The Department of War’s “Reforming CMMC” request for information closed at noon Eastern on Friday, August 14. If you hold a defense contract — or want one — here’s what that deadline actually was, what happens next, and what it changes about your obligations right now. Short version of that last part: nothing. But the next 30 days will tell you a lot about what CMMC becomes.
What just happened
On July 13, DoW suspended CMMC Phase 2 and stood up a reform task force with a 60-day clock. A week later it published the RFI — the one formal channel for industry to tell the review what’s broken. The RFI asked seven questions, and they’re worth reading as a list of what the Pentagon already suspects: What are the top cost drivers? Which security controls actually reduce risk, and which are overhead with minimal benefit? How could commercial cybersecurity solutions be better recognized? What’s hard about the Phase 1 self-assessment process? What policy reforms would cut costs for small and non-traditional businesses? How does any of this improve actual resilience against attack?
Notice what those questions assume. They don’t ask whether the program costs too much relative to the security it buys — they ask where. The announcement that suspended Phase 2 said the quiet part out loud: “the math just simply doesn’t math.” The RFI is the task force collecting evidence for a conclusion the leadership has already signaled.
The part nobody’s telling you: the responses aren’t public
Here’s something most coverage skipped. Comments weren’t filed on regulations.gov. They were emailed to two DoW inboxes. That means there is no public docket, no response count, no way to read what the DIB actually said — except for the respondents who choose to publish their own submissions, which in practice means trade associations and large firms.
Two consequences. First, whatever picture emerges publicly in the next few weeks is a selected picture: the loudest published voices are consultancies, assessor-ecosystem players, and primes — whose interests are not identical to a 50-person machine shop’s. A consultancy’s “reform” ask preserves the complexity it sells navigation of. A prime’s ask manages its own flow-down liability. Read every published response with the question: what does this organization sell, and does its recommendation protect that?
Second, if you’re a small contractor who filed nothing — which is nearly all of you — you weren’t heard, and you can’t even check whether anyone spoke for you. That’s not a reason to panic; it’s a reason to watch the two documents that come next, because those are where the actual decisions surface.
What actually got published (and who stayed quiet)
The RFI closed without ceremony — no DoW statement, no submission tally. And as of the deadline, the visible public record is strikingly thin. That thinness is the finding.
One assessment firm, Redspin, published its full response. Its five asks: risk-tiered verification (independent assessment reserved for the highest-risk CUI), recognition of existing certifications like FedRAMP, SOC 2, and ISO 27001 as direct evidence, weighting the 110 NIST controls by actual risk-reduction value instead of treating them equally, expanded self-attestation paired with automated evidence checks, and small-business cost relief through subsidized assessments. It’s a thoughtful submission — and it’s also an assessor proposing a future that still includes assessments. Apply the filter from the previous section.
Beyond that, the public record is mostly compliance vendors publishing how-to-respond guides and response-builder tools (we published one too). The major trade associations — NDIA, PSC, AIA — whose members had the most at stake had not published their submissions as of the close; NDIA’s public commentary so far has been limited to reactions to the July suspension itself. Maybe those submissions surface in the coming weeks. But the practical upshot stands: the reform review’s inputs are essentially invisible to the companies its output will govern. What industry “said” will have to be inferred from what the task force does — starting with the report due around mid-September.
What doesn’t change, no matter what industry asked for
While the reform review runs, Phase 1 is fully in force. You still need a current NIST SP 800-171 self-assessment, a score posted in SPRS, and a senior official’s affirmation standing behind it — and that affirmation carries False Claims Act exposure whether or not Phase 2 ever comes back.
This is the anchor worth repeating because every reform outcome shares it: no scenario on the table makes a current, accurate self-assessment wasted work. If reform lands on optimized self-attestation, your self-assessment is the compliance mechanism. If Phase 2 resumes in narrowed form, it’s your readiness baseline. If there’s a full restructure, it’s still the 800-171 posture every successor framework will build from. If you’re not sure where you stand, our free SPRS score tool takes about ten minutes and maps you against all 110 requirements.
What to watch next
Two dates. August 31: a gap report to Congress is expected — the “here’s what’s broken” half of the story, likely quantifying exactly why Phase 2 was unaffordable. ~September 11: the task force’s 60-day clock expires and its recommendations are due — the “here’s what we’re doing” half. Read them as one document in two parts. We’ll break both down within 48 hours of each landing.
Know exactly where you stand — free
Whatever the task force recommends, a current self-assessment is the floor. Run the free SPRS self-assessment: your real score against all 110 requirements, your prioritized gaps, and your next moves. No signup.
Calculate your SPRS score →Score, document, plan — free
The reform debate will run for months; what your contracts require today won’t wait for it: calculate your SPRS score, draft your SSP, and build your POA&M — all free, in your browser. New to all of this? Start with Where Do You Stand? For the background to this story, see CMMC Phase 2 Suspended: What It Actually Means, why your SPRS score outlived the deleted Basic Assessment tier, and what you’re signing in the annual affirmation.