The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · primary-source RFI record

CMMC RFI Response: The Window Closed August 14 — Here's the Full Record

Last updated:

Last verified: against SAM.gov, the CMMC Program Rule, DFARS, NIST, SPRS, Cyber AB, and respondent-published sources.

STATUS — RESPONSE WINDOW CLOSED · AUGUST 14, 2026 · 12:00 P.M. ET

By The Defense Compliance Report Editorial Team · Published August 15, 2026 · Last verified August 15, 2026

Independent research. Primary sources checked and listed at the bottom of this page.


The CMMC RFI response deadline passed at noon Eastern on Friday, August 14, 2026. The notice said late submissions would not be considered, and we found no amendment reopening it. But the seven questions show what the Department explicitly invited industry to challenge during the CMMC Reform Task Force's review — which makes them a better map than any press release of the program elements open for discussion.

Here is what the notice asked, what publicly released responses are arguing, and the status question that matters after the deadline: what you still owe while the review runs.

Quick orientation:

Your question — The answer today — What to do about it
Your questionThe answer todayWhat to do about it
Can I still submit a response?No. The written deadline passed at 12:00 p.m. ET on August 14, 2026, and the notice stated that late submissions would not be considered.Check the SAM.gov notice for a formal amendment. Nothing else changes this.
What did it ask?Seven questions covering cost drivers, which controls actually reduce risk, which requirements cost the most for the least benefit, commercial security capabilities, Phase I self-assessments, and two on reform.Read the seven questions →
Was it a solicitation?No. It was market research. No contract was promised, and response costs were not reimbursed.Treat public responses as industry positions, not policy.
Did responding count as CMMC self-attestation?No. The notice said so explicitly.Your SPRS records, assessment results, and CMMC affirmation are separate obligations.
Did any of this pause my current obligations?The RFI did not. Phase I Level 1 (Self) and Level 2 (Self) requirements remain active, and DFARS 252.204-7012 safeguarding duties remain in effect where the clause applies.See what's still binding →

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citations for material regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

Terms, defined once: CMMC (Cybersecurity Maturity Model Certification) is the Department's program for assessing whether defense contractors have implemented the cybersecurity requirements that apply to their systems. RFI (Request for Information) is a market-research notice — the government asking questions, not buying anything. CUI (Controlled Unclassified Information) is sensitive unclassified information the government requires you to safeguard. FCI (Federal Contract Information) is information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service, excluding information the Government has made public and simple transactional information such as payment-processing data. SPRS (Supplier Performance Risk System) is the government system where NIST assessment results and CMMC status and affirmation records are maintained. C3PAO (CMMC Third-Party Assessment Organization) is an organization authorized or accredited to perform official Level 2 certification assessments. DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) is the government body that conducts Level 3 certification assessments and other government-led assessments.


Can you still submit a CMMC RFI response?

No. The response window for the Department of War's RFI, "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base," closed at 12:00 p.m. Eastern Time on Friday, August 14, 2026. The notice stated that submissions received after the specified date would not be considered. Only a formal amendment posted to the SAM.gov notice would change that.

We want to be blunt about this, because guides still online will tell you otherwise.

Several of the "how to respond to the CMMC RFI" guides still online were written in late July and early August. They were accurate then. They are not accurate now. If you land on one of those, you will find submission email addresses, a ten-page limit, and a file-format rule — all of it describing a door that closed at noon on August 14.

The noon detail is what caught people. This was not an end-of-business deadline and it was not midnight. It was 12:00 p.m. Eastern. If you drafted a response and planned to send it Friday afternoon, you did not miss it by a day. You missed it by hours.

Where to check the notice yourself

The RFI lives on SAM.gov, the federal government's contract-opportunity system. One quirk worth knowing before you go looking: two different identifiers circulate for this notice, and both are real. The human-readable notice ID is DoDCIOReformingCMMCforDIB001. The SAM.gov URL uses a different internal opportunity-record identifier, 89ef9bfb0834473791e991c712698d94. If a search on one comes up empty, try the other, or search the full title.

Our damaging admission, up front

This page cannot reopen a closed federal response window, and we are not going to pretend otherwise.

There is no back channel. There is no "just email it anyway and see." The notice set a hard cutoff and said submissions after it would not be considered. Sending a late unsolicited document to a government inbox does not put it into the timely RFI record — it just puts your company's compliance gaps in a stranger's inbox for no benefit.

What we can do is give you the complete record: the seven questions in plain English, a source-checked look at what publicly released respondents actually argued, and a clear-eyed read on what you still owe while the Task Force works. That last part is where contractors can be quietly exposed right now, and it is the part that determines whether the policy news costs you money.

If you came here for a different problem

Missed a contract deadline, not a policy window? If your actual problem is a lapsed SPRS score, an overdue annual affirmation, a POA&M (Plan of Action and Milestones) closeout clock, an option-year exercise, or a prime's flow-down date — this is the wrong page and you should not spend another minute here. Those are contractual deadlines with real consequences, and they work nothing like an RFI window. Start with our CMMC readiness checklist and SPRS score guide instead.

Want the full suspension picture? The July 13 Phase II suspension is its own story with its own consequences. We cover it in depth in what the July 13 suspension actually changed.

Next: the seven questions. They are the most useful artifact to come out of this whole episode, because they show you what the Department explicitly invited industry to challenge.

Read the seven questions the Department asked →


What did the CMMC RFI actually ask?

