The Future of CMMC Is Being Written.
Your Experience Matters.
The Department of War has issued an RFI seeking practical recommendations on how to improve the CMMC Program while continuing to safeguard federal information. There are two ways to participate: directly, or collaboratively with the CMMC Industry Standards Council.
“The strongest cybersecurity programs are not built solely through regulation. They are strengthened by the collective experience of the Patriots that implement them every day. Protecting CUI protects our Warfighters.”
This Is Not a Pause in Protecting CUI
Following the Department’s announcement temporarily suspending implementation of CMMC Phase II, it established a CMMC Reform Task Force and issued this RFI. For perhaps the first time since CMMC was introduced, every organization, from the smallest supplier to the largest prime, has a direct line to influence the next evolution of the program.
This review is not a reduction in the importance of protecting Controlled Unclassified Information. It is an opportunity to improve how those protections are implemented and assessed across the DIB.
Choose your path.
Doing both is encouraged.
CISC submissions are compiled separately into a consensus-based industry response for the CMMC Reform Task Force. A CISC submission does not replace a direct response to the Department; the two channels are complementary. Either way, the response builder below assembles your draft.
Contribute to the CISC industry response
Your input is compiled with the rest of the ecosystem into a single consensus-based response. Submit as an individual, on behalf of an organization, or anonymously, in whole or in part. One strong, specific recommendation is enough.
Respond to the official RFI on SAM.gov
Organizations are strongly encouraged to also respond directly to the Department in accordance with the official instructions in the RFI notice on SAM.gov.
Pick the ones you have lived.
Build your response.
You do not need to answer all seven. One strong, specific recommendation on a single question can be more valuable than a lengthy response to every one. Use this to capture your thinking; your finished response goes in as a Word or PDF document, and the panel walks you through the steps.
How can the DoW better leverage existing commercial cybersecurity capabilities to protect CUI and reduce compliance burden?
How can the DoW optimize self-attestation or other self-verification mechanisms to maintain trust while reducing cost and administration?
What specific requirements, processes, or documentation could be streamlined or eliminated to reduce burden without reducing security?
What are the top cost drivers in achieving and maintaining compliance, and how can they be reduced?
How can CMMC requirements be structured to support, not hinder, small, medium, and non-traditional businesses in the supply chain?
What reforms would best encourage innovation, operational resilience, and broad adoption of secure commercial solutions?
What other ideas, approaches, or policy changes should the CMMC Reform Task Force consider?
The Department asks for the point of contact name, address, phone, email, and fax in the submitted document.
The email opens pre-addressed to the CISC with the subject line filled in. Attach your finished Word or PDF document.
What to send, and what to leave out.
- MS Word or PDF only
- 10 pages maximum, single-spaced, 10-pt Times New Roman, 1 inch margins
- Text in graphics, tables, and figures no smaller than 9-pt
- Plus a 1-page cover letter, not counted toward the limit
- Responses must be unclassified
- Company name, DUNS or UEI, CAGE Code, and point of contact, unless submitting anonymously
- Responses to any of the seven questions
- Feedback on feasibility
- Potential risks, challenges, or innovations worth considering
- Proprietary information. Materials marked proprietary will not be considered or returned
- Hard copies
- Extraneous materials such as brochures
This RFI is for market research and planning purposes only and does not constitute a solicitation. Responses are not offers and cannot be accepted by the Government to form a binding contract. The Department will not reimburse any costs associated with responding. Submissions to this RFI do not equate to self-attestation for CMMC.
The appearance of U.S. Department of War (DoW) visual information does not imply or constitute DoW endorsement. The CMMC Industry Standards Council will compile and consider all submissions received by August 2 for inclusion in a consensus-based industry response. Individual submissions to the Department are also encouraged.
This page is provided by FutureFeed as a contribution to the CISC community response effort. Publication does not imply FutureFeed’s endorsement of the CISC final submission or of any individual recommendation contained within it. CMMCISC.org · futurefeed.co