Everyone published the suspension. Almost nobody published the part where the Department asked you a direct question and left a mailbox open for the answer.

The CMMC Reform Task Force RFI is a Request for Information issued by the Department of War on July 14, 2026, titled “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB).” It asks seven questions about what CMMC compliance has cost, which security controls delivered real risk reduction, and what should replace the third-party assessment model. Responses are due by 12:00 p.m. Eastern Time on Friday, August 14, 2026, submitted by email. The answers feed the CMMC Reform Task Force, which must report to the Department CIO roughly sixty days after the July 13 suspension.

KEY TAKEAWAYS
  • Responses close at 12:00 p.m. Eastern on Friday, August 14, 2026. There is no filing fee, no registration, and no portal. It is an email.
  • Five of the seven questions ask about cost, administrative burden, or reform. The Department asked the Defense Industrial Base to price its own compliance, which is a question small subcontractors can answer better than anyone.
  • Primes and trade associations have people whose job is to file these. A 14-person machine shop does not, which is exactly why the record will skew toward large-business experience unless small firms write in.
  • Dollar figures, hours, and named controls carry weight. Adjectives do not. The RFI asks for your top five cost drivers, not your opinion of the program.
  • Nothing you file changes your current obligations. DFARS 252.204-7012, NIST SP 800-171 Rev 2, your SPRS score, and your annual affirmation are all still live while the Task Force works.

What Is the CMMC Reform Task Force RFI, and Who Is It Actually For?

On July 13, 2026, the Department of War suspended Phase 2 of the CMMC program. Phase 2 was the milestone that would have made third-party certification by a C3PAO a condition of award on contracts involving controlled unclassified information, starting November 10, 2026. The suspension came through two memoranda rather than a rule: a policy memorandum from the Department CIO and an implementation memorandum from the Under Secretary of Defense for Acquisition and Sustainment. Reporting on the announcement noted that the CIO memo suspends all pending and future CMMC milestones until further notice, which pulls Phase 3 and Phase 4 into the pause as well.

Alongside the suspension, the Department stood up a CMMC Reform Task Force and told it to come back with recommendations within sixty days. On July 14 it posted the RFI that feeds that work.

An RFI is not a rulemaking. There is no docket on regulations.gov, no formal comment period under the Administrative Procedure Act, and no legal obligation on the agency to respond to what you send. What there is instead is a Task Force on a very short clock that has publicly said it wants to reduce cost and barriers for small, medium, and non-traditional businesses, and a mailbox that closes in a matter of days.

That combination is unusual. Most of the time, small defense subcontractors experience federal cybersecurity policy as something that arrives fully formed in a contract clause. This is the narrow window where the direction of travel is still open.

Timeline showing July 13 CMMC Phase 2 suspension, July 14 RFI posting, August 14 RFI close, and the mid-September Task Force report

Why Would a 14-Person Shop’s Response Carry Any Weight?

Because of who else is writing.

Large primes maintain government affairs functions. Trade associations maintain policy staff. Both will file, both will file well, and both will describe compliance from the vantage point of an organization with a dedicated security team, an existing GRC platform, and the ability to absorb an assessment cycle as a line item.

The experience the Task Force says it wants to understand belongs to a different population. A firm with 14 employees, one person handling IT alongside three other jobs, and a single DoD program does not have a government affairs function. It has a Tuesday. The result is a predictable asymmetry in the record: the loudest documented burden comes from organizations for whom the burden was survivable.

There is a second reason, more practical. The RFI does not ask for a position paper. It asks for data. Question one asks for your top five cost drivers. Question three asks which specific requirements generated the most administrative overhead for the least measurable security improvement. Those are questions you can answer from your own invoices and calendar in an afternoon, and the answers are not available to the Department from any other source.

What Are the Seven Questions the RFI Asks?

