The hosts pick apart the reform task force’s seven RFI questions and argue the whole exercise is structurally confused: it asks for feedback on things outside the CMMC program’s actual scope, crowdsources security judgments from people who never implemented the controls, and promises to cut bureaucracy while inviting the exact clarifications that create more of it.
Key takeaways:
- Wrong scope from question one. CMMC is a verification program, not the requirements. FIPS, FedRAMP, GCC High/data sovereignty, and DFARS 7012 aren’t CMMC’s doing — they come from export-control law, the FAR/DFARS, and NIST. Asking the RFI to “fix” them misunderstands the program.
- Bad data source. Asking the ~75% of the DIB who never implemented the controls which ones are most/least effective just collects opinions from non-implementers treating this as a reprieve. The government already has the answer (MITRE ATT&CK ↔ 800-53 mapping).
- You can’t cut bureaucracy by adding clarity. Every demand to define “significant change” or “FedRAMP equivalency” is more bureaucracy — and you’ll get the government’s answer, not yours (see: how SSPs became mandatory).
- The MSP fix was already in the original rule. Certifying MSPs so clients inherit was the efficient path; removing it pushes redundant work onto every company. Rev 3’s supply-chain-risk family may partly cover it going forward.
- The timeline is unrealistic. Recommendations land ~end of September, with no interim bridge between “doing nothing” and “changing everything,” and rulemaking can’t clear before the 2028 election. Meanwhile, DIBCAC keeps assessing critical suppliers.
Transcript
Jacob: All right, folks. It is July of 2026, and the DoD Chief Information Officer has suspended CMMC Phase 2 requirements and directed a CMMC reform task force to comprehensively review the program and deliver actionable recommendations for reform. They want your feedback on an RFI, and responses are due by 12:00 p.m. Eastern on Friday, August 14th. That’s what we’re going to talk about today.
Jason, the DoD wants to reduce compliance and cost burdens while also uplifting IT and OT resiliency across the DIB. I don’t know about anybody else, but those two ideas seem like they’re kind of in tension.
Jason: So — I agree with you wholeheartedly. And the other thing that really throws me off here is: there were so many problems that we had to pause Phase 2, but we need you to tell us what those problems are so that we can address them. It’s definitely a weird one, because they’re like, “Hey, we’re going to pause this verification program because people are struggling with these existing requirements” — but then they’re talking about OT requirements and other new IT requirements, and asking for feedback on seemingly expanding those requirements. Somehow they’re also going to do that while reducing burden, complexity, and cost. I don’t know how that’s possible, but we’ve got to look at the questions in the RFI to maybe see what they’re hinting at.
Jason: Yeah, one of the main things was modernizing your environment, right? Replacing legacy systems immediately stands out to me as one of those things that’s not cost-saving in nature.
Jacob: Yeah, I don’t think so. But hey, that’s what the RFI is for. And that’s the beauty of public feedback, right, everybody? So let’s look at the requested information in the RFI. What do you know — we had nothing to do with this, trust us — there’s seven questions. There’s seven.
Jason: It’s always seven.
Jacob: We’re not taking credit for this one, but they probably got the idea from us. Anyways, first question here: “Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced or anticipates when attempting to comply with the CMMC framework and NIST SP 800-171 Revision 2.” Everybody stop. Everybody stop what you’re doing — don’t stop your car if you’re driving while you’re listening to this, but everybody stop, metaphorically.
I thought we were reviewing the CMMC program. How many times have we covered this concept? The CMMC program is not a set of requirements. The CMMC program fills a massive, incredibly naive policy gap that the DoD has maintained since 2011: they send sensitive controlled DoD data into non-federal networks, and they don’t ever ask for proof that that data is being protected. The entire reason the CMMC program exists is to try to address that problem — the proof that the requirements are being implemented. It is not the program the requirements; it’s the verification program.
We did a whole episode after the 32 CFR CMMC final rule was published where I literally spent 10 minutes walking through and saying every single thing that was submitted in a public comment to the program rule that is out of scope of the CMMC program. What’s in scope is scoping guidance, levels, assessment processes, roles and responsibilities, oversight. Things like the NIST requirements, CUI policy and marking, DFARS 7012 language, FedRAMP requirements, ITAR and data sovereignty requirements, international agreements — completely out of the scope of the CMMC program. So why, in the first question on the RFI reviewing the CMMC program, are we asking about things that aren’t part of the program?
