Reforming CMMC and Reducing Compliance Burden for the DIB

With wars breaking out around the world, it is imperative that the United States Department of War (“DoW”) is prepared to defend our nation.  To do this effectively, we must ensure that companies in the DoW Supply Chain (“DSC”) safeguard critical information about DoW, our nation’s weapons systems, and DoW personnel.  When unclassified, this information is considered Controlled Unclassified Information (“CUI”) and numerous laws, regulations, and government-wide policies (“LRGWP”) have been passed that require its safeguarding. 

Unfortunately, as discussed in more detail in the enclosure, recent history has shown that companies in the DSC often fail to implement the safeguards spelled out in the corresponding LRGWPs.  This has led to adversarial nations like China gaining access to plans for some of our nation’s most advanced weapons systems.  As a result, our adversaries can not only stand toe-to-toe with our warfighters on the battlefield, they can probe for weaknesses in our most advanced systems from the comfort of their homes.  This puts our warfighters lives in jeopardy.

Since 2016, DoW has been gradually increasing pressure on those in the DSC to safeguard CUI, but most of the DSC companies simply did not respond.  This is due, in part, to DoW’s procurement policies which reward those who spend the least.  Some in DoW recognized this foundational problem, and in 2020 the Cybersecurity Maturity Model Certification (“CMMC”) program was launched.

After a few rounds of refinement, DoW passed a series of regulations in 2024 and 2025 which enabled DoW to incorporate CMMC requirements in its solicitations and contracts.  DoW created a 4-phase roll-out that would see the CMMC requirements gradually show up in increasing numbers of contracts.  Phase 2, which required third-party certification of companies’ compliance with these safeguarding requirements, was due to begin November 10, 2026.  The looming threat of Phase 2 spurred tens of thousands of companies to begin following the laws established by Congress and safeguarding CUI.  

Put more plainly, the CMMC Phase 2 requirement for independent third-party certification has accomplished, in just eighteen months, what DoW’s self-assessment regime failed to achieve in nearly a decade: meaningful improvement in the cybersecurity posture of the defense industrial base and the nation.        

On July 13, 2026, DoW Chief Information Officer Hon. Kirstin Davies announced at a press conference the suspension of CMMC Phase 2 efforts.  Ms. Davies suggested that DoW needed to return to allowing contractors to self-assess their compliance because CMMC third-party assessments created a barrier to entry for emerging technology companies and small businesses.  Ms. Davies argued that the “Arsenal of Freedom”, DoW’s new manufacturing initiative, would allow the nation to dominate on the battlefield, and that that should be our highest priority.

Our nation’s ability to out manufacture our adversaries will mean nothing if our adversaries can defeat our weapons systems, or worse use them against us, before our warfighters ever leave our shores.

We believe DoW’s recent decisions will do more harm than good for our nation and our warfighters.  The CUI Institute would therefore appreciate your support on urging DoW to make common-sense changes to the CMMC program, including keeping third-party assessments, rather than throwing the baby out with the bathwater.

Our proposed changes to the CMMC program, which are described in the attachment, are designed to increase competition, lower cost, and allow emerging technology companies and small businesses to help strengthen the DSC while still ensuring CUI is properly safeguarded.  At a high level, our proposal are:

  1. Postpone CMMC Phase 2 until November 10, 2028, to allow the ecosystem more time to mature.
  2. Amend DoW procurement policy to require not less than 15%, and up to 25%, of the Technical Evaluation Criteria for any given solicitation to be awarded to offerors who can demonstrate that their entire supply chain complies with the CMMC requirements applicable based on the nature of the information they will handle under the solicitation. This will encourage companies to implement proper safeguards for the government’s information.
  3. Exempt from CMMC Level 2 (C3PAO) Certification Requirements:
    1. Companies in Phase I or Phase II of the Small Business Innovation and Research (“SBIR”) Program;
    2. Companies that have earned less than $6,000,000 from government contracts over the prior 3 years; and
    3. All contracts for less than $50,000 (including subcontracts).
  4. Award tax breaks to companies earning a CMMC Level 2 (C3PAO) Certification.
  5. Remove the FedRAMP Moderate requirement from 32 CFR 170 and 48 CFR 252.204-7012.
  6. Substitute a commercial background check for a Tier 3 Background Investigation.
  7. Streamline the education requirements needed to become a CMMC Certified Assessor (“CCA”) or Lead CCA.
  8. Allow company business units and other Affiliates to take advantage of the company’s CMMC-compliant information system (including making appropriate Commercial and Government Entity (“CAGE”) Code changes in the CMMC Enterprise Mission Assurance Support System (“eMASS”) system).
  9. Allow C3PAOs to conduct delta and/or surveillance assessments.
  10. Overhaul DoW’s CUI program to properly align with the Constitution, federal regulations, Executive Order 13556, and 32 CFR 2002.
  11. Train DoW personnel on the revised CUI program and hold DoW personnel accountable for violating the CUI Program requirements or exceeding authority.
  12. Update 32 CFR 170 to allow the CMMC program to grow and change as the National Institute for Standards and Technology (“NIST”) updates Special Publication (“SP”) 800-171 by:
    1. Implementing a 12-month transition period that begins 30 days after NIST publishes the final version of a new NIST SP 800-171 revision.
    2. Permitting new assessments begun during the transition period to be conducted under either the old or new requirements, at the contractor’s option.
    3. Allowing the corresponding certification to remain valid for CMMC compliance purposes until the end of its 3-year expiration period or until the certification is rendered invalid due to significant changes to the assessed information system.

Our full recommendations can be downloaded below.