The RFI asked seven numbered questions. In order: your top five cost drivers and burdens; which controls delivered the most real risk reduction; which requirements cost the most while delivering the least; how you already use commercial cybersecurity capabilities, platforms, managed services, or other strategies and how the Department could recognize them; what makes Phase I self-assessments hard to maintain, verify, and report; what policy changes would cut cost and barriers for small, medium, and non-traditional businesses over the next sixty days; and what changes would improve actual operational resilience against attacks over that same period.

Our read of the question set: five of the seven questions are about burden, cost, process, recognition, or reform. Two are about security outcomes. The numbered questions did not ask whether CMMC should exist. They asked industry to price it, and to say which parts of it work.

The seven questions, in plain English

The table below is our plain-English restatement of the seven questions in the order the notice asks them. It is not the official text. The official wording lives in the RFI attachment on SAM.gov, and you should read it there if exact language matters to you.

# — What the question asks — Our read of what the Department was trying to learn
#What the question asksOur read of what the Department was trying to learn
1Your top five most prohibitive cost drivers, administrative burdens, or operational challenges in complying with CMMC and NIST SP 800-171 Rev. 2 — experienced or anticipatedWhere the money and hours actually go, from the people paying the bill
2Which specific security controls delivered the most tangible cybersecurity uplift and real risk reductionWhich parts of the standard are earning their keep
3Conversely, which specific regulatory requirements or security controls impose the highest administrative and financial burden while producing the least measurable improvement in your postureWhich parts could be cut or restructured without losing the security objective
4How your organization already uses commercial cybersecurity capabilities, platforms, managed services, or other strategies — and how the Department might better recognize or accept those within a compliance or risk frameworkWhether existing commercial evidence can reduce duplicative CMMC work
5Regarding Phase I self-assessments: what administrative or technical challenges you face maintaining, verifying, and reporting compliance; how the process could be streamlined; and whether self-assessment produced a more dynamic security posture or was performed only for complianceWhether self-assessment is doing real work or generating paper
6What specific, actionable policy changes or regulatory reforms the Task Force should recommend over the next sixty days to reduce cost and barriers to entry for small, medium, and non-traditional businesses without degrading protection of federal dataThe near-term fix list and its security guardrails
7What specific, actionable policy changes or regulatory reforms the Task Force should recommend over the next sixty days to improve operational resilience against cyber attacks at your organizationThe operational-outcome list

How we sourced this: we checked the content and order against the RFI attachment itself on August 15, 2026. The attachment contains the noon deadline, the late-submission rule, all seven numbered questions, and the statement that submissions do not equate to CMMC self-attestation. The SAM.gov notice and attachment are the source of record. If you need to quote the questions verbatim, pull the attachment rather than trusting any restatement, including ours.

One thing to watch: not every "seven questions" list is the same seven questions

This matters more than it sounds.

At least one public CMMC RFI response tool published a seven-prompt framework that does not match the official numbered question set or its order. FutureFeed's response builder leads with commercial cybersecurity capabilities and includes prompts about optimizing self-attestation and encouraging innovation — themes drawn from the Department's stated goals for the review rather than the numbered questions in the notice itself.

That is not necessarily bad faith. The Department described its interest areas in the announcement and the notice in slightly different language, and a vendor building a drafting tool reasonably worked from the themes. But if you are trying to reconstruct what was actually asked — and especially if you are writing about it — the distinction between "the Department's stated themes" and "the seven numbered questions" is real. Treat thematic prompts as drafting aids, not as the official question set.

What the questions did not do

Just as important as what the RFI asked is what it did not touch:

  • The RFI did not amend 32 CFR Part 170, the CMMC Program Rule.
  • It did not suspend DFARS 252.204-7012 safeguarding or cyber-incident-reporting duties.
  • It did not create, change, or pause any contractor's CMMC status.
  • It did not commit the Department to adopt a single recommendation.
  • It was not a solicitation, and it did not promise a contract or reimburse response costs.
  • Submitting a response did not constitute CMMC self-attestation. The notice said so directly.

That last bullet has tripped up more than a few people, so we will say it plainly: writing to the Department about your compliance costs does not put an assessment result or CMMC status into SPRS, and it does not satisfy anything you owe under a solicitation, contract, or subcontract.


The right CMMC provider isn't the same for every contractor

The category you need — a C3PAO (CMMC Third-Party Assessment Organization), an RPO/RP (Registered Provider Organization / Registered Practitioner), an MSSP (Managed Security Service Provider), a GRC platform, or a CUI enclave — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation, contract, or flow-down identifies the status you must hold; a generic checklist does not. The required status tells you the destination. The unfinished work tells you who to hire first.

Because a general answer can't resolve those facts for you, compare the CMMC provider categories first, verify any claimed Cyber AB role in the Cyber AB Marketplace, then use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


What made a CMMC RFI response actually useful?

Responses that give the Task Force something to work with share one trait: bounded evidence. A number, a scope denominator, a time period, and a measurable outcome. Statements like "CMMC is too expensive for small business" are positions, not evidence — and the Department itself cited prohibitive compliance costs and administrative burdens in the July 13 suspension memorandum and the RFI.

We are including this section for a specific reason, and it is not nostalgia for a closed deadline. The Task Force is conducting a 60-day review. A later rulemaking, follow-on notice, or other public process may create another input window; an internal memorandum or class deviation may not. The evidence that would have made a good RFI response is still the evidence you will need to defend a budget, challenge a bad requirement, answer a prime, or participate in the next process that actually invites input. Build it now while your numbers are fresh.

