Aerospace Sourcing
Cybersecurity compliance

CMMC Certification Cost, Levels and Timeline for Small Shops

DoD estimates a small company spends about $5,977 a year on a CMMC Level 1 self-assessment and about $104,670 over three years for a Level 2 certification assessment by a third party. Those figures cover only the assessment, not the work to meet the 110 NIST SP 800-171 requirements, which is where most small shops spend the real money.

The short answer on CMMC cost

Which CMMC level you need depends on the data you touch, and the cost depends on how far your systems are from the requirements today. DoD's own numbers are a floor, not a budget.

In the regulatory analysis for the CMMC program rule (32 CFR part 170, published October 15, 2024), DoD estimated these costs for a small entity:

  • Level 1 self-assessment and affirmation: $5,977, repeated every year.
  • Level 2 self-assessment: $37,196 over three years, including two annual affirmations.
  • Level 2 certification assessment by a C3PAO: $104,670 over three years, including two annual affirmations.

DoD said plainly that it did not count implementation costs for Levels 1 and 2. It assumed contractors already meet the 15 basic safeguarding requirements in FAR 52.204-21 and, where they hold controlled unclassified information (CUI), the NIST SP 800-171 requirements that DFARS 252.204-7012 has required since the end of 2017. If your shop has not done that work, the gap is extra.

The three CMMC levels at a glance

LevelData it protectsRequirementsAssessmentHow often
Level 1Federal contract information (FCI)15 requirements from FAR 52.204-21Self-assessment, no open items allowedEvery year, with an affirmation
Level 2Controlled unclassified information (CUI)110 requirements of NIST SP 800-171 Rev 2Self-assessment or a certified third-party assessor (C3PAO), as the contract specifiesEvery three years, with annual affirmations
Level 3CUI on higher priority programsLevel 2 plus 24 selected requirements from NIST SP 800-172DCMA DIBCAC, after a Final Level 2 (C3PAO) statusEvery three years, with annual affirmations

Level 1 does not allow a plan of action and milestones (POA&M). Level 2 allows a limited one: you need a score of at least 80 percent of the requirements to get a conditional status, and open items must be closed out within 180 days or the status expires.

Which level applies to a small machine shop or process house

If the work involves CUI, plan on Level 2. If it only involves FCI, Level 1 is the requirement.

FCI is non-public information the government provides or generates under a contract, such as order details that are not marked for public release. CUI is narrower and marked: technical drawings, specifications and export-controlled technical data on DoD programs are common examples a job shop sees. A machine shop that receives a marked DoD drawing to make a part is handling CUI on whatever computer opens that file.

Subcontractors get their level from the prime. The DFARS clause 252.204-7021 requires contractors to flow the right CMMC level down to subcontractors that will process, store or transmit FCI or CUI. So the level you need is usually written into the purchase order or subcontract from the company above you. Ask for it before you quote.

DoD cost estimate breakdown for a Level 2 certification

DoD built its Level 2 certification estimate for a small entity from labor hours. The pieces show where assessment money goes:

PhaseDoD estimate (small entity)
Planning and preparing for the assessment$20,699
Conducting the assessment (your staff and outside help)$45,509
Reporting results$2,851
C3PAO engagement (3-person team, 120 hours)$31,234
Initial affirmation$1,459
Triennial assessment and affirmation$101,752
Two more annual affirmations$1,459 each
Three-year total$104,670

The hourly rates behind these numbers came from DoD's assumptions about directors, IT staff and outside service providers. Real C3PAO quotes are set by each assessment company and the size of your environment. The Cyber AB marketplace lists authorized C3PAOs you can request quotes from.

What the DoD numbers leave out

The assessment is the exam. Implementation is the coursework, and DoD did not price it for Levels 1 and 2. For a small shop the usual cost drivers are:

  • Where CUI lives. If drawings sit on the same network as CNC programs, email and the front office PC, every one of those systems is in scope.
  • Cloud and email. Storing CUI in the cloud means using services that meet the DFARS cloud requirements, which often means a different tenant or plan than standard office software.
  • Technical controls. Multifactor authentication, encryption, audit logging, account management and patching across every in-scope device.
  • Documentation. A system security plan, policies and evidence for each of the 110 requirements.
  • People time. Someone has to own it. In a 15 person shop that is often the owner or quality manager.

We are not publishing a remediation price range because we could not find one from a primary source, and vendor estimates vary too much to be useful. Get a gap assessment first, then price the fixes against your actual environment.

CMMC timeline: the phase-in dates

CMMC is already in contracts. The DFARS rule that puts it into solicitations took effect November 10, 2025, which started Phase 1. Each later phase begins one year after the one before it.

