Ditch Microsoft & Google Today!

CMMC for Small Defense Contractors: 2026 Deadlines, Phases and Cost Estimates by Level

CMMC compliance costs for a small defense contractor are estimated by the Department of Defense at $5,977 a year for a Level 1 self-assessment and $104,670 per three-year cycle for a Level 2 third-party certification, before any security upgrades. Third-party certification requirements are due to begin on November 10, 2026. This guide covers the deadlines, DoD’s cost tables and the readiness data.

Last reviewed: October 6, 2026. This is general information, not legal or compliance advice. Vendor data is flagged as such.

Key takeaways

  • Phase 1 began on November 10, 2025, and Phase 2, which adds Level 2 third-party certification, is due on November 10, 2026.
  • DoD estimates CMMC compliance costs for a small entity at $5,977 a year for Level 1, $37,196 per cycle for Level 2 self-assessment and $104,670 per cycle for Level 2 certification.
  • Those figures leave out the cost of implementing the security requirements.
  • DoD estimates 35,560 small entities will need an assessment in year four of phase-in.
  • One vendor counted 104 authorized assessment organizations in May 2026.

CMMC deadlines and phases

DoD published the program rule, 32 CFR Part 170, in the Federal Register on October 15, 2024, effective December 16, 2024. The DFARS rule that puts the clauses into contracts was published on September 10, 2025. A Cooley summary gives the effective date as November 10, 2025. The program rule says each phase starts one calendar year after the one before.

Per that summary, Phase 1 (November 10, 2025) added Level 1 and Level 2 self-assessment requirements. Phase 2 (November 10, 2026) adds Level 2 third-party certification. Phase 3 (November 10, 2027) adds Level 2 certification as a condition for exercising option periods, plus Level 3. Phase 4 (November 10, 2028) is full implementation. From today, October 6, Phase 2 is 35 days away (our own arithmetic).

Level 1 covers Federal Contract Information with 15 requirements. Level 2 covers Controlled Unclassified Information using NIST SP 800-171 practices. Level 3 adds 24 NIST SP 800-172 requirements.

What CMMC compliance costs DoD expects small entities to pay

The cost tables in the 32 CFR Part 170 final rule give per-assessment estimates for small entities. Figure 1 shows the three that apply to most contractors.

Horizontal bar chart of CMMC compliance costs per assessment for small entities: Level 1 self-assessment $5,977 a year, Level 2 self-assessment $37,196 and Level 2 third-party certification $104,670 every three years
Figure 1. DoD estimate of per-assessment cost for small entities. Source: 32 CFR Part 170 final rule, Table 10.

For other-than-small entities the Level 2 certification estimate is $117,768. Level 3 is estimated at $10,933 for a small entity, or $12,802 with a plan of action and milestones, because DoD runs that assessment.

The same rule says these tables exclude the cost of implementing the security requirements. DoD reasons that FAR 52.204-21 (effective June 15, 2016) and DFARS 252.204-7012 (implementation by December 31, 2017) already required them. A contractor that never implemented them has costs the tables do not show. These are DoD projections, so real CMMC compliance costs will differ with assessor quotes.

How many small businesses are affected

DoD says it awards contracts containing DFARS 252.204-7012 to an average of 31,338 unique awardees a year, and 23,475 of them (75%) are small entities. As the phases begin, CMMC compliance costs reach more small entities each year, and Figure 2 shows DoD’s estimate of how many.

Bar chart of small entities needing a CMMC assessment per year: 1,104 in year 1, 5,565 in year 2, 18,554 in year 3 and 35,560 in year 4
Figure 2. DoD estimate of small entities needing a CMMC assessment, years 1 to 4. Source: 32 CFR Part 170 final rule, Table 6.

Over seven years that table totals 163,987 small entities, of which 56,689 need Level 2 certification. The later DFARS final rule uses a different count. It estimates 337,968 unique entities, subcontractors included, and 229,818 (68%) of them small. The documents count different things, so we do not combine them.

Readiness data so far

We found no DoD figure for certificates issued. Secureframe, a compliance software vendor, analyzed Cyber AB marketplace data and reported 103 authorized C3PAOs and 759 certified assessors in March 2026, and 104 and 988 in May 2026. The vendor also reports a certification rate, but its articles give conflicting certificate totals and no clear denominator, so we leave that out.

What this means for a small business

Your CMMC compliance costs depend on the data your contracts involve. The table maps each case to the DoD estimate.

Your situation What the DoD estimate says
Federal Contract Information only Level 1 self-assessment, estimated at $5,977 a year for a small entity
Controlled Unclassified Information, self-assessment allowed Level 2 self-assessment, estimated at $37,196 over a three-year cycle
Controlled Unclassified Information, certification required Level 2 third-party certification, estimated at $104,670 over a three-year cycle, against $117,768 for larger firms
Gaps in your current controls Not in the DoD figures, so budget separately for remediation

Three steps for small defense contractors

1. Find out which level your contracts need

Read each solicitation for the level required and whether you handle Federal Contract Information or Controlled Unclassified Information. Subcontractors should ask their primes what flows down.

2. Run a gap check against NIST SP 800-171

Score your current controls before you book an assessor. Unfixed gaps drive CMMC compliance costs more than the assessment fee does.

3. Plan your IT and your assessor

Decide who hosts and secures the systems in scope. Our public sector IT page describes the government-facing work we do. Book a C3PAO early if you need Level 2 certification.

Frequently asked questions about CMMC compliance costs

What is CMMC?

The Cybersecurity Maturity Model Certification program checks that defense contractors protect Federal Contract Information and Controlled Unclassified Information. The Department of Defense set it up in 32 CFR Part 170, which took effect on December 16, 2024.

When does third-party certification start?

Phase 2 begins on November 10, 2026, according to a law firm summary of the final DFARS rule. It adds the Level 2 certification assessment requirement in applicable solicitations and contracts.

Does Level 1 need an outside assessor?

No. Level 1 is an annual self-assessment against the 15 requirements in FAR 52.204-21, for contractors that handle Federal Contract Information only.

Do the DoD estimates include the price of security upgrades?

No. DoD left out the cost of implementing the security requirements because FAR 52.204-21 and DFARS 252.204-7012 already required them. A contractor with gaps will pay for fixes on top of the assessment figures.

Are there enough assessors?

A vendor analysis of Cyber AB marketplace data counted 104 authorized C3PAOs and 988 certified CMMC assessors in May 2026. It is vendor data we could not check against the Cyber AB.

Sources