The three cost layers almost nobody separates

This is the distinction that makes a cost claim usable, and it is the one we see collapsed most often in industry commentary.

Layer — What it covers — What the July 13 suspension changed
LayerWhat it coversWhat the July 13 suspension changed
1. Security implementationActually building and running the controls — MFA, logging, encryption, access control, incident response, the environment itselfNothing where the underlying clause still applies. DFARS 252.204-7012 continues to require NIST SP 800-171 implementation for covered contractor information systems.
2. Evidence and assessment recordsWriting and maintaining the System Security Plan (SSP), POA&Ms, policies, procedures, artifacts, and screenshots; producing the legacy NIST assessment result required by DFARS 252.204-7019/-7020; and producing CMMC self-assessment results and affirmations where the CMMC clauses applyNothing categorical. Phase I self-assessment requirements remain active. The legacy NIST score and the newer CMMC status are different SPRS records, and a contractor may need both.
3. Independent verificationPaying a C3PAO to perform a Level 2 certification assessment, or preparing for a Level 3 DIBCAC assessmentThe new procurement designations were paused. During the suspension, government program offices may not newly designate Level 2 (C3PAO) or Level 3 (DIBCAC) in procurement request and requirement documents. The Cyber AB states that voluntary Level 2 certification assessments remain operational and available.

Why this matters: when someone tells you CMMC costs a small firm six figures, ask which layer they are counting. A policy change can eliminate most of layer 3 without touching a dollar of layer 1. The July action removed the near-term government procurement mandate for new Level 2 (C3PAO) and Level 3 designations during the suspension. It did not erase implementation costs, evidence obligations, legacy SPRS score duties, existing private subcontract terms, or voluntary certification work. We walk through the arithmetic in should I stop CMMC compliance and break down the spend in our CMMC Level 2 cost guide.

The evidence fields that make a cost or benefit claim credible

This is our editorial framework, not a government rubric. But if you are building a record for the next input window — or for your own budget defense — these are the fields that turn an anecdote into evidence.

Question area — Evidence that makes it decision-useful — What to leave out
Question areaEvidence that makes it decision-usefulWhat to leave out
Cost and burden (Q1, Q3)One-time vs. recurring cost; internal hours by role; employee count; number of in-scope users and assets; CUI scope; delay created; which of the three layers the cost sits inCustomer names, rates tied to specific programs, architecture detail
Controls that worked (Q2)Requirement ID; the condition before and after; coverage percentage; the measurement period; a metric — incidents, dwell time, failed authentications, patch latency, recovery timeClaims that a control "prevents attacks"
Commercial capability (Q4)Capability class; what data it touches; the shared-responsibility boundary; which requirements the service supports; the assurance artifact (FedRAMP authorization, SOC 2 Type II, ISO 27001); what remains your responsibilityCredentials, tenant identifiers, network diagrams
Self-assessment (Q5)Assessment cycle time; staff hours; how stale your evidence gets between cycles; the friction points in SPRS; what triggers a re-scoreSPRS credentials, CAGE-linked system detail, the underlying evidence itself
Reform proposals (Q6, Q7)The specific action; who owns it; what authority is needed; the expected cost effect; the security guardrail that replaces what you removed; how you would measure whether it workedVague asks like "make it simpler"

The formula that separates a serious proposal from a complaint:

Change [specific process] because it costs [bounded evidence], while preserving [the security objective] through [replacement control, sampling, evidence method, or oversight].

Every proposal missing the second half of that sentence is asking the Department to accept less security in exchange for lower cost. Some of those proposals may be right. But they should be argued on those terms, not disguised as free savings.

A warning about what you write down

Do not put CUI, drawings, credentials, network diagrams, vulnerability scan output, penetration test results, export-controlled data, or sensitive contract details into any policy submission, worksheet, or intake form — including ours. Use sanitized categories, ranges, and summaries.

This is not boilerplate. The RFI required unclassified responses, warned respondents against including proprietary material, and said submitted materials would not be returned. Treat every attachment as if more people may read it than you intended.

Build the record now, while the numbers are fresh. Our readiness checklist covers scope, the SSP and POA&M, SPRS records, evidence organization by control family, provider sequencing, and the records behind a credible cost or effectiveness claim.

Download the CMMC Readiness Checklist →

Free. No CUI, drawings, or sensitive contract details — this is a general readiness resource, not an intake for sensitive material.


What are public CMMC RFI responses actually saying?

A small set of organizations published their submissions or source-level summaries. Across that sample, recurring themes include duplicated evidence work, unclear scope or CUI handling, recognition of existing commercial assurance, and some form of risk-based reform. There is no agreement on verification — and that, more than the existence of cost, is the real fault line in this reform.

Three notes before the table.

First, this is a sample, not a survey. Only responses a respondent chose to make public are visible. The Department said before the deadline that it had received more than 170 responses, but it has not published a confirmed final count or a public repository of all submissions. Do not read agreement in this visible sample as agreement across the Defense Industrial Base.

Second, every named respondent has an institutional or commercial stake in the outcome. The accreditation body, assessment firms, software companies, and trade associations all see different failure modes because they sit in different parts of the system. That does not make their arguments wrong. It means the business or institutional position belongs beside the recommendation, not hidden underneath it.

Third, every row below is first-party verified. We excluded a DEFCERT row that appeared in secondary excerpts because we did not locate the full 2026 response at DEFCERT's own site as of August 15, 2026. We would rather have a shorter tracker than a wrong one.

