A subcontract renewal lands in your inbox. Buried in the flow-down clauses: a CMMC Level 1 self-assessment must be on file before the next award. There's no compliance team to hand this to, just you or whoever handles IT part-time, trying to price it out before the deadline hits.
One vendor quotes $8,000. Another quotes $40,000, with a third-party assessor Level 1 doesn't even require. The Department of War's own rulemaking puts the real number closer to $5,977 a year for a small entity, and that obligation didn't change when CMMC Phase 2 was suspended this summer.
Also Read: DoD Suspends CMMC Phase 2: What It Means for You
What CMMC Level 1 Actually Requires
Before any of those vendor quotes make sense, it helps to know exactly what's being quoted for. CMMC Level 1 applies if your company handles Federal Contract Information, the kind of data that shows up on nearly every DoD subcontract even without anything classified or CUI involved. Most small contractors doing routine parts, services, or supply work fall here, not at Level 2.
The requirement is 15 basic safeguarding requirements from FAR 52.204-21, which was renumbered to FAR 52.240-93 for new solicitations issued from February 1, 2026. CMMC Level 1 assessment material still references FAR 52.204-21, while new solicitations use FAR 52.240-93. The clause title and all 15 requirements remain unchanged.
There's no third-party assessor. You self-assess, and a senior official, often the owner at this size, affirms the result in the Supplier Performance Risk System (SPRS). All 15 requirements must show Met. No partial credit, and no Plan of Action and Milestones to fall back on.
Why This Still Matters After the Phase 2 Suspension
The suspension made national headlines this summer, but most of that coverage was about Level 2. On July 13, 2026, the Department of War suspended CMMC Phase 2, which would have required third-party C3PAO certification for most Level 2 contracts starting November 10, 2026. A Reform Task Force is now reviewing the program, with recommendations due within 60 days.
Level 1 was not part of that suspension. Phase 1 self-assessment requirements, in force since November 2025, remain unchanged.
This is where small contractors are most exposed. A prime or a compliance firm tracking every DoD memo will catch the Level 1/Level 2 distinction immediately. A small shop relying on news headlines might not, and headlines about CMMC being "paused" rarely mention that Level 1 was excluded. If your contract carries the Level 1 clause, that self-assessment and affirmation are still due on schedule.
Also Read: How to Complete Your CMMC Level 1 Self-Assessment: 5 Steps
What CMMC Level 1 Actually Costs
That gap between an $8,000 quote and a $40,000 quote is worth unpacking, starting with where the government's own number actually comes from. The CMMC final rule's Regulatory Impact Analysis puts a small entity's annual Level 1 self-assessment cost at $5,977 per year, compared with $4,042 for an other-than-small entity. That figure covers the labor to run the assessment and file the affirmation. It does not cover getting your environment ready to pass it.
Real-world first-year spending, including remediation, typically lands between $3,000 and $15,000. For a small contractor, that's not a rounding error against a compliance budget line, it's often money coming straight out of operating cash flow.
| Cost category | Typical range | What it covers |
|---|---|---|
| Gap assessment | $0-$8,000 | Outside help identifying which of the 15 requirements aren't met yet. Skippable if you can self-assess accurately. |
| Technical remediation | $0-$5,000 | MFA, endpoint protection, access control cleanup. Often minimal if IT hygiene is already reasonable. |
| Documentation | $500-$3,000 | Basic policies supporting each requirement. Level 1 does not require a full System Security Plan. |
| Internal labor | Unbudgeted in most quotes | Staff time spent on the assessment itself. This is the cost most estimates leave out entirely. |
| Annual maintenance | $1,000-$4,000/year | Re-running the self-assessment and refiling the SPRS affirmation each year. |
Source note: The CMMC final rule's Regulatory Impact Analysis provides the $5,977 annual Level 1 self-assessment estimate for a small entity. The cost ranges in this table are editorial estimates for typical gap assessment, technical remediation, documentation, internal labor, and annual maintenance costs and are not figures directly specified by the CMMC final rule.
Key Cost Drivers for Small Contractors
The table above shows the categories, but not why one shop lands at $3,000 and another at $15,000 for the same checklist. That difference usually comes down to five things:
- Current security maturity: Shops already running MFA and basic endpoint protection land near the DoD floor. Shops starting from shared logins and no antivirus push toward the higher end fast.
- Number of systems touching FCI: A five-person shop running everything off two laptops and a shared drive has far less to secure than one running a separate ERP, email server, and shop-floor terminals.
- Who's actually doing the work: At this size, there's rarely dedicated security staff. The work usually falls to an outsourced IT provider, the owner, or an office manager, and their existing familiarity with the requirements swings labor cost more than any tool purchase does.
- Whether IT is already outsourced: A shop with an existing IT contract can often fold remediation into that relationship at little extra cost. A shop with no formal IT support starts from a higher baseline.
- Cloud tools in scope: FCI sitting in a personal email account or an unmanaged file-sharing tool adds cost fast, since it usually means migrating to a properly configured business platform before anything else can be verified.
Common Budgeting Mistakes
Most of the shops that end up over budget didn't do the math wrong, they just left things out of it. The same handful of gaps show up again and again:
- Treating the assessment as the whole cost: DoD's $5,977 figure covers the assessment itself, not the remediation work needed to pass it.
- Skipping the annual reaffirmation: Level 1 compliance repeats every year, and that recurring cost belongs in next year's budget too.
- Assuming a C3PAO is required: It never is at Level 1. A vendor quoting third-party assessment fees for Level 1 work is quoting Level 2.
- Assuming small size means Level 1: Level applies based on data handled, not company size. A single customer drawing marked CUI can push a small shop into Level 2 territory.
- Budgeting for partial compliance: Plans of Action and Milestones aren't allowed at Level 1. All 15 requirements must show Met before you can affirm.
- Leaving out internal labor: Staff time spent gathering evidence and running the self-assessment rarely appears in vendor quotes, but it's real cost.
- Ignoring PIEE account lead time: SPRS access requires an approved Contractor Administrator role through PIEE first. That approval can take longer than the assessment itself.
Strategies to Keep Costs to a Minimum
Fixing those mistakes is half the battle. The other half is sequencing the work so you're not paying for things a little planning would have avoided:
- Self-perform when the scope is simple: With only 15 requirements and no third-party assessor, many small shops with modest IT setups can complete the entire assessment in-house using DoD's free Level 1 Self-Assessment Guide.
- Draw the boundary narrowly and honestly: Limiting the assessment scope to only the systems that actually touch FCI, rather than the whole network, shrinks both the remediation list and the documentation load.
- Fix the free things first: Several of the 15 requirements cost nothing to fix, like enforcing unique logins and removing shared passwords. Closing these gaps before calling a vendor shrinks the paid remediation list before you ever get a quote.
- Fold work into an existing IT relationship: If a managed service provider already handles your systems, ask whether Level 1 remediation can be added to that contract instead of bought as a separate engagement.
- Time the annual reaffirmation deliberately: Scheduling the yearly review during a slower operational stretch avoids rush pricing from consultants and overtime for internal staff.
Also Read: CMMC Level 1 vs Level 2: Which Does Your Contract Require?