In Part 1, we explored the background of CMMC, discussed the timeline of its implementation and laid the groundwork for why those in the homeland and national security contracting spaces should be paying attention to what’s happening over in the Department of Defense. Here, in Part 2, we will explore estimated costs and potential obstacles of obtaining CMMC, detail the parties a company will interact with during their CMMC journey, and provide some practical advice not just for those pursuing CMMC but for any government contractor.
It doesn’t matter if CMMC is implemented in DHS, or in other national security / federal civilian agencies. What the program aims to accomplish in terms of promoting better cyber hygiene, fostering cultures of security awareness, and moving from a model of general cybersecurity self-attestation to one of verification, validation and certification is vital. While obtaining certification under CMMC may not be a “need” for some companies, it is still worthwhile to understand the program, its purposes, and why that matters to us in govcon.
Obtaining CMMC Certification: What’s the expected typical cost breakdown?
The estimated cost for a company to obtain Cybersecurity Maturity Model Certification (CMMC) Level 2 certification can vary widely, but current industry and DOW estimates range between $100,000 and $200,000 for most small and midsized defense contractors that require a third-party assessment. A significant factor influencing cost is level of preparedness: how many control documents a company already has drafted versus how many will need to be created.
Typical cost breakdown may include (prepared by Paramify):
- Preparation & Documentation: $5,000–$70,000 (e.g., gap assessments, policies, implementation)
- Third-party Assessment: $76,000–$118,000 (includes triennial assessment and annual affirmations)
- Remediation/Implementation: $20,000–$150,000 (e.g., closing security gaps, enhancements to tools/processes)
- Annual maintenance/monitoring: $6,500–$25,000+ (ongoing compliance costs)
The total cost of achieving CMMC Level 2 certification may vary, depending on company size, current cybersecurity posture, and complexity of required remediation. Additionally, factor in the staff time that will be required to support the initiatives listed above.
Melvin Mooring II, the founder of Polished Technologies, is in the midst of pursuing CMMC compliance, and as a small business owner passes along advice to other enterprises for whom cost may be a significant factor; “We are in the process of getting our CMMC cert as we have some upcoming subcontracts that will require it now. I do worry that other small businesses may find it a pretty expensive endeavor.”
Polished Technologies, LLC is an Information Technology and Management Consulting firm providing hands-on and dedicated website and mobile application design and development to commercial and federal clients.
Self-assessment options for some Level 2 contracts may cost substantially less (e.g., $37,000–$49,000 annually), but most contractors will need a formal third-party audit, which comes with higher costs. This is where we meet the CMMC Third-Party Assessor Organization (C3PAO) and later the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Note: At time of publication, C3PAO assessments are currently starting at $35k, but average between $45-75k. Large and complex environments will drive the assessment costs even higher. Scoping will be a key activity a contracting organization can invest in to help control its assessment costs.
Obtaining Level 2: The C3PAO and External Assessment
A C3PAO, or CMMC Certified Third-Party Assessor Organization, is an independent entity authorized by the CMMC Accreditation Body (now known as The Cyber AB) to conduct official Cybersecurity Maturity Model Certification (CMMC) assessments for companies seeking certification. The primary role of a C3PAO is to evaluate whether a defense contractor or supplier meets the cybersecurity requirements set by the Department of War (DOW), particularly for CMMC Level 2 and above, which are required for handling Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
Brian Gadbois, President of Fidelis Consulting and a Lead CMMC Certified Assessor (LCCA, CCA, CCP) observes, “What makes CMMC fundamentally different from other government cybersecurity compliance frameworks is its zero-tolerance approach to non-compliance. Unlike FISMA, the Risk Management Framework, or even FedRAMP – where an authorizing official can accept residual risk and grant an Authority to Operate despite control deficiencies – CMMC offers no such flexibility. Every one of those 110 controls at Level 2 must be fully implemented and operational. This pass/fail structure means preparation isn’t optional—it’s critical for contractors’ ability to compete for DOD work. While limited POA&Ms are allowed, they have strict 180-day remediation requirements and cover only minor deficiencies. There’s no ‘accept the risk’ option here. Engaging certified CMMC consultants early can guide companies through requirements and identify gaps before a C3PAO assessment.”
