The Compliance Bill Was Already Due
Most contractors are comparing the cost of compliance to the cost of certification as if they were the same thing. They are not. Here is the distinction the whole debate keeps missing.
Walk into almost any conversation about CMMC and you’ll hear the same objection: “It costs too much.” The problem is that most contractors are comparing the cost of compliance to the cost of certification as if they’re the same thing… They aren’t.
The government isn’t charging you to become compliant. It’s charging you to prove you already are.
That’s the distinction the whole debate keeps missing.
CMMC didn’t create the compliance bill. It created the audit.
The obligations already existed
This is the part that ends the “too expensive” argument.
Since 2017, DFARS clause 252.204-7012 has required contractors handling CUI to implement the 110 controls in NIST SP 800-171. Since November 2020, clauses 252.204-7019 and 7020 have required you to self-assess against those controls and post your score in SPRS. Without a current score, you couldn’t be considered for award.
None of that is new. It has been in your contracts for years. CMMC simply adds one thing on top: verification. So when a large implementation bill suddenly appears, that cost didn’t arrive because of CMMC. It arrived because work that should have been completed years ago is finally being checked.
The government’s number isn’t what you think it is
When people quote “the cost of CMMC,” they are usually quoting the government’s estimate. What that estimate covers is the assessment and annual affirmations. It does not include the cost of implementing your security program.
The government’s estimate isn’t wrong. It’s answering a different question.
The government isn’t estimating implementation costs because it doesn’t view implementation as a future activity. It views it as an existing contractual obligation.
The number itself: roughly $104,670 for a small business, spread across a three-year assessment cycle. That works out to about $35,000 a year, and it pays for the audit, not the security program. Real money, but not the six-figure wall it looks like on first read.
It is also not a fixed price. The assessment market is still young. As more C3PAOs come online and more of the preparation work moves from consultant hours into purpose-built platforms, competition keeps pushing the cost of getting assessed down, not up.
A new stop every Tuesday and Thursday.
Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.
Your SPRS score is a representation, and someone signed it
Here’s where this stops being a cybersecurity conversation and becomes a governance one, and why the cost conversation matters less than the representation conversation.
The government isn’t evaluating what you intended to do. It’s evaluating what you said you already did.
The score you posted in SPRS isn’t an internal metric. It’s a representation to the federal government. Someone in your organization, your Affirming Official, formally attested that it was accurate, and CMMC’s annual affirmation extends that same accountability forward.
Ultimately, that’s the person accountable for the representation. Not the IT team, not the vendor, but the official who signed.
If the company can’t support its SPRS score with evidence, the question becomes who affirmed that the score was accurate in the first place. That’s why the role of the Affirming Official matters: they’re the person responsible for the representation the company made to the government.
The real risk isn’t the assessment cost
So if cost isn’t the real problem, what is?
It’s the gap: the risk that your SPRS score and your evidence don’t match. A score gets entered. People leave. Documentation drifts. Assumptions harden into facts. Years pass. Then someone asks for proof, and the number on file turns out to describe a company that no longer exists.
That gap has teeth. A false or unsupportable score can become a matter under the False Claims Act, the government’s primary tool against those who defraud it. In 2021, the DOJ launched its Civil Cyber-Fraud Initiative to pursue exactly these cases, and it’s no longer hypothetical.
Paid in 2025 after reporting a score of 104 when its actual score was negative 142.
Paid in a related matter. Both began with whistleblowers: insiders who knew the real story and had a financial reason to tell it.
And the standard isn’t limited to deliberate lies. It reaches reckless disregard for the truth. “We assumed we were compliant” is not a defense.
What I’d do if I were in your seat
So, now what? None of this calls for panic. It calls for validation. If you were sitting across from me, here’s where I’d start.
Recalculate your real score
Against the environment you have today, not the one you had when you last posted, or the one you hope to have when you schedule an assessment.
Compare it honestly to SPRS
What’s filed versus what you can actually prove.
Close the gap, or document the plan
Correct the score and back it with a credible Plan of Action & Milestones (POA&M).
Keep your evidence
Your SSP, POA&M, logs, and scans are what turn a number into a defensible position.
A lower, honest score backed by a real plan is defensible. An inflated one never was. Don’t panic. Start validating what you can prove.
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
Sources and references
- DoW CMMC Program cost estimates (32 CFR Part 170 regulatory analysis): approximately $104,670 for a small entity over a three-year cycle, covering assessment and affirmation.
- U.S. Department of Justice, Office of Public Affairs, settlement announcements: MORSECORP Inc. ($4.6 million, March 2025) and Raytheon Company / RTX / Nightwing ($8.4 million, May 2025).
- DOJ Civil Cyber-Fraud Initiative (announced October 2021).
- False Claims Act: 31 U.S.C. §§ 3729-3733, including the qui tam (whistleblower) provisions.
- DFARS 252.204-7012, -7019, and -7020: NIST SP 800-171 implementation, self-assessment, and SPRS reporting.
- 32 CFR Part 170: CMMC Program.