Jason: Yeah. So this is what immediately came to mind for me: why does the first request for information match up with a majority of the comments for the programmatic rule that we read, that the DoD specifically said were outside the scope of this specific rule? It boggles the mind, but hey, that’s what they want feedback on. They got a lot of feedback on the public comments on all three CMMC rules at this point about stuff like this, but they said it was out of scope. So I’m not sure what will be different this time. It’s pretty confusing. But let’s move on to the next question. So the next question: “Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction?”
Jacob: Two thoughts here. One — per my last email, literally to the DoD CIO in January, when I flew all the way across the country to meet her in person, I sent her our research mapping MITRE ATT&CK techniques and NIST SP 800-53 controls — MITRE’s own analysis of which NIST controls mitigate real-world advanced persistent threat activity. Since 800-171 is derived from 800-53, it’s not much of a jump to say which 800-171 controls help address, to some degree, real-world bad-guy cyber activity. We’ve done the research on Chinese APTs. We’ve done the research on Iranian APTs. Sent this in an email directly to the DoD CIO, in addition to putting it out on our platforms. Never got a response. Never got a response. But pro tip, DoD: that’s a great place to start. You already have the data. But it’s strange to me that we’re talking about reducing burden on 75% or more of the DIB who don’t understand the security requirements, and then asking them which security requirements are the most effective. Are you going to get the quality of answer that you’re looking for?
Jason: Do you think a majority of the respondents to this RFI are going to be organizations that are sitting with a pretty 110, that went through the process, that did all of these things, and they’re going to say, “This was the most problematic control for me”? Or are we going to get the opinions of organizations with negative 32 SPRS scores that say, “This one — or none of these controls — offered any tangible security benefit to my organization”? That’s the issue with this open-sourced feedback: you get the opinions of organizations that aren’t implementing it, that don’t have any intention to implement it, and now see this as a reprieve from requirements that they’ve let sit for a while, right?
Jacob: I mean, they’re asking which controls contribute to actual risk reduction. Shouldn’t you guys be telling us? Aren’t you the government, with access to all the intel and the reporting and the analysis and the projects that did all the mapping with the FFRDCs and all that stuff? Shouldn’t you be telling us what your risk tolerance is and what you think the controls are that mitigate the risk? That’s what 800-171 was.
Jason: I read the question more like the expectation is, “Tell me a time when a control you implemented as part of this framework helped you stop Iran, or helped you stop China.” I don’t know if the people you’re asking know that.
Jacob: And like I said, they should be telling us. They should be telling us. But we’ll see how people respond.
Jason: Still haven’t implemented the controls — that’s what we’ve been trying to tell you.
Jacob: Pretty hard to say which ones are the most effective if you haven’t implemented them. That’s a great point. Moving on to question three: “Conversely, which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture?” Two thoughts here. First of all, for all of you out there who blame CMMC for needing to migrate into sovereign cloud solutions like GCC High — again, that is a data sovereignty problem imposed on you by export control regulations that predate CMMC by literal decades. The requirement to keep data sovereignty is not imposed on you by the CMMC program trying to get assurance over requirements imposed on you by the FAR and the DFARS. Other than that — because I’m sure people are going to be like, “moving to GCC High is so expensive” — CMMC ain’t the thing making you move to GCC High, or any of the sovereign cloud solutions. Beyond that, I already know what everybody’s going to say: FIPS validation. FIPS validation. FIPS validation. We can all agree it’s very expensive, and the case for validating cryptographic modules for security benefit is a case — but not necessarily one that a lot of people find compelling.
Jason: Yeah, I can’t argue with that. I think anybody who answers, for question two, that none of the controls provide tangible uplift and benefit — “tangible,” it’s a terrible word for me, I get it — I think those same people, conversely on “which ones are problematic,” are going to answer “all.” All are problematic.
Jacob: “Yeah, that’s why we haven’t implemented it — it was just too much of a burden for us.” Multifactor authentication of all flavors.
Jason: You caught the tater. “I couldn’t do it because it was just too much of a burden,” right? Like — not beneficial. Turning on logging and monitoring — not beneficial, too much burden, too much overhead.
