The five cost buckets of CMMC Level 2
- Tooling. SSP/POA&M automation, evidence management, SIEM, EDR, MFA, vulnerability scanning. $15k–$120k/year depending on stack overlap.
- Enclave / GCC High. Microsoft 365 GCC High is the most common path; licensing runs ~$40–$60/user/month above commercial M365, plus migration cost. Sovereign AWS GovCloud is similar in spirit.
- Readiness work. Gap assessment, policy authoring, evidence collection, POA&M build-out. $30k–$250k depending on size and whether the work is in-house or outsourced.
- C3PAO assessment. The certifying body itself. $25k–$120k for Level 2 depending on scope, asset count, and travel.
- Continuous monitoring (year 2+). Annual affirmation, evidence freshness, triennial reassessment. Often forgotten and often the largest line item over a five-year window.
Realistic timelines by company size
10-seat contractor, scoped enclave: 4–7 months end-to-end. Quick-score → enclave migration → 90-day evidence collection → C3PAO assessment.
50-seat contractor, mixed environment: 9–14 months. The middle of the curve. Scoping decisions, SRM negotiation with the MSP, and POA&M closure dominate the timeline.
250-seat contractor, complex boundary: 18–30 months. Multi-site, subsidiaries, inherited controls from cloud providers, deeper documentation burden. Usually overlaps with a parallel SOC 2 or ISO 27001 program.
The fastest path at every size is the same: shrink scope first, then collect evidence, then assess. Most overruns come from reversing that order.
What inflates cost
- Unbounded scope. Assessing the whole company instead of an enclave can 5× every other cost bucket.
- Late evidence collection. Producing 12 months of operational evidence in the last 30 days before the assessment is the most expensive mistake teams make.
- No shared responsibility matrix. Without an SRM you cannot inherit controls from GCC High or your MSSP — you reimplement them.
- POA&M failures at assessment. A POA&M with non-eligible controls or no closure dates triggers a conditional cert at best, a fail at worst — both expensive to recover from.
- Tool sprawl. Buying point tools for each control rather than consolidating against the 320 NIST 800-171A objectives.
What an Athena-run program looks like
Athena runs the readiness and ongoing-monitoring buckets — Quick Score for sizing, the Assessment Pack for end-to-end readiness, then continuous evidence freshness and SPRS recalculation post-cert. We do not sell GCC High licenses or perform the C3PAO assessment itself. See pricing for the Assessment Pack tiers; the readiness assessment page covers what the readiness bucket produces.