PhaseStart dateWhat DoD intends to require
Phase 1November 10, 2025Level 1 (Self) or Level 2 (Self) as a condition of award on applicable contracts
Phase 2Was November 10, 2026; suspended July 13, 2026Would add Level 2 (C3PAO) certification as a condition of award; on hold pending the CMMC Reform Task Force review
Phase 3November 10, 2027Level 2 (C3PAO) also for option periods; Level 3 (DIBCAC) where required
Phase 4November 10, 2028Full implementation in all applicable solicitations and contracts, including option periods

Contracts solely for commercially available off-the-shelf items are excluded. Your status is posted in the Supplier Performance Risk System (SPRS), and contracting officers check it before award, so a lapsed status can cost you a job even if the work itself is routine.

How long it takes you depends on your starting point. A shop with clean IT, an existing NIST SP 800-171 self-assessment in SPRS and a documented system security plan is in a very different place from one that has never scored itself.

Update: on July 13, 2026 the Department of War suspended the transition to Phase 2 and later phases and set up a CMMC Reform Task Force to review the program. As of this writing no outcome has been published, and DFARS 252.204-7012, NIST SP 800-171 and SPRS self-assessment scores still apply. Check the DoD CIO CMMC page for current status before planning around any date.

How to keep CMMC cost under control

  • Shrink the scope. Keep CUI on a small set of machines or a dedicated enclave instead of the whole shop network.
  • Do not collect CUI you do not need. If a job can be quoted from an unmarked sketch, quote it that way.
  • Score yourself honestly. An inflated self-assessment is a liability, not a shortcut. The annual affirmation is signed by your affirming official, a senior person in the company.
  • Use public help. Florida APEX Accelerator centers, a statewide network led by the University of West Florida, list cybersecurity training among their government contracting services.
  • Line it up with ITAR controls. If you hold export-controlled data, the access controls overlap. See our ITAR registration guide.

Get matched to work at the level you hold

When you sign up free as a Aerospace Sourcing supplier, tell us your current CMMC status, even if it is just a self-assessment in progress. The signup includes an option for help getting CMMC ready. We do not move CUI, ITAR or EAR data through the website. Controlled data moves by secure transfer to US persons only, and every supplier signs a flow-down NDA before seeing customer files.

We review every signup and reach out when a job fits your capability and compliance status. Related reading: the aerospace supplier guide, AS9100 certification cost, and small business subcontracting.

Questions

How much does CMMC Level 2 certification cost a small business?

DoD estimated $104,670 over three years for a small entity's Level 2 certification assessment by a C3PAO, including the triennial assessment, the initial affirmation and two annual affirmations. That covers assessment and affirmation only. DoD did not include the cost of implementing the 110 NIST SP 800-171 requirements, because it assumed contractors handling CUI were already meeting them under DFARS 252.204-7012.

What does CMMC Level 1 cost?

DoD estimated $5,977 per year for a small entity to complete a Level 1 self-assessment and affirmation. Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21 for federal contract information. The self-assessment is repeated every year, and no plan of action and milestones is allowed, so every requirement must be met at the time you affirm.

Do subcontractors need CMMC?

Yes, when they will process, store or transmit FCI or CUI in performing the subcontract. DFARS 252.204-7021 requires the prime to flow the appropriate CMMC level down to those subcontractors. A shop that only receives FCI needs Level 1. A shop that receives CUI, such as marked DoD technical drawings, generally needs Level 2, either self-assessed or certified by a C3PAO depending on the requirement.

When do I need a third-party CMMC assessment?

Phase 2 was scheduled to begin November 10, 2026, making Level 2 certification by a C3PAO a condition of award on applicable contracts. On July 13, 2026 DoD suspended Phase 2 and later phases pending a task force review, so check current status before planning around that date. During Phase 1, which began November 10, 2025, most contracts require a Level 1 or Level 2 self-assessment, though DoD may require C3PAO certification earlier on specific contracts.

Can I get a conditional CMMC status with open items?

At Level 2 and Level 3, yes, within limits. You need to meet at least 80 percent of the requirements, only certain requirements may be left on a plan of action and milestones, and every open item must be closed within 180 days or the conditional status expires. Level 1 does not allow any open items.

How do I find a C3PAO?

The Cyber AB, the accreditation body for the CMMC ecosystem, runs a marketplace that lists authorized C3PAOs. Request quotes from more than one, describe your environment accurately, and ask how they scope the assessment. A smaller, well-defined CUI environment usually means fewer assessment hours.

Related

Sources

Free to
join.

We contact you when work fits your shop.

Join the supplier network