Fidelis Consulting provides cybersecurity, compliance, and risk-management services to government contractors, with specialized expertise in CMMC implementation. They conduct assessment readiness reviews, implement compliant solutions, and perform comprehensive gap analyses to prepare companies for successful C3PAO assessments.
During the assessment process, a C3PAO reviews the organization’s policies, procedures, technical controls, and evidence to determine if they comply with the CMMC framework. The C3PAO then submits the assessment results to The Cyber AB, which makes the final decision on whether to grant certification. Only C3PAOs are authorized to perform these assessments for Level 2 and Level 3 certifications; Level 1 may be self-assessed by the contractor in some cases.
At time of publication, there are currently 83 authorized CMMC Third-Party Assessment Organizations (C3PAOs) listed on the official Cyber AB Marketplace. The full, up-to-date list is available at:
In summary, a C3PAO is a crucial part of the CMMC ecosystem, providing the independent validation required for DOW contractors to demonstrate their cybersecurity maturity and eligibility for defense contracts. Companies would be wise to consider that these requirements may soon carry over to non-Defense contracts as well.
Preparing for Level 2 Certification and a C3PAO visit
To maximize your likelihood of achieving CMMC Level 2 certification before engaging a C3PAO, your business should take several key steps to ensure readiness and minimize surprises during the formal assessment.
Narpender Bawa, Senior Director with REI Systems, states that “one of the most critical elements of preparing for a level 2 assessment is scoping. It establishes the boundaries of the assessment, what’s in-scope (systems handling CUI) and what’s out-of-scope (systems that do not). It defines what systems, assets, and environments are evaluated for compliance with the Cybersecurity Maturity Model Certification (CMMC) requirements. We found that by clearly defining the scope of assessment and isolating CUI systems from other corporate or IT systems through use of a secure enclave, we were able to reduce the time and effort to achieve compliance and also control our assessment costs. “
REI Systems, a 100% employee-owned technology solutions provider with over 35 years of experience – partnering with federal, state, local, and nonprofit organizations to solve complex challenges, enable data-driven decision-making, streamline operations, and enhance citizen services aligned with strategic goals.
First, thoroughly review and implement all 110 security controls outlined in NIST SP 800-171, as these form the backbone of CMMC Level 2. This includes controls across 14 domains and covers a myriad of factors such as access control, audit and accountability, awareness and training, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
According to Koren Wise, CEO and Lead Assessor at Wise Technical Innovations of Norfolk, VA (a certified C3PAO), “the most prolific issue assessors are seeing is that contractors have not been educated about the assessment process. Since contractors interacting with CUI will need to self-assess, they need to understand the fundamentals of a NIST SP 800-171 assessments. The single most important component, the 320 assessment objectives within NIST SP 800-171A. Each requirement is broken down into assessment objectives. All assessment objectives must be met in order for contractors to achieve a finding of “MET” for each of the 110 requirements. If one objective beneath a requirement is not met, the requirement itself is scored as “NOT MET”. Every control has a point value of 1, 3, or 5. If all objectives are not met for a given control, the corresponding point value must be deducted for that control. The perfect score of 110 must be achieved to receive a CMMC L2 Certification. The lowest score is -203. There are limited options for POA&Ms, which can remain outstanding for 180 days max. Furthermore, the POA&M options are quite limited. Contractors do not receive credit for any requirement that has an associated POA&M.”
Wise Technical Innovations is an Authorized Training Provider (ATP) and Certified Third-Party Assessment Organization (C3PAO) for the CMMC Program.
Koren Wise is the Vice Chair of the Cyber AB Accreditation Committee, as well as a member of the Cyber AB Scheme & Certification Exam Appeals Committee.
Next, conduct a comprehensive gap analysis to compare your current cybersecurity practices against the CMMC Level 2 requirements. Identify any deficiencies and develop a detailed remediation plan (often called a Plan of Action and Milestones, or POA&M) that outlines specific steps, responsible parties, and timelines for addressing each gap.
Develop and maintain a robust System Security Plan (SSP). This document should clearly describe how your organization meets each of the 110 controls, including system boundaries, hardware and software inventories, network architecture, and relevant policies and procedures. The SSP is one of the first documents a C3PAO will review, so it must be accurate and up to date. Note that these plans must be written at the objective level, and inclusive of all 110 controls and 320 assessment objectives.
Gather and organize evidence for each control. This includes policies, procedures, screenshots, logs, training records, and other documentation that demonstrates your compliance. Make sure this evidence is easily accessible and mapped to the relevant controls, as assessors will request to see proof for each requirement.