The full text lives in the notice on SAM.gov. The Office of Advocacy at the Small Business Administration published the question list in its regulatory alert, which is the easiest place to read them without navigating the contract opportunity system. In summary, the RFI asks:

  1. Your top five most prohibitive cost drivers, administrative burdens, or operational challenges in complying with CMMC and NIST SP 800-171 Rev 2, whether already experienced or anticipated.
  2. Which specific security controls delivered the most tangible cybersecurity uplift and actual risk reduction.
  3. Conversely, which specific requirements or controls created the highest administrative and financial burden with the least measurable improvement to your security posture.
  4. How your organization already uses commercial cybersecurity capabilities, platforms, or managed services, and how the Department might recognize or accept those within a compliance or risk framework.
  5. What administrative or technical challenges you face maintaining, verifying, and reporting Phase 1 self-assessment compliance, how that could be streamlined, and whether self-assessment actually changed your posture or was performed purely for compliance.
  6. What specific, actionable policy changes the Task Force should recommend in the next sixty days to reduce cost and barriers to entry for small, medium, and non-traditional businesses without degrading protection of federal data.
  7. What specific, actionable policy changes the Task Force should recommend to improve operational resilience against cyber attacks at your organization.

Three-column breakdown of the seven CMMC RFI questions grouped into burden, value, and reform

Read as a set, the questions have a shape. Five of the seven are about burden or reform. Question two is the only one that invites you to defend the program, and question four is a fairly transparent invitation to argue that a commercial security stack should count for something.

What Belongs in the Cost-Driver Answer?

Numbers you can stand behind.

The most useful response to question one is a short list of line items with dollar figures and hours attached, sourced from things you already have. Consultant invoices. The quoted price of a C3PAO engagement, if you got one. The cost of the tooling you bought specifically to close a control gap, separated from tooling you would have bought anyway. Hours spent building the system security plan, and by whom. Hours spent per year maintaining evidence for a self-assessment nobody has yet asked to see.

Two distinctions are worth drawing explicitly, because they are the ones that get collapsed in aggregate industry data:

Separate security spend from compliance spend. Multi-factor authentication is security spend. It would have been worth doing without a clause. Writing the policy document that describes your MFA implementation, mapping it to 3.5.3, collecting the screenshot, and storing it where an assessor could find it is compliance spend. Both are real. Only one of them stops an intrusion, and question three is asking you to name the second category.

Separate one-time from recurring. A gap assessment is a one-time cost. The annual affirmation, the SPRS update, and the evidence refresh are recurring, and for a small firm the recurring number is often the one that decides whether DoD work stays viable. If you have already worked through what implementation actually costs at your size, the underlying figures are in our breakdown of NIST 800-171 implementation cost.

If your numbers are scattered across email threads and memory, that is itself a finding worth reporting. Most small subs cannot produce a clean compliance cost figure on demand, and the Department should know that.

Which Controls Should You Name as High Value, and Which as High Burden?

Name them by number. “Documentation requirements are burdensome” is a sentence the Task Force will read four hundred times. “3.12.4 consumed roughly 60 hours of owner time and produced a document that has never been read by anyone outside this building” is a data point.

For question two, the honest answers from small manufacturers tend to cluster in a few places: multi-factor authentication, removable media restrictions, and access control changes that visibly reduced the attack surface. Say so if that matches your experience. A response that only complains reads as an argument against security rather than against compliance overhead, and it is the second argument the Task Force actually asked for.

For question three, the candidates are usually the requirements where the artifact is the deliverable rather than the control. Policy documents that duplicate what a written procedure already says. Evidence collection cadence that exceeds any plausible review frequency. Scoping documentation for environments with a handful of endpoints. Whatever your version is, describe the work and the output, then say what the output was worth.

What Does the Department Want to Hear About MSPs and Commercial Tooling?

Question four is the one with the clearest policy intent behind it. The Department asked how it might recognize or accept commercial cybersecurity capabilities within a compliance framework, which is a way of asking whether an existing attestation, a managed service provider’s controls, or a platform’s built-in compliance mapping could substitute for part of an assessment.

