Frontline Feedback: DIB Pushes Back on CMMC Costs as Task Force Weighs Reform

The Department of War’s request for information on reforming its cybersecurity certification program has drawn more than 170 responses from the defense industrial base, signaling widespread industry concern over compliance costs and assessor shortages.

The Office of the DoW Chief Information Officer announced the response volume in a LinkedIn post, noting that over 650 people have also participated in listening sessions regarding the Cybersecurity Maturity Model Certification program. The feedback comes as a newly formed CMMC Reform Task Force conducts a 60-day review of the program.

DoW Chief Information Officer Kirsten A. Davies suspended the CMMC Phase II requirements on July 13, 2026. The suspension halted a Nov. 10, 2026, deadline that would have required third-party assessments for contractors handling controlled unclassified information. In a memo signed that day, Davies wrote that “administrative compliance cannot come at the cost of warfighting capability and industrial base growth.”

Davies cited data from the Small Business Administration indicating that the current CMMC program is structurally incompatible with the need to rapidly expand the defense industrial base. The SBA estimated that compliance costs could reach $593,800 per certification for small firms requiring third-party assessments, potentially costing small and mid-sized businesses more than $7 billion annually. SBA Administrator Kelly Loeffler said CMMC compliance was “becoming an untenable barrier pushing them out of the Defense Industrial Base.”

The suspension also reflects a structural mismatch between demand and assessor capacity. More than 100,000 companies were projected to need third-party certifications under Phase II, but the Cyber Accreditation Body had only around 1,000 certified assessors in place — far short of the 2,000 to 3,000 estimated as necessary for full implementation, according to Federal News Network.

The CMMC Reform Task Force is mandated to deliver recommendations by mid-September 2026. The task force aims to align the program with Secretary of War Pete Hegseth’s Acquisition Transformation System, which prioritizes speed to capability and lowering barriers for small and non-traditional businesses. A DoW press release described the review as a “top-to-bottom” examination of the certification program.

The RFI, published on SAM.gov under notice ID DoDCIOReformingCMMCforDIB001 and administered by Washington Headquarters Services, asked contractors to identify prohibitive cost drivers and administrative burdens associated with CMMC compliance. The comment period closed Aug. 14, 2026. Comments from the LinkedIn post thread reflect the contested nature of the debate: some respondents argued that CMMC assessment costs are overstated by conflating implementation costs with certification fees, while others said solopreneurs and very small businesses remain underrepresented in the RFI process.

During the suspension, the department continues to enforce baseline compliance with NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments. Existing contractual cybersecurity clauses, including DFARS 252.204-7012 on safeguarding covered defense information, remain in effect. The DoW’s Cyber Crime Center, the NSA Cybersecurity Collaboration Center and the Office of Small Business Programs’ Project Spectrum continue to serve as no-cost resources for DIB companies.

Industry experts warn that the suspension does not eliminate cybersecurity obligations. According to McCarter & English government contracts attorneys, the shift away from third-party assessors places the legal risk of self-attestation directly on contractors, increasing exposure under the Department of Justice’s Civil Cyber-Fraud Initiative. “The compliance burden went down; the weight on your affirmation went up,” the firm wrote. “Only one of those carries treble damages.”

The CMMC program has now been paused twice — once by the Biden administration in 2021 and again under the current administration. The Cyber AB’s chief executive Matthew Travis called the latest suspension “both surprising and disappointing,” but said the organization remained confident that third-party verification would “prove itself indispensable under a rigorous review.”

AI generated