CMMC's Real Cost Is Red Tape, Not the Assessor

Behind every $45,000 assessment week stands a mandate, not a markup - three certified professionals whose expertise costs what the DoD says it must cost. The true burden of CMMC compliance isn't in the assessors' fees; it's in the tangled cost of security itself, paid in full by the small businesses least equipped to afford it.

Risk Level

Read Time

With the recent (and unexpected) announcement of the suspension of CMMC third-party assessments as part of a 60-day review period, there has been a large amount of discourse around the cost of becoming CMMC certified. As part of these discussions, there have been factually incorrect statements made that C3PAOs are inflating fees on a whim and are a major contributing factor to the cost of compliance. 

This discourse is, at best, objectively untrue and, at worst, damaging for good-faith assessment teams and contributes to the ever-growing confusion as to where the true cost of contractual compliance comes from.

The price of your assessment week

One topic that comes up often in these discussions is the cost of a CMMC assessment. Numbers can vary wildly depending on a large number of factors (type of implementation, size of company, level of hours expected, etc.), but the most commonly reported cost of an assessment week is somewhere in the ballpark of $45,000. And while this number might have sticker-shock, it is important to understand where this number comes from and (what is often not discussed) why C3PAO teams are crippled by mandatory requirements for fielding a full assessment team

To combat disingenuous discussions of C3PAO teams inflating assessment costs, let’s break down expenses on just the C3PAO assessment team alone:

  • Each assessment is governmentally mandated and required to have at least three credentialed cybersecurity professionals fully booked for a week-long assessment. 

    • Each assessment must have a Lead Assessor

      • In order to become a Lead Assessor, you must:

        • Hold a Certified CMMC Professional (CCP) certification, which requires a full week of training ($1,350 to $3,500 on average), an exam cost ($760per attempt, unless you pay ISACA a membership fee, which reduces the exam cost to $575 per attempt), and an application fee of $200.

        • Hold a Certified CMMC Associate (CCA) certification, which requires a full week of training (again, $1,350 to $3,500 on average) an exam cost ($760per attempt, unless you pay ISACA a membership fee, which reduces the exam cost to $575 per attempt), an application fee of $50, as well as already having a DoD-approved 8570 baseline certification (most commonly Sec+) and an annual renewal fee of $500.

        • Receive approval for Lead CCA status, which requires a $100 registration fee as well as already having a DoD-approved 8570 higher-level certification (most commonly CISM or CISSP), and 5+ years of both cybersecurity and management experience, with a $100 yearly renewal fee on top of the CCA renewal fee.

      • Each assessment must ALSO have a separate CCA, which comes with the above requirements, other than the final Lead CCA bullet.

      • Each assessment must ALSO have a separate Quality Assurance (QA) individual, which comes with the same requirements as a CCA.

In order to become a CCA you must first be a CCP and have a minimum of one year of assessment experience. When bringing in experienced cybersecurity professionals who don’t have assessment experience, this may mean carrying an entire additional junior team member for up to a year before they can be considered part of the minimum assessment team count.

What this ultimately means is that each assessment week, to even meet governmental requirements, must have three cybersecurity professionals each with years of experience and DoD-approved certifications fully blocked off and dedicated to that Organization Seeking Certification (OSC) alone. The concept of hiring cheaper labor to lower the cost of assessments functionally does not exist at the CCA and Lead CCA certification levels given the nature of experience and knowledge required for each individual. 

With just the above numbers in mind, let’s do some quick math. Assuming the individual manages to pass each exam on the first attempt, it would cost a C3PAO around $5,000 to $10,000 (depending on the training provider) to raise a single individual to Lead CCA status. To field a full team of one Lead CCA, one CCA and one QA individual, a C3PAO would expect to pay anywhere between $12,000 to $21,000 for a single assessment team in just exam and maintenance fees alone. 

Keep in mind that these certifications are not just incredibly expensive, but also incredibly niche. Unlike standard cybersecurity certifications, (which are still required to become CCA and Lead CCA certified, mind you), these certifications are only useful within the CMMC ecosystem. A C3PAO could hire an experienced professional with a wealth of certifications and experience, but without paying the exorbitant fees associated with the CMMC certifications, that professional cannot legally do work on an assessment team.

But wait, there’s more!

