August 14, 2026
Re: Request for Information — Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base
Dear Members of the CMMC Reform Task Force:
Redspin, a Clearwater company, submits the following comments in response to the Department of War’s (“DoW”) Request for Information, Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (“RFI”). Redspin provides CMMC readiness, assessment support, and cybersecurity advisory services to Defense Industrial Base (“DIB”) companies of all sizes, giving us direct visibility into the compliance costs, assessment bottlenecks, and administrative burdens the Department has identified as barriers to a resilient, competitive industrial base.
We commend the Department’s decision to pause CMMC Phase II and undertake a top-to-bottom review before locking the DIB into a certification model that, as the Department has recognized, does not scale to the more than 100,000 companies that need it. Our comments below are organized around the RFI’s stated themes: (1) protecting federal data and uplifting operational resilience while reducing compliance costs and administrative burden; and (2) leveraging commercial cybersecurity capabilities, optimizing self-attestation, and streamlining compliance.
Executive Summary
Redspin’s central recommendation is that CMMC reform should shift the program’s currency from paperwork intensive demonstration to demonstrated control effectiveness — without abandoning independent verification altogether. Specifically, we recommend that the Department:
- 1. Adopt a risk-tiered verification model that reserves independent (third-party or government-led) verification for the CUI categories and contract types that carry the highest consequence of compromise, while relying on strengthened self-attestation for lower-risk information.
- 2. Recognize existing commercial certifications and managed security services (FedRAMP-authorized cloud, SOC 2 Type II, ISO 27001, MSSP-delivered continuous monitoring) as direct evidence of control satisfaction, reducing duplicative assessment work rather than requiring a parallel, from-scratch CMMC evaluation.
- 3. Weight the 110 NIST SP 800-171 controls by demonstrated risk-reduction value, rather than treating them as a flat checklist, and prioritize investment and audit attention on the small set of controls that drive the majority of real-world risk reduction.
- 4. Pair expanded self-attestation with lightweight, automated evidence validation and a credible spot-check/enforcement mechanism, so that reduced paperwork does not become reduced assurance.
- 5. Address the root cause of the Phase II bottleneck — assessor capacity — so that any future independent-verification requirement, for whichever subset of contracts still needs it, does not recreate the same unworkable math.
1.Protecting Federal Data and Operational Resilience While Reducing Cost and Burden
1.1 Cost drivers and administrative burdens the Department should prioritize for reduction
In our engagements across small, mid-size, and prime DIB companies, the largest cost and time drivers are not the underlying security controls themselves, but the compliance overhead layered on top of them:
- Scoping ambiguity — companies routinely over-scope their CMMC boundary (enclaving decisions, cloud-service-provider inheritance, managed-service-provider responsibility matrices) because current guidance leaves too much room for interpretation, driving both cost and risk of an inaccurate SPRS score.
- Recertification ambiguity — current guidance on what constitutes a recertification (Significant change, adding new CAGE Codes, changing service providers) leaves too much room for interpretation leading to increased cost and risk of an inaccurate SPRS score.
- Lack of approved templates — System Security Plan (SSP) and Plan of Action and Milestones (POA&M) formats that are unstructured and free-text, which multiplies both preparer time and assessor/reviewer time on each cycle.
- We receive continuous feedback from DIB Contractors that the DoW is still not properly marking CUI data leading to confusion and increased risks of data being marked improperly.
- Assessor and consultant scarcity relative to demand, which — as the Department’s own data shows — drove cost far beyond what the underlying technical work requires, particularly for small businesses with limited compliance staff. Additionally, requiring the assessment team structure to consist of all CCAs, rather than allowing the C3PAO to determine the team structure to best align with the technical work required to reduce cost burden for the OSC.
- Tier 3 Background Checks – Per 32 CFR §§ 170.11 and 170.13, CCAs and/or CMMC CCPs are required to complete a Tier 3 background investigation. Candidates who currently hold an active security clearance may complete the process in under one month, whereas candidates without a prior clearance should anticipate a processing period of twelve months or more. Given the extended duration and inherent unpredictability of adjudication timelines, organizations have assessors sitting on the bench until their investigation clears. Additionally, candidates are not eligible to initiate a Tier 3 application until after successful completion of the applicable CCP or CCA examination. Recommend allowing a “temporary status to operate” to avoid backlogs and to get assessors engaged now vs. later while their background checks complete.
Recommendation: publish standardized, policy, procedures, SSP, and POA&M templates to ensure consistency and to reduce labor burdens; issue authoritative scoping and inheritance guidance (including a safe-harbor determination process for common architectures); permit companies to satisfy overlapping federal cyber requirements through a single harmonized evidence package rather than parallel submissions; enforce data classification and marking compliance across all agency’s; allow the C3PAOs to determine the assessment team structure to reduce costs, and provide a temporary clearance status to get assessors engaged quickly.
1.2 Which NIST SP 800-171 controls deliver meaningful risk reduction
Based on assessment and incident data across our client base, a relatively small subset of controls accounts for most of the realized risk reduction. We recommend the Department weight compliance verification toward:
- Multi-factor authentication for all privileged and remote access (3.5.3).
