CMMC Compliance Cost for DFW Defense Contractors: What to Budget While Phase 2 Is Paused

CMMC compliance cost in DFW comes down to 2 numbers that rarely sit side by side. The Pentagon prices a small company’s Level 2 certification at $104,670 over 3 years. The median DFW business that took DoD prime contract money in FY2025 received $110,419. Phase 2 is paused, and that buys time, not a discount. Still unsure the clause applies to you? Start with our guide to CMMC compliance for Dallas defense suppliers.

For a small DFW defense contractor, DoD estimates CMMC assessment costs at $5,977 a year for Level 1 and $37,196 to $104,670 every 3 years for Level 2. Those figures exclude the security work itself, which is usually the bigger bill and which the SBA prices far higher.

Here’s the uncomfortable part. The official numbers leave out the expensive work.

The 2024 CMMC Program rule prices the assessment, the paperwork and the yearly affirmations. It assumes you already meet the 110 security requirements in NIST SP 800-171 Revision 2, because DFARS 252.204-7012 has required them of defense contractors handling CUI since the end of 2017, on every system that stores or transmits it. So the rule counts the exam. Not the studying.

I run a managed IT and cybersecurity company with an office on Alpha Road in North Dallas, and I’d rather hand a North Texas shop owner the whole bill than a friendly number that falls apart in the first gap assessment. This post uses the federal government’s own estimates, a fresh pull of FY2025 award data for Dallas, Tarrant, Collin and Denton counties, and the policy changes from the last 2 weeks. Then it tells you what to fund now and what to hold.

What does CMMC compliance cost actually include?

CMMC compliance cost is everything a company spends to protect Controlled Unclassified Information to the NIST SP 800-171 standard, prove it through a self-assessment or a third-party assessment, and affirm it every year after that. It has 3 layers. Implementation, assessment and upkeep. Most quotes cover only 1.

Implementation is the tooling, configuration and policy work that closes gaps against the 110 requirements, from multifactor authentication and encrypted storage to the incident response plan and the security awareness training every employee has to complete. Assessment is the scoring, whether you do it yourself or pay a Certified Third-Party Assessment Organization, usually shortened to C3PAO. Upkeep is the monitoring, evidence collection and annual affirmation that keep a score honest long after the assessor has packed up and gone home. If you want the full list of what the standard asks of your systems, our page on what CMMC requires of your IT in Texas walks through it.

Level matters too. Companies that only handle Federal Contract Information sit at Level 1, with 15 basic safeguarding requirements. Anyone handling CUI sits at Level 2. Level 3 adds requirements from NIST SP 800-172 and is assessed by the Defense Contract Management Agency’s DIBCAC team rather than a private assessor, and the rule says it will affect only a small subset of the defense industrial base. Most DFW shops can ignore it.

What does DoD estimate a small business will spend?

DoD published its estimates in the final CMMC Program rule on October 15, 2024. They’re built from labor hours, priced at $190.52 an hour for a company director and $260.28 an hour for an outside service provider. Very specific. Also very narrow.

Assessment pathHow oftenDoD estimate for a small entityStatus in September 2026
Level 1 self-assessmentEvery year$5,977 per yearStill required where the clause applies
Level 2 self-assessmentEvery 3 years, plus annual affirmations$37,196 over 3 years ($34,277 in year 1)The current operating standard
Level 2 C3PAO certificationEvery 3 years, plus annual affirmations$104,670 over 3 years ($101,752 in year 1, of which $31,234 is the assessor)Pulled from contracts by Class Deviation 2026-O0025, Revision 3
Annual affirmationEvery year$1,459 eachStill required

Look closely at the certification row. Of the $101,752 first-year figure, only $31,234 is the assessor’s engagement, which DoD modeled as a 3-person team working 120 hours. The rest is your own people and your IT provider preparing for the assessment, sitting through it and reporting the results. That preparation time is where small shops get surprised. Every time.

And the whole table assumes the controls already work. DoD says so in the rule text. It left implementation out because contractors were already obligated to meet the requirements under FAR 52.204-21 and DFARS 252.204-7012. On paper, that’s fair. In practice, plenty of suppliers signed those clauses years ago without ever closing the gaps.

Why is the SBA’s number more than 5 times bigger?

Because it counts the part DoD skipped. In a July 13, 2026 statement, the Small Business Administration said total compliance costs can reach about $593,800 per certification for a small firm that needs a third-party assessment, and about $388,600 for a firm eligible to self-assess.

I wouldn’t treat either figure as your quote. They’re averages across a huge range of companies. Useful, but blunt. A 12-person machine shop with one CUI workstation and a 180-person electronics assembler with engineering data on every laptop won’t get the same bill. Not even close.