Believe it or not, the certification fees are minimal in comparison to what it costs to become a C3PAO and set up an environment that is qualified to review assessment data and materials in. C3PAOs need their own CMMC Level 2 compliant environments, assessed by DIBCAC, before they can even perform assessments. The same costs small defense contractors are shouldering to become CMMC Level 2 compliant are the same costs C3PAOs face just to be able to perform assessments. On top of that, C3PAOs are also required to be ISO 27001 accredited with a CMMC-specific overlay. These costs require an initial $35,000 payment that only covers up to 5 CCAs. Every CCA over that 5-individual count is an additional $2,000 added to the baseline. This fee is paid every two years. Then there’s the annual $5,000 maintenance fee, plus a fee of $1,000 per certificate issued, and another $17,000 mid-year surveillance fee for the year a C3PAO doesn’t go through the full accreditation process again. So you can see, the costs of simply functioning as a C3PAO start to add up. 

Do assessments actually require that many bodies, though?

In practice, do the assessments often require a full 3-person team to assess 110 security controls? Speaking from experience, absolutely not. As an assessor who has overseen dozens of assessments across all facets of the DIB, the number of governmentally required certified and experienced assessors that require thousands of dollars in upfront cost and yearly recurring certification expenses in a niche cybersecurity field to do the work for an individual assessment could be considerably lowered. And with this hypothetical lowering of governmentally mandated and required employees, assessments would immediately see a shift in cost.

This is, however, not possible with current federal requirements placed squarely on the shoulders of assessment teams; the primary cost of your assessments for C3PAOs comes down to the personnel required. When you book an assessment, you are paying for highly technical, specialized assessment teams who must possess deep knowledge of complex government frameworks, because those are the assessment members that the DoD has deemed uniquely responsible for overseeing assessments through multiple layers of cost-restrictive and experience-restrictive requirements. 

The Cost of Contractual Compliance

Taking in everything that has already been said, let’s state the obvious - becoming CMMC certified is wildly expensive, especially for small businesses. The overall discussion around the burden on small businesses is honestly unsurprising - if the most financially vulnerable businesses are expected to meet CMMC requirements to handle CUI for extremely small contracts, the contracts themselves can become a financial burden.

However, the reality is that the cost of the assessment week, widely considered the CMMC “finish line”, can be a drop in the bucket to the true cost of a CMMC certification. The highest expected cost is in the implementation of upgrading to enterprise-grade security, purchasing specific compliance tools, and fielding highly experienced teams to meet contractual obligations of protecting CUI when the contracts themselves may not be financially significant enough to justify those requirements. It is therefore unsurprising that a large number of small DIB companies have simply chosen to not pursue CMMC compliance.

What is most notable about the recent announcement, and a point that is often overlooked, is that the pause in assessments has no impact on the requirements currently established. Any OSC seeking to work with DoD contracts must still comply with DFARS 252.204-7012. Not complying or, as seen in the past, falsely representing compliance has real consequences through the False Claims Act. For a lot of OSCs, a third party assessment can be a safety net that separates not just a failed certification but potentially millions of dollars in litigation costs for not meeting contractual obligations, whether knowingly or unknowingly.

Questions that must be asked

As it stands, very few members of the CMMC ecosystem can claim to know what the future holds for CMMC contractual requirements. Currently, the financial burdens that are experienced on the road to compliance vary wildly depending on the size of the OSC looking to become certified.

While the 60 day pause is in place, there are very important discussions that must be held, and vital questions must be answered. Most notably, however, is this:

If there is a financial burden of compliance on small businesses, and a financial burden of mandated staffing on C3PAO teams, what is the true cost of the red tape required to meet the security requirements of governmental contracts?

We’re still here for you

Let’s not sugarcoat it - CMMC has never had the most transparent requirements to meet. With the 60-day review currently underway, these requirements are even more confusing and, in some cases, nerve-wracking, especially because there has been no change in compliance requirements. If you were required to meet CMMC compliance before the pause, you are still on the hook today.

Luckily, even with the pause, Hive Systems is fully equipped to assist you in your compliance journey. If you anticipate the requirement from your Prime or contracts, reach out to us in how we can assist in certification assessments, supporting internal self-assessments, or readiness and implementation support to help identify right-size solutions that meet your unique requirements.


Navigate the red tape with our CMMC experts.


 

Follow us - stay ahead.

Next
Next

FortiBleed: What 86,000 Compromised Firewalls Reveal About Security Basics