Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
The Pentagon Asked Defense Contractors How to Fix CMMC. The Comment Period Just Closed.

The public comment window on reforming the Pentagon's cybersecurity certification program closed Friday, August 14. What happens to the roughly 220,000 companies in the Defense Industrial Base now depends on a task force with about a month left to turn thousands of industry submissions into a recommendation.
How the Program Got Here
The Cybersecurity Maturity Model Certification, or CMMC, exists to verify something the Department of War has required by contract for years but historically took on faith: that companies handling Federal Contract Information and Controlled Unclassified Information actually protect it. Before CMMC, contractors self-attested to following NIST SP 800-171's 110 security controls. CMMC added a verification layer — Level 1 and Level 2 self-assessments, and, for Phase II, mandatory third-party audits by Certified Third-Party Assessment Organizations (C3PAOs) on contracts involving CUI.
Phase II was scheduled to begin November 10, 2026. On July 13, the Department suspended it. The stated reasons were cost, a shortage of qualified assessors, and concern that the compliance burden was pushing small and mid-sized firms — exactly the innovative suppliers the Pentagon says it wants to keep in the defense industrial base — out of government contracting entirely. Alongside the suspension, the Department stood up a CMMC Reform Task Force and opened a formal Request for Information, asking industry to identify the top cost drivers, the controls that deliver real security value versus the ones that mostly generate paperwork, and specific policy changes that could lower the barrier to entry without lowering the security bar.
Phase I self-assessment requirements, and the underlying DFARS 252.204-7012 obligation to protect CUI, were never paused. Only the third-party certification requirement was.
What Independent Observers Are Watching For
The reform effort now sits with a task force that has to produce recommendations by roughly mid-September — a compressed timeline for digesting an open comment period on a program touching a supply chain this large.
Dr. Jim Purtilo, an associate professor of computer science at the University of Maryland, told ClearanceJobs the task force faces a genuine tradeoff, not just an administrative cleanup. "Last year's pause of phase II requirements was intended to lighten the administrative burden of compliance," Purtilo said. "We get it: third-party audits are indeed expensive, and the tight deadlines would have excluded a number of smaller companies from competing in the DoW space. Now the task force is in the tough position of trying to find a way for DoW to have its cake and eat it too, which is to say, come up with low-burden practices that will still yield high technical standards of assurance."
Purtilo's caution is that lowering the audit burden and lowering actual risk are not automatically the same thing. "We get nothing for free," he said. "Higher assurance will demand stronger scrutiny and more discipline in operating practices. The task force will thus inevitably need to grapple with tradeoffs. And that's really tough since in many ways the science for objectively vetting such things isn't there yet." He pointed to a deeper problem behind the debate: the data needed to know which specific controls actually reduce breach risk, versus which just generate compliance overhead, is not well established. "Practices thus risk degenerating into implementation of folklore and guesses, meaning expense that arises from 'abundance of caution.' That this is what the task force will need to cut through."
In the meantime, Purtilo noted, contractors are back to self-assessment — a standard he does not describe as rigorous. "That, honestly, is not a high bar to get over at all," he said. "So the sooner that we're given strong guidance, the better."
What Industry Is Asking For
The RFI drew formal responses from across the compliance and managed-services side of the industry. CloudFit Software, a managed CMMC compliance provider and a sponsor of this publication, was among the companies that filed. Its submission, shared with Unbiased Headlines, argued for keeping NIST SP 800-171 as the security baseline while restructuring how compliance with it gets proven — a framing consistent with the broader industry position that the fix belongs in the verification process, not the underlying standard.
The specifics in CloudFit's filing track closely with the concerns Purtilo and others have raised publicly: assessment burden that does not scale with actual risk, evidence requirements built around static paperwork rather than the operational data systems already generate, and a certification model that can require every customer of the same Managed Service Provider to separately re-verify identical, provider-operated controls. That last point is a structural inefficiency Purtilo's framing implies too — if the task force is genuinely trying to lower administrative cost without lowering assurance, redundant verification of controls that don't vary between customers is close to a textbook example of cost with no corresponding security benefit.
CloudFit's submission also proposed narrower, standardized CUI enclaves to shrink the number of systems in scope for assessment, modernized evidence standards drawing on logs and configuration data instead of manually assembled documentation, and — as a longer-term idea — a government-sponsored secure environment option for the smallest DIB companies, those under 100 users, who currently face the choice of building a compliance environment from scratch or going without.
The Open Question
Nobody outside the task force knows yet which of the ideas submitted during the comment period will survive into an actual rule. The Department has not published a timeline for a formal response to individual RFI submissions, and the mid-September target for task force recommendations is itself informal.
For contractors, the practical situation has not changed since the July pause: the certification calendar is under genuine revision, but the underlying legal obligation to protect Controlled Unclassified Information has not moved. Whatever the task force recommends, security work tied directly to that obligation — access control, monitoring, incident response, a documented and current record of who owns which control — remains work worth doing regardless of how the assessment framework around it is eventually rebuilt.
This article includes sponsored content from CloudFit Software, a founding sponsor of Unbiased Headlines. CloudFit's RFI submission is reported here as its stated position and disclosed accordingly; Unbiased Headlines has not independently verified every claim in the filing. This article is general informational content and does not constitute legal or compliance advice. Contractors should consult qualified legal counsel and a registered CMMC practitioner for guidance specific to their situation.
CloudFit Software is a founding sponsor of Unbiased Headlines. easyCMMC is CloudFit's managed CMMC Level 2 compliance offering, built on Microsoft GCC High and Azure Government infrastructure.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.