What: The U.S. Department of War (DoW) issued a request for information (RFI) seeking feedback from companies in the defense industrial base. The information will be used to inform the DoW’s new Cybersecurity Maturity Model Certification (CMMC) Reform Task Force.
Why: CMMC is a tiered program used to assess the cybersecurity compliance of anyone doing business with DoW. On July 13, 2026, the DoW suspended Phase II CMMC requirements, which were supposed to take effect on November 10, 2026. The DoW also established a CMMC Reform Task Force “to comprehensively review the program and deliver actionable recommendations for reform.”
The DoW is seeking “industry perspectives on utilizing existing commercial cybersecurity capabilities, leveraging and optimizing self-attestation capabilities, and streamlining cybersecurity compliance requirements.”
In the RFI, DoW poses the following questions:
- Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced, or anticipates to experience, when attempting to comply with the CMMC framework and NIST SP 800-171 Rev 2.
- Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction?
- Conversely, which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture?
- Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk, and how the DoW might better recognize or accept these commercial solutions within a compliance or risk framework.
- Regarding Phase I self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance, and how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture approach, or are they performed only for compliance purposes?
- What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses without degrading the protection of federal data?
- What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically improve operational resilience against cyber-attacks at your organization?
The information gained from the RFI will be used by the DoW’s CMMC Reform Task Force to “definitively reduce compliance and cost burdens on small, medium, and non-traditional companies.”
Action: Read the memo suspending the Phase II CMMC requirements and submit comments before the August 14, 2026, deadline.
Comments must be emailed to whs.mc-alex.ad.mbx.eosd-psb-branch-mailbox@mail.mil and leanne.m.condren.civ@mail.mil. Additionally, all comments must conform to the instructions in the “Format” section of the RFI.
MEMO:
Implementing the Suspension of the Advancement to CMMC Phase 2 Requirements
(PDF, 736 KB)
REQUEST FOR INFORMATION:
Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)
CONTACT:
Nick Goldstein
EMAIL:
Regulatory Alerts
Is your small business or entity being impacted by a proposed rule? If yes, write a comment letter to the proposing agency.