Public response tracker — verified August 15, 2026

Respondent — Stake in the system — Stated date — Core position — Verification status
RespondentStake in the systemStated dateCore positionVerification status
The Cyber ABCMMC accreditation body and ecosystem operatorAugust 14, 2026Preserve independent third-party verification as a trust mechanism; reduce unnecessary cost, duplicative documentation, inconsistent interpretations, and administrative friction; keep the NIST SP 800-171 Rev. 2 implementation obligation visible.Verified at source. Full response published by the Cyber AB.
Redspin (a Clearwater company)CMMC readiness, assessment support, managed services, and cybersecurity advisoryAugust 14, 2026Shift the program from paperwork-heavy demonstration to demonstrated control effectiveness without abandoning independent verification. Use risk-tiered verification, recognize FedRAMP/SOC 2 Type II/ISO 27001/MSSP evidence, automate limited evidence validation, and preserve credible spot checks and enforcement.Verified at source. Full response published by the company.
Peak InfoSecCMMC certification assessments and consultingAugust 3, 2026Reduce the burden of implementing NIST SP 800-171 and getting certified; delay Phase II because much of the DIB would not be ready for FY2027 C3PAO mandates; do not treat the delay as permission to stop security work. Peak also states it will continue voluntary Level 2 certification assessments during the suspension.Verified at source. Submission date and position published by the company.
Deep FathomCMMC compliance softwareAugust 13, 2026Preserve the near-term Level 2 baseline, reduce duplicated evidence work, replace the binary self-versus-C3PAO model with graduated verification tied to risk and material change, and use machine assistance only to organize and test evidence under accountable human validation.Verified at source. Complete submitted response published by the company.
Professional Services CouncilTrade association for federal professional and technology services companiesAugust 14, 2026Establish a single current cybersecurity framework, reduce the cost and administrative burden of demonstrating compliance without weakening control implementation, and move toward a risk-based model that recognizes contractors' existing Level 2 investments.Verified at source. PSC published the submission notice and its three priorities.

The real disagreement is not cost. It's verification.

Here is our editorial read, and we want to be clear it is a judgment rather than a regulatory finding.

Every source-verified response in this tracker proposes some reduction in cost, duplication, friction, or administrative burden. Agreement on the problem tells you almost nothing about the solution.

The actual fight is over what replaces — or preserves — the C3PAO check.

  • The Cyber AB says there is no substitute for third-party verification and argues that the independent conformity mechanism is the trust layer that self-assessment could not create at scale.
  • Peak InfoSec favors delay rather than abandonment and continues to offer voluntary certification assessments. That position preserves the model while moving the procurement clock.
  • Redspin and Deep Fathom both propose graduated or risk-tiered verification. They reserve deeper independent or government review for higher-consequence situations and use stronger self-assessment, reusable evidence, sampling, or targeted validation below that line.
  • PSC calls for a risk-based model that recognizes existing investments and reduces the cost of proving what is already implemented.

A third axis cuts across those camps: how much evidence review can be automated without automating the legal or governmental decision. Redspin proposes lightweight automated validation and spot checks. Deep Fathom is explicit that AI may organize and test evidence, but should not make award, certification, affirmation, or enforcement decisions. That is materially different from replacing human judgment with a machine.

What unites the serious proposals is that each names something to replace what it removes: independent verification, targeted government review, spot checks, reusable source-linked evidence, accountable human validation, enforcement, or some combination of them.

Why this should matter to you as a contractor rather than a spectator: if the Department moves toward tiered verification, your future obligation may turn more heavily on the consequence of the CUI, mission, system, or contract involved — not simply on company size. That is a scoping and contract-reading problem, and it is work you can start now without guessing how the Task Force will resolve the policy.

What these responses do not prove

  • They do not indicate what the Department will adopt.
  • They do not represent the Defense Industrial Base — the visible sample is self-selected and institutionally concentrated.
  • They do not establish typical costs. A respondent's estimate of burden or savings is evidence from that respondent, not a universal market result.
  • They do not change any current requirement. Not one word of a public RFI response is binding on a contractor, contracting officer, prime, or subcontractor.
  • They do not establish a final response count. "More than 170" was an official interim figure before the window closed, not the final total.

What the CMMC RFI did not change about your status

The RFI changed nothing about your CMMC status. The July 13 implementation memorandum did change which assessment designations government program offices may add during the suspension, but it did not erase Phase I Level 1 (Self) and Level 2 (Self) requirements, DFARS 252.204-7012 duties, legacy NIST assessment-result obligations, or the status-and-affirmation gate in a solicitation that carries DFARS 252.204-7025.

This is the section that turns deadline coverage into a contractor decision page, and it is where policy stops being interesting and starts costing money.

First, do not confuse the two SPRS records

A contractor can have two different cybersecurity records in SPRS, created by different clauses for different purposes.

Record — Governing provisions — What it contains — What it is not
RecordGoverning provisionsWhat it containsWhat it is not
Legacy NIST SP 800-171 DoD Assessment resultDFARS 252.204-7019 and -7020A current Basic, Medium, or High assessment result and summary-level score tied to covered systemsIt is not, by itself, a CMMC status or CMMC certification.
CMMC status record32 CFR Part 170; DFARS 252.204-7021 and -7025The applicable CMMC status, CMMC UID, and current affirmation of continuous complianceA legacy score of 110 does not automatically create this record.