Still, the SBA figure is nearer to what a first-time Level 2 effort feels like from the inside, because it includes the licensing, hardware, consulting and staff hours that make a passing score true rather than merely claimed. DoD’s table is the floor. The SBA’s is the warning.

How big is a CMMC bill next to a typical DFW defense contract?

Almost nobody runs this comparison. So we ran it.

On September 16, 2026, we pulled FY2025 DoD prime contract obligations from USAspending.gov, covering October 2024 through September 2025, contract award types A through D, with place of performance in Dallas, Tarrant, Collin or Denton County. The query returned 883 recipient records. Of those, 686 had positive net obligations for the year, adding up to about $45.95 billion.

Two Lockheed Martin records account for 89.0% of that money. Everyone else splits the rest. Mostly small checks. The median record, the business sitting right in the middle, received $110,419.

FY2025 DoD obligations per recipientRecipient recordsShare of recordsDoD’s $104,670 Level 2 estimate against 1 year of obligations
Under $250,00042862.4%More than 41%
$250,000 to $1 million9814.3%About 10% to 42%
$1 million to $10 million11917.3%About 1% to 10%
$10 million to $100 million324.7%About 0.1% to 1%
$100 million or more91.3%Under 0.1%
All positive records686100%About 95% at the median of $110,419

Read that table with the caveats in mind. Obligations aren’t revenue, a parent company can show up under more than 1 record, and many of these firms sell commercially too. Even so, the shape is hard to argue with. For 62.4% of the DFW businesses that held a DoD prime contract last year, DoD’s own 3-year estimate for Level 2 certification is more than 41% of a full year of that federal work, and that’s before a single control gets fixed.

And those are the primes. The larger CMMC population in North Texas is the subcontractor tier, the shops that receive DFARS clauses on a purchase order from a bigger company and never show up in federal award data at all. We’ve written about how the obligation reaches DFW subcontractors in detail. For a sub, the ratio can be worse. Its defense revenue is a slice of a slice.

Three staff at a DFW defense supplier reviewing a purchase order for CMMC and DFARS flow-down terms

Did the Phase 2 pause lower the cost?

It changed the timing. Not the obligation.

DoD suspended CMMC Phase 2 on July 13, 2026, which pulled the start date for mandatory third-party assessments that had been set for November 2026. Then on September 3, John Tenaglia, DoD’s principal director for defense pricing, contracting and acquisition policy, signed Class Deviation 2026-O0025, Revision 3. As Washington Technology reported, it directs contracting officers to strip third-party assessment requirements out of contracts while continuing to require self-attestation of NIST compliance.

That’s binding now. Undoing it takes more than a memo.

A reform task force had until September 11 to finish its 60-day review. The report goes to DoD CIO Kirsten Davies first, and she decides what becomes public, so as of September 16 no recommendations had been released and no replacement Phase 2 schedule had been announced. Nobody outside the Pentagon knows whether Level 2 certification returns in its current form, in a lighter form or on a new date. I’d be skeptical of anyone who claims otherwise.

What stayed put is the expensive part. Controls cost money. DFARS 252.204-7012 still requires the NIST SP 800-171 controls, and your self-assessment score is still something a company officer signs. So the pause moved roughly $31,234 in assessor fees off this year’s calendar. It didn’t move the remediation.

What does a wrong self-assessment cost?

More than any C3PAO. The Justice Department has made that point twice this year.

In June, Huntsville contractor LOGZONE agreed to pay $507,144 to resolve False Claims Act allegations after the Defense Contract Management Agency scored its NIST SP 800-171 implementation at negative 170, near the bottom of a range that runs from negative 203 to 110, according to the DOJ announcement. On September 1, Honeywell Aerospace agreed to pay $2,042,518 over allegations that a business unit billed DoD while falling short of the same NIST requirements from April 2020 through December 2023. Big company, small company. Same exposure.

Here’s my honest take. The pause makes self-attestation more important, not less. When no assessor checks the score, the signature becomes the control. And if the number is optimistic, the False Claims Act does the auditing.

Where does a DFW supplier’s money actually go?

Here’s where the budget lands, in the order we’d scope it.

  1. Scoping the CUI. Deciding exactly which systems, people and files touch controlled information sets the size of everything after it.
  2. Identity and email. Multifactor authentication, conditional access and a Microsoft 365 tenant that can hold CUI, whether that’s a controlled enclave or a full GCC High move.
  3. Endpoints and logging. Managed detection on every in-scope device, plus audit logs kept long enough to investigate an incident.
  4. Policies and the System Security Plan. The written evidence an assessor, or a prime’s supply chain team, will ask to see.
  5. Ongoing monitoring. The monthly work that keeps a score true after the project team moves on.

Scope is the lever. A company that pushes CUI into a small, well-defined enclave assesses and maintains a handful of systems. A company that lets controlled drawings live on every laptop, every shared drive and every personal email account assesses and maintains all of them, one device at a time, year after year. Same requirements. Very different bill.

