When the Department of War suspended CMMC Phase 2 on July 13, it did two things at once. It froze third-party certification, and it opened a Request for Information asking the defense industrial base how the program should be rebuilt. We covered what the CMMC Phase 2 suspension changed — and what it didn't — separately. This is about the second half, and it has a clock on it: the RFI closes at 12:00 PM ET on Friday, August 14, 2026. After that, a 60-day Reform Task Force writes its recommendations from the record it has.

Here is the part that should move you to act. The firms with the most to gain from a cheaper compliance model are the ones least likely to file. Primes and trade associations have people whose job is to submit these. A fourteen-person shop does not. So unless small contractors write in, the record — and the reforms built on it — skews toward large-business experience.

What the RFI asks

The RFI poses seven questions. Five of them ask about cost, administrative burden, or reform. The first asks you to identify your top five most prohibitive cost drivers, administrative burdens, or operational challenges in complying with the CMMC framework and NIST SP 800-171 Rev 2. Others ask which security controls delivered real risk reduction, how the Department might recognize the commercial cybersecurity tools and managed services you already run, and what should replace the third-party assessment model.

Notice the framing: the Department asked industry to price its own compliance. That is a question a small subcontractor can answer better than almost anyone, because you lived the invoice.

How to file

There is no portal, no registration, and no fee. Responses go by email to the two mailboxes named in the RFI and must follow the instructions in its Format section. You do not have to answer all seven questions — answer the ones where you have real experience.

What carries weight is specificity. Dollar figures, hours spent, and named controls move a Task Force; adjectives do not. Instead of "the documentation burden was significant," give the actual number: the hours your team spent, the dollars you paid a consultant, the specific control you could not implement without new hardware. If you walked away from a pursuit because of CMMC cost, say that too — a firm that never certified because the math didn't work is exactly the data point the Department says it wants.

What filing does not change

Nothing you submit alters your current obligations. DFARS 252.204-7012 remains in effect, Phase 1 self-assessments still apply, and your SPRS score and annual affirmation stay live while the Task Force works. On the civilian side, the FAR CUI rule is unaffected by the DoD pause, so contractors working both defense and civilian sides get no reprieve.

The move

Block two hours before Friday noon. Pull one real invoice or one real time estimate, answer the questions where you have data, and email it. This is the rare moment when a small contractor's cost figures can actually move federal policy, and the window closes in days. Confirm the deadline, the mailboxes, and the format requirements against the RFI itself before you send.

FAQ

When is the CMMC RFI deadline?
Responses are due by 12:00 PM ET on Friday, August 14, 2026, submitted by email.

How do I submit a response?
By email to the two mailboxes listed in the RFI. There is no portal, no registration, and no fee, and responses must follow the instructions in the RFI's Format section.

Do I have to answer all seven questions?
No. Answer the questions where your organization has real experience or data. Partial responses are acceptable.

Does filing change my current CMMC obligations?
No. DFARS 252.204-7012, Phase 1 self-assessments, NIST SP 800-171 Rev 2, and your SPRS affirmation all remain in force during the review.

Who should respond?
Any defense industrial base firm, but small, medium, and non-traditional contractors especially — reducing their burden is the Department's stated goal, and their voices are the most likely to be missing from the record.

The RFI closes in days, and the recommendations that follow will shape defense cybersecurity compliance for years. Federal Cyber Brief tracks the federal IT and cybersecurity rules that gate small-business work — what changed, what it costs you, and what to do about it — every Tuesday.

Sources

U.S. Small Business Administration, Office of Advocacy, DoW Requests Information for CMMC Reform Task Forcehttps://advocacy.sba.gov/2026/07/20/dow-requests-information-for-cmmc-reform-task-force/

ArentFox Schiff, CMMC Reform Task Force RFI: Defense Contractors Have a Chance to Shape Federal Cybersecurity Requirementshttps://www.afslaw.com/perspectives/alerts/cmmc-reform-task-force-rfi-defense-contractors-have-chance-shape-federal

Sheppard Mullin, DoW Hits Pause on CMMC: What Contractors Need to Know Nowhttps://www.sheppard.com/insights/blogs/dow-hits-pause-on-cmmc-what-contractors-need-to-know-now