Schedule a call

Compliance

Your contract decides the assessment. Scope decides the effort.

Two numbers get quoted for CMMC Level 2, and they are far apart.

On the SBA’s figures, certification runs roughly $593,800 for a small firm needing a third-party assessment, and about $388,600 where a self-assessment is permitted.

Which one applies to you is decided by the requirement, not by your architecture. The program office or requiring activity determines the CMMC level and assessment type; the contracting officer puts that determination into the solicitation, and it flows into the contract. You cannot configure your way from one column to the other.

One thing to hold alongside that, because it changes what you can be asked for today: Phase II is suspended, and while it is, requiring activities are not designating new Level 2 (C3PAO) assessments. The two numbers above still describe what the assessment types cost. They do not describe a choice available in a new solicitation right now.

What scope does decide is how much work each costs.

Where Controlled Unclassified Information lives determines your assessment boundary: which systems, users and processes fall inside it. Most firms find that boundary is wider than it needs to be. CUI sits on a general file share because that is where it landed. A workstation touches it because someone opened an attachment once.

Enclaving the data first shrinks the boundary, and a smaller boundary means fewer systems to bring up to 110 requirements, fewer to evidence across 320 objectives, and less to assess. That is real money either way — it is just not the difference between those two headline numbers.

So the useful question before a quote is not “can we avoid a C3PAO”. It is “what does our contract actually require, and how much of our environment are we dragging into it”.

More updates