The SPRS score guide walks that distinction in detail. The practical point is simple: a solicitation can require the legacy score, the CMMC status, or both. Read the actual clauses instead of treating "SPRS compliant" as one undifferentiated box.

The identifier almost nobody talks about

Read the actual solicitation provision — DFARS 252.204-7025, Notice of Cybersecurity Maturity Model Certification Level Requirements. We pulled the current text from Acquisition.gov on August 15, 2026. Four things are in it, and the fourth is the one that surprises people.

Paragraph — What it requires
ParagraphWhat it requires
(b)(1)The contracting officer inserts the required level: CMMC Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). That level, or higher, is required prior to award for every contractor information system that will process, store, or transmit FCI or CUI during performance.
(b)(2)The offeror is not eligible for award without both a current CMMC status in SPRS at the required level and a current affirmation of continuous compliance in SPRS for each applicable system.
(c)An offeror with a Conditional status must close out a valid POA&M under 32 CFR 170.21 to reach Final.
(d)The offeror shall provide, in the proposal, the CMMC unique identifiers issued by SPRS for each system that will handle FCI or CUI — and must update the list as new UIDs are generated. The provision says SPRS provides those UIDs after the offeror enters the self-assessment results for each system.

Now pair that with DFARS 204.7503, the companion procedure that tells contracting officers what to do. It directs them to check SPRS and not award to an offeror lacking a current CMMC status at the required level for each CMMC UID the offeror provided. The same check applies before exercising an option or extending a period of performance.

Here is the consequence, stated the way a proposal manager needs to hear it:

At proposal stage, DFARS 252.204-7025 provides no award-eligibility category called "in progress." For the self-assessment path, the provision ties the UID to entered results, while the SPRS operating tutorial shows the UID being assigned after the affirming official completes the affirmation. A company can have real controls, a serious SSP, and a mostly remediated environment — but if it has not completed the required SPRS record, it may have no CMMC UID to place in the proposal.

That is an operational conclusion from the provision and the SPRS workflow, not a quotation from the clause. In the source set and coverage we reviewed, we did not find another page that connects paragraph (d) to the prerequisite in the last sentence of that same paragraph and then checks it against the live SPRS affirmation workflow. The coverage we reviewed usually stops at eligibility. The submittable artifact, and the fact that it has a precondition, is where contractors actually get caught.

What the suspension did and did not touch

The original rule schedule put Phase 1 from November 10, 2025 through November 9, 2026, with Phase 2 beginning November 10, 2026. The July 13 action suspended that transition, and the Department now says implementation is paused in Phase 1.

Still binding where the clause or instrument applies — Suspended or held during the review — Still operational but not newly mandated by DoW during the suspension
Still binding where the clause or instrument appliesSuspended or held during the reviewStill operational but not newly mandated by DoW during the suspension
FAR 52.204-21 basic safeguarding for FCIThe November 10, 2026 transition to Phase 2Voluntary Level 2 C3PAO assessments, according to the Cyber AB's July 15 operational statement
NIST SP 800-171 Rev. 2 implementation where DFARS 252.204-7012 appliesNew procurement-request and requirement-document designations of Level 2 (C3PAO) or Level 3 (DIBCAC)Existing CMMC certifications and ecosystem functions
DFARS 252.204-7012 safeguarding and 72-hour cyber-incident reportingPending and future CMMC implementation milestones held in abeyance until further noticeReadiness, implementation, and assessment-preparation services
DFARS 252.204-7019/-7020 current NIST assessment-result requirements where includedCMMC waiver approvals during the review — the implementation memo says none will be grantedPrivate contract requirements unless the parties modify them
Phase I Level 1 (Self) and Level 2 (Self) CMMC requirements
SPRS posting and the required CMMC affirmation by an affirming official where the CMMC clauses apply
Existing contract and subcontract terms that have not been modified

Three traps in that table.

First: CMMC Level 2 is still assessed against NIST SP 800-171 Revision 2, not Revision 3. NIST withdrew Rev. 2 from its own publication catalog in May 2024 and replaced it with Rev. 3. For CMMC purposes, 32 CFR 170.14 still incorporates Rev. 2 and makes the Level 2 requirements identical to Rev. 2 — 110 security requirements across 14 families. Do not let a vendor present Rev. 3 as today's CMMC-controlling version unless the Department amends the rule or your contract separately requires it.

Second: the same version trap now exists at Level 3. NIST withdrew the February 2021 edition of SP 800-172 in May 2026 and published SP 800-172 Rev. 3. The current CMMC rule still uses 24 selected requirements from the February 2021 edition for Level 3. A newer NIST publication does not silently rewrite an incorporated regulation.

Third: relief does not flow downhill automatically. The July 13 implementation memorandum directs government program managers, requiring activities, and contracting personnel. It does not amend the private subcontract in your file. If a prime is still requiring Level 2 certification of you, ask in writing for the contractual basis, required status, systems in scope, and deadline before you change course.

If your solicitation still names a C3PAO assessment

This happens, and it is worth checking rather than assuming.

The implementation memorandum directed program offices to amend active solicitations to remove Level 2 (C3PAO) and Level 3 (DIBCAC) designations and directed removal from existing contracts by modification before the next option exercise or during the next scheduled administrative modification. Amendments and modifications are the instruments that change the procurement in front of you.

So a live solicitation that still names a C3PAO assessment may not yet have been amended — but you confirm that with the contracting officer in writing, not with a news article and not with this page. Ask whether an amendment is forthcoming. Get the answer in your file. Do not assume a memorandum rewrote the posted solicitation, and do not assume the posting remains controlling without asking about the directed amendment.

