CMMC Assessment Checklist
If you think you are ready for a CMMC assessment, use this resource to test where you actually are before contacting a professional.
Key Takeaways:
The cost of the CMMC certification journey is one of the most frequently discussed topics in the ecosystem. This was true even when the Department of Defense launched CMMC 1.0. In particular, small to mid-size organizations expressed concerns about whether they would be able to afford CMMC compliance or whether they will eventually find themselves priced out of DoD contract work.
One of the obstacles in the way of offering a “ballpark” price for a CMMC assessment is that organizations have different factors in their journeys. Organizations already compliant with ISO 9001, AS9100, ISO 27001, or IATF 16949 may have an easier time preparing for a CMMC assessment than a business starting from scratch. A company with some existing cybersecurity infrastructure will have an easier time, and a less expensive time, than a company building a cybersecurity defense from scratch.
Beyond these factors, a contractor might hire a Managed Service Provider (MSP) or a Managed Security Service Provider to assist. They may hire a Cloud Service Provider or a vendor who sells GRC software. Consultants may also appear to help fill gaps after a CMMC pre-assessment. All of these vendors charge their own rates, and often those rates also vary by project.
Last but not least, a C3PAO will need to complete your CMMC third-party assessment, and C3PAO pricing also varies by project and by vendor.
At Smithers, we use our 30 years of experience as an ANAB-accredited certification body to make the quoting process as seamless and transparent as possible. This means no flat rates, and all quotes are customized. Smithers bases quotes on the size of the organization, the number of locations, what types of systems we will assess, and more. Everything is spelled out and itemized in the documentation.
Smithers does not control your vendor choices in any other area of your CMMC compliance journey, although consultant recommendations are available when needed.
Are you ready to start your CMMC assessment quote? Let’s kick off an initial conversation. Contact Smithers today. We are looking forward to learning about your organization.