Cybersecurity Maturity Model Certification (CMMC) Unlocked
All Episodes
CMMC Freeze: Reform, RFI Fallout, and Small Contractor Relief

CMMC Freeze: Reform, RFI Fallout, and Small Contractor Relief

0:00|0:00

The hosts break down the July 13 CMMC Phase II freeze, the Department of War’s 60-day reform task force, and the immediate fallout for defense contractors facing new uncertainty. They also examine a detailed RFI response focused on upstream accountability, post-award verification, and how over-marking and compliance overhead are reshaping the defense supply chain.


Chapter 1

The July 13 CMMC Shockwave and the 60 Day Reform Mandate

Eric Marquette

On July 13, 2026, the Department of War completely froze the CMMC Phase II rollout, halting a process that was slated for November 10. They set up a 60 day CMMC Reform Task Force to deal with what they called prohibitive compliance costs for defense contractors. Paul, as a Certified CMMC Assessor, where were you when that July 13 announcement dropped?

Paul Netopski

I, uh, I was literally sitting at my desk reviewing a system security plan for a small machine shop in Massachusetts. They had spent close to $40,000 getting ready for an assessment. And then, boom, Phase II suspended overnight. My phone just lit up with panicked calls from small business owners asking if all that capital was just thrown down the drain.

Roz the Rulemaker

Well, from a regulatory standpoint, that sudden halt is fascinating. The Department opened a compressed 30 day public comment window ending August 14, 2026 at 12:00 PM Eastern, directed right to Ms. Leanne Condren. When you see an agency issue an RFI with a tight 30 day turnaround like that, it usually means the policy reforms are already largely pre drafted inside OIRA or the Secretary office. They are looking for specific evidence to justify decisions they have already mapped out.

Paul Netopski

Look, the pre award certification model was fundamentally broken. Forcing small suppliers to spend hundreds of thousands of dollars on pre award certification against a completely unknown scope, before they even know if they will win the contract, it, it turned compliance into a massive barrier to entry. You have small machine shops bowing out of the defense industrial base entirely.

Roz the Rulemaker

I get the financial strain, Paul, I really do, but suspending Phase II without an immediate replacement creates massive legal ambiguity. DFARS clause 252 dot 204 7012 is still active in existing contracts. Contracting officers are now left in limbo, unsure how to verify self attestations while the Task Force deliberate, which opens up huge False Claims Act exposure for contractors trying to navigate this gap.

Eric Marquette

So we have this tension between immediate financial relief for small suppliers and total regulatory uncertainty across the supply chain.

Chapter 2

Netopski's RFI Blueprint Reclaiming Upstream Accountability

Paul Netopski

That is exactly why I submitted my formal response to the RFI on August 9. Firsthand testimony, not commentary. My blueprint rests on a three part thesis. First, fix upstream government practices like over marking and improper flowdowns. Second, move verification post award where it is funded by contract revenue. And third, take the money currently wasted on Project Spectrum and reallocate it to direct, SBA led education for small contractors.

Roz the Rulemaker

That 75 25 split you cited in your response caught my eye at OMB. You argued that small business compliance is 75% documentation and only 25% technical controls.

Paul Netopski

Because the government has never authoritatively defined what done looks like! Small businesses do not lack the will to secure their systems; they lack clear guidance. So they hire predatory commercial consultants who sell them 500 page template packages. Then, when an assessor comes in, we have to audit them against their own over engineered policies, which go way beyond what NIST SP 800 171 actually requires.

Eric Marquette

Wait, so they build policies that bind them to rules the government never even asked for?

Paul Netopski

Precisely. And it compounds with the marking problem. Government systems routinely append automatic CUI banners to totally blank forms or standard outbound emails. An email with no sensitive data arrives stamped CUI, and boom, that contractor whole email server is suddenly pulled into CUI scope. It is a contagious over marking cycle that expands scope in only one direction.

Roz the Rulemaker

And if a small contractor challenges the marking, they risk alienating the program manager who awards their next contract. The economic incentive is to stay quiet, absorb the massive scoping cost, and pass it downstream to subcontractors.

Eric Marquette

That is the core battleground for the Task Force. In our upcoming episodes, we are going through Paul RFI submission question by question to see if the Department will enforce real self discipline or just shuffle the burden around. Thanks for joining, see you next time.