CMMC Level 2 gap assessment
What it costs, and who says so.
Ours is $5,000, one time, published, for the gap assessment only. Below is how that sits against the Department of Defense's own estimate, with the source named beside the figure.
Nothing on this page is an average, a typical customer, or a figure we worked out ourselves. If we cannot say where a number came from, it is not here.
Our price
PUBLISHED$5,000, one time, for most small and mid-sized contractors.
That covers scoring all 110 NIST SP 800-171 controls against your environment, calculating your SPRS score, reviewing the evidence you already hold, and a broad POA&M for closing each gap. It does not review or write your policies or your System Security Plan. Larger firms are scoped and quoted individually rather than against the published figure. There is no portal subscription and no per-seat licensing, and the deliverables do not stop working when a contract ends.
We publish it because you should not need a sales call to learn a number, and because a firm that will not say its price before it understands your urgency is telling you something about how it prices.
The number that dwarfs ours
DOD REGULATORY IMPACT ANALYSISThe Department of Defense's own CMMC 2.0 Regulatory Impact Analysis puts a small entity's Level 2 assessment by a C3PAO, with its affirmations, at $104,670 over three years.
Two things have to be said in the same breath or the comparison is dishonest. That figure is the assessor's cost, not ours, and it assumes the security requirements are already implemented. And our own pricing does not include the C3PAO fee, because we are not a C3PAO and do not perform certification assessments.
The point of putting it here is not that we are cheaper. It is that the gap assessment is the small number in this picture. The expensive part of CMMC is the work the gap assessment tells you that you have to do, and the calendar time evidence collection takes whether you start today or in March.
What we will not tell you
What your CMMC program will cost in total
It depends on how much is already in place, how wide your CUI boundary turns out to be, and whether your contract requires a C3PAO. Anyone quoting you a total before scoping is guessing, and a guess presented as a number is worse than no number.
That the cheapest assessment is the right one
A gap assessment that misses scope is expensive later, in remediation you did not plan and evidence you cannot produce. Price is one input.
Already know you want to talk?
BOOK A CALLSkip the form. Pick a time and talk to us directly.
What happens in 30 minutes
- We read your contract's CMMC and DFARS clauses with you.
- We confirm which level applies and how it will be assessed.
- We tell you the first step, whether or not it involves us. No slides.
Ready to see where you actually stand?
A CMMC Level 2 gap assessment scores all 110 controls against your real environment. No portal, no subscription, documents you keep.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.