That’s why the GCC High question deserves real analysis before anyone signs a migration. Migrations hurt. For many DFW suppliers, a controlled enclave inside Microsoft 365 covers the CUI workload with far less disruption, and our Microsoft 365 team in Dallas scopes both paths. Some companies genuinely need GCC High, especially those holding export-controlled technical data under ITAR, a topic we cover in IT compliance for DFW manufacturers. Many don’t.

IT engineer configuring a network rack that supports a scoped CUI enclave for a DFW defense manufacturer

What should you fund while Phase 2 is paused?

Fund what stays true no matter what the task force recommends. Hold anything that only exists for a certification date nobody can name yet.

Worth funding now

  • A documented CUI scope and data flow, since every future version of CMMC starts there
  • A current NIST SP 800-171 self-assessment score you’d be comfortable defending line by line
  • MFA, endpoint detection and log retention on every in-scope system
  • A System Security Plan and a plan of action that match what’s actually deployed

Worth holding for now

  • Booking a C3PAO date only to beat the old November 2026 deadline
  • Mock assessments priced as if certification were due this quarter
  • A full GCC High migration nobody has weighed against an enclave

One exception. If a prime wrote a certification requirement into your purchase order terms, that language still governs your relationship with that customer, whatever the class deviation tells government contracting officers. Read your POs. Then call the buyer.

How should a 20 to 200 person DFW company budget this?

Think in 3 buckets. Keep them separate.

The first bucket is one-time remediation. It’s the big one. That’s the scoping, configuration and documentation work, and its size depends almost entirely on how far your current environment sits from the 110 requirements. Only a gap assessment can size it honestly. Anyone quoting it sight unseen is guessing.

The second is recurring operations. It never ends. Managed security, licensing uplifts and monitoring arrive every month, and they’re far easier to plan when they’re rolled into a flat managed IT agreement instead of scattered across 4 vendors and 3 credit cards. Our managed IT pricing for Dallas businesses shows how we structure that.

The third is assessment and affirmation. It’s the most predictable. Use DoD’s table here. Plan on about $37,196 over 3 years if you’ll self-assess and about $104,670 if you’ll need a C3PAO, then park the certification portion until DoD publishes a real date.

Want to track those dates as they move? Our CMMC timeline for Texas defense contractors follows every change. And if you’d rather have someone own the whole program, our cybersecurity services for Dallas businesses cover the controls, the monitoring and the evidence. Most owners don’t want this job. Fair enough.

Operations manager at a DFW electronics assembler tracking CMMC remediation tasks on a tablet

Questions DFW contractors ask about CMMC cost

How much does CMMC Level 2 certification cost for a small business?

DoD estimates $104,670 over 3 years for a small entity, including a $31,234 assessor engagement and 2 annual affirmations. That figure leaves out the cost of implementing NIST SP 800-171, which is usually the larger expense.

Is CMMC still required after the Phase 2 suspension?

Yes, in part, because Phase 1 self-assessments and the NIST SP 800-171 requirements in DFARS 252.204-7012 still apply. What’s paused is the third-party assessment requirement, which Class Deviation 2026-O0025, Revision 3 told contracting officers to remove from contracts on September 3, 2026. The reform task force’s review was due September 11, and its recommendations hadn’t been published as of September 16. Expect guidance later this fall, and keep your self-assessment score current in the meantime.

Can a DFW subcontractor self-assess instead of paying a C3PAO?

Right now, most can. With third-party requirements removed from government contracts, self-assessment plus annual affirmation is the working standard, though a prime can still set stricter terms in its own purchase orders.

Does GCC High make CMMC compliance cheaper?

Usually not by itself. GCC High licenses cost more per seat than commercial Microsoft 365, and a full tenant migration adds project work on top. For many small suppliers, a tightly scoped CUI enclave meets the requirement with far fewer seats in the expensive environment. Companies holding ITAR technical data are the common exception.

What happens if our SPRS score is wrong?

You could face False Claims Act exposure. DOJ settled with LOGZONE for $507,144 in June 2026 after DCMA scored its implementation at negative 170, and Honeywell Aerospace agreed to pay $2,042,518 in September 2026 over NIST SP 800-171 gaps. Both cases turned on claims for payment made while required controls weren’t in place. If your score reflects plans rather than deployed controls, reassess it before your next affirmation, and document what changed.

Who pays for CMMC compliance, the prime or the sub?

In most cases the subcontractor pays. Flow-down clauses pass along the requirement, not the budget.

Not sure what your CMMC bill really looks like? Uprite’s team of 42 runs gap assessments for DFW defense suppliers from our Dallas office, sizes the remediation honestly and tells you what can wait for the task force. We aren’t a C3PAO, so there’s no assessment to sell you.

Speak to an IT Expert

About Author

Learn More