If you run on a managed service provider, describe the arrangement concretely: what they operate, what they attest to, what evidence they hand you, and what you still have to prove yourself. If you have ever paid twice for the same assurance, once to your MSP and once to a consultant translating the MSP’s work into 800-171 language, that is precisely the duplication the question is fishing for. The mechanics of where provider responsibility ends are covered in our piece on CMMC external service provider requirements.

How Do You Actually Submit It?

By email, to the two addresses listed in the notice, formatted according to the Format section of the RFI itself. Read that section before you write. It governs file format and structure, and a response that ignores it can be set aside for reasons that have nothing to do with its content.

The submission addresses published by SBA’s Office of Advocacy are whs.mc-alex.ad.mbx.eosd-psb-branch-mailbox@mail.mil and leanne.m.condren.civ@mail.mil. The deadline is 12:00 p.m. Eastern on Friday, August 14, 2026. Noon, not midnight.

A few practical notes. Do not include CUI, proprietary pricing you are not willing to see summarized, or anything you would not want read by someone outside your company. Mark clearly whether you are responding as an individual firm or on behalf of members. State your size, your role in the supply chain, and your CMMC level, because context is what makes a cost figure interpretable. And keep it short. A focused four pages that answers the questions asked will be read; thirty pages of program history will not.

What Does Not Change While the Task Force Works?

This is the part where the suspension coverage has done real damage.

Two-column comparison of CMMC requirements suspended after July 13 versus requirements still in force

The suspension changed how compliance gets verified. It did not change what you owe. DFARS 252.204-7012 still requires implementation of NIST SP 800-171 Rev 2. Phase 1 self-assessment requirements remain in applicable solicitations. Your SPRS score is still a representation you made to the government, and your annual affirmation is still due. Government-led assessments continue, which is the topic of our piece on DIBCAC assessment preparation.

False Claims Act exposure is untouched. The Department did not suspend the Civil Cyber-Fraud Initiative, and a score that does not match the evidence behind it carries the same risk on August 15 that it carried on July 12. For the fuller version of this, see Is CMMC Still Required?.

The practical consequence is that the work you would do to answer question one well is the same work you should be doing anyway. You cannot report what compliance cost you without knowing what you implemented, and you cannot know what you implemented without evidence. Our walkthrough of self-assessment evidence covers what that record needs to contain.

If you are assembling that record from scratch under a deadline, the CMMC Level 2 Readiness Kit: 5 NIST 800-171 Tools ($147) bundles the scoping worksheet, SSP template, SPRS workbook, evidence tracker, and POA&M tracker into one set. It exists for the moment when a prime asks for documentation on two weeks’ notice and there is no security team to hand it to. If all you need is the evidence side, the CMMC Level 2 Evidence Tracker for NIST 800-171 Audit ($67) is the standalone.

Common Questions

Do I have to be a registered SAM.gov entity to respond? The RFI is posted as a contract opportunity on SAM.gov, but submission is by email to the addresses in the notice. Read the Format section for any conditions the Department placed on respondents.

Will my response be made public? Treat it as though it will be. RFI responses are routinely summarized, and agencies are not obligated to keep them confidential absent a specific claim. Do not include anything sensitive.

Does responding create any obligation or risk? Responding to an RFI does not obligate the government or the respondent, and it is not a proposal. That said, do not describe your compliance posture in terms that contradict what you have attested to in SPRS. Consistency matters more than usual right now.

Is it too late to matter if I file on August 13? No. The Task Force reads what arrives before the close. Late is a different question, and the close is a specific clock time.

Should I still pursue certification readiness? Your contract governs, not the memo. If a clause is in your awarded contract, it binds until a contracting officer modifies it, and primes are largely holding their flow-down requirements steady because their own obligations did not change on July 13.

The Bottom Line

The Department asked the Defense Industrial Base a question it has never asked this directly: what did this cost you, and what did you get for it. It gave thirty-one days to answer and it is going to write recommendations from whatever shows up.

The firms with the most to gain from a cheaper compliance model are the firms least equipped to make the case for one. That gap is not going to close on its own by August 14. It closes when someone with 14 employees and a real invoice spends two hours writing it down.

Sources