Schedule a call

Compliance

What CMMC Level 2 actually costs

Cloud Kings

It is the first question every defense contractor asks and the one the market answers worst. Search for it and you will find ranges spanning an order of magnitude, each presented with equal confidence, most of them generated by somebody who has never seen an environment resembling yours.

We are not going to add another number to that pile. What is genuinely useful is understanding what you are paying for, and which decisions move the total — because one of them moves it far more than the rest, and it is made before anybody quotes you.

The five things you are actually buying

Providers bundle these differently, which is the main reason quotes are hard to compare. Separating them is most of the work of reading a proposal.

1. Scoping and gap assessment. Establishing what is in the boundary, assessing against all 110 requirements, and producing a System Security Plan and a POA&M. Smallest line item, largest influence on every other one.

2. Remediation. Closing what the assessment found. For most businesses this is the biggest number, and it is the one nobody can estimate honestly in advance, because its size depends entirely on what the assessment turns up.

3. Tooling and licensing. Monitoring, logging, endpoint protection, and possibly a change of Microsoft environment. Recurring rather than one-off, which matters more than the initial figure.

4. The assessment itself. Paid to a C3PAO, not to your provider, where a third-party assessment applies. It is the only line that is genuinely comparable between providers, because it is not theirs.

5. Keeping it true. The affirmation is annual, the environment keeps changing, and staff join and leave. This is the line most consistently underestimated, and the one that decides whether year three is expensive.

Scope is the lever, and it is pulled first

If you take one thing from this: how much of your business sits inside the boundary determines nearly everything else.

The instinct is to treat the whole organization as in scope. It feels thorough and it is frequently unnecessary. If CUI touches four people in engineering, then an enclave containing those four people and the systems they use means fewer systems to control, fewer people to train, less evidence to produce, and less surface to keep true afterwards. Every one of the five items above shrinks with it.

The trade is that the boundary has to be real. A line that exists on an architecture diagram but not in the configuration is worse than no line at all, because it produces confident answers that turn out to be wrong at exactly the moment they are examined. An enclave that leaks — a shared file server, someone emailing a drawing to a colleague outside it, a laptop that roams between both sides — is not a smaller scope. It is the full scope with a diagram attached.

Which is why scoping is the highest-value hour in the engagement and why it happens before anyone quotes. A provider who gives you a price without having had that conversation has priced a business they imagined.

What makes it more expensive

None of these are unusual, and none are anyone’s fault. They are worth knowing in advance because they are the difference between two businesses of identical size paying very different amounts.

  • Legacy systems that cannot meet the requirements. Machinery controlled by an unsupported operating system is the classic. It is often the single largest driver, because the options are compensating controls, isolation, or replacement, and none is cheap.
  • CUI spread across the business rather than concentrated. This is really a scoping consequence, and it is the most common reason an enclave is not available.
  • On-premises infrastructure, which brings physical security and media protection requirements that a cloud-first business has largely delegated.
  • Nothing documented. Where the environment exists only in one person’s memory, part of what you are buying is writing it down for the first time.
  • Export-controlled data, which is what usually forces GCC High — a permanent per-seat premium rather than a one-off.
  • A contractual deadline. Compressing the work costs money in every industry, and assessor availability is not something your provider controls.

What makes it cheaper

  • Already being in Microsoft 365, configured properly. A well-run commercial tenant covers a meaningful share of the 110 before anyone starts.
  • A narrow, genuine enclave.
  • Capable internal IT who can take the remediation work with guidance rather than delivery.
  • Starting before the deadline. This is the largest discretionary saving available and it is entirely within your control.
  • Discovering you need Level 1 instead. A good number of businesses are quoted Level 2 work when their contracts only require basic safeguarding of Federal Contract Information. It is worth ten minutes of checking against a proposal you have already received.

Why we will not publish a number

Because the honest range is wide enough to be useless.

