The CMMC Reform Task Force: What the RFI Asked, and What to Do During the Pause | Stealth Technology Group
Update — July 13, 2026: DoD paused CMMC Phase 2 certification. NIST 800-171 and your signed affirmation did not pause. See What Still Applies →
Compliance & Certification

The CMMC Reform Task Force: What the RFI Asked — and What to Do While Washington Deliberates

Michael Bannach, CISSP August 2026
~6 min read

The comment window closed at noon Eastern on August 14, 2026. With it, the CMMC Reform Task Force — stood up alongside the July 13 Phase 2 suspension — collected industry's answers to some pointed questions, and moved into the synthesis phase of its 60-day review. Recommendations are expected in the coming weeks.

Here's what the government actually asked, what the questions signal about where reform may land, and — most practically — what to do with your compliance program while the answer is being written.

What the RFI Asked Industry

The Request for Information posed seven questions. Read as a set, they sketch the Department's concerns clearly:

  • The top cost drivers and administrative burdens in CMMC compliance — with an explicit focus on small and medium businesses;
  • Which security controls deliver measurable cybersecurity improvement (and, implicitly, which deliver paperwork);
  • How existing commercial cybersecurity capabilities could be recognized in place of bespoke compliance machinery;
  • How self-assessment processes could be streamlined while maintaining accountability;
  • What specific, actionable policy changes would reduce burden without weakening protection of federal data.

Notice what's absent: any question about whether contractors should protect CUI at all. The 110 NIST 800-171 controls aren't up for debate. The machinery of verification is.

The Plausible Outcomes

Nobody outside the task force knows what it will recommend, and officials have declined to rule anything out. But the realistic range looks like this:

Phase 2 resumes on a delayed timeline

The program proceeds as designed, with the calendar pushed to let assessor capacity catch up. Everything contractors prepared transfers directly.

Third-party certification narrows

C3PAO certification survives but applies to fewer organizations — higher-sensitivity programs, specific data categories — while more of the base operates on strengthened self-assessment.

Self-assessment plus executive accountability becomes the norm

Attestation with teeth: streamlined verification for most contractors, backed by the affirmation regime and False Claims Act enforcement already in place.

Deeper restructuring

A substantial rework of the model itself — possible, but the slowest and least likely path given how much rulemaking it would reopen.

Key Takeaway: Every one of those outcomes rests on the same foundation — NIST 800-171, implemented and evidenced. There is no plausible future in which the 110 controls stop mattering. That's what makes "wait and see" the one strategy guaranteed to lose.

The No-Regrets Playbook for the Pause

Work that pays off under every outcome:

  • Verify your SPRS score against evidence. The annual executive affirmation continued right through the pause — accuracy is a legal matter today, not a future one.
  • Finalize your CUI scoping. Data-flow maps, asset categorization, boundary diagrams. Cheap now, decisive later.
  • Close POA&M items rather than carrying them. Every closed gap raises your score and shrinks your risk regardless of what verification looks like.
  • Keep your evidence living. Access reviews, training records, log retention — the artifacts that can't be backfilled when an assessment date lands on the calendar.
  • Stay aligned with your primes. Their supplier deadlines didn't pause, and their flow-down requirements remain your contract terms.

The Queue Math Nobody Should Forget

If third-party certification returns in any form, the capacity imbalance that triggered the pause — a hundred-odd assessment organizations against a hundred-thousand-contractor base — returns with it. The contractors who spent the pause getting evidence-ready will book assessments first and bid unencumbered. The ones who spent it waiting will stand in the longest line in federal contracting.

The task force will report soon. Until then, the smartest position in the DIB is simple: be the contractor for whom the announcement, whatever it says, changes nothing.

Michael Bannach

Michael Bannach, CISSP

Michael Bannach is the President & CEO of Stealth Technology Group, a CyberAB Registered Provider Organization. He holds the Certified Information Systems Security Professional (CISSP) credential and brings 25+ years of enterprise IT and cybersecurity experience guiding defense contractors through NIST 800-171 implementation and CMMC readiness.

Want a pause strategy instead of a pause?

We'll assess where you stand today and build the no-regrets roadmap that pays off under every reform outcome.

Get Started Today