- Boundary protection, network segmentation, and monitoring of connections to external systems (3.13.1, 3.13.5).
- Vulnerability scanning and timely remediation (3.11.2, 3.11.3).
- Encryption of CUI at rest and in transit (3.13.11, 3.13.16).
- Audit logging, review, and alerting sufficient to detect and reconstruct an incident (3.3.1–3.3.5).
- Least-privilege access control and timely account deprovisioning (3.1.1, 3.1.2, 3.1.5).
- Incident response and reporting capability, including practiced procedures rather than a documentation-only plan (3.6.1–3.6.3).
By contrast, a number of controls function primarily as documentation exercises with limited independent risk-reduction value once the technical controls above are in place. We recommend the Department consider a two-tier control model: a smaller set of “must demonstrate” controls subject to technical validation, and a broader set of “must document” controls satisfied through self-attestation alone.
2. Leveraging Commercial Capabilities, Self-Attestation, and Streamlined Compliance
2.1 DIB usage of existing commercial cybersecurity capabilities
Most DIB companies, particularly those that have already invested in cloud infrastructure and managed security services, are already meeting a substantial share of NIST SP 800-171 requirements through commercial tools that were never built with CMMC evidence collection in mind. The Department should recognize this reality rather than require a separate assessment layered on top of it:
- Grant direct control-satisfaction credit for FedRAMP-Moderate-or-higher authorized cloud services used to process, store, or transmit CUI, rather than requiring the DIB company to independently re-demonstrate controls the cloud provider has already been assessed against.
- Recognize current, in-scope SOC 2 Type II and ISO/IEC 27001 certifications as mapped evidence for the corresponding NIST SP 800-171 control families, subject to a gap analysis limited to the controls those frameworks do not cover.
- Recognize MSSP-delivered continuous monitoring, endpoint detection and response (EDR/XDR), and managed SIEM services as satisfying the underlying technical control when the MSSP can produce a standardized attestation of the service actually delivered to that client environment.
This approach shortens assessment timelines, reduces cost, and — importantly — rewards companies that have already made real security investments rather than requiring them to re-litigate that investment in CMMC-specific terms.
2.2 Optimizing self-attestation
Redspin supports an expanded role for self-attestation, provided it is paired with mechanisms that preserve its credibility. Self-attestation without any form of verification shifts risk onto the Department and onto the honest majority of contractors who compete against attesters who may not be accurately reporting their posture. We recommend:
- A risk-tiered model: FCI-only environments (Level 1) rely on self-attestation alone; CUI environments (Level 2) rely on self-attestation reinforced by targeted, risk-based government-led spot checks (as the Department is already doing during the interim period); and a narrow category of the highest-consequence CUI (e.g., export-controlled technical data, information tied to critical weapons or intelligence programs) retains independent verification.
- Automated, evidence-based attestation where feasible — validating control configuration directly from the environment (e.g., confirming MFA enforcement, patch status, or logging configuration) rather than relying solely on a manual, point-in-time narrative — to reduce both preparer burden and the risk of stale or inaccurate SPRS scores.
- Continued, visible enforcement under the Department of Justice’s Civil Cyber-Fraud Initiative for knowingly false attestations, paired with clear guidance so contractors understand what a defensible self-attestation record looks like. Absent credible consequences and clear expectations, self-attestation will not carry the confidence needed to fully replace independent verification for CUI.
2.3 Streamlining cybersecurity compliance more broadly
- Harmonize CMMC with other federal cybersecurity regimes (FedRAMP, StateRAMP, and the proposed government-wide CUI rule) so a company is not proving the same control three different ways for three different agencies.
- Establish formal reciprocity timelines and a public crosswalk between CMMC control requirements and common commercial certifications, so companies and assessors are working from the same mapping rather than each developing their own.
- Address assessor and reviewer capacity directly. The Department’s own analysis — more than 100,000 companies needing evaluation against roughly 100 accredited third-party assessors — was the proximate cause of the Phase II suspension. Any reformed model that retains independent verification for a subset of contracts should simultaneously expand who can perform that verification, so the same bottleneck does not recur at smaller scale.
- Provide cost relief specifically targeted at small businesses — subsidized or voucher-funded assessments, shared or pooled security services, and clearer guidance scaled to company size — consistent with the Small Business Administration’s findings on where the current cost burden falls hardest.
Conclusion
Redspin appreciates the opportunity to comment and supports the Department’s stated goal of achieving both meaningful cybersecurity and a lower-friction path for the DIB to compete and innovate. We believe that goal is best achieved not by choosing between rigor and speed, but by directing rigor precisely where the risk is highest and removing it everywhere it was only ever measuring paperwork. We would welcome the opportunity to provide additional detail, data, or briefings to the Task Force as its review proceeds.
Disclaimer: This RFI response reflects Redspin’s submission as of August 13, 2026. Additional updates may be included in the final submitted version and will be reflected here when possible.



