That CMMC line in the RFP is not boilerplate. Primes now have to flow the requirement down to subcontractors, so your next award can hinge on proof that your shop meets it. This guide explains what CMMC compliance requires at each of the three levels, what a fair quote looks like, and how to get there without burning a year.
The Short Answer
CMMC compliance requires proving at one of three levels that your company protects government information, with Level 2 being the most common for small businesses handling Controlled Unclassified Information (CUI), requiring a third-party assessment every three years. The process typically takes 12 to 18 months from a typical small-business IT setup and involves mapping CUI environments, gap assessments against NIST SP 800-171, closing gaps with controls like MFA and encryption, and collecting evidence for assessors. Microsoft’s research shows MFA blocks about 99% of automated account compromises, making it a critical first step.
What CMMC Compliance Means for Defense Contractors
CMMC compliance means proving, at one of three defined levels, that your company protects the government information flowing through its contracts. If you sell to the Department of Defense, or to a prime that does, the requirement now appears in contract language, and you cannot win or keep that work without meeting it.
The current version is CMMC 2.0, and it has three levels, not the five the original model used. Which level applies depends on the kind of information you handle, not on headcount or revenue. A five-person machine shop can sit at Level 2 while a 200-person staffing firm never leaves Level 1.
The rollout runs in phases. DoD began writing CMMC requirements into new contracts in 2025, and coverage expands over the next few years, so a contract that says nothing today can demand certification at renewal. Waiting for the clause to show up is the most expensive way to discover you have a year of work ahead of you.
The Three Levels of CMMC 2.0
Each level maps to the sensitivity of the information on your contracts. Here is the short version.
| Level | Who it covers | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Contractors handling Federal Contract Information (FCI) only | 15 basic safeguarding practices | Annual self-assessment with an executive affirmation |
| Level 2 | Contractors handling Controlled Unclassified Information (CUI) | 110 controls from NIST SP 800-171 | C3PAO third-party assessment every 3 years for most contracts; a small subset self-assess |
| Level 3 | Contractors on the most sensitive programs | Level 2 plus requirements from NIST SP 800-172 | Government-led assessment by DIBCAC |
Level 1 covers Federal Contract Information, the routine non-public data almost any contract generates. Its 15 practices are things a well-run IT shop already does: passwords, patched systems, limited access, basic boundary protection. Most companies can handle it internally, and our CMMC Level 1 checklist walks through every practice in plain language.
Level 2 is where the real work lives. It aligns with the 110 controls in NIST SP 800-171, and most Level 2 contracts require a third-party assessment by a C3PAO every three years. A smaller group of Level 2 contracts allows self-assessment, but you will not know which type applies until the solicitation says so.
Level 3 sits on top of Level 2 for the most sensitive programs. It adds requirements from NIST SP 800-172 and a government-led assessment by DIBCAC. Few small contractors will ever see it, so the rest of this guide focuses on Levels 1 and 2.
Which Level Applies to You
The deciding question is whether you touch Controlled Unclassified Information. FCI is any non-public information tied to performing a contract, and nearly every defense contractor has some. CUI is the narrower category: technical drawings, specifications, export-controlled data, and other material the government marks for safeguarding.
Check your contracts before you guess. DFARS clause 252.204-7012 in an existing contract signals that CUI obligations already apply to you, and clause 252.204-7021 is the one that carries the CMMC requirement itself. Your prime’s flow-down letters matter just as much, because primes push the requirement to every subcontractor who touches the data.
When in doubt, ask your contracting officer or your prime, in writing, which data on your contract counts as CUI. Guessing high wastes money, and guessing low can cost you the contract.
The Path to Level 2, Step by Step
Plan on 12 to 18 months if you are starting from a typical small-business IT setup. Here is the sequence that works.
- Scope your CUI environment. Map where CUI enters, where it lives, and who touches it. Shrinking that footprint, often into a separate enclave, cuts every cost that follows.
- Run a gap assessment against NIST SP 800-171. Score yourself against all 110 controls and post the result to SPRS, the government’s supplier database. Contracts carrying clause 7012 already expect a score there.
- Close the gaps. That usually means MFA everywhere, encryption, logging, access reviews, an incident response plan, and the written policies that prove it all. Microsoft’s 2023 peer-reviewed research shows MFA blocks roughly 99% of automated account compromise, so start there if you start anywhere.
- Collect your evidence. Assessors want artifacts, not assurances: screenshots, configurations, tickets, training records.
- Book the C3PAO early. Assessor capacity is tight, and the certificate is what lets you sign the next contract.
Be honest at every step. Contractors have faced False Claims Act cases for overstating their security posture, and that exposure dwarfs any compliance budget. Our guide to what NIST non-compliance costs breaks down the downside in detail.
