What does CMMC readiness actually cost a small machine shop?
Corey Payne · August 14, 2026
Start with DoD's own numbers, not a vendor's. The CMMC final rule estimates a Level 1 self-assessment at $5,977 a year for a small entity, a Level 2 self-assessment at $37,196 per three-year cycle, and a Level 2 certification assessment at $104,670 per cycle. Those are assessment costs only — implementing the 110 required controls is separate, and scoping drives it.
The numbers DoD itself published
When DoD finalized the CMMC program rule (32 CFR Part 170, published October 15, 2024 — 89 FR 83092), it included its own cost analysis. For a small entity: a Level 1 self-assessment and affirmation runs $5,977 a year. A Level 2 self-assessment runs $34,277 for the assessment event — $37,196 over the three-year cycle once the two annual affirmations are added. A Level 2 certification assessment, the kind a C3PAO conducts, runs $101,752 for the assessment event and $104,670 over the three-year cycle. Inside that figure DoD models the C3PAO engagement itself at $31,234 — a three-person team for 120 hours.
Two honesty notes, both from the rule itself. First, DoD says plainly that its estimates are “not actual prices of C3PAO services available in the marketplace” — “market forces of supply and demand will determine C3PAO pricing.” Second, the estimates assume the work is already done: the rule states there are no engineering costs in its model “since it is assumed the contractor or subcontractor has implemented the NIST SP 800-171 R2 security requirements.” In other words: this is the cost of taking the test, not of studying for it.
The part nobody can quote you sight-unseen
Implementation — actually meeting the 110 security requirements of NIST SP 800-171 that Level 2 demands — is where the real money goes, and it depends on facts about your shop that no article can know: how many machines and users touch controlled information, what your current environment looks like, and what you can honestly answer today. The CyberSheath/Merrill Research 2025 survey found the median defense contractor’s SPRS score is 60 against the required 110, and a Kiteworks–Coalfire study found 57% of surveyed defense-industrial-base leaders hadn’t completed a NIST SP 800-171 gap analysis at all — so most shops genuinely don’t know their own starting point yet.
Scoping is the lever you control
This part is our analysis, not DoD’s: the single biggest implementation-cost decision a small shop makes is scope — whether controlled unclassified information touches your whole environment or a deliberately small, separated part of it. The rule itself notes that “the size and complexity of the network within the scope of the assessment impacts the costs.” Ten machines in scope cost less to secure, document, and assess than fifty. Scoping before spending is the order of operations that keeps small shops solvent.
The clock
CMMC became contractual on November 10, 2025, when the DFARS acquisition rule took effect. The schedule beyond that changed after this article first ran: on July 13, 2026, DoD announced the immediate suspension of Phase 2 — which would have expanded C3PAO certification requirements starting November 10, 2026 — pending a comprehensive review of the program, while stating that all Phase 1 self-assessment requirements “remain firmly in place.” A suspension is not a repeal: the acquisition rule stays on the books, and the 110 requirements a gap assessment measures against haven’t changed. Only 1% of defense contractors surveyed by CyberSheath/Merrill Research call themselves fully prepared. The math above is why waiting is still expensive: the gap assessment that tells you your real number costs a fraction of guessing wrong.
Sources
- CMMC Program final rule, 32 CFR Part 170 — Federal Register, 89 FR 83092 (October 15, 2024) — every assessment-cost figure above, and both C3PAO pricing caveats, quoted from the rule's small-entity cost analysis
- DFARS final rule: Assessing Contractor Implementation of Cybersecurity Requirements — Federal Register, 90 FR 43560 (September 10, 2025) — effective November 10, 2025 — the date CMMC became contractual
- DoD CIO: Cybersecurity Maturity Model Certification program page — Phase 2 suspension announced July 13, 2026; Phase 1 self-assessment requirements remain in place
- NIST SP 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations — the 110 requirements the CMMC rule assesses Level 2 against (Rev. 2, per the rule — NIST has since published Rev. 3)
- CyberSheath / Merrill Research: 2025 State of the DIB report announcement — median SPRS score of 60; 1% of contractors fully prepared
- Kiteworks–Coalfire: State of CMMC 2.0 Preparedness in the DIB (March 26, 2025) — 57% of 209 surveyed DIB leaders had not completed a NIST SP 800-171 gap analysis
Frequently asked questions
Can we self-assess instead of hiring a C3PAO?
That depends on your contracts, not your preference. Level 1 and some Level 2 work allows self-assessment; other Level 2 work requires C3PAO certification — the contract clause governs. What you can always do first is a gap assessment against the same 110 requirements, which tells you your honest starting score before any assessor arrives.
Are DoD's figures what we'd actually pay a C3PAO?
No — and DoD says so itself: its figures model the effort, and "market forces of supply and demand will determine C3PAO pricing." Treat $104,670 per cycle as the government's own planning baseline, not a quote.
What does OneBody charge for CMMC work?
Quoted after scoping, never sight-unseen — a real number requires knowing your environment and your gap. The path and what it covers are on the Cybersecurity & CMMC page. You attest; no consultant can certify you.
Find your real starting point while the clock is paused
CUI scoping and a NIST SP 800-171 gap assessment — quoted after scoping, never sight-unseen.