Perform an internal self-assessment using the CMMC Level 2 Assessment Guide, which details the assessment objectives and methods for each requirement. Document your findings and ensure that all controls are fully implemented and operating as intended.
Train your staff on cybersecurity best practices and their specific responsibilities under CMMC. Security awareness and role-based training are required controls, and assessors will look for evidence that your team understands and follows your security policies.
Koren offers deeper insight into what her organization is experiencing from their end of the CMMC certification and assessment process: “There are two types of companies we interface with: Those that prepared with at least one professional who received the official CMMC training authorized by the Cyber AB (RP, CCP, CCA) and those that did not.” As with all things, preparedness is key to success.
Finally, ensure you have a process for continuous monitoring, vulnerability scanning, patch and change management, incident response, and regular reviews of your security posture. This includes maintaining audit logs, reviewing events, and updating your SSP and POA&M as your environment changes. Do not let these plans and documents be static relics that sit on a shelf – incorporate them into the very fabric of your organization’s daily operations – foster a culture of cybersecurity awareness.
By completing these steps before engaging a C3PAO, you will be well-prepared for the formal assessment, reduce the risk of delays or failures, and demonstrate a mature, well-documented approach to cybersecurity compliance.
Koren warns, “CMMC C3PAO led assessments are unlike any other. There may be similarities and common controls (RMF, FedRamp), but the CMMC rule has a unique purpose and is somewhat rigid and unforgiving. As a C3PAO, we want companies to succeed. In order to succeed they must meet all of the prerequisites (ESP requirements, SSP, Asset Inventory, Network Diagram) and then be ready for an assessment that will delve into the 320 objectives in NIST SP 800-171A.” Rigor, thoroughness and adherence to standard seem to be the resounding theme of “what to expect” when undergoing third party assessment.
Do not delay in your preparation; current lead-times for C3PAO inspections are between 3-6 months, and could go longer as more companies join the effort to obtain Level 2 certification.
Is CMMC worth the investment?
In short, there is not much choice in the matter, not for those wishing to continue doing business with DOW. CMMC is here, and at least, for now, it is here to stay. It will be a requirement for industry in defense contracting, and will likely expand to those who support other national security programs in other agencies. Beyond “we have to,” what would compel a company to pursue CMMC certification?
- Eligibility for Contracts: Without CMMC, you cannot bid on or participate in most DOW contracts (remember, CMMC requirements flow down also to subcontractors), which can mean losing significant business opportunities.
- Competitive Advantage: Early certification can set you apart from competitors, both within and outside the defense sector, as more private clients value strong cybersecurity, and as cybersecurity readiness becomes a weighted evaluation factor for the consideration of proposals.
- Stronger Security: Implementing CMMC controls helps to increase resiliency to cyberattacks, data breaches, and costly downtime. Additionally, it can help foster a culture of security across your organization.
- Regulatory Alignment: CMMC helps you meet multiple federal cybersecurity requirements, streamlining compliance and reducing the risk of fines or contract loss.
- Long-Term Savings: While there is an upfront cost, CMMC can lead to operational efficiencies and cost savings by preventing incidents and reducing liability.
Aaron Pujanandez, the Founder of Delta Lima LLC, shared his perspective as his firm works toward CMMC certification: “We are fully committed to achieving CMMC compliance because cybersecurity is vital to protecting our nation’s supply chain. That said, the process has proven to be far more about crafting extensive documentation and formalized procedures than implementing practical security controls. For small businesses like ours, the challenge isn’t the technology; it’s navigating the layers of bureaucracy and paperwork that seem designed for much larger organizations. We’ve had to be creative in interpreting and fulfilling compliance roles that weren’t built with small teams in mind, and I worry that the sheer administrative burden is what will ultimately discourage many from pursuing compliance.”
Delta Lima provides data science strategy, visualization and engineering services to law enforcement, federal civilian and commercial clients. They focus on human-centered design principles to deliver scalable technical solutions and architectures.
Bottom line: If you want to do business with the DOW or as a sub to its major contractors, CMMC is not optional. Even for organizations outside the defense sector, the framework offers a clear, scalable path to stronger cybersecurity and market differentiation. Hence, substantiating a business argument that obtaining CMMC certification is a path even for those not currently pursuing defense contracts.
