Why "Free" Self-Assessment Costs $388,600
There's no assessor to pay. So where does the money go? SBA's own number, read correctly, is the most useful thing published all month.
SBA's estimate of what total compliance costs can reach for a small firm eligible for self-assessment — an upper bound, not a typical invoice. Source linked below.
On July 13, 2026 — the same day the Department of War suspended CMMC Phase II — the Small Business Administration published a statement applauding the move. Buried in it was a pair of numbers that deserve more attention than they've gotten.
According to SBA, total compliance costs for a small firm requiring third-party assessment can reach roughly $593,800 per certification. And for firms eligible for self-assessment — no C3PAO, no third-party audit, no assessor invoice at all — total costs can still reach roughly $388,600.
Sit with that second number for a second. Self-assessment is the pathway with no assessor to pay. It's the one the market has spent five years calling "the free option." And SBA says it can still cost a small business nearly four hundred thousand dollars.
Read carelessly, that number makes self-assessment look impossible — one more reason for a small contractor to freeze. Read correctly, it's the opposite. It tells you exactly what the real cost driver of compliance is, and it turns out to be the one variable you can actually change.
What SBA Actually Said (and What It Didn't)
First, precision — because these figures get mangled constantly, and the mangled versions will mislead you.
Three things to be clear about:
- These are total compliance costs, not audit fees. They cover remediation, tooling, platform migration, documentation, internal labor, and the assessment itself. Anyone who tells you "$593,800 is what an audit costs" is misreading the source — the assessment is one line item inside a much larger total.
- They are upper bounds, not typical invoices. SBA's language is what costs "can reach" — the ceiling, not the median. Plenty of small contractors get compliant for far less. But the ceiling exists for a reason, and that reason is the subject of this article.
- The gap between the two figures is smaller than you'd expect. Removing the entire third-party assessment apparatus — the C3PAO, the audit prep, the formal certification event — takes about $205,000 off the ceiling. That leaves $388,600 that has nothing to do with anyone assessing you.
Which raises the obvious question. If the assessor isn't the expense, what is?
Where the Money Actually Goes
SBA published totals, not a line-item breakdown. So to be explicit: what follows is our analysis — drawn from years of working with small defense contractors on exactly this — of where compliance labor and money actually disappear when a small firm attempts NIST SP 800-171 work without structure. SBA didn't itemize this; we're showing you what we see in the field.
Bad scoping — the single most expensive mistake
A contractor who doesn't know how to draw the assessment boundary defaults to the safe-feeling answer: everything is in scope. Then they spend months hardening laptops, servers, and cloud accounts that never touch federal contract information. Every control applied to a system that didn't belong in the boundary is pure waste — and over-scoping can multiply the size of the job several times over before a single artifact is produced.
The rework cycle
Build documentation from a blog post and a template found online. Discover months later — from a prime's questionnaire, a peer, or a closer reading of the standard — that it doesn't actually evidence the practice. Rebuild it. Repeat. We routinely meet contractors on their second or third full rebuild of the same document set. The practices didn't change. The understanding did, one expensive iteration at a time.
Hourly consultants explaining the basics
Traditional consulting bills by the hour — and for a small contractor starting cold, the first many hours are spent on questions like "what is an SSP?" and "what counts as evidence?" That's real money spent acquiring orientation, not progress. The meter runs the same whether the hour produces an artifact or a vocabulary lesson.
Tooling nobody needed
Enterprise security products sold to five-person shops. SIEM subscriptions for environments with nothing to feed them. Compliance platforms that generate dashboards but not evidence. When you don't know what the requirement actually asks for, "buy something" feels like progress — and it compounds annually.
Months of owner evenings
The least visible cost and often the largest one. In a small shop, the person doing compliance is the owner or the one technical employee — and every evening spent wandering through NIST SP 800-171 is an evening not spent on billable work, proposals, or the business itself. Internal labor at the owner's true hourly value is where a "free" pathway quietly becomes a six-figure one.
Notice what every one of those categories has in common. None of them is a fee. None of them is imposed by the government. Every single one is a function of doing the work without knowing what the work is.
The expensive part of compliance was never the assessment. It was doing it without a map. The requirement is fixed. The wandering is optional.
The Requirement Is Fixed. The Wandering Isn't.
Here's why this matters more right now than it did a month ago.
Since Phase II was suspended on July 13, self-assessment isn't the budget alternative anymore — it's the assessment path. Phase I self-assessment requirements remain firmly in place, DFARS 252.204-7012 still binds you, NIST SP 800-171 Rev 2 is being enforced during the interim, and primes are still gating awards on compliance. (We covered all of this in Part 2 and Part 3 of this series.)
So every small contractor in the DIB is now looking at the same to-do list. The controls you must implement are the same for everyone. The evidence a defensible self-assessment requires is the same for everyone. What varies — enormously — is how much labor gets burned getting there. Two contractors with identical environments can spend wildly different amounts reaching the same defensible posture, and the difference is almost entirely explained by one thing: whether they knew where they were going.
That's what makes SBA's number our favorite statistic in this entire news cycle. It quantifies the fog. And unlike the requirement itself, the fog is something you can eliminate.
