3 min read

How to Comment on the CMMC Reform RFI (Due August 14)

The Reform Task Force is asking contractors what CMMC actually costs. The mechanics, the seven questions in plain English, and how to write a comment that gets used instead of discarded.
How to comment on the CMMC Reform Task Force RFI - due August 14, 2026 (CMO-GUIDE-014)

The Phase 2 suspension came with a homework assignment, and it is addressed to you. The CMMC Reform Task Force is running a formal request for information titled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base," and it asks contractors directly, with explicit emphasis on small, medium, and non-traditional businesses, to say what CMMC actually costs and what should change. Comments are due August 14, 2026. If the review produces the framework you will live with for the next decade, this window is where you get a say in it. (Context on the suspension itself: what changed and what did not.)

The mechanics: where, how, by when

  • What: a request for information, "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)," issued by the Department of War.
  • Where: posted on SAM.gov as Notice ID 89ef9bfb0834473791e991c712698d94 - search that ID at SAM.gov to pull the notice. Responses go by email to the submission mailbox listed in the notice (whs.mc-alex.ad.mbx.eosd-psb-branch-mailbox@mail.mil), following the notice’s instructions for subject line and point of contact.
  • When: due August 14, 2026.
  • Who: DIB companies. The notice singles out small, medium, and non-traditional businesses, which is most of the readership of this site.

Work from the live notice: confirm the mailbox, format instructions, and deadline against the SAM.gov posting before you send. Agencies amend notices.

The seven questions, in plain English

The RFI asks seven things. Translated from acquisition-speak:

  1. Your top five cost drivers or burdens under CMMC and NIST SP 800-171 Rev 2. What actually hurts.
  2. Which controls genuinely reduce risk. What you would keep even if nobody made you.
  3. Which requirements are expensive paperwork. Highest overhead, least measurable security improvement.
  4. What commercial tooling you already use and how the Department should recognize it in the compliance framework. This is where MDM, cloud suites, and managed platforms belong.
  5. What is hard about Phase 1 self-assessments and how to streamline them.
  6. What policy changes would drastically cut cost and barriers for small and non-traditional businesses.
  7. What reforms would actually improve resilience against real attacks, not just audit posture.

How to write a comment that gets used

Task force staff will read hundreds of submissions. The ones that shape the report share a pattern:

  • Open with who you are. Employee count, contract types, whether you handle CUI, your platform mix. A two-sentence identity paragraph makes every number that follows credible.
  • Answer the numbered questions in order. Not an essay: seven labeled answers. Staff compile responses question by question.
  • Give numbers, not adjectives. "Compliance is expensive" gets discarded. "Our 12-person shop spent $38,000 in year one: $14,000 consultant, $9,000 tooling, roughly 400 staff hours" gets quoted. The Department already has the aggregate estimates; your line items are what make them real.
  • Pair every burden with one concrete ask. The change that would fix it, stated in a sentence.
  • Keep it short. A page or less per question. Three tight pages beat fifteen loose ones.

What not to put in a submission

An RFI response is a disclosure to the government that can be compiled, shared, and released. Treat it like a public document:

  • No CUI or FCI, no client or prime names tied to sensitive work, nothing exported from a contract deliverable.
  • No network details. Describe cost and burden, not architecture: "proving FIPS-validated encryption on endpoints" is fine; your enclave diagram is not.
  • No vulnerabilities or incident specifics. If a weakness motivates your comment, describe the requirement, not your exposure.
  • Cost figures and hours are yours to share. If pricing is competition-sensitive, use ranges.

If you run Macs, say so

Platform-diversity costs are exactly the burden the task force cannot see unless shops like yours write it down. Fair game for questions 1, 3, and 4: the cost of proving FIPS-validated encryption on platforms the guidance never mentions, cloud MDM FedRAMP ambiguity forcing architecture decisions bigger than the underlying requirement, assessor unfamiliarity with macOS evidence, and the GCC High cost cliff for a ten-person shop. If commercial Apple management tooling already enforces your baseline, question 4 is where you ask the Department to recognize it.

A skeleton you can start from

  1. Who we are: size, DIB role, CUI footprint, platforms. Two sentences.
  2. Questions 1 through 7: labeled answers, numbers first, one concrete ask each. Skip questions where you have nothing; a blank beats filler.
  3. Close: what a right-sized framework looks like from your seat, and whether you are willing to participate in follow-up.

The free readiness pack workbook doubles as a cost-evidence generator here: if you have scored yourself against the 110, you already know which controls consumed your hours. That is question 1 and question 3 data.

Dates: comments close August 14, 2026; the task force report is due roughly mid-September. Both clocks are on the key dates page, and we will analyze the report when it lands.

Sources: the SAM.gov notice (ID above) and the SBA Office of Advocacy summary; suspension context from the July 13 release and memo 26-P-1023. Verified July 2026. Educational, not legal advice.