One of the most frequent questions I hear from our clients about the new Cybersecurity Maturity Model Certification, after a few choice words, is: "How much is this going to cost me?"
It's a great question, and one I can't fully answer because, unfortunately, they haven't even rolled out the auditor program yet!!
That being said, it does appear that the Office of the Under Secretary of Defense for Acquisition & Sustainment is wiling to foot the bill... Kind of. Because according to their FAQ page:
"The cost of certification will be considered an allowable, reimbursable cost and will not be prohibitive..."
Which is great, isn't it? But there are no further details mentioned, and it is followed by this caveat,
"For contracts that require CMMC you may be disqualified from participating if your organization is not certified."
But, as you can probably imagine, there are going to be other costs besides just auditing. That said, if you actually have all the NIST SP 800-171 security controls in place (which, of course you do! I mean, doesn't everyone?) like you are supposed to have before you won any contracts in the first place, then they shouldn't be significant. I will go ahead and take a stab at calculating the costs, outside of auditing, but since there are no concrete answers yet, I'm just making educated guesses and these costs are, of course, subject to change.
I've broken down the expected costs into three categories:
Preparation costs
Security Control costs
Audit costs
Naturally, the total cost to your company is going to vary, based on a multitude of factors, such as:
Just how far along you've come with the NIST SP 800-171 security controls (is that nervous laughter I hear?)
The size and scope of your business (number of employees, locations, devices/stations, networks, etc...)
Your current IT situation (do you have an internal department or do you outsource?)
Target CMMC Level
The scope of your data (is it CUI or just FCI?)
I know those are a lot of unknown variables, but it's reasonably safe to assume that your goal, at least initially, will be CMMC Maturity Level (ML) 3, so to not overwhelm you, let's go with that.
From here, to figure out your preparation costs, we are going to look at the costs of those who have most of the NIST SP 800-171 security controls in place (like you, right?) and those who don't...
Security Controls Implemented: $35,000 to $100,000
Preparation Costs
CMMC Readiness Assessment: $15,000 to $35,000
This is the cost for medium-sized, 250-person firm with multiple locations and whose security controls were handled in-house.
We got this by comparing it to an ISO 27002 Gap Assessment, which has a similar number of controls.
CMMC Gap Remediation to fix any lapses found in the Readiness Assessment
Prepared: $0-$10,000
Less Prepared: $0-25,000
This is dependent on the findings and what it will take to make your company ready.
Security Control Costs: $0
If you have stayed on top of your security controls over the last five years, it is likely this will cost you nothing.
Audit Costs: $20,000-$40,000 (initial preparedness is irrelevant)
Please keep in mind that the costs I'm estimating above are just that... ESTIMATES. Even though the first version of the CMMC has been released, it is subject to change. Sometimes I wish I could read the future, but alas.... I cannot.
However, if you have any other questions and would like us to go over your particular situation, feel free to schedule a free consultation online, or give us a call at 919-348-4912, and we will be more than happy to answer your questions!
Need help implementing these strategies?Our cybersecurity experts can assess your environment and build a tailored plan.
CEO, Founder & AI Architect, Petronella Technology Group
Craig Petronella founded Petronella Technology Group in 2002 and has spent 20+ years professionally at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential issued by the Cyber AB and leads Petronella as a CMMC-AB Registered Provider Organization (RPO #1449). Craig is an NC Licensed Digital Forensics Examiner (License #604180-DFE) and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. He also holds CompTIA Security+, CCNA, and Hyperledger certifications.
He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.
Under his leadership, Petronella Technology Group has served hundreds of regulated SMB clients across NC and the southeast since 2002, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.