
Sixty Days to Fix CMMC: Class Deviations and Real Reform
The hosts break down what can actually be changed in a sixty-day CMMC reform sprint, from emergency Class Deviations to stopping pre-award flowdowns that burden small defense contractors. They also explore automatic reciprocity, self-attestation, and continuous telemetry as ways to cut compliance costs without weakening security.
Show Notes
- DoW Requests Information for CMMC Reform Task Force: https://advocacy.sba.gov/2026/07/20/dow-requests-information-for-cmmc-reform-task-force/
Chapter 1
The Sixty Day Mandate: Real Policy Levers Versus Bureaucratic Wish Lists
Eric Marquette
Question six from the Department of War RFI is, uh, it is surprisingly blunt. It asks directly what policy changes or regulatory reforms should the CMMC Reform Task Force recommend within their sixty day sprint window. Sixty days. That is not a lot of time to rewrite federal acquisition rules.
Paul Netopski
No, it is, uh, it is practically a second in government time. But if you want to give small defense contractors actual relief, you have to stop playing with templates and look at the real pressure point. The, the single biggest drain right now is prime contractors forcing pre award flowdowns of DFARS 252 204 7012 down to subcontractors who haven't even won a dollar of work yet.
Roz the Rulemaker
And, and from a regulatory standpoint, Paul is spot on. You cannot change thirty two CFR Part 170 in sixty days. Full Administrative Procedure Act rulemaking takes months, usually over a year, with notice, public comments, and interagency review. So if the Task Force wants immediate movement before the November Phase Two freeze, the only legal instrument on the table is issuing emergency Department of War Class Deviations and interim policy guidance.
Eric Marquette
Wait, so a, a Class Deviation just bypasses that whole year long notice and comment process?
Roz the Rulemaker
Um, exactly. It allows the Department of War to temporarily alter how standard clauses like the 7012 flowdown are applied in active procurements without waiting for a permanent CFR update.
Paul Netopski
Firsthand testimony here, not commentary. I just worked with a thirty person machine shop in Ohio. They were told by a tier one prime that to even bid on a sub component, they needed full CMMC Level 2 readiness verified by an outside team. They spent eighty thousand dollars on compliance consulting for a contract they ended up losing. Eighty thousand dollars down the drain for a bid. That is completely unworkable for small business.
Eric Marquette
Eighty thousand dollars just to put in a bid. That, that is absurd.
Paul Netopski
It is destroying the supplier base. A Class Deviation stopping pre award enforcement instantly cuts that burden.
Chapter 2
Reciprocity, Telemetry, and Breaking the Cost Barrier Without Compromising Security
Eric Marquette
So if emergency deviations fix the immediate pre award bottleneck, what about the actual cost of meeting the technical controls themselves? We talked last time about that seventy five percent documentation to twenty five percent technical split, but how do we fix the tech side?
Paul Netopski
You build automatic reciprocity. Right now, small shops are being forced into expensive GovCloud enclaves because commercial cloud platforms are locked behind rigid FedRAMP Moderate requirements. If a vendor already maintains a SOC 2 Type II or ISO 27001 certification, or uses a commercial cloud platform with equivalent controls, the Task Force should grant automatic recognition.
Roz the Rulemaker
And, and legally, the Department of War can do that for non prioritized Level 2 acquisitions right now. Instead of forcing every single supplier into a third party assessment organization bottleneck, where the math says it would take decades to audit everyone, you expand self attestation. You require the chief executive to sign off personally, backed by civil False Claims Act enforcement.
Eric Marquette
So, so the legal teeth come from the False Claims Act, not an expensive auditor showing up at the door?
Roz the Rulemaker
Precisely. If an executive lies about their security posture on an attestation, the Department of Justice can come after them under the False Claims Act for triple damages. It keeps accountability high without creating a physical traffic jam of assessors.
Paul Netopski
And pair that attestation with automated continuous telemetry instead of static paper binders. Stop making small businesses maintain two hundred page System Security Plans that sit on a shelf. Verify multi factor authentication, verify endpoint logging, verify automated patching through continuous digital reporting. That actually stops threat actors while stripping away the bureaucratic bloat.
Eric Marquette
It really comes down to whether leadership takes bold action within this sixty day window or lets the compliance status quo hold the line.
Paul Netopski
That is the choice. Real security or more paperwork.