CMMC Reform Task Force RFI: Defense Contractors Have a Chance to Shape Federal Cybersecurity Requirements

On July 13, in connection with the suspension of its Cybersecurity Maturity Model Certification (CMMC) Phase II roll-out, the US Department of Defense/War established a CMMC Reform Task Force, charged with reviewing and proposing reforms to the Department’s cybersecurity program requirements for the Defense Industrial Base (DIB).

On

To help inform the Task Force’s review, the Department has issued a Request for Information (RFI) seeking industry input on ways to reduce administrative burdens and costs while still ensuring the security of federal data.

The Department has found that the costs and administrative requirements of CMMC Phase II may be prohibitive for small, medium, and non-traditional businesses. In addition, the Department has found unnecessary duplication within the existing cybersecurity requirements framework. The review and reform effort is intended to streamline the regulations and to eliminate roadblocks for small, medium, and non-traditional businesses to partner with the Department. 

To help the Task Force achieve those objectives, the RFI poses the following seven specific questions.

  1. Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced, or anticipates to experience, when attempting to comply with the CMMC framework and NIST SP 800-171 Rev 2.

  2. Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction?

  3. Which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture?

  4. Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk, and how the Department might better recognize or accept these commercial solutions within a compliance or risk framework.

  5. Regarding Phase I self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance, and how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture approach or are they performed only for compliance purposes?

  6. What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses without degrading the protection of federal data?

  7. What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically improve operational resilience against cyberattacks at your organization?

Although the stated purpose of the review is to ensure federal data remains secure without imposing undue burdens on small and non-traditional businesses, accomplishing those objectives will benefit the entire DIB, and DIB entities of all sizes and types should consider submitting responses to the RFI. Indeed, because of the costs and administrative requirements, many small and non-traditional businesses may not have pursued certification at all. As a result, they may have limited information to inform responses to some or all of the questions posed, while larger, traditional businesses can provide helpful insights about the costs, challenges, feasibility, risks, and benefits of the CMMC regime from actual data and experience.

If you would like more information or to discuss submitting a response to the RFI, please contact one of the authors of this article. 

Contacts

Continue Reading