My company, a 20-person landscaping firm, is looking at a federal grounds maintenance contract for a military base, NAICS 561730. It's a set-aside for small businesses. The Request for Proposal (RFP) states CMMC Level 2 is required by the time of award. I got two quotes for a CMMC Level 2 assessment, and they were really different, but neither explained why. One was super high and the other was low enough to make me nervous. I understand the CMMC Level 2 self-assessment is conducted every 3 years. What factors actually drive the cost of these assessments? Is it the number of systems, the locations we have, or something else? I am also trying to figure out what the preparation work typically costs in staff time for a firm our size. Can a small enclave approach lower the bill for a CMMC Level 2 assessment?
What drives the cost of a CMMC Level 2 assessment for a 20-person firm, and what is the hidden part?
Ask a question2 answers
The cost of a CMMC Level 2 assessment is driven by the complexity of your information systems and the scope of the data you handle. A CMMC Level 2 self-assessment is required for your firm. The 110 requirements of NIST SP 800-171 Revision 2 must be met for CMMC Level 2. The number of systems, network architecture, and locations where Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) are processed, stored, or transmitted directly affect the effort needed to implement and assess these requirements. The hidden part is the internal staff time and resources required to achieve compliance before the assessment. A small enclave approach can lower the bill by reducing the scope of your information system that needs to meet CMMC requirements, provided you can effectively isolate FCI and CUI within that enclave. This means fewer systems and processes need to be assessed, which reduces the labor for both your team and the assessor.
The cost of a CMMC Level 2 assessment is also driven by whether your firm chooses a self-assessment or a certification assessment, which depends on the contract. Tom is right that the 110 requirements of NIST SP 800-171 Revision 2 are the standard for Level 2. The 32 CFR CMMC Program rule specifies that a CMMC Level 2 self-assessment is conducted every three years, and it is valid for three years. The contracting officer will check your CMMC Status through the Supplier Performance Risk System, which is where your self-assessment results are posted. A smaller enclave can definitely reduce the scope, but make sure it can actually handle the work required by the federal contract.