Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
The Department Asked Seven Questions. Read Them Closely. | Overwatch Tools
Analysis · The Deviation, Part 2

The Department Asked Seven Questions. Read Them Closely.

The Task Force report isn't public. The questions that shaped it have been public since July — and almost nobody has read them carefully.

By Rob Maupin, Overwatch Tools — author of the CMMC Practical Guides series: Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2.

Published October 1, 2026. This article reflects the Department of War memorandum of July 13, 2026, the class deviation memorandum of September 3, 2026, and reporting available at the time of writing. The CMMC Reform Task Force's internal reporting deadline was September 11, 2026; publication of its recommendations is at the discretion of the Department Chief Information Officer and guidance may change. We will update this article as the situation develops.

Since July, a lot of small defense contractors have picked up the same habit. Open a browser, search "CMMC," scan the headlines for the word report, close the tab. Try again tomorrow.

The answer they are waiting for is not public yet. But the single most useful document in this whole episode has been public since mid-July. It is short, it is free, and almost nobody outside a policy shop has read it closely: the Request for Information (RFI) the Department of War (DoW) published when it stood up the CMMC Reform Task Force.

An RFI is an agency asking out loud, and agencies do not pick questions at random. What they choose to ask is the closest thing to a direction indicator anyone outside the building can get — and unlike the report, it costs nothing to read.

This article will not tell you what the Task Force recommended. Nobody outside the Department knows, including me. It will read the seven questions the way you would read a clause in your own contract — slowly, asking what each one is reaching for.

That is not a prediction. It is a reading of what was asked.

The Setup, Briefly

On July 13, 2026, Department Chief Information Officer Kirsten Davies signed the memorandum suspending CMMC Phase 2 — the November 10 transition that would have made a certified third-party assessor organization (C3PAO) assessment the default for many contracts — along with every pending and future milestone. The same memo stood up the CMMC Reform Task Force, reporting to the CIO, with 60 days for a top-to-bottom review of the program.

The RFI, titled Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base, went up on SAM.gov alongside it and closed at noon Eastern on August 14. Davies told the Billington Cybersecurity Summit on September 9 that the Department received more than 1,100 responses; at the Department's DIBX conference in Philadelphia in late August she put the volume at more than 11,000 pages. The Task Force's internal deadline was September 11. What happens to its report after that, including whether and when it is published, is the CIO's decision.

One thing in the rulebook has actually moved since July, and precision matters here. The pause no longer lives only in a memo. Revision 2 of class deviation 2026-O0025 carried it into acquisition instruction on July 16, and Revision 3, signed September 3, is the current operative text. I walked through that sequence — and what the September reporting got half-right — in Part 1 of this series. So far, the deviation is the only concrete instrument in this entire story. Everything else is still questions.

So let's read them.

The Seven Questions, in Plain English

Each question is paraphrased below; the full text is on SAM.gov and reproduced by the SBA Office of Advocacy, both linked in Sources. Under each is what the question is actually reaching for, written for a contractor with fifteen employees and no IT department.

1

What are your five biggest cost drivers?

What was asked: name the five most prohibitive cost drivers, administrative burdens, or operational challenges you have experienced — or anticipate — in complying with the CMMC framework and NIST SP 800-171 Rev 2.

This is a question about which parts of the program produce paperwork rather than protection. Notice that it names two things in one breath: the CMMC framework and NIST SP 800-171. Those are not the same thing. One is a verification program; the other is the safeguarding standard itself. Asking about the burden of both together is how you find out where the cost actually sits — in the controls, or in proving the controls to someone else.

2 & 3

Which controls actually reduce risk — and which cost the most for the least?

What was asked: Question 2 asks which specific security controls delivered the most tangible uplift and actual risk reduction. Question 3 asks the reverse: which requirements or controls create the highest administrative overhead and financial burden with the least measurable improvement to your security posture.

These two are a matched pair, and they are the most analytically interesting pair in the set. Together they ask industry to help the Department rank controls by value. That is a question you ask when you are considering whether every control has to carry equal weight. It does not tell you what the Department concluded about that. It tells you the Department wanted the ranking.