A ten-person firm already in Microsoft 365, with a clean enclave and four people touching CUI, and a manufacturer with legacy machinery, an on-premises domain and CUI in three departments, are both “CMMC Level 2”. They are not comparable engagements, and a single published figure would either be a low number that no real project matches or a high one that frightens off a business whose obligation is genuinely small.

We would rather scope it and tell you. If that turns out to be more than you expected, you will at least know what the money is for — and if it turns out you need less than you were quoted elsewhere, we will say that too.

More on how we handle this generally in what it costs.

Questions worth putting to any quote

These are useful whoever you are talking to, and the answers are usually more informative than the price:

  1. What scope did you assume? If two quotes are far apart, this almost always explains it.
  2. What is excluded? Hardware, licensing and the assessment fee are commonly outside the number. Ask, then stay quiet.
  3. What happens if the gap assessment finds more than expected? There is a right answer — a change process agreed in advance — and a wrong one, which is a shrug.
  4. Is the C3PAO fee in this? Frequently not, and it is not the provider’s money.
  5. What does year two cost? Compliance is continuous. A proposal that stops at certification has answered half the question.
  6. Which of the 110 remain ours? No provider can hold them all. Training, personnel screening, physical security and much of the policy work stay with you regardless of what a proposal implies — our shared responsibility matrix sets out where the lines usually fall.

And one red flag worth naming: a guaranteed certification outcome. Nobody can promise it. The assessment is not theirs to decide, and a provider offering that guarantee is telling you something about how they sell rather than about how they work.

Where to start

Settle whether you hold CUI or only FCI, because that decides which obligation applies and therefore most of this. Then find out where it lives, because that determines whether an enclave is available to you. Those two answers get you most of the way to a real number, and neither requires buying anything.

We offer a free CMMC gap assessment for qualifying contractors, which covers exactly that ground along with where you stand against all 110 requirements. Schedule a call — and if it turns out your contracts only require Level 1, we will tell you that rather than quote you for the larger piece of work.

Frequently asked

Why won't you publish a price for CMMC Level 2?
Because the honest range is so wide it would tell you nothing. The same certification costs a ten-person firm with one cloud tenant and four people touching CUI a fraction of what it costs a manufacturer with legacy machinery, an on-premises domain and CUI spread across three departments. A published number would either be a low figure that no real engagement matches, or a high one that scares off businesses whose obligation is genuinely small. Both are misleading, so we scope first and quote after.
What is the single biggest factor in the cost?
Scope, and it is not close. How much of your business sits inside the boundary determines how many systems need controlling, how many people need training, how much evidence needs maintaining, and how much of it stays true afterwards. An enclave containing the few people who actually touch CUI is a materially smaller undertaking than certifying an entire organization — and getting that decision right is the highest-value hour in the whole engagement.
Is the assessment fee the main expense?
Usually not. For most businesses the remediation — fixing what the gap assessment finds — is larger than the assessment itself, and the ongoing maintenance is larger than people plan for. Treating the assessor's invoice as the cost of CMMC is how budgets get set at a fraction of what the work requires.
Can we reduce the cost by doing some of it ourselves?
Yes, and some of it you have to. Personnel screening, physical security, training and much of the policy work sit with the business whatever your provider promises — no provider can hold all 110 requirements for you. Businesses with capable internal IT often take a substantial share. What rarely works is splitting the technical controls halfway, because the evidence then has two owners and neither has the full picture.
Do we have to pay for GCC High as well?
Only if your obligations require it, and not every contractor's do. What usually forces GCC High is export-controlled data or a contract naming it, rather than CUI in itself. It costs more per seat permanently and trails commercial Microsoft 365 on features, so buying it defensively is an expensive way to avoid making a decision. Establish the requirement before budgeting for it.
How do we compare two quotes that are far apart?
Ask both what scope they assumed, and you will usually find the gap explains itself. Then ask what is excluded, what happens when the gap assessment finds more than expected, whether the price includes the assessment fee, and what the ongoing annual cost looks like. A quote that cannot answer those was not produced by anyone who looked at your environment.

Continue reading

Keep in the loop