If that check turned up a real gap, sequence matters more than speed. The most expensive CMMC mistake is buying a platform, an enclave, or an assessment slot before confirming what your scope and level actually are. Tell the Find My CMMC Path tool your required level, whether you handle FCI or CUI, your assessment type, your environment, and your timeline, and it maps your situation to the provider category to compare first — readiness, managed security, GRC, or enclave. It routes to a category, never to a named provider. It is not a score, a ranking, or compliance advice.

Find My CMMC Path — map my situation to a provider category →

Free · Two minutes · No obligation · Educational triage only · Do not submit CUI, drawings, or sensitive contract details.


What happens after the CMMC RFI deadline?

The confirmed next step is completion of the CIO's top-to-bottom 60-day review, with the CMMC Reform Task Force charged to provide recommendations for a reformed cybersecurity and operational-resilience framework. Counting sixty calendar days from July 13 lands on September 11, 2026, so mid-September is the practical review marker. The memoranda promise further guidance at the conclusion of the review. They do not guarantee a public report on September 11, a publication format, an automatic Phase II restart, or any particular outcome.

The authority ladder — what actually changes a requirement

We built this because the single most common error we see right now is treating a recommendation, a memo, or a news story as though it changed a contract. Each rung binds differently.

Rung — What it is — What it binds
RungWhat it isWhat it binds
1. A public RFI responseStakeholder inputNothing. Not the Department, not you.
2. A Task Force recommendationPolicy advice to the CIONothing until the Department adopts it through an instrument with authority.
3. A Department memorandumOfficial internal directionGovernment personnel within its stated scope. The July 13 memoranda sit here.
4. A solicitation amendment or contract modificationThe instrument for your specific procurementYou. This is the rung that changes the solicitation or contract in your file.
5. A class deviation, final rule, or clause revisionA department-wide acquisition action, or an amendment to 32 CFR Part 170 or the DFARSThe covered acquisitions or regulated parties under its stated effective and applicability dates.

Practical read: the policy suspension starts on rung 3. The implementation memorandum then directs government personnel to create rung-4 amendments and modifications. Until your specific instrument changes, read the instrument and ask the contracting officer. Nothing on the current eCFR page has removed the four-phase text from 32 CFR Part 170, and the codified DFARS clauses remain published.

Confirmed versus not confirmed

Confirmed — Not confirmed
ConfirmedNot confirmed
A CMMC Reform Task Force is conducting a top-to-bottom 60-day program review.The exact date a public report will appear.
The RFI was issued to inform that review.Whether the Department will publish the responses.
The Task Force is charged to provide recommendations for a reformed framework.The final number of responses received.
Further guidance was promised at the conclusion of the review.A replacement Phase II date or automatic restart trigger.
The November 2026 Phase 2 transition and pending and future implementation milestones are suspended or held in abeyance until further notice.Which recommendations, if any, will be adopted.
Phase I self-assessment requirements remain active.Whether the outcome arrives as another memorandum, a class deviation, a solicitation action, a DFARS action, or a 32 CFR rulemaking.
No CMMC waiver requests will be granted during the review.Whether the eventual model preserves, narrows, or restructures C3PAO and DIBCAC requirements.

One published practitioner timeline worth knowing, because it is more conservative than most: Peak InfoSec has publicly stated it expects Task Force recommendations in mid-September, the earliest formal determinations around mid-October, and a substantial chance that nothing formal surfaces until late 2026 or early 2027. We cite that as an attributed industry expectation, not a prediction of our own.

What to watch, and where

If you monitor nothing else, monitor these four. They are the places a real change is most likely to appear first.

Source — What it tells you
SourceWhat it tells you
The Department CIO's CMMC pageTask Force output, new memoranda, implementation guidance, and program announcements
SAM.gov — the RFI noticeAny amendment, reopening, or follow-on notice tied to this market-research record
eCFR — 32 CFR Part 170Whether the CMMC Program Rule itself has been amended
Acquisition.gov — DFARS cyber clauses and proceduresWhether clause text, prescriptions, procedures, or a class deviation changed

Signals that would genuinely change what you owe — as opposed to changing the conversation — include a solicitation amendment, contract modification, class deviation, DFARS rule change, or amendment to 32 CFR Part 170. The exact instrument matters because each one reaches a different set of people and procurements.

Do not wait for a headline to tell you whether your own record is ready. Use the checklist to review scope, the 14 Rev. 2 families, SPRS records, affirmations, and the evidence behind them.

Download the CMMC Readiness Checklist →

Free. No CUI, drawings, or sensitive contract details.


What we actually verified

We do not ask you to take our word for any of this. Here is the source set, what each one supports, and — just as important — what we could not confirm.

