What does CMMC readiness actually cost a small machine shop?
Corey Payne · August 11, 2026
Start with DoD's own numbers, not a vendor's. The CMMC final rule estimates a Level 1 self-assessment at $5,977 a year for a small entity, a Level 2 self-assessment at $37,196 per three-year cycle, and a Level 2 certification assessment at $104,670 per cycle. Those are assessment costs only — implementing the 110 required controls is separate, and scoping drives it.
The numbers DoD itself published
When DoD finalized the CMMC program rule (32 CFR Part 170, published October 15, 2024 — 89 FR 83092), it included its own cost analysis. For a small entity: a Level 1 self-assessment and affirmation runs $5,977 a year. A Level 2 self-assessment runs $34,277 for the assessment event — $37,196 over the three-year cycle once the two annual affirmations are added. A Level 2 certification assessment, the kind a C3PAO conducts, runs $101,752 for the assessment event and $104,670 over the three-year cycle. Inside that figure DoD models the C3PAO engagement itself at $31,234 — a three-person team for 120 hours.
Two honesty notes, both from the rule itself. First, DoD says plainly that its estimates are “not actual prices of C3PAO services available in the marketplace” — “market forces of supply and demand will determine C3PAO pricing.” Second, the estimates assume the work is already done: the rule states there are no engineering costs in its model “since it is assumed the contractor or subcontractor has implemented the NIST SP 800-171 R2 security requirements.” In other words: this is the cost of taking the test, not of studying for it.
The part nobody can quote you sight-unseen
Implementation — actually meeting the 110 security requirements of NIST SP 800-171 that Level 2 demands — is where the real money goes, and it depends on facts about your shop that no article can know: how many machines and users touch controlled information, what your current environment looks like, and what you can honestly answer today. The CyberSheath/Merrill Research 2025 survey found the median defense contractor’s SPRS score is 60 against the required 110, and a Kiteworks–Coalfire study found 57% of surveyed defense-industrial-base leaders hadn’t completed a NIST SP 800-171 gap analysis at all — so most shops genuinely don’t know their own starting point yet.
Scoping is the lever you control
This part is our analysis, not DoD’s: the single biggest implementation-cost decision a small shop makes is scope — whether controlled unclassified information touches your whole environment or a deliberately small, separated part of it. The rule itself notes that “the size and complexity of the network within the scope of the assessment impacts the costs.” Ten machines in scope cost less to secure, document, and assess than fifty. Scoping before spending is the order of operations that keeps small shops solvent.
The clock
CMMC became contractual on November 10, 2025. Phase 2 — which expands C3PAO Level 2 certification requirements — begins November 10, 2026, with full enforcement phasing in by November 2028 (Federal Register, CMMC program rule; DoD CIO). Only 1% of defense contractors surveyed by CyberSheath/Merrill Research call themselves fully prepared. The math above is why waiting is expensive: the gap assessment that tells you your real number costs a fraction of guessing wrong.
Frequently asked questions
Can we self-assess instead of hiring a C3PAO?
That depends on your contracts, not your preference. Level 1 and some Level 2 work allows self-assessment; other Level 2 work requires C3PAO certification — the contract clause governs. What you can always do first is a gap assessment against the same 110 requirements, which tells you your honest starting score before any assessor arrives.
Are DoD's figures what we'd actually pay a C3PAO?
No — and DoD says so itself: its figures model the effort, and "market forces of supply and demand will determine C3PAO pricing." Treat $104,670 per cycle as the government's own planning baseline, not a quote.
What does OneBody charge for CMMC work?
Quoted after scoping, never sight-unseen — a real number requires knowing your environment and your gap. The path and what it covers are on the Cybersecurity & CMMC page. You attest; no consultant can certify you.
Find your real starting point before the November clock does
CUI scoping and a NIST SP 800-171 gap assessment — quoted after scoping, never sight-unseen.