The public comment period for the Pentagon's CMMC Reform Task Force's request for information closed Friday, August 14, 2026, at 12:00 p.m. ET — roughly midway through the 60-day review clock that started when the task force was announced in mid-July — moving the industrial base a step closer to a decision on whether third-party audits survive as the backbone of the Cybersecurity Maturity Model Certification program.

Background

DoD posted the RFI, titled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)," to SAM.gov on July 13, 2026, under Notice ID 89ef9bfb0834473791e991c712698d94. The notice asked contractors, assessors and other stakeholders to weigh in on how to cut compliance costs under CMMC without gutting the assurance the program was built to provide.

CMMC has been in flux for months. Phase 2 of the rollout, which was supposed to take effect November 10, 2026 and require Level 2 certification for companies handling controlled unclassified information, remains suspended. Phases 3 and 4 are on hold as well, pending the outcome of the review. In the meantime, contractors have defaulted to self-assessment rather than certified third-party assessment organization (C3PAO) review, the higher-assurance path CMMC was designed around.

DoD stood up the CMMC Reform Task Force to sort out what comes next. Its membership pulls from acquisition and sustainment, intelligence and security, the CIO's office, general counsel and legislative affairs, plus representatives from the Small Business Administration and the White House — a cross-section deliberately built to weigh security requirements against the practical cost of compliance for the companies that have to meet them. DoD CIO Kirsten Davies announced the task force's formation in mid-July alongside the RFI, starting a 60-day review clock; that window points to a decision point around September 11, 2026, followed by roughly 15 more days to synthesize findings before a public report expected around late September.

That timeline means contractors are operating in a holding pattern that has now stretched across multiple fiscal quarters. Companies that built compliance roadmaps around the original November 2026 Phase 2 deadline have had to shelve or slow those plans without a firm replacement date, and the closed RFI comment period was the first formal opportunity for the industrial base to put its concerns on the record before DoD commits to a direction.

Key Details

The central question industry has been asking since the RFI dropped is whether the task force will recommend dropping the mandatory C3PAO assessment requirement in favor of continued self-assessment — the practice contractors have already fallen back on during the Phase 2 pause. A decision to make self-assessment permanent, rather than a temporary bridge, would reshape CMMC's core compliance model rather than simply adjust its timeline.

Davies has framed the review as an effort to widen the front door to defense work rather than narrow it. "We are going to listen to what the defense industrial base has to say, especially small and innovative companies... to make sure that we are truly reducing barriers to entry for them to do business with the department," she said, according to reporting on the task force's early work.

Not everyone views a lighter compliance load as a clean win. Cybersecurity researcher Dr. Jim Purtilo has cautioned that the tradeoff is real, not cosmetic. "We get nothing for free," he said. "Higher assurance will demand stronger scrutiny and more discipline in operating practices." His point cuts at the premise behind the reform push: third-party audits exist because self-attestation alone left gaps in verifying that contractors handling CUI actually meet the security controls they claim to meet.

There is also a competitive-dynamics angle the task force will have to weigh. Companies that invested early in C3PAO readiness — hiring assessors, building documentation, budgeting for recurring audits — did so on the expectation that third-party verification would be the standard path to compliance and, by extension, a market differentiator against less-prepared competitors. If the task force recommends dropping the mandatory audit requirement, those early movers absorb costs that latecomers relying on self-assessment would not have to match under a lighter-touch regime.

What It Means for Contractors

Contractors handling CUI now have a specific date to watch: on or about September 11, 2026, the task force is due to hand its recommendations to Davies, with a public report to follow roughly two weeks later. Until then, Phase 2's Level 2 third-party certification requirement stays suspended, and self-assessment remains the de facto standard.

Companies that already hold or are pursuing C3PAO certification should not assume that investment is wasted regardless of what the task force recommends. A finding that keeps some form of third-party verification — even a scaled-back or risk-tiered version — would preserve the value of assessment work already underway. A finding that formalizes self-assessment as the permanent standard would still leave a market for companies that can demonstrate stronger security postures than self-attestation alone communicates, particularly on contracts where program offices or primes want assurance beyond the CMMC floor.

Small and mid-sized businesses have the most riding on the outcome. The task force's stated small-business focus signals that reducing the cost of proving compliance is a priority, but Purtilo's warning points to the other side of that ledger: lower verification requirements can mean lower assurance across the industrial base, a tradeoff DoD will have to defend if it materializes as a security gap down the line. Contractors should treat the coming weeks as a window to prepare for either outcome rather than a lull, since Phases 3 and 4 of CMMC remain queued up behind whatever the task force decides about the audit requirement at the center of Phase 2.

Firms currently relying on self-assessment should keep documentation current in case a shift back toward third-party review arrives with a shorter transition timeline than the original Phase 2 schedule allowed. Firms holding C3PAO certifications should watch for signals on whether that status becomes optional, tiered by contract sensitivity, or retained as the standard for CUI-handling primes and subcontractors doing business with the Department of Defense.

Sources