With a Map vs. Without One
❌ Without a Map
- Scope the boundary by guesswork — usually too wide, occasionally too narrow, both expensive
- Discover the artifact list one surprise at a time, months in
- Write documentation, learn it's inadequate, rebuild it — twice
- Translate generic enterprise templates to your actual platform yourself
- Pay hourly for orientation before anyone touches an artifact
- Buy tools first, ask what the requirement wanted later
- Timeline: open-ended. Cost: whatever it turns out to be.
✅ With a Map
- Know the full artifact list on day one — all 142 of them for Level 1
- Scope the boundary correctly before hardening anything
- Work from templates written for your platform — Microsoft 365 or Google Workspace — no translation step
- Follow step-by-step configuration guides for every device type
- Ask an expert when you're stuck, in scheduled sessions — no meter running
- Build each document once, correctly, with the evidence standard in view
- Timeline: most clients finish Level 1 in 2–4 weeks.
Same requirement. Same 15 practices. Same destination. The only variable that changed is structure — and structure is the entire difference between a contained project and an open-ended one.
An Honest Cost Comparison (Done Right)
This is the part of the article where a vendor usually puts its price next to the scariest available number and lets the contrast do the selling. We're not going to do that, because the naive version of that comparison is dishonest — and you'd be right to distrust it.
So let's be precise about what our L1 Turnkey Package does and doesn't do:
What $2,495 does not do
It does not "replace" $388,600, and we won't pretend it does. That figure is an upper bound on total compliance cost, and a large share of any real total is your own labor — implementing controls, configuring systems, gathering evidence. That labor doesn't vanish because you bought a package. You still do the work.
What it does do
It attacks the wasted portion of that labor — which, in our experience, is the portion that turns a manageable project into a runaway one. The wandering, the over-scoping, the rebuilt documentation, the hourly orientation, the tooling detours: those are the costs that structure eliminates. What's left is the necessary work, done once, in the right order, with someone to ask when you're stuck.
That's the honest pitch. Not "we make compliance free." Rather: we make compliance cost what it actually needs to cost — instead of what confusion inflates it to.
For contractors handling CUI, the same logic applies at Level 2 — the L2 CUI Enclave Package maps 110 practices to 182 defined artifacts on a dedicated enclave, with no Active Directory, SIEM, or enterprise IT required.
What the Map Looks Like
The Turnkey CMMC Level 1 Compliance Package — $2,495/year (limited time: save $500 off the regular $2,995) — is the map, drawn in full before you take a step:
- All 15 CMMC Level 1 practices broken into 142 required artifacts — the complete list, visible on day one, so nothing surprises you in month four
- Platform-specific templates for Microsoft 365 or Google Workspace — written for the environment you actually run, not a generic enterprise you don't
- All 8 device & network configuration guides — Windows, Mac, iOS, Android, home and small-office networks, step by step
- 8 bi-weekly expert consultation sessions — scheduled structure that keeps momentum, and a person to ask before a wrong turn becomes a rebuild
- Evidence Locker & SPRS report — evidence organized as you go, so the assessment at the end is an assembly, not an excavation
- Self-assessment documentation, packaged and date-stamped — the finished, defensible product
Most clients complete their Level 1 self-assessment in 2–4 weeks. Timelines vary with your existing infrastructure and responsiveness — but they vary in weeks, not in fiscal quarters, because nobody is wandering.
Find Out Where You Actually Stand — Free
Before spending a dollar, spend 30 minutes. Our free CMMC Assessment Tool evaluates all 15 Level 1 practices and hands you an instant gap report with a prioritized roadmap. No credit card, no obligation.
Run the Free Assessment ToolThe Barrier Was Never the Certificate
SBA's numbers were published as an argument for regulatory relief, and fair enough — the Phase II suspension relieved real pressure. But for the small contractor deciding what to do this quarter, the more useful reading is the one almost nobody wrote about.
The $388,600 ceiling on a "free" pathway proves that fees were never the problem. The audit was never the problem. The problem, all along, was the fog — not knowing the boundary, not knowing the artifact list, not knowing whether the document you just wrote will hold up. The fog is what inflates a bounded project into a six-figure ordeal.
And the fog is the one part of this you can buy your way out of — for a great deal less than what wandering costs.
The requirement stands. Your obligations under DFARS 7012 stand. Your prime's expectations stand. The only question left is whether you'll meet them with a map or without one.
Talk It Through With Us — Free 30 Minutes
Bring your questions about scoping, your platform, your contracts, or SBA's math. We'll tell you honestly what your path looks like — including whether our package is the right fit. No pressure, no meter running.
Book a Free 30-Minute ConsultationSources
- SBA — Statement on the Department of War's Suspension of CMMC Phase II (July 13, 2026)
- Department of War — Official Release on the CMMC Phase II Suspension (July 13, 2026)
- DefenseScoop — Pentagon Halts CMMC Phase 2 Requirements
- National Defense Magazine — Pentagon Suspends Phase 2 of CMMC Program
- NIST SP 800-171 Rev 2 — Protecting Controlled Unclassified Information
This article is provided for informational purposes only and does not constitute legal advice. Cost figures cited are SBA-published upper bounds on total compliance costs, not typical invoices, and individual results vary. Consult your contracts and, where appropriate, qualified counsel regarding your specific obligations.
Overwatch Tools — CMMC Compliance Specialists
Making CMMC Compliance Achievable for Small Defense Contractors
Chesapeake, Virginia · overwatchtools.com · info@overwatchtools.com
The Self-Assessment Era — Part 5 of 6. Next: the move that's right no matter what the Task Force decides.