Jacob: So I think people are going to say FIPS — that’s perfectly valid, I personally agree with them. Here’s the problem: it’s not part of the CMMC program scope. That’s a perfectly valid thing, and you keep saying that FIPS validation needs to be taken out of the requirements — CMMC doesn’t make it a requirement. It’s not part of the CMMC program. So sure, we’re going to get the same feedback we’ve had all along. Is the CMMC program review task force going to change the government’s rationale around FIPS validation and get NIST to take it out of the baseline? I don’t know. They didn’t in the past. Everybody’s been clamoring and complaining about FIPS for seven years.
Jason: So you’re going to say everyone will say FIPS, and you say FIPS. I agree — FIPS is one of those problematic ones. But when you dig deeper into the foundational parts of the implementation, right — change management, the overhead requirements, the gravity of every single change, and the financial restrictions that come not only with making the changes and implementing the technology, but whatever overhead comes with that. And in addition, the thought process of the change possibly taking you out of scope and making you get reassessed — another financial addition. Those are things people are going to consider, and they should be considered — however, had they not been considered already, Jacob…
Jacob: But this gets to this point: everyone agrees the guidance around significant change is way too nebulous, and nobody knows what to do. And this gets to a point we’ve made on this show many, many times. The entire case that the CIO and the under secretary and the SBA are making is that there’s too much bureaucracy. And what is everybody going to say? “You need to explain to us what this means.” What’s that called, everybody? All together now: bureaucracy. You’re asking for government answers to open-ended, nebulous statements. If you want specifics around what FedRAMP equivalency means, you are asking for more bureaucracy. If you want specifics around what significant change means, you’re asking for more bureaucracy. Fast-forward 60 to 75 days from now — they’re not going to make these more open-ended.
Jason: And to the open-ended comment, Jacob — the more clarification you ask for, the more specifics you get, the more prescriptive the requirements get. And therefore, the less flexibility you as an organization have to make this bend around your business. Which is the intent.
Jacob: Word to the wise: system security plans were originally not a requirement. And then the defense industrial base went to the DoD and said, “How do you want us to document this?” And the DoD literally was like, “Are you sure about that? You sure you want us to tell you how we would document it, rather than coming up with your own solution for documentation?” Okay — guess how the government documents stuff. Endless SSPs and paperwork. If you want to know how significant change is going to be explained — guess what, you’re going to get their answer for what significant change means, instead of your answer. We’ve covered that topic a bunch. I guarantee you that’s going to be an issue coming out of the review. But let’s keep moving.
Number four: “Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk — and how the Department of War might better recognize or accept these commercial solutions within a compliance or risk framework.” Here’s a hint: go back to the original 32 CFR proposed rule and require that managed service providers — who are responsible for the vast majority of contractor security, IT, and resiliency out there — go get the certification that proves that they’re implementing the requirements for their clients, and then let people inherit all of that from their MSPs. We were this close to being very effective and efficient at solving this problem. But by removing that requirement, you’re now asking every individual company at every level in the DIB to then go to the one MSP that they all use, in these clusters around the supply chains, to do this work over and over and over and over and over again. We already had the answer in the original rule.
Jason: We did already have the answer, but I think the answer requires us to go back and then go forward, right? Last week we said “two steps forward, two steps back.” We’re two steps back and two steps forward. I 100% agree that MSPs, because of the surface they represent, need to be certified. There needs to be verification there. But if we think forward, Jacob — isn’t there a whole new family that’s going to cover this in 800-171 Revision 3?
Jacob: As far as we know. So you’d be documenting the way you’re managing risk with your supply chain — all of these vendors, not just MSPs, because there’s software, there are organizations that don’t use an MSP. So where is the risk being managed in the supply chain that you use to compile the things you’d normally get from an MSP? So can we go backwards, make that a requirement so we have that extra assurance, and then go forwards and use the Rev 3 supply chain risk management stuff that needs to be put in place to make sure we thoroughly do it this time?
Quick note on the last question — when they say “how the DoD might better recognize or accept these commercial solutions within a compliance or risk framework,” you know what that is? Bureaucracy. It’s bureaucracy, because you’ve got to get them to explain their rationale — how it’s going to work, how it won’t work, exceptions, waivers, edge cases, blah blah blah. Guess what that’s called? It’s bureaucracy. So, bureaucratic red tape being removed for bureaucratic orange. I don’t know how to tell you guys, but you’ve got to embrace the bureaucracy if you want to actually make it better. You can’t come out and say, “We’re suspending this entire program because bureaucracy bad,” spend an entire week demonizing bureaucracy, and then invite questions about how to clarify things that you can only do through the bureaucracy. But whatever — I don’t run PR for these guys.