Source — Read — What it supports
SourceReadWhat it supports
SAM.gov notice and RFI attachment — Reforming CMMC and Reducing Compliance Burden for the DIBAug. 15, 2026The August 14, 2026 12:00 p.m. ET deadline; late-submission rule; market-research status; no-award/no-reimbursement terms; seven numbered questions; no-self-attestation statement; notice identifiers
FAR 15.201(e)Aug. 15, 2026RFI responses are not offers, cannot form a binding contract, and RFIs have no required FAR-wide format — while this RFI separately imposed its own response format
July 13 CMMC reform memorandum and implementation proceduresAug. 15, 2026Phase II suspension; top-to-bottom 60-day review; Level 1 (Self) and Level 2 (Self) designations during the suspension; no new Level 2 (C3PAO)/Level 3 (DIBCAC) procurement designations; solicitation amendments and contract modifications; no waiver approvals; DFARS 252.204-7012 remains in effect
32 CFR Part 170 and the 2024 CMMC Program final ruleAug. 15, 2026Current codified Program Rule and its Federal Register source; original four-phase structure; Level 2 maps to NIST SP 800-171 Rev. 2; 110 requirements across 14 families; Level 3 uses 24 selected February 2021 SP 800-172 requirements; POA&M and affirmation rules
DFARS 252.204-7012Aug. 15, 2026NIST safeguarding requirement where the clause applies; 72-hour cyber-incident reporting; cloud and flow-down duties
DFARS 252.204-7019 and DFARS 252.204-7020Aug. 15, 2026Legacy NIST SP 800-171 DoD Assessment requirements, score posting, Basic/Medium/High assessment mechanics, and SPRS treatment
DFARS 252.204-7021Aug. 15, 2026Maintaining the required CMMC status, annual affirmation, flow-down, POA&M closeout, and CMMC UID reporting duties
DFARS 252.204-7025 and DFARS 204.7503Aug. 15, 2026Four status options; award eligibility; current affirmation; Conditional/POA&M rule; proposal CMMC UID requirement; contracting-officer SPRS check before award, option exercise, and extension
2025 CMMC Acquisition final ruleAug. 15, 2026November 10, 2025 effective date, which set the original Phase 1 start and November 10, 2026 Phase 2 date under 32 CFR 170.3(e)
NIST SP 800-171 Rev. 2 and Rev. 3Aug. 15, 2026NIST withdrew Rev. 2 in May 2024 and published Rev. 3, while the CMMC rule still incorporates Rev. 2
NIST SP 800-172 (February 2021) and SP 800-172 Rev. 3Aug. 15, 2026NIST withdrew the 2021 edition in May 2026 and published Rev. 3, while the CMMC rule still incorporates selected requirements from the February 2021 edition
SPRS CMMC guidance and tutorialsAug. 15, 2026Self-assessment entry, affirmation workflow, CMMC UID assignment, annual affirmation, and the distinction between CMMC and NIST assessment records
Cyber AB current downloads, including the CMMC Assessment Process, and the Cyber AB MarketplaceAug. 15, 2026The current official CAP source and Marketplace were checked. This page does not assert a CAP version number, turn CAP procedure into regulatory text, or claim a Marketplace status for a named provider.
Cyber AB July 15 operational statementAug. 15, 2026The Cyber AB's statement that voluntary C3PAO Level 2 assessments and ecosystem functions remain available; treated here as attributed operational information, not as a Department regulation
Cyber AB, Redspin, Peak InfoSec, Deep Fathom, and PSCAug. 15, 2026Each respondent's stated date, institutional or commercial position, and summarized recommendations in the public-response tracker
Department CIO social-media archiveAug. 15, 2026The official interim statement that more than 170 responses had been received before the deadline; not a final total

What we could not verify, and therefore did not publish as settled fact:

  • The final number of responses received. The Department publicly said it had more than 170 responses before the deadline, but no final official total was available as of August 15, 2026.
  • Whether the Department will release any or all responses. We found no publication commitment or official public response repository.
  • An exact date for a public Task Force report. The memoranda establish a 60-day review and promise further guidance; they do not promise a public document on a named day.
  • A replacement Phase II date, automatic restart mechanism, or final reform model.
  • A full first-party 2026 DEFCERT submission. We found secondary excerpts but did not include them in the source-verified tracker.
  • Any claim that NIST SP 800-171 Rev. 3 or SP 800-172 Rev. 3 already controls CMMC. The current rule text says otherwise.

How this page was produced: primary-source comparison against the governing regulations and clauses, direct review of respondent-published materials, and a regulation-stated-versus-operationally-reported distinction where the Cyber AB describes ongoing ecosystem operations. Written by The Defense Compliance Report Editorial Team. This page has not been formally reviewed by a CMMC Subject Matter Advisor.


Frequently asked questions about the CMMC RFI response

Is the CMMC RFI still open? No. The response window closed at 12:00 p.m. Eastern Time on Friday, August 14, 2026. We found no amendment reopening it as of August 15, 2026.

Can I submit a late CMMC RFI response? The notice stated that submissions after the specified date would not be considered. Only a formal amendment posted to the SAM.gov notice would change that. Sending an unsolicited late document does not make it a timely response.

Was the CMMC RFI a solicitation? No. It was a Request for Information — market research. Under FAR 15.201(e), responses to an RFI are not offers and cannot be accepted by the Government to form a binding contract. This RFI also said no award was intended and response costs would not be reimbursed.

Did submitting a response count as CMMC self-attestation? No. The notice stated explicitly that submissions did not equate to CMMC self-attestation. Your NIST assessment result, CMMC self-assessment result, CMMC status, CMMC UID, and annual affirmation are separate records or obligations.

What CMMC phase is active now? Phase 1. The CMMC Acquisition rule became effective November 10, 2025. Under the original four-phase schedule, Phase 1 was scheduled to run through November 9, 2026 and Phase 2 would have begun November 10, 2026. The Department suspended that transition on July 13, 2026 and now states that implementation is paused in Phase 1.

