Skip to main content
Rule Updates

The CMMC Reform RFI Is Open: Contractors Have Until August 14 to Shape What Replaces Phase 2

When the Department of War suspended CMMC Phase 2, the more consequential document was the one it posted the same day: a Request for Information asking the Defense Industrial Base what should replace it. Responses close August 14, 2026 — the window for contractors to put their real cost-and-burden data on the record.

Brandon Hancock, J.D., CMMC-RPPublished July 20, 2026Updated July 20, 20266 min read

When the Department of War suspended CMMC Phase 2 on July 13, the headline was the pause. The more consequential document was published the same day: a Request for Information asking the Defense Industrial Base what the program should become. Responses close August 14, 2026.

On July 13, 2026 — the same day it suspended CMMC Phase 2 — the Department of War (DoW) posted a Request for Information (RFI) on SAM.gov titled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)" (Notice ID DoDCIOReformingCMMCforDIB001), with responses due by 12:00 p.m. ET on Friday, August 14, 2026. The RFI feeds the newly stood-up CMMC Reform Task Force, which is due to deliver recommendations to the DoW Chief Information Officer within 60 days. For contractors, this is the rare moment when the agency is openly asking the industry what to keep, what to cut, and what to replace — before it decides. It is a comment window, and it is short.

Why This Is Not the Same Story as the Suspension

The Phase 2 suspension told contractors what is paused. The RFI is where the replacement gets written. The Task Force's report — expected around mid-September 2026 — will shape whatever comes next, and that report is being built substantially from what the DIB submits over the next few weeks. A contractor that spent the last year preparing for C3PAO certification has direct, on-the-ground evidence of exactly the cost and burden data the Department says drove the pause. This is the channel to put that evidence on the record. Sitting it out means the reform gets shaped by whoever does respond.

What the Department Is Actually Asking

The RFI is not a general "tell us your thoughts" solicitation. It poses targeted questions, and answering them specifically is what makes a response useful. The Department is asking, among other things:

  • Where the real cost and burden sits. The most significant cost, administrative, and operational challenges of complying with CMMC and NIST SP 800-171 Rev. 2 — the interim baseline during the review.
  • Which controls actually reduce risk. Which cybersecurity requirements deliver the greatest measurable reduction in cyber risk, and which impose high administrative or financial burden while offering limited security benefit.
  • How industry already protects data. How companies use commercial cybersecurity technologies, managed services, and self-attestation to safeguard sensitive information and improve operational resilience.
  • What reforms are feasible now. Policy and regulatory changes that could lower barriers to entry for small, medium-sized, and nontraditional contractors while maintaining a security baseline.

Responses are accepted by electronic means only, per the instructions in the SAM.gov notice. Read the notice itself before drafting — the submission mechanics and any page or format limits are set there, not in secondary summaries.

How to Make a Response Count

A useful RFI response is concrete, not rhetorical. Generalized complaints about "burden" carry less weight than a specific control paired with a specific cost and a specific alternative that achieves the same security outcome. If a requirement is expensive and low-value in your environment, say which control, quantify the cost, and describe what you would do instead. If a commercial tool or managed service already delivers a required outcome, name it and explain how the Department could recognize that investment. Grounding your comments in your actual NIST SP 800-171 framework implementation — the controls you have mapped, assessed, and scored — is what turns an opinion into evidence the Task Force can act on.

What Does Not Change While You Comment

Responding to the RFI is not a substitute for compliance. DFARS 252.204-7012 still applies, Phase 1 self-assessment obligations remain in force, and NIST SP 800-171 Rev. 2 is the interim enforcement baseline. The Department has been explicit that suspending Phase 2 "does not eliminate the requirement for companies to protect federal data." False Claims Act exposure tied to inaccurate SPRS scores — the through-line in DOJ's cyber-fraud settlements, including the recent LOGZONE Navy resolution — is unaffected by the reform review. Use the comment window to influence the future rules; keep meeting the current ones in the meantime.

Key Takeaways

  • The CMMC Reform RFI closes August 14, 2026, at 12:00 p.m. ET. It is posted on SAM.gov (Notice ID DoDCIOReformingCMMCforDIB001) and feeds the CMMC Reform Task Force's ~60-day report to the DoW CIO — this is the window to influence what replaces Phase 2.
  • Specific beats general. Name the control, quantify the cost or burden, and propose an alternative that preserves the security outcome; ground it in your actual NIST SP 800-171 Rev. 2 implementation.
  • Commenting is not compliance. DFARS 252.204-7012, Phase 1 self-assessments, and SPRS accuracy still apply — and FCA enforcement risk continues regardless of the review.

Not sure which requirements actually apply to your contract mix before you comment? Start with Find My Requirements, work the control detail on Frameworks, and use our program-building guide to keep remediation moving while the reform review runs.

---

This article is educational information about federal procurement and cybersecurity requirements. It is not legal advice, and it does not create an attorney-client relationship.

Primary source: U.S. Department of War, Request for Information, "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)," Notice ID DoDCIOReformingCMMCforDIB001, posted July 13, 2026, responses due August 14, 2026 (SAM.gov). See also DoW release, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026), war.gov.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?