Part of our work on aerospace and defense
Aerospace and Defense
What DFARS Compliance Actually Costs a 200-Person Subcontractor
Big Sky Consulting Group · August 31, 2026 · 7 min read

You budgeted for a certificate. You are paying for a calendar.
Ask a 200-person defense subcontractor what compliance costs and you will get a number that came off a quote. Assessment fee, maybe a readiness engagement, maybe a year of a managed security provider. It is a clean figure, it fits on a slide, and it is the smallest part of what the shop actually spends.
The real cost does not arrive as an invoice. It arrives as three people losing a day a week, permanently, out of the same headcount that ships parts.
That is the number nobody quotes, because nobody sells it. Search this question and page one is assessment firms, managed service providers and compliance software, each pricing the piece they happen to sell. None of them price your quality manager's Thursday.
The published figure, and what it deliberately leaves out
Start with the only authoritative number in this space. In its regulatory analysis for the CMMC final rule, published as 32 CFR Part 170 in October 2024, the Department of Defense priced a small entity's Level 2 certification assessment at roughly $101,752, and about $104,670 across the full three-year cycle. The self-assessment path came in near $34,277.
Those are real numbers from the government's own economic analysis, not vendor marketing, and they are worth holding onto. But read what DoD said it excluded. The cost of actually implementing NIST SP 800-171 was left out of the estimate, on the grounds that contractors had already been required to do it since DFARS 252.204-7012 landed in 2017.
That is a reasonable position for a regulator writing a cost analysis. It is a terrible basis for a budget. The published figure assumes you arrived at the assessment already compliant. Most shops did not, which is why an industry consultant could claim on a public webinar that three years past the 2017 deadline, roughly one percent of defense contractors were genuinely there. Take the number loosely; it came from someone who then sold a $1,997 do-it-yourself kit, which tells you most of what you need to know about how this market is served. Take the direction seriously. The gap between what was required and what was done is the thing you are now funding.
So the DoD figure is a floor. Not a budget, not an estimate, a floor.
The recurring cost is a staffing decision nobody made
Here is the part that decides whether this hurts. The assessment is an event. The obligations around it are a calendar, and calendars consume people.
Under DFARS 252.204-7019 and 7020 you post and maintain a score in the Supplier Performance Risk System. Under the CMMC program you file an annual affirmation of continuous compliance, signed by a named senior official, with False Claims Act exposure sitting behind that signature. DoD's analysis puts the annual self-assessment and affirmation at just under $6,000 for a small entity, which sounds trivial until you notice it is priced as labor. Somebody's labor. And under 252.204-7012 you flow the whole apparatus down to your own suppliers, which means you now operate a small compliance program pointed at other companies.
Between those events sits evidence upkeep. Access reviews that have to be current, not reconstructed. Configuration changes documented as they happen. Training records, incident logs, asset inventories, a system security plan that matches the systems you are actually running rather than the ones you described eighteen months ago. None of that is hard. All of it is continuous, and it is invisible until an auditor or a prime's portal questionnaire asks for it on a date you did not pick.
In a 200-person shop, three roles absorb this. Quality, because it already owns the audit muscle and the document control habit. IT, which is frequently one or two people who also fix laptops. And program management, because the flowdown and the customer portal submissions live where the contract lives. Nobody hired for it. It was added to existing jobs, in slices small enough that no single week looks like a problem.
The right question is therefore not what CMMC costs. It is which three roles permanently lose a day a week to it, and whether that is the trade you would have made if anyone had put it in front of you as a trade. We have watched the same pattern outside defense: a recurring obligation gets absorbed into existing headcount and never appears in a budget line, which is the same dynamic we described in what an AI pilot costs when you include the parts nobody quotes. Cost that never becomes a line item never gets managed.
This is the general shape of the problem. Which parts apply to your process depends on answers only your systems can give.
Put us on it, from $5,000The Phase 2 pause changed the deadline, not the burden
If you have been waiting this out, the last twelve months rewarded you and then took the reward back.
The acquisition side of the rule took effect on November 10, 2025, adding DFARS 252.204-7021 and making CMMC status a condition of award. Phase 2, which would have required third-party certification on most Level 2 contracts, was set for November 10, 2026. On July 13, 2026, DoD suspended it and froze the later phases, and stood up a task force to run a top-to-bottom review of the program.
Read the suspension carefully, because a lot of people have read it as amnesty. It is a policy memorandum governing what DoD's own contracting officers must impose. The regulation was not amended. 7012, 7019, 7020 and 7021 remain in force exactly as written. Phase 1 self-assessments still apply. Annual affirmations through SPRS still apply, and the Justice Department's civil cyber-fraud work still treats a false one as a false claim.
And relief does not flow downhill. Your obligations as a subcontractor are set by your prime's subcontract terms, not by a DoD memo addressed to DoD personnel. Primes that have already issued supplier notices with hard dates are under no obligation to withdraw them, and several have not.
So what the pause actually removed was the third-party assessment fee, on a schedule, for a while. It removed the single largest quoted number and left every recurring obligation standing. If your compliance plan was a purchase order, you just got a reprieve. If your compliance plan was three people and a spreadsheet, nothing changed and you now have less external pressure to fix it, which is worse.
What is actually automatable here, and what is not
The honest split matters, because this is where shops waste money in both directions.
Evidence collection is genuinely automatable. It is rule-driven, it produces artifacts, and it runs on a schedule: pulling access reviews, capturing configuration state, timestamping training completions, assembling the same package for the same portal every quarter. That is the profile automation handles well, and the same reasoning applies to document control and audit routing under AS9100 for shops carrying both. If you are trying to think about which recurring work justifies the build, our note on how to calculate automation ROI covers the arithmetic, and what workflow orchestration actually is covers the plumbing that makes a multi-system evidence pull hold together.
Judgment is not automatable, and buying software to avoid hiring for it is the expensive mistake. Somebody has to decide whether a finding is a deficiency or a documented risk acceptance. Somebody has to sign the affirmation. Somebody has to sit across from an assessor and explain a decision made two years ago. A tool that assembles evidence and nobody who can defend it produces a very well-organized failed assessment.
The inverse error is just as common and costs more over time. Hiring a compliance manager to solve what is fundamentally a data-gathering problem means paying a salaried professional to build spreadsheets, and they will leave, and their spreadsheets will not survive them.
Most 200-person shops need less of both than they have been quoted, arranged differently. The evidence layer should be built once and cheaply. The judgment should sit with someone senior enough to sign, part-time. Getting that split right is worth more than the certification fee either way. Call it the compliance cost of doing business, though in this case it is more like the business of doing compliance costs.
The question to answer before you spend anything
Not "are we compliant." That question has no useful answer at a point in time, because compliance here is a state you maintain, not a state you reach.
Ask instead: if a prime sent a portal questionnaire tomorrow with a 30-day date on it, whose calendar would clear to answer it, and what would stop moving while they did? Every shop we have looked at can answer that immediately, and the answer is always a name, and it is usually the same name that runs first-article inspection or closes the month.
That is your compliance cost. It has been on the books for years. It was just never written down.
If you are trying to work out which parts of this genuinely need a person, which parts should have been automated in 2019, and what the Phase 2 pause means for the specific flowdown language sitting in your subcontracts, that is a conversation about your contracts and your headcount, not a checklist. Talk to us and we will look at what you are actually obligated to do, and tell you where you are overbuying.