What a Fair CMMC Quote Looks Like
No single number covers CMMC, because the spend splits across tools, services, and the assessment itself. You can still sanity-check every line item against the market.
| Line item | Fair market band |
|---|---|
| Endpoint detection and response (EDR) | $8 to $15 per device per month |
| Managed detection and response (MDR) | $15 to $25 per device per month |
| Zero trust identity and access stack | $5 to $15 per user per month |
| Penetration test | $5,000 to $20,000 per project |
| C3PAO assessment | Varies by scope; get three quotes against one written scope |
On the tooling side, endpoint detection and response runs $8 to $15 per device per month, and managed detection and response runs $15 to $25. A zero trust stack for identity and access lands between $5 and $15 per user per month. Those subscriptions, configured properly, satisfy a surprising share of the 110 controls.
On the services side, a penetration test runs $5,000 to $20,000 per project depending on scope. Gap assessments and remediation consulting vary too widely for one honest number, so judge those quotes by day rate and day count rather than the bottom line, and ask every consultant to show both.
Assessment pricing from C3PAOs moves with the size of your environment, which is one more reason to shrink your CUI scope before you request quotes. Get at least three bids, and make every bidder price the same written scope so the numbers actually compare.
How to Choose a CMMC Compliance Provider
The market is full of firms that added CMMC to their menu last year. Sorting them takes about five questions.
Start with track record: how many 800-171 or CMMC engagements they have finished, and whether they can point to a client your size. Then ask who does the work day to day, because some firms sell senior names and staff the project with juniors. Probe their view on enclaves, since a good advisor tries to shrink your scope before selling you anything. Finally, confirm they are not also your assessor, because a C3PAO cannot assess an environment it helped build.
Watch for two traps. The first is the compliance-in-a-box pitch, a tool subscription sold as if software alone could get you certified; the tooling helps, but assessors grade evidence and process, not licenses. Trap two is the endless retainer, a roadmap that somehow never ends. A fair provider hands you a fixed-scope plan with a finish line.
The cheap option is fine at Level 1, where a checklist, a competent IT person, and a few weekends usually get you there. At Level 2, with a contract on the line, experience is what you are paying for.
This is where being a broker helps. We work like a mortgage broker, but for business security: as of this writing, 54 providers in our network run security risk assessments, 52 do penetration testing, and 40 offer virtual CISO services. Tell us your contract situation and we will hand you three vetted matches from our CMMC compliance services network within 24 hours, free, with no sales calls until you say go. We genuinely do not care which one you pick. Vendors pay us, you never do, and you can read exactly how we make money before you talk to anyone.
Frequently Asked Questions
What is CMMC compliance?
CMMC compliance means meeting the Cybersecurity Maturity Model Certification requirements that DoD attaches to its contracts. The model has three levels: Level 1 for Federal Contract Information, Level 2 for Controlled Unclassified Information, and Level 3 for the most sensitive programs. Your solicitation tells you which level applies and whether you can self-assess or need a third-party assessment.
How much does CMMC compliance cost?
It depends on your level and your starting point. Level 1 mostly costs staff time, since its 15 practices ride on basics like passwords and patching. At Level 2 the spend spans tooling subscriptions, consulting, remediation, and the C3PAO assessment, and totals vary so much by scope that any single figure would mislead you. Shrinking your CUI footprint into an enclave is the biggest cost lever you control.
How long does it take to get CMMC certified?
Most small contractors starting from scratch need 12 to 18 months to reach Level 2. That window covers scoping, closing 800-171 gaps, gathering evidence, and waiting for a C3PAO slot. Level 1 moves much faster, often a few weeks of cleanup plus the annual self-assessment. Starting before the clause lands in your contract is the only reliable way to avoid losing a bid over timing.
Do subcontractors need CMMC certification?
Yes, when FCI or CUI flows down to them, and it usually does. Primes must push the requirement to every subcontractor that handles covered information, so your level follows the data you touch, not your position in the chain. A sub that only receives FCI needs Level 1, while one handling CUI needs Level 2.
Can we self-assess instead of hiring a C3PAO?
Only at Level 1, and for a small subset of Level 2 contracts. Level 1 always uses an annual self-assessment with an affirmation from a company executive. Most Level 2 contracts demand a C3PAO third-party assessment every three years, and the solicitation states which type applies, so read it before you budget either way.
Written by Russ Herman, founder of Defend My Business. We are a technology broker, like a mortgage broker but for business security, internet, and voice. We hold agreements with 400+ vetted providers. Vendors pay us, you never do. See exactly how we make money. Questions: 1-877-453-8759 or [email protected].
Get a Tailored CMMC compliance Shortlist
3 vetted vendors matched to your size, industry, and budget. Free, vendor-neutral, 24-hour turnaround.
Get a Quote →Want help getting your compliance program right?
Defend My Business helps SMBs cut through the marketing and get their compliance program right for their environment, budget, and compliance needs — then deploy and manage it. Through our 400+ vendor network we can often secure better pricing and terms than buying direct, and we stay vendor-neutral, so the recommendation fits you, not a sales quota. Want a second opinion? Pair this with our compliance services or talk it through with an advisor.
Book a free call with a DMB advisor →