According to advocacy.sba.gov, the U.S. Department of War (DoW) has issued a request for information (RFI) seeking feedback from companies in the defense industrial base to inform its newly established Cybersecurity Maturity Model Certification (CMMC) Reform Task Force.
Background
CMMC is a tiered program used to assess the cybersecurity compliance of any organization doing business with the DoW. On July 13, 2026, the DoW suspended Phase II CMMC requirements, which had been set to take effect on November 10, 2026. Alongside that suspension, the department established a CMMC Reform Task Force tasked with comprehensively reviewing the program and delivering actionable recommendations for reform.
Through the RFI, the DoW is seeking industry input on using existing commercial cybersecurity capabilities, optimizing self-attestation processes, and streamlining compliance requirements overall.
What the RFI Is Asking
The RFI poses several specific questions to industry, including requests to:
- Identify the top cost drivers, administrative burdens, or operational challenges organizations face (or expect to face) in complying with the CMMC framework and NIST SP 800-171 Rev 2.
- Flag which security controls have delivered meaningful cybersecurity improvement versus which create high administrative or financial burden with little measurable benefit.
- Describe how companies currently use commercial cybersecurity platforms or managed services, and how DoW might better recognize those solutions within a compliance framework.
- Detail challenges with Phase I self-assessments and how that process could be streamlined.
- Recommend specific policy changes the task force should make within 60 days to reduce costs and barriers for small, medium, and non-traditional businesses without weakening protection of federal data.
The DoW says it will use the responses to help “definitively reduce compliance and cost burdens on small, medium, and non-traditional companies.”