Question five: “Regarding phase one self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance? And how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture approach, or are they performed only for compliance purposes?” We’re going to jump through six and seven here, because they all kind of lead up to the same thing. Question six: “What specific actionable policy changes or regulatory reforms should the CMMC reform task force recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses without degrading the protection of federal data?” And the last question: “What specific actionable policy or regulatory reforms should the reform task force recommend over the next 60 days to drastically improve operational — as in OT — resilience against cyber attacks at your organization?”
Okay, let’s just talk realistically here. Everybody watching this knows we talk about rulemaking a lot. Everybody knows rulemaking ain’t fast. Even if you get the clearance for interim final rules — which is an incredibly rare anomaly to be able to get — you’re not going to get the recommendations from this task force, and then 15 days, according to the DoD CIO’s latest interview, to get the report together, until the end of September. And that’s if the government stays open. So any major structural changes to the CMMC program — let alone other changes outside the scope of the program, like DFARS 7012, FedRAMP, NIST requirements, CUI policy, any of those other things that aren’t even part of the CMMC program — all have to go through rulemaking.
Jason: Does anybody remember there’s an election in 2028? Which means, from the time this ends — assuming the government stays open — we’re going to be into the holidays, when not a lot of stuff gets done. So you’re probably going to come up with a plan or a proposal by the end of the year. And then any of these changes, to be effective, have to go through rulemaking before that election gets done. Remember how everybody would berate us about how the election is going to slow stuff down, or change things, or any of that? We’re right back over here, and now everybody’s like, believing that we’re just going to rapidly get through regulatory changes. It ain’t going to happen. You just don’t have enough time to affect those changes before 2028. But even if you have the rules persist through 2028 and into the next administration — which would dramatically slow things down, because there’s going to be regulatory freezes, there’s going to be program reviews, there’s going to be new appointees, all this stuff — what does everybody do in the interim?
Jacob: We’re just going to stay on Rev 2. We’re not going to do any OT requirement. What are we all going to do in the end? What’s the plan here? These are all big-picture questions, and I agree with a lot of them, but the realistic way of navigating the bureaucracy and actually getting them implemented doesn’t sound realistic on the timeframes they’re talking about. Unless they have some sort of magic easy button that no one before this current leadership team has ever been able to find or create, they’re not going to be able to get these types of recommendations that they’re asking for done in time.
Jason: So you’re looking at, technically, kind of what you’ve been wishing for — the prolonged extension of phase one. Meanwhile, like we talked about last week, DIBCAC’s out here running assessments on targeted companies, on critical suppliers. We already have the answers here. They already know what they can do. It doesn’t take this long rule—
Jacob: Well, this is the problem — they’re talking about changing the program. If you only change the nature of the program and nothing else, it still requires rulemaking. So what are you going to do in the interim? That’s the big question, and I don’t think they’re going to have an answer for it. I think they might have a lot of good ideas at the end of 60 to 75 days — a lot of big-picture stuff that sounds great, makes everybody really happy — but they’re not going to have a plan in the interim. I have yet to see an indication from the RFI that they’re going to have a bridge of what to do between currently, which is basically doing nothing, and then changing everything all together, all at once. And then there’s the defense of changing a federal regulation — you have to have statistics to prove that this is legitimate change, right? Not just, “This is what we feel like. This is a threat to our national security. Let’s pull this.” Well, there are limits to supplanting rules and rulemaking through a bunch of random memos. There is an upper limit to how long you can get away with doing that. But anyways, those are the questions in the RFI. They’re interested in your feedback. We’re interested to hear what people think. We’re definitely interested to see if they just take all these recommendations and throw them into an LLM and go, “Hey, fix CMMC. Don’t make any mistakes.” Regardless, your responses are due by 12 Eastern on August 14th — that’s a Friday. Make sure you do your homework ahead of time. Make sure you like and subscribe, and we’ll see you next week.
Jason: See you next week.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
