On July 13, 2026, the Department of War suspended CMMC Phase 2 — the third-party certification rollout that was set to begin November 10, 2026 — and stood up a 60-day CMMC Reform Task Force to recommend a better approach. Alongside it, the Department opened a public Request for Information (RFI) titled “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB).” It’s posted on SAM.gov, and it’s open to anyone in the DIB — including you.
This guide is for the small contractor who has never answered an RFI and isn’t sure it’s even allowed to. It is. Here’s what the RFI is, why your input actually counts, and exactly how to send one before the deadline.
What an RFI actually is (and isn’t)
An RFI is a formal, public request for input. The government uses it to gather facts before it writes a rule or a program — in this case, before the task force recommends what replaces CMMC Phase 2.
A few things it is not, so you can relax: it is not a solicitation — you’re not bidding on anything. It is not a contract or a commitment. And responding does not put you on a “list,” cost you money, or obligate you to anything. You are simply giving the people rewriting the rules the ground truth they asked for. Responses may be used to shape the task force’s recommendations to the DoW Chief Information Officer, whose report is expected around mid-September 2026.
Why your voice matters — especially if you’re small
The RFI explicitly asks about the burden on small, medium, and non-traditional businesses — cost drivers, administrative load, and whether the security controls actually deliver security or just paperwork. That’s not boilerplate. It’s the exact data the task force says it’s missing.
Here’s the uncomfortable math: the large primes have compliance departments and outside counsel who will absolutely file detailed responses. The small shop — the one where the owner is the IT department and the compliance officer and the proposal writer — is the least likely to respond and the most affected by the outcome. If the only voices on the record are the ones who can afford lobbyists, the “reform” gets written around their reality, not yours. A short, specific email from a real 12-person machine shop is worth more to this task force than another polished white paper.
This isn’t a fire drill and we’re not going to pretend it is. It’s a narrow, real window: the rules are genuinely being rewritten, and they asked. For what it’s worth, we submitted our own response on July 16. We’re not going to tell you what to write — we’re telling you that you can, and how.
What the RFI is asking
The notice organizes its questions around two themes:
- Protecting federal data and staying resilient against cyber-attacks — while cutting compliance cost and administrative burden.
- Bigger-picture ideas: using existing commercial cybersecurity capabilities, leveraging and optimizing self-attestation, and streamlining the requirements.
Underneath those, the RFI poses a set of specific questions covering topics like: what actually drives your compliance cost and hours; which controls deliver measurable security versus paper burden; what commercial tools already solve the problem; the practical challenges of the Phase 1 self-assessment; and what policy changes would lower the barrier for smaller firms. Read the exact questions on the SAM.gov notice and answer the ones you have real experience with — you don’t have to answer all of them.
Exactly how and where to submit
This is the part that trips people up, so here it is plainly. Responses go in by email only (“electronic means only”), to the point of contact listed on the RFI’s SAM.gov notice. Deadline: 12:00 PM Eastern (noon), Friday, August 14, 2026 — note that’s noon, not end of day.
- Open the notice on SAM.gov — search “Reforming CMMC and Reducing Compliance Burden.” It lists the submission email address and any format instructions.
- Write your response as a short document or straight in the email body. Answer only the questions you have real experience with.
- Email it to the point of contact shown on the notice, well before noon ET on August 14. Give it a clear subject line (e.g., “RFI Response — Reforming CMMC — [Your Company]”).
- Keep your sent copy. That’s your record that you weighed in.
You don’t need a SAM.gov account, a UEI, or any registration to send an email response. One caveat: government notices get updated — always take the current submission address and instructions from the SAM.gov posting itself, which is the authoritative source.
What to say — and what to avoid
Say the specific, true things only you know:
- Real numbers. What does compliance actually cost you — in dollars and in hours? “We spent about 240 hours and $18k over eight months to get to a 74” lands harder than “it’s expensive.”
- Which controls hurt, and why. Name the ones that are disproportionately hard or costly for a shop your size, and what makes them hard.
- What you already use. If a commercial tool you already pay for — your Microsoft 365 GCC tenant, your managed-detection service, your password manager — already satisfies a control, say so. The RFI is explicitly hunting for that.
- What would actually help. Concrete, workable suggestions for making self-assessment realistic for small firms.
Avoid:
- Venting. A rant gets skimmed and discarded. One concrete example beats ten complaints.
- “Abolish the whole thing.” The duty to protect defense information isn’t going away — the memo itself calls data protection “critical and non-negotiable,” and the RFI asks how to optimize self-attestation, not whether to keep it. The useful input is “here’s how to make self-assessment workable,” not “make it disappear.”
- Oversharing your own security gaps. You’re giving policy input, not handing over a map of your vulnerabilities. Speak to cost and process, not “here’s exactly where we’re exposed.”
- Over-promising. Keep it honest and grounded in what you’ve actually lived.
Professional, concise, specific. A single page is plenty.
While the RFI is open, your obligations haven’t changed
This is the part it’s easy to miss in the “CMMC is suspended” headlines. The pause hit the third-party audit. It did not pause your self-assessment. If your contract carries a CMMC clause, you still self-assess against NIST SP 800-171, post your SPRS score, and sign the annual affirmation — exactly as before July 13.
And with third-party audits paused, your self-attestation is now the standard — which raises the stakes on getting it right. As the law firm Hunton Andrews Kurth lays out, the SPRS affirmation a senior official signs is a direct certification to the government; under the civil False Claims Act (31 U.S.C. § 3729), a certification that’s false when made — or made with reckless disregard for the truth — can carry treble damages and per-claim penalties, and you don’t need intent to defraud to be liable. The Department of Justice’s Civil Cyber-Fraud Initiative recovered $52 million in FY2025 and has settled multiple cases over inflated or unsupported SPRS scores. None of that is suspended.
Do this before August 14
- Read the RFI on SAM.gov and note the questions you can speak to.
- Jot down your real costs, hours, and pain points — the specifics only you have.
- Send a short email response to the point of contact on the notice before noon ET on August 14. Keep the copy.
- Regardless of how reform lands, make your own self-assessment honest and documented. Whatever replaces Phase 2, “self-assess against 800-171 and be able to prove it” is the floor.
Know your real number — free
Before you tell the government what compliance costs you, know exactly where you stand. Run the free SPRS self-assessment: your real score against all 110 requirements, your prioritized gaps, and your next moves. No signup.
Calculate your SPRS score →Frequently asked questions
Do I have to respond?
No — it’s voluntary. But it’s a rare, time-boxed window to put a small contractor’s reality in front of the people rewriting the rules. If the cost and burden have hit you, this is where that goes on the record.
Will responding put me on a list or hurt my chances at work?
No. It’s a public request for policy input, not a solicitation and not a bid. You’re giving input, not competing for anything.
Does the pause mean I can stop self-assessing?
No. Phase 1 self-assessment, your SPRS score, and your annual affirmation are all still required, and the False Claims Act exposure behind that affirmation is unchanged. See CMMC Phase 2 Suspended: What It Actually Means.
When will we know what actually changes?
The 60-day task force report is expected around mid-September 2026 — the first real signal of what replaces Phase 2. Nothing is final yet; that’s exactly why input now matters.
Does my response need to be formal?
No. A professional, concise email that answers the questions you have experience with is exactly right. One page is plenty.
Score, document, plan — free
The reform debate will play out over months. What your contracts require today won’t wait for it: calculate your SPRS score, draft your SSP, and build your POA&M — all free, in your browser. New to all of this? Start with Where Do You Stand? For what the July 13 suspension did and didn’t change, see CMMC Phase 2 Suspended and self-assessment vs. C3PAO.