Compliance
Your contract decides the assessment. Scope decides the effort.
Two numbers get quoted for CMMC Level 2, and they are far apart.
On the SBA’s figures, certification runs roughly $593,800 for a small firm needing a third-party assessment, and about $388,600 where a self-assessment is permitted.
Which one applies to you is decided by the requirement, not by your architecture. The program office or requiring activity determines the CMMC level and assessment type; the contracting officer puts that determination into the solicitation, and it flows into the contract. You cannot configure your way from one column to the other.
One thing to hold alongside that, because it changes what you can be asked for today: Phase II is suspended, and while it is, requiring activities are not designating new Level 2 (C3PAO) assessments. The two numbers above still describe what the assessment types cost. They do not describe a choice available in a new solicitation right now.
What scope does decide is how much work each costs.
Where Controlled Unclassified Information lives determines your assessment boundary: which systems, users and processes fall inside it. Most firms find that boundary is wider than it needs to be. CUI sits on a general file share because that is where it landed. A workstation touches it because someone opened an attachment once.
Enclaving the data first shrinks the boundary, and a smaller boundary means fewer systems to bring up to 110 requirements, fewer to evidence across 320 objectives, and less to assess. That is real money either way — it is just not the difference between those two headline numbers.
So the useful question before a quote is not “can we avoid a C3PAO”. It is “what does our contract actually require, and how much of our environment are we dragging into it”.
More updates
-
Why Phase II paused, according to the announcement
The Department of War cited compliance costs and burden on small business, not assessor capacity. The obligations did not pause with the assessments.
-
Backups rarely fail in a ransomware event. Recovery does.
The backup job is green. The restore is what breaks — usually on recovery order, an encrypted backup server, or a restore time nobody measured.
-
MFA is not the finish line it used to be
Modern attacks do not defeat multi-factor authentication. They wait for it — through prompt fatigue and stolen session tokens.