Time-Sensitive
How to Submit a Comment on the CMMC Reform RFI Before the August 14 Deadline
The Department of War is asking industry how to fix CMMC, and small contractors have a short window to answer. Here is where the notice lives, how to send your comment by email, and how to write one that actually gets read. Comments are due August 14, 2026 at 12:00 p.m. ET.
Last reviewed: August 10, 2026 · 7 min read
Deadline: Friday, August 14, 2026 at 12:00 p.m. Eastern Time
You comment by email, not through a public portal. The task force is expected to hand in its recommendations around September 13, 2026, so this is your one clean shot to put small contractor reality on the record.
The short version
After suspending CMMC Phase 2 on July 13, 2026, the Department of War asked the defense industry for input to guide a CMMC Reform Task Force. Any contractor can respond, and small businesses are exactly who they say they want to hear from.
To comment: email a Word or PDF of up to 10 pages to both official addresses before noon Eastern on August 14, 2026. Lead with real numbers, not general complaints, and answer only the questions where you have actual experience.
Where to find the notice, and where these instructions come from
Everything below comes straight from the official RFI notice, which the Department of War posted on SAM.gov (the government's system for contract opportunities). You can read the full notice yourself here:
Official RFI notice on SAM.gov (Notice ID 89ef9bfb0834473791e991c712698d94)
If that link ever moves, go to SAM.gov and search the Notice ID above, or the title "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base." The U.S. Small Business Administration's Office of Advocacy also published a plain summary of the same questions, linked in the sources at the bottom.
One habit worth keeping: the government can amend a notice. Before you hit send, open the SAM.gov posting and confirm the mailbox, the format rules, and the deadline against the live version.
The short version: where, how, by when
What it is
A request for information (RFI) from the Department of War, titled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base." It is market research, not a contract or a formal rule.
Where it lives
Posted on SAM.gov under Notice ID 89ef9bfb0834473791e991c712698d94. That posting is the source of every instruction on this page.
How you respond
By email only. There is no regulations.gov docket, so do not wait for a comment portal that is never coming.
By when
By 12:00 p.m. Eastern Time on Friday, August 14, 2026.
Who they want to hear from
Defense Industrial Base companies. The notice specifically calls out small, medium, and non-traditional businesses.
The seven questions, in plain English
The RFI asks seven things. You do not have to answer all of them. Pick the ones where you have real experience and skip the rest:
1. What costs you the most
Your top five most expensive or time-consuming burdens under CMMC and NIST SP 800-171 Rev 2. What actually hurts.
2. What is worth it
Which security controls genuinely reduce your risk. The ones you would keep even if nobody made you.
3. What is just expensive paperwork
Which requirements eat the most time or money for the least real security. This is the question most small shops have the strongest answer to.
4. What you already run
The commercial tools and managed services you already pay for (cloud suites, managed security, device management) and how the Department should give you credit for them.
5. What is painful about self-assessments
What makes Phase 1 self assessments hard to do and report, and how the process could be simpler.
6. What would help small businesses
Specific policy changes that would cut cost and lower the barrier to entry for small and non-traditional businesses.
7. What would actually make you safer
Changes that improve real resilience against attacks, not just audit paperwork.
How to send it, step by step
Write it as a Word or PDF file
Word or PDF only. Keep the body to 10 pages or less: single spaced, 10 point Times New Roman, 1 inch margins. Any text inside tables or graphics should be at least 9 point.
Add a cover letter if you want one
A one page cover letter is allowed and does not count against your 10 pages. Optional.
Say who you are
Include your company name, DUNS or UEI number, CAGE code, and a contact person, unless you are commenting anonymously.
Email both addresses
Send to [email protected] and [email protected]. Missing the second address risks your comment not being counted.
Use this subject line
Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB).
Send it before noon Eastern on August 14
The clock is the receiving mailbox, not your outbox. Do not send it at 11:58.
Email only. There is no regulations.gov portal for this RFI.
Treat your response as a public document. Assume it can be compiled, shared, or released.
No CUI, no client or prime names tied to sensitive work, and no network or vulnerability details. Describe the cost and the burden, not your architecture.
Keep proprietary information out. The notice says proprietary material may not be considered or returned.
How to write one the task force will actually use
Staff will read a lot of these. The ones that shape the final report all look similar. Aim for this:
Open with two sentences on who you are: employee count, what you do for the defense supply chain, whether you handle CUI, and the CMMC level you are working toward.
Answer the numbered questions in order, labeled 1 through 7. Not an essay. Staff compile answers question by question, so make yours easy to drop into a pile.
Give numbers, not adjectives. "Compliance is expensive" gets skipped. "Our 12-person shop spent about $38,000 in year one, including $14,000 in consulting and roughly 400 staff hours" gets quoted.
Separate security spending from paperwork. Turning on multifactor authentication makes you safer; assembling audit evidence is overhead. That split is exactly what question 3 is asking for.
Pair every burden with one concrete fix. If something is painful, say in one sentence what change would fix it.
Keep it tight. Three focused pages that answer two or three questions well beat a padded ten.
A simple structure you can copy
If a blank page is the hard part, start with this and fill in your own numbers:
Who we are: size, role in the defense supply chain, whether you handle CUI, main tools you run. Two sentences.
Questions 1 through 7: labeled answers, numbers first, one concrete ask each. Skip any question where you have nothing to add. A blank beats filler.
Close: what a right-sized set of requirements would look like from where you sit, and whether you are open to follow-up.
What still applies to you right now
The suspension changes the assessment schedule. It does not pause your current contract obligations. While the review runs, all of this still applies:
DFARS 252.204-7012 still requires you to safeguard covered defense information and report cyber incidents.
NIST SP 800-171 Rev 2 is still the standard if you handle controlled unclassified information.
Your SPRS self assessment score still needs to be reported and should match what you actually do.
The False Claims Act still applies, so anything you say about your cybersecurity, including in this RFI, should line up with your records.
A note before you send
This is general information to help you take part, not legal advice about your contracts. If your response touches sensitive contract details, prior attestations, or your SPRS score, have counsel or your compliance lead look it over first, and confirm the instructions against the live SAM.gov notice before you hit send.
Sources
- Official RFI notice on SAM.gov, Notice ID 89ef9bfb0834473791e991c712698d94 (source of the submission address, format rules, and deadline)
- U.S. Small Business Administration, Office of Advocacy: DoW Requests Information for CMMC Reform Task Force (July 20, 2026)
- Holland & Knight: DoW Suspends CMMC Phase II Requirements (July 2026)
- ArentFox Schiff: CMMC Reform Task Force RFI, Defense Contractors Have a Chance to Shape Federal Policy
- 32 CFR Part 170 (CMMC Program rule), eCFR
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information
This guide is general information for defense contractors, not legal or compliance advice for your specific situation. CMMC rules and DoD contract clauses change over time. Confirm current obligations against your contract language and official DoD and Cyber AB sources before making decisions.
Keep reading