Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Congress Wants to Help Small DoD Contractors Pass CMMC — Is It Enough?

While the Pentagon's own CMMC Reform Task Force works through more than 1,100 industry comments behind closed doors, Congress has started moving on its own track — with two bills that approach the small-contractor CMMC problem from opposite ends: information versus money.
Two Bills, Two Different Fixes
On September 16, the House Small Business Committee voted 23-0 to advance the Cybersecurity for Small Businesses Act (H.R. 10238), introduced by Rep. Tony Wied (R-WI) with Reps. Beth Van Duyne (R-TX) and Kimberlyn King-Hinds (R-CNMI) as original cosponsors. The bill doesn't change any CMMC requirement. It requires the Small Business Administration to work with CISA on general cybersecurity guidance, and — more specifically to CMMC — to coordinate with the Department of War to give small businesses clearer information on which certification level actually applies to them, distributed through SBA district offices, Small Business Development Centers, and online publication. Wied's office cited SBA's own estimate that some small firms had spent "upwards of hundreds of thousands of dollars" complying with requirements they may not have actually needed, in the absence of clear guidance on tiering.
Separately, the Senate Armed Services Committee has advanced a provision in the FY2027 National Defense Authorization Act creating a direct-cost grant program: up to $100,000 per company toward the direct costs of a CMMC Level 2 third-party assessment, with total program funding capped at $50 million and priority given to companies that have not previously held a DoD contract or subcontract. If it survives conference and becomes law, DoD would have to stand up the program by July 1, 2027. As of this week it remains a committee-passed provision, not enacted law.
Both bills exist because of the same underlying number: the SBA has estimated third-party CMMC Level 2 certification can run as high as roughly $593,800 for a small firm, a figure widely cited as a driver of the Pentagon's July 13 decision to suspend Phase II third-party audit requirements and stand up the Reform Task Force in the first place. That task force reportedly delivered its own recommendations to the Department's CIO around September 11, but the contents have not been made public, and a formal response to the RFI submissions is still pending.
What the Bills Don't Touch
CloudFit Software, a managed CMMC compliance provider and a founding sponsor of Unbiased Headlines, filed its own comments with the Reform Task Force in August, arguing for keeping NIST SP 800-171 as the security baseline while restructuring how compliance with it gets proven. Measured against that filing, both congressional bills land on different problems than the ones CloudFit flagged as the real cost drivers.
Assessment scaling. CloudFit's filing argued the current model applies close to the same assessment burden to a five-person shop and a 500-person prime, regardless of actual CUI footprint. The Senate's grant program addresses the resulting sticker shock — up to $100,000 toward the assessment bill — but a fixed per-company cap and a $50 million total pool cover a small fraction of the roughly 80,000 contractors estimated to eventually need Level 2 certification if Phase II is reinstated as originally scoped. It offsets cost; it doesn't change how the assessment scope is set.
Control inheritance. CloudFit's filing pointed to a specific inefficiency: every customer of the same Managed Service Provider can be required to separately re-verify identical, provider-operated controls, even when nothing about the customer's own environment differs. Neither bill touches inheritance rules. That's a Department of War policy and assessment-methodology question, not something an information-clearinghouse bill or a cost-offset grant program is built to fix — and it's also the piece most directly inside the Reform Task Force's own mandate, not Congress's.
Evidence modernization. CloudFit proposed modernized evidence standards built on the logs and configuration data systems already generate, rather than manually assembled documentation — plus narrower, standardized CUI enclaves to shrink assessment scope, and a longer-term government-sponsored secure-environment option for the smallest DIB firms (under 100 users). None of that appears in either bill. H.R. 10238's information mandate could plausibly help a small contractor scope which enclave or documentation approach it actually needs once guidance exists, but it doesn't create that guidance itself, and it doesn't fund building it.
The Honest Answer
Both bills are real, and both address something small contractors have genuinely struggled with — confusing tiering guidance in H.R. 10238's case, upfront assessment cost in the Senate NDAA provision's case. Neither is nothing. But measured against the specific structural complaints in CloudFit's own RFI filing — assessment scope that doesn't track actual risk, redundant re-verification of inherited controls, and evidence requirements built for paper rather than the operational data systems already produce — the answer to whether Congress's current moves are "enough" is no, at least not yet. Those three issues sit with the Reform Task Force and the Department of War's own rulemaking, not with SBA guidance or a capped grant fund. The task force's recommendations, still unreleased as of this writing, will determine far more about what small contractors actually face than either bill moving through Congress this month.
This article discloses sponsored content from CloudFit Software, a founding sponsor of Unbiased Headlines. CloudFit's RFI submission and its characterization here reflect the company's stated position; Unbiased Headlines has not independently verified every claim in the filing. This article is general informational content and does not constitute legal or compliance advice. Contractors should consult qualified legal counsel and a registered CMMC practitioner for guidance specific to their situation.
CloudFit Software is a founding sponsor of Unbiased Headlines. easyCMMC is CloudFit's managed CMMC Level 2 compliance offering, built on Microsoft GCC High and Azure Government infrastructure.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.