← Custodia

What CMMC Actually Costs in 2026

Real numbers, by level and by path. Most of the industry keeps these vague because vague is profitable. Here is the breakdown we give our own customers.

Level 1 filing: $0Guided platform: $249/monthConsultant: $10k to $20k

The answer in 50 words

CMMC Level 1 costs nothing to file: it is a free self-assessment affirmed in SPRS. Your real cost is implementation, from $0 DIY to a $249/month guided platform to a $10,000 to $20,000 consultant. Level 2 certification adds a C3PAO assessment, commonly $20,000 to $60,000+.

CMMC Level 1 cost, by path

Every path below ends at the same place: a completed self-assessment of the 15 FAR 52.204-21 safeguarding requirements, a System Security Plan, and a senior-official affirmation posted to SPRS. The difference is time, risk, and price.

PathCash costYour timeTypical duration
DIY with official guides$020 to 40 hours1 to 3 months
Custodia Self Service$249/month8 to 15 hoursAbout 30 days
Custodia + compliance officer$397/month5 to 10 hoursAbout 30 days
Consultant engagement$10,000 to $20,00010 to 20 hours4 to 8 weeks
CMMC MSP retainer$1,000 to $5,000/monthLowOngoing

SPRS and PIEE cost nothing to use. There is no filing fee, no application fee, and no assessor at Level 1.

Why Level 2 quotes are 10x higher, and why that may not be your problem

When contracts involve Controlled Unclassified Information, CMMC requires certification against 110 NIST SP 800-171 requirements, assessed by an authorized C3PAO. The assessment alone commonly quotes at $20,000 to $60,000 for a small scope, and remediation, enclaves, and GCC High licensing multiply from there. Much of the sticker shock in CMMC pricing articles is Level 2 pricing quoted to companies that never see CUI.

The two-minute question worth thousands of dollars: does your work involve CUI, or only Federal Contract Information? If it is FCI only, you are a Level 1 company, and every number in the table above applies instead. The free check sorts this out from your actual contracts.

What moves your number up or down

What information you handle

FCI only means CMMC Level 1 and a self-assessment. CUI in scope means a higher level with third-party assessment and much higher cost. Confirming you are FCI-only is the single biggest cost saver available, most small subcontractors are.

Your current stack

A company already on Microsoft 365 Business Premium or Google Workspace has most Level 1 controls one setting away. A company on personal Gmail and shared logins pays in remediation time before anything else.

How the work gets done

The same 15 requirements cost $0 in software if you DIY with the official guides, $249/month on a guided platform, or $10,000 to $20,000 through a consultant. The deliverable, a defensible SSP and affirmation, is the same.

Evidence habits

Contractors who keep screenshots and exports as they configure spend hours on their assessment. Contractors reconstructing evidence months later spend days. The habit is free; the reconstruction is not.

CMMC cost: FAQ

How much does CMMC certification cost?

It depends on the level. CMMC Level 1 has no certification fee at all: it is a self-assessment you affirm in SPRS for free, so your only cost is implementation, anywhere from $0 DIY to $249/month on a guided platform to $10,000 to $20,000 with a consultant. CMMC Level 2 certification requires a paid C3PAO assessment, commonly $20,000 to $60,000 for a small scope before remediation costs.

How much does CMMC Level 1 cost?

Filing costs nothing: the self-assessment and the SPRS affirmation are free. The real cost is doing the work on the 15 FAR 52.204-21 requirements. DIY with the official guides costs only your time, typically 20 to 40 hours. Custodia guides the whole cycle for $249/month, or $397/month with a credentialed compliance officer, and most companies finish inside a month.

How much does a CMMC Level 2 assessment cost?

Published C3PAO assessment quotes for small scopes commonly run $20,000 to $60,000, and complex or larger scopes can go well past $100,000. Remediation, enclave tooling, and consultant preparation are extra. This is why it pays to confirm whether you actually handle CUI before assuming you need Level 2: many small subcontractors only handle FCI and belong at Level 1.

Is CMMC certification free?

At Level 1, effectively yes: there is no assessor, no application fee, and SPRS submission is free. You pay only for whatever help you choose. At higher levels, no: third-party assessment is a paid engagement with an authorized C3PAO.

How much do CMMC consultants charge?

For Level 1, consultant-led engagements commonly quote $10,000 to $20,000 and take four to eight weeks. Hourly advisory rates in the niche often run $250 to $400. Competitors pay $15 to $67 per click to advertise on these terms, which tells you the margins involved. For a 15-requirement self-assessment, most small contractors can get to the same defensible outcome with guided software.

Will the government reimburse my CMMC costs?

There is no general DoD reimbursement program for CMMC compliance costs. Costs are typically treated as ordinary business expenses, and for many contractors they are allowable as indirect costs in rates. Some primes assist key suppliers, but do not plan on outside money: plan on the cheapest legitimate path for your actual level.

Get the Level 1 outcome without the Level 1 markup

Guided self-assessment, evidence review, auto-generated SSP and affirmation, SPRS walkthrough. $249/month, cancel anytime, 7-day free trial with no credit card.

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements, no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual, two months free)