CMMC Pricing
- Home
- CMMC Pricing
"Published prices. Written scope. No discovery call required to learn the number."
What CMMC readiness costs
Most firms in this space will not quote you a number until you have sat through a discovery call. Here are ours. Fixed scope, fixed price, and the boundaries of each engagement written down before you commit.
Gap assessment
- All 15 FAR 52.204-21 practices assessed
- Federal Contract Information scoping across your systems
- Findings report with each gap rated by effort
- Prioritised remediation plan you can action or hand to us
- Self-assessment walkthrough and affirmation guidance
- 60-minute readout with your team
Gap assessment
- All 110 NIST SP 800-171 Rev 2 controls assessed
- CUI scoping across CAD/CAM, ERP, MES and shop-floor systems
- Boundary recommendation — what stays out, and why it is defensible
- SPRS score calculation and improvement path
- System Security Plan gap review
- POA&M with owners, effort and sequence
Assessment readiness
- Everything in the Level 2 gap assessment
- Evidence package built and organised to assessor expectations
- System Security Plan authored and maintained
- Mock assessment against C3PAO methodology
- Remediation support through to close-out
- We sit with you for the assessment itself
Something that doesn't fit these three?
Enclave design and build, OT-adjacent segmentation, continuous compliance tooling, supplier flow-down, or ongoing managed compliance are quoted on time and materials against a written scope. So is anything multi-site.
Book a free consultationWhat these prices assume
A single site, one CUI or FCI boundary, and up to 100 in-scope endpoints. Multi-site operations, more than one enclave, or unusual OT environments change the number — we will tell you that on the call rather than after the invoice.
Prices are in USD and exclude any third-party licensing and the C3PAO's own assessment fee, which you pay the assessor directly.
One thing worth knowing before you buy anything
In July 2026 the Department of War suspended CMMC Phase II's third-party certification requirement, which had been due to take effect on 10 November 2026. That pause is real, and no timeline has been announced for its return.
What did not pause: NIST SP 800-171's 110 controls, DFARS 252.204-7012 and its 72-hour incident reporting, and your SPRS score and annual affirmation. Primes will keep asking for the score. If a vendor is still selling you a November deadline, they have not read the memo.