No-cost steps businesses can take internally to prepare for CMMC
Businesses can take several practical steps to prepare for CMMC compliance internally, without hiring an outside consultant or C3PAO. The process is especially manageable for CMMC Level 1, which is the minimum requirement for most DOW contracts and can be achieved through self-assessment.
Begin by determining which CMMC level your business needs to meet, based on the type of information you handle and the requirements in your DOW contracts. For most small businesses, Level 1 is sufficient and focuses on protecting Federal Contract Information (FCI).
Next, identify all systems, devices, and processes that store, process, or transmit FCI. This step is crucial because only these assets are in scope for your CMMC self-assessment. Document where FCI resides, how it moves through your organization, and who has access to it.
Review the 15 basic safeguarding requirements outlined in FAR 52.204-21, which form the foundation of CMMC Level 1. These include practices such as limiting information system access to authorized users, protecting against malicious code, and regularly updating software. The official CMMC Level 1 Self-Assessment Guide provides detailed explanations and examples for each requirement.
Conduct a self-assessment using the methods described in the guide: examine (review policies and configurations), interview (ask staff about their practices), and test (verify that controls are working as intended). Document your findings, noting any gaps or areas for improvement. For each requirement, keep evidence such as screenshots, policy documents, or training records to demonstrate compliance if asked.
Develop or update simple written policies and procedures that reflect your actual practices. Make sure all employees are trained on these policies, especially those who handle FCI. Actual training on and adherence to the policies a company outlines is a great step in the direction of good cyber hygiene. Regularly review and update your security practices, and perform periodic self-assessments to ensure ongoing compliance.
Finally, maintain a record of your self-assessment and be prepared to submit an annual affirmation of compliance, as required by the DOW. By following these steps, businesses can build a strong foundation for CMMC compliance without the need for external consultants, while also improving their overall cybersecurity posture.
Koren Wise of Wise Technical Innovations offers a free “SPRS Friday” the last Friday of each month for 1 hour to companies who want to learn how to properly self-assess (www.wti.us to register).
She continues in her advice to the Homeland and National Security Enterprise, “In reality, a much higher level of training is needed. The Certified CMMC Professional course is highly recommended for any company attempting CMMC L2 Certification. This official course with curriculum approved by the CyberAB and DoW. It is intended to be the first class for CMMC assessors but has become wildly popular with the DIB. It is the primary way to understand the CMMC Program, Scoping, the CMMC Assessment Process, and the 110 requirements/320 objectives in the CMMC L2 Assessment Guide.” Registration for the CMMC Professional course is not limited to only those pursuing professional certification. Contracting organizations who think CMMC may be an issue in their future would do well to ascertain if sending internal staff members through the training would be a worthwhile investment of time and money.
External help to prepare for CMMC
While an internal champion and responsible party is absolutely vital for true CMMC compliance, there are several third-party and external resources that a company can engage to help in their CMMC journey. These come with an added cost, but are an option to bring in outside expertise to augment internal capability.
Unlike larger organizations with dedicated IT, compliance, and risk management departments, small companies often rely on just one or a few individuals with broad responsibilities. For these organizations, third-party consulting firms can offer crucial support by guiding them through the complex CMMC requirements and helping develop the necessary documentation and cybersecurity policies. Preparation typically involves conducting an initial gap assessment to identify deficiencies, building policies and procedures, implementing required controls, and providing training to staff. Consultants may also prepare companies for the official C3PAO inspection by conducting mock audits, managing remediation efforts, and creating evidence packages tailored to the CMMC framework.
The cost of engaging these third-party firms varies depending on the complexity of the organization, the level of CMMC sought, and the firm’s service scope. For CMMC Level 2, estimates for preparation support typically range from $12,000 to $70,000 for small businesses, with additional remediation and implementation costs of $20,000 to $150,000 depending on existing security gaps. Some providers offer bundled or subscription services – including ongoing guidance, documentation updates, and virtual support – to help organizations maintain compliance and pass annual affirmations. Ultimately, these outside partners can save small businesses substantial internal effort and reduce the risk of failing a C3PAO inspection, which could result in lost opportunities or the need for costly re-assessment.
Nicolas Chaillan, CEO and Founder of Ask Sage and former Chief Software Officer of the U.S. Air Force and Space Force, has seen firsthand and acted on the rollout of new requirements across the public and private sectors.