Did the Phase II suspension cancel CMMC? No. It suspended the November 2026 Phase II transition and held pending and future implementation milestones in abeyance until further notice. Phase I Level 1 (Self) and Level 2 (Self) requirements remain active, DFARS 252.204-7012 remains in effect where included, and 32 CFR Part 170 has not been amended to repeal the program.

Did the suspension stop voluntary C3PAO assessments? No Department source we reviewed says the assessment market was shut down. The Cyber AB states that voluntary Level 2 C3PAO certification assessments remain operational and available. That is operational information from the accreditation body, not a new contractual requirement.

Is NIST SP 800-171 Revision 3 now the CMMC Level 2 standard? No. NIST superseded Revision 2 in its own publication catalog, but 32 CFR 170.14 still incorporates Revision 2 for CMMC Level 2 — 110 security requirements across 14 families. Revision 2 governs CMMC Level 2 until the Department amends the rule or a separate contractual requirement says otherwise.

Does NIST SP 800-172 Revision 3 now control CMMC Level 3? No. NIST published SP 800-172 Rev. 3 in May 2026, but the current CMMC rule still uses 24 selected requirements from the February 2021 edition of SP 800-172 for Level 3.

How many CMMC RFI responses were submitted? The Department said before the deadline that it had received more than 170 responses. That was an interim figure. No official final total had been published as of August 15, 2026.

Will the Department publish all the responses? We found no commitment to publish responses and no official public repository. The responses visible today are ones respondents chose to publish themselves.

When will the CMMC Reform Task Force report? The Task Force is conducting a 60-day review that began July 13, 2026 and is charged to provide recommendations. Sixty calendar days lands on September 11, placing the review marker in mid-September. The memoranda promise further guidance at the conclusion of the review but do not guarantee a public report on that date or a publication format.

What is a CMMC UID and where do I get one? A CMMC unique identifier is assigned in SPRS for a CMMC assessment record. DFARS 252.204-7025(d) ties the UID to entered self-assessment results, and the SPRS operating tutorial shows the UID being assigned after the affirming official completes the affirmation. The provision requires offerors to provide the applicable UIDs in the proposal.

Is my legacy SPRS score the same as my CMMC status? No. The legacy NIST SP 800-171 DoD Assessment result under DFARS 252.204-7019/-7020 and the CMMC status record under 32 CFR Part 170 and DFARS 252.204-7021/-7025 are different records. A solicitation can require one or both.

My solicitation still says Level 2 (C3PAO). Is that enforceable? Ask the contracting officer in writing. The July 13 implementation memorandum directed amendment of active solicitations to remove Level 2 (C3PAO) and Level 3 (DIBCAC) designations during the suspension. A posting that still carries one may not yet have been amended, but the answer belongs in the solicitation record — not in an assumption.

Does the suspension change what my prime contractor can require of me? Not automatically. The memorandum directs government personnel; it does not modify a private subcontract. If a prime still requires certification, ask in writing for the clause or subcontract term, required status, scope, and deadline.

Can I still use a CMMC RFI response template? As a private evidence worksheet, yes — and we would encourage it. It can help separate cost layers, record internal hours, identify control outcomes, and prepare for a later public process if one opens. As a way to make a timely submission to this RFI, no. That window is closed.

Was this RFI a rulemaking comment period? No. There was no regulations.gov docket. It was an email-based market-research request. A future rulemaking would carry its own formal comment process, with different rules and a different deadline.


Where this leaves you

The RFI is a closed chapter, but it was never the thing that binds you. Your solicitation is. Your contract clause is. Your SPRS record is. Your prime's subcontract is. Those instruments did not move because the RFI closed on August 14.

The July 13 memoranda did move the government's phase-in plan, and they directed amendments and modifications. That is why the next step is not panic and it is not denial. It is to identify the instrument in front of you, the data your systems handle, the status that instrument requires, and the record you can actually prove.

If the past month left you unsure which category of help you actually need — readiness, managed security, evidence workflow, a scoped environment, or an assessment — that is the right question to resolve before you spend anything.

Need help deciding what type of CMMC provider you need?

Start with your level, scope, assessment path, environment, and timeline. The category tool tells you which kind of provider to investigate first. If you already know the category and want source-checked provider options, use the quote form.

Find My CMMC Path → · Request source-checked provider options → · Download the CMMC Readiness Checklist →

Free · No obligation. Provider matching or qualified introductions may generate referral or lead-routing compensation, disclosed at the point of recommendation. Do not submit CUI, drawings, export-controlled content, credentials, vulnerability data, or sensitive contract details.


Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial & Advertising Policy.

On the organizations named on this page: The Cyber AB, Redspin, Peak InfoSec, Deep Fathom, and the Professional Services Council appear here because they published positions on this RFI, not as recommendations. This tracker does not evaluate their services, and nothing here should be read as an endorsement or review. Any commercial relationship applicable to a named organization must be disclosed under our Editorial & Advertising Policy.

Independence: The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the Cyber AB, the Department of Defense, the Department of War, DCMA DIBCAC, NIST, or any U.S. government agency.

Not advice: This article is educational research and is not legal, contractual, cybersecurity, or compliance advice. CMMC requirements vary by solicitation, contract, subcontract, scope, system, and CUI handling. Confirm applicability and contractual consequences with a qualified CMMC practitioner and, where legal interpretation or representations are involved, a qualified federal-contracts attorney.

Published August 15, 2026 · Last verified August 15, 2026 · Corrections policy · Methodology · Editorial Standards · Editorial Review Process