reduce the cost that much?

It can, because scope determines how many systems the 110 requirements apply to. The limitation is that an enclave only holds if CUI actually stays inside it. Email attachments, personal devices and shared drives routinely pull data back out, and once that happens the boundary is fiction.

How much will CMMC cost our company specifically?

Nobody can answer that without examining your environment, and a fixed price quoted beforehand is a guess. The variables that matter most are scope, the maturity of your identity and device management, and whether you have central logging today. The range between a well-managed cloud tenant and a flat network is wide enough that any single figure would mislead one of them.

If you hold DoD contracts and want a straight read on where your environment stands against the 110 requirements, call the LayerLogix office in The Woodlands at 713-571-2390. Texas-based, 20+ years of experience, and we will say so if the honest answer is rebuild before you assess.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call