“Let’s be clear: CMMC compliance isn’t optional if you want to do business in the federal space—it’s the bare minimum for protecting our nation’s sensitive data. Yet, too many small and mid-sized businesses are overwhelmed by the complexity and cost of these requirements, leaving them vulnerable and risking their place in the supply chain. The truth is, compliance doesn’t have to be this hard, especially with Generative AI as an option. By automating the heavy lifting of compliance documentation with Ask Sage’s ‘In-A-Box’ platform, we’re empowering organizations to cut through the noise and focus on building a foundation of security and trust that ensures long-term success in high-stakes environments. We’re able to turn months of work into just hours, especially critical when resources are limited. It’s time to stop making excuses and start taking action.”
Ask Sage is a secure, extensible, and multi-modal Generative AI platform designed to empower government teams and regulated industries with cutting-edge generative AI capabilities. Ask Sage’s “In-A-Box” suite is a generative AI application built to streamline document creation, including those required for cybersecurity compliance frameworks like FedRAMP®, ATO, and CMMC, as well as business-related documents such as proposals, marketing materials, legal contracts, and HR policies.
“Services like Ask Sage and CMMC in-a-box specifically target small and mid-sized businesses looking for an affordable, streamlined solution to CMMC compliance. Engaging an outside vendor can help simplify the path to readiness and reduce the burden on small teams or individuals most commonly responsible for CMMC compliance in small businesses. For a full list of authorized and registered practitioners, assessors, consultants and more – visit the CMMC Cyber Accreditation Body and check out the “CMMC Marketplace.” www.cyberab.org.”
Secure your company’s future with CMMC
The implementation of CMMC represents a sweeping transformation in how national security contractors approach cybersecurity in the federal space. With the phased rollout beginning November 10, 2025, certification is no longer a mere procedural detail; it is a ticket to entry for all new DOW contracts and is already shifting expectations across the broader federal marketplace. The progression from self-attestation to independent verification through third-party assessors marks a substantial elevation in compliance rigor, designed to close persistent gaps in supply chain security and reinforce national resilience against sophisticated cyber threats.
Beyond the immediate impact on defense contracting, the trajectory for CMMC clearly signals expansion. Agencies like the Department of Homeland Security and the Department of Justice, and the Intelligence Community are poised to adopt similar requirements, especially for contracts involving Controlled Unclassified Information (CUI). This impending government-wide adoption means that the need for preparation and action reaches far beyond traditional defense contractors. Every business in the national security ecosystem – including prime vendors and subcontractors – must now actively review their cybersecurity practices, assess readiness, and invest in meeting CMMC’s evolving standards.
Although the path to certification can be daunting with its significant financial and resource commitments, the payoff is clear: eligibility for lucrative contracts, stronger security postures, and competitive differentiation in a crowded marketplace. Early engagement with third-party assessors, thoughtful investment in documentation and self-assessment, and robust internal training are not just compliance steps—they are strategic actions that protect both your business and national interests.
For all national security-focused contracting companies, ignoring the CMMC mandate is no longer feasible. The risks – lost market access, costly remediation, and reputational damage – far outweigh the investment. Now is the moment to rigorously evaluate your CMMC posture, engage with assessors and partners, and future-proof your organization against an inevitable government-wide shift toward robust cyber compliance. Proactive adaptation will not only ensure regulatory eligibility; it will also fortify your place at the forefront of secure government contracting in the years ahead.
Editorial credit goes to Megan Norris for assistance in getting this two-part series ready.
Important References
Department of War CMMC Resources & Documentation available at: https://dodcio.defense.gov/cmmc/Resources-Documentation/
Department of War CMMC Accreditation Guide available at: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL2v2.pdf
The CMMC Accreditation Body (Cyber AB) website: https://cyberab.org/
National Institute of Standards and Technology (NIST) Resources:
NIST SP 800-171 Rev. 2: Protecting CUI in Nonfederal System
NIST SP 800-171A: Assessing Security Requirements for Controlled Unclassified Information
NIST SP 800-172: Enhanced Security Requirements for Protecting Controlled Unclassified Information
NIST SP 800-172A: Assessing Enhanced Security Requirements for Controlled Unclassified Information
NARA CUI Registry: https://www.archives.gov/cui
DoD CUI Registry: https://www.dodcui.mil/


