> ## Content Index
> Fetch the complete content index at: https://www.cmmcoperator.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# How the CMMC Reform RFI Worked: The Seven Questions and How to Respond
- URL: https://www.cmmcoperator.com/cmmc-reform-task-force-rfi-how-to-comment/
- Published: 2026-07-24T01:28:08.000Z
- Updated: 2026-08-19T23:46:18.000Z
- Description: The Reform Task Force asked contractors what CMMC actually costs. The seven questions in plain English, the submission mechanics, and a template for writing a comment that gets used - kept as reference for future RFI cycles.
- Author: HydratedSec
- Tags: Documentation & Assessment, NIST 800-171

The Phase 2 suspension came with a homework assignment, and it is addressed to you. The CMMC Reform Task Force is running a formal request for information titled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base," and it asks contractors directly, with explicit emphasis on small, medium, and non-traditional businesses, to say what CMMC actually costs and what should change. **Comments closed August 14, 2026.** If the review produces the framework you will live with for the next decade, that window was where contractors got a say in it - and the mechanics below apply to any future RFI cycle the task force or a successor opens. (Context on the suspension itself: [what changed and what did not](https://www.cmmcoperator.com/cmmc-phase-2-suspended/).)

**Status, updated August 19, 2026.** The comment period closed on August 14\. The Reform Task Force is expected to deliver its recommendations to the DoW CIO in mid-September, and the instruments on the table include a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170\. The earliest realistic date for a formal announcement is mid-October, with a credible chance nothing lands until late 2026 or early 2027\. Those expectations come from practitioner reporting on the July 13 suspension memo, not from a published DoD milestone, so treat them as forecasts rather than deadlines. Nothing has changed for contractors in the meantime: Phase 2 is suspended, not repealed. 32 CFR Part 170 has not been rescinded, and DFARS 252.204-7012, NIST SP 800-171 Rev 2 self-assessments and annual affirmations in SPRS all still apply.

## The mechanics: where, how, by when

- **What:** a request for information, "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)," issued by the Department of War.
- **Where:** posted on SAM.gov as Notice ID 89ef9bfb0834473791e991c712698d94 \- search that ID at [SAM.gov](https://sam.gov/?ref=cmmcoperator.com) to pull the notice. Responses go by email to the submission mailbox listed in the notice (whs.mc-alex.ad.mbx.eosd-psb-branch-mailbox@mail.mil), following the notice’s instructions for subject line and point of contact.
- **When:** this RFI's window closed **August 14, 2026**. The process below is the template for responding to any future DIB-facing RFI.
- **Who:** DIB companies. The notice singles out small, medium, and non-traditional businesses, which is most of the readership of this site.

*Work from the live notice: confirm the mailbox, format instructions, and deadline against the SAM.gov posting before you send. Agencies amend notices.*

## The seven questions, in plain English

The RFI asks seven things. Translated from acquisition-speak:

1. **Your top five cost drivers or burdens** under CMMC and NIST SP 800-171 Rev 2\. What actually hurts.
2. **Which controls genuinely reduce risk.** What you would keep even if nobody made you.
3. **Which requirements are expensive paperwork.** Highest overhead, least measurable security improvement.
4. **What commercial tooling you already use** and how the Department should recognize it in the compliance framework. This is where MDM, cloud suites, and managed platforms belong.
5. **What is hard about Phase 1 self-assessments** and how to streamline them.
6. **What policy changes would drastically cut cost and barriers** for small and non-traditional businesses.
7. **What reforms would actually improve resilience** against real attacks, not just audit posture.

## How to write a comment that gets used

Task force staff will read hundreds of submissions. The ones that shape the report share a pattern:

- **Open with who you are.** Employee count, contract types, whether you handle CUI, your platform mix. A two-sentence identity paragraph makes every number that follows credible.
- **Answer the numbered questions in order.** Not an essay: seven labeled answers. Staff compile responses question by question.
- **Give numbers, not adjectives.** "Compliance is expensive" gets discarded. "Our 12-person shop spent $38,000 in year one: $14,000 consultant, $9,000 tooling, roughly 400 staff hours" gets quoted. The Department already has the aggregate estimates; your line items are what make them real.
- **Pair every burden with one concrete ask.** The change that would fix it, stated in a sentence.
- **Keep it short.** A page or less per question. Three tight pages beat fifteen loose ones.

## What not to put in a submission

An RFI response is a disclosure to the government that can be compiled, shared, and released. Treat it like a public document:

- **No CUI or FCI**, no client or prime names tied to sensitive work, nothing exported from a contract deliverable.
- **No network details.** Describe cost and burden, not architecture: "proving FIPS-validated encryption on endpoints" is fine; your enclave diagram is not.
- **No vulnerabilities or incident specifics.** If a weakness motivates your comment, describe the requirement, not your exposure.
- Cost figures and hours are yours to share. If pricing is competition-sensitive, use ranges.

## If you run Macs, say so

Platform-diversity costs are exactly the burden the task force cannot see unless shops like yours write it down. Fair game for questions 1, 3, and 4: the cost of proving FIPS-validated encryption on platforms the guidance never mentions, cloud MDM FedRAMP ambiguity forcing architecture decisions bigger than the underlying requirement, assessor unfamiliarity with macOS evidence, and the GCC High cost cliff for a ten-person shop. If commercial Apple management tooling already enforces your baseline, question 4 is where you ask the Department to recognize it.

## A skeleton you can start from

1. *Who we are:* size, DIB role, CUI footprint, platforms. Two sentences.
2. *Questions 1 through 7:* labeled answers, numbers first, one concrete ask each. Skip questions where you have nothing; a blank beats filler.
3. *Close:* what a right-sized framework looks like from your seat, and whether you are willing to participate in follow-up.

The free [readiness pack](https://www.cmmcoperator.com/cmmc-l2-readiness-pack/) workbook doubles as a cost-evidence generator here: if you have scored yourself against the 110, you already know which controls consumed your hours. That is question 1 and question 3 data.

Dates: comments closed **August 14, 2026**; the task force report is expected roughly mid-September. Both clocks are on [the key dates page](https://www.cmmcoperator.com/cmmc-key-dates/), and we will analyze the report when it lands.

*Sources: the SAM.gov notice (ID above) and the [SBA Office of Advocacy summary](https://advocacy.sba.gov/2026/07/20/dow-requests-information-for-cmmc-reform-task-force/?ref=cmmcoperator.com); suspension context from the July 13 release and memo 26-P-1023\. Verified July 2026\. Educational, not legal advice.*