The useful part: you can run that ranking for your own company today. Some practices do a great deal of protective work for little effort — controlling who can log in, keeping systems patched, knowing where your contract data lives. Others are mostly documentation of things you already do. Knowing which is which is valuable under any version of the program, and it is exactly how both volumes of my CMMC Practical Guides are organized — Volume 1 and Volume 2 group the practices by what they actually protect rather than by citation order, because that is the order in which a small business can reason about them.

4

Can the commercial tools you already pay for count?

What was asked: how you use existing commercial cybersecurity capabilities, platforms, managed services or other strategies to protect data, improve resilience and reduce risk — and how the Department might better recognize or accept those commercial solutions within a compliance or risk framework.

The second half is the operative part: whether an existing platform, managed service, or vendor attestation could be recognized inside the compliance framework instead of being re-proven by every contractor who uses it.

If you have ever paid twice for the same assurance — once to your managed service provider to run the controls, and again to a consultant to translate the MSP's work into NIST SP 800-171 language — that is the duplication this question is reaching for. The RFI's own framing paragraph names the use of existing commercial capabilities as one of the three areas it wanted input on. A question about recognizing commercial solutions is a question you ask when you are considering whether the work a platform already does could stand in for some of the paperwork contractors currently produce about it. It is a question, not an answer.

5

Are Phase I self-assessments actually working?

What was asked: specifically regarding Phase I self-assessments — what administrative or technical challenges you face in maintaining, verifying and reporting compliance, and how that process could be fundamentally streamlined. And then: whether self-assessments have led to a more dynamic cyber posture, or are performed only for compliance purposes.

Read this one twice. It is not a general question about self-attestation in the abstract. It is about Phase I self-assessments — the thing you are already required to do, and the thing the July memo explicitly left in place.

The first half is practical, and its three verbs describe three different jobs. Maintaining is keeping the assessment true as your environment changes. Verifying is being able to show someone why it is true. Reporting is getting it into the Supplier Performance Risk System (SPRS) with an affirmation attached. The Department asked where each of those breaks down, and how the whole process could be fundamentally streamlined. That adverb is the Department's word, not mine, and it is not a casual one.

The second half is the most revealing sentence in the entire RFI. The Department asked, in writing, whether the self-assessments it requires have produced a more dynamic security posture — or whether contractors are performing them only for compliance purposes.

That is an agency asking whether the exercise it requires is working.

I am not going to read an answer into it. The Department has not published one, and we have not read the 1,100 responses. But it is worth naming plainly what kind of question this is. It is not a question about burden. It is a question about meaning — whether the self-assessment on file describes the network, or describes a form someone filled out.

And here is the part only you can answer. If your self-assessment is a spreadsheet that gets opened once a year, updated from memory, and submitted the week the affirmation comes due, you already know which half of that question describes your company. That is not a judgment and it is not a warning. It is simply the question the Department chose to ask, applied to the one company you control.

6 & 7

What should we actually do — on cost, and on resilience?

What was asked: Question 6 asks what specific policy changes or regulatory reforms the Task Force should recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium and non-traditional businesses, without degrading the protection of federal data. Question 7 asks the same about drastically improving operational resilience against cyber-attacks at your organization.

These are the open floor, and two things about them are worth noticing. First, they are addressed to industry, not to the Task Force's own analysts — the Department asked the people who carry the burden to write recommendations in their own words.

Second, Question 6 carries its own boundary inside the sentence: reduce cost and barriers without degrading the protection of federal data. That clause is not decoration. It marks the outer edge of what the question invites. Question 7, meanwhile, is not about compliance at all. It is about resilience — whether your company can take a hit and keep operating.

Read together

Lay the seven side by side and they describe an agency asking three things: which requirements it could drop or lighten, whether commercial tools and managed services could substitute for some assessment work, and how far self-attestation can be stretched — along with whether, as practiced today, it is worth stretching. That lines up with the RFI's own framing paragraph, which names using existing commercial capabilities, leveraging and optimizing self-attestation, and streamlining compliance requirements as the areas it wanted perspectives on.

That is not a prediction. That is what was asked.

Answer Question 5 for your own company.

The free CMMC Assessment Tool walks all 15 Level 1 practices and returns an instant gap report with a prioritized remediation roadmap. Under 30 minutes, no credit card — and a fast way to find out whether your self-assessment describes your network or a form.

Run the Free Level 1 Gap Check

What the Department Has Said Out Loud

Questions show what an agency is curious about. On-the-record statements show where it has drawn lines.

"We're not relaxing any standards by any means." — Michael Duffey, Under Secretary of War for Acquisition and Sustainment, to reporters on July 13, 2026 (Breaking Defense)

In the same remarks, Duffey said businesses are to adhere to the standards NIST has outlined, and described what was being removed as the bureaucracy of third-party assessment — not the requirement underneath it.

Davies at the Billington Cybersecurity Summit, September 9. She said cybersecurity remains critical and vital, and that the Department wanted to hear from the defense industrial base about meaningful, dynamic cybersecurity. Note the word dynamic — the same word Question 5 uses. That is an observation about vocabulary, not a forecast.

Davies at DIBX, August 26. At the Department's inaugural DIBX conference in Philadelphia, she framed the goal as results rather than red tape — performance rather than paperwork — and described protecting federal data as table stakes: a regulatory requirement that never went away.

Davies on the current assessment model. She has characterized it as a check-the-box, point-in-time view of how a company handles sensitive data. Set that beside Question 5 and the two read as the same concern stated twice: a snapshot taken once a year says little about the other 364 days.

And one line from outside the Department, as a counterweight to the "CMMC is dead" crowd. Professional Services Council president Stephanie Kostro told Federal News Network on September 15: "This is not the death knell of CMMC."

How to read these together

Treat these statements as the boundaries the Department has drawn around its own reform conversation. Across officials and venues, the position on the record has been consistent: the burden is the target, not the standard. All seven questions fit inside that line — and Question 6 writes it directly into the sentence.

From the author

Volume 1: CMMC Level 1 — A Practical Guide for Small to Medium GovCon Contractors

All fifteen practices, the evidence behind them, the system description, and the self-assessment and affirmation that close it out — written for the 5- to 50-employee contractor. Volume 1 on Amazon

Volume 2: CMMC Level 2 — A Practical Guide for Small to Medium GovCon Contractors

The 110 practices across 14 domains, the enclave approach, and the documentation set a small business can actually maintain. Volume 2 on Amazon

Both by Rob Maupin, published by Overwatch Press. Kindle from $12.99.

See the series on Amazon

Where the Report Stands Today

The Task Force's report went to the CIO on or about September 11. As of this morning, October 1, it has not been released, and publication is the Department's decision. Industry observers have anticipated a public report somewhere in a late-September to early-October window — that is industry's read, not a schedule the Department has committed to. Which means any analysis of the report's contents circulating right now is speculation, including anything we might write. That is exactly why this article is about the questions instead. The questions are on the record. The report is not.

The One Place This Points That Matters to You

Look only at the parts of the RFI that touch verification: Question 4, Question 5, and the framing paragraph's language about leveraging and optimizing self-attestation. Every one of them points toward self-attestation carrying more weight, not less. Not because the Department has announced an outcome — it has not — but because that is what those questions are about: how much to lean on what contractors, and their vendors, already say about themselves.

Whatever shape the program takes, the same contractor is well positioned under every version of it. The one who can produce:

  • An accurate determination — MET or NOT MET on each of the 15 Level 1 practices, and at Level 2, an SPRS score that matches the actual network
  • A current system description at Level 1, or a System Security Plan (SSP) at Level 2
  • Dated evidence that the controls actually run — not just that a policy says they should
  • An annual affirmation signed by someone who is genuinely comfortable putting their name on it

The contractor who cannot produce those things is exposed under every version too. Including right now, with no program change required at all — the affirmation is already a representation to the federal government, today, under the rules already in force. DFARS 252.204-7012 and NIST SP 800-171 did not go anywhere in July, and neither did the Phase 1 self-assessment requirements.

If you hold Controlled Unclassified Information (CUI), the same logic stacks. Level 2 always sits on top of Level 1, never instead of it: 110 practices across 14 domains, an SSP, a POAM framework, a risk register, and evidence that each control runs. For a small business with limited CUI needs, a dedicated enclave on Google Workspace or Microsoft 365 GCC High — no Active Directory, no SIEM, no enterprise IT department — keeps that documentation set small enough to maintain honestly. Our L2 CUI Enclave Package provides the templates, configuration guides, and consulting for that work; clients implement.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

What to Actually Do With the Next Three Weeks

None of this requires knowing what the report says. All of it is regime-proof, unglamorous, and useful under every version of the program.

  1. Know your scope. Which systems, which people, and which locations touch federal contract data. Write it down on one page. If you cannot draw the boundary, nothing else on this list has a place to stand.
  2. Know what you hold. Federal Contract Information (FCI), CUI, or both. FCI brings Level 1; CUI brings Level 2 on top of it. Your contracts and your contracting officer are the authority on which you hold — if a marking or a clause is unclear, ask them in writing.
  3. Have a current self-assessment. Check the date on the one in SPRS. If your environment has changed since then — new staff, a new laptop fleet, a new cloud service — it describes a network you no longer run.
  4. Collect the evidence while you still remember where it lives. Screenshots, configuration exports, account lists, training records, visitor logs — each one dated. Evidence is perishable in a way that policies are not.

For the Level 1 gap check specifically, the free CMMC Assessment Tool covers all 15 practices in under 30 minutes and tells you which ones to fix first.

The Preview and the Verdict

The questions were the preview. The report, whenever the Department chooses to publish it, is the verdict. And a verdict on a recommendation is still not a rule — that is the subject of Part 3 of this series, on what a task force report can and cannot change.

For you, the most important thing about all of it is how little it changes the to-do list. An accurate self-assessment, a current description of your system, dated evidence, and an affirmation you can stand behind are the same four things whatever the Task Force recommended.

Either way, the work is the same work.

Read your own questions with someone who reads the memos.

Book a free 30-minute consultation. We will look at what your contracts actually require today, how current your self-assessment really is, and where your evidence stands — at Level 1, at Level 2, or both. No pressure, no six-figure quotes.

Book a Free 30-Minute Consultation

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

About the author

Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small and medium defense contractors, and the author of the CMMC Practical Guides series published by Overwatch Press — Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2, Kindle from $12.99. Overwatch Tools provides templates, configuration guides, and consulting; clients implement.

A guided documentation path for the L2 CUI Enclave Package is in development.

Sources & Further Reading

  • SAM.gov — Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (RFI)
  • SBA Office of Advocacy — DoW requests information for CMMC Reform Task Force (full question list) (July 20, 2026)
  • U.S. Department of War — release on the Phase II suspension (July 13, 2026)
  • DoD CIO — implementing memorandum, CMMC Phase II suspension
  • Breaking Defense — Pentagon announces immediate suspension of CMMC Phase II mandates (July 13, 2026)
  • DefenseScoop — Task force kickoff (July 17, 2026)
  • DefenseScoop — Pentagon pores over heaps of industry feedback on CMMC reform (September 9, 2026)
  • Federal News Network — As the Pentagon rethinks CMMC, cybersecurity isn't pausing (September 15, 2026)
  • Covington / Inside Government Contracts — CMMC Reform Task Force updates (September 21, 2026)
  • Class deviation memorandum, 2026-O0025 Revision 3, TAB A (September 3, 2026)
  • NIST SP 800-171
  • DoD CIO — CMMC program

This article is general information about an evolving regulatory situation, not legal advice. Contract interpretation and any question touching False Claims Act exposure should go to your attorney.

Tags: cmmc, FCI_vs_CUI, Google, L1, L2, MS365
Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
“Suspended” Is the...
"Suspended" Is the Wrong Word. So Is "Cancelled."
What a Task Force Report Can and Cannot Change
What a Task Force Report Can a...

Related posts

Your Whole Office Doesn't Need to Be Level 2
Read more

Your Whole Office Doesn’t Need to Be Level 2

Your Whole Office Doesn’t Need to Be Level 2 | Overwatch Tools The Enclave Build · Part 1 of 6 Your Whole Office Doesn’t Need to Be Level 2 If your CUI lives on one or two contracts, a Level 1 workplace with a small Level 2 enclave is often the better build: easier to work in,... Continue reading
What a Task Force Report Can and Cannot Change
Read more

What a Task Force Report Can and Cannot Change

What a Task Force Report Can and Cannot Change | Overwatch Tools Reference · The Deviation, Part 3 What a Task Force Report Can and Cannot Change The report will be read as a verdict. It is closer to an opening argument. Here is how to read it when it arrives, and the three documents that actually... Continue reading
"Suspended" Is the Wrong Word. So Is "Cancelled."
Read more

“Suspended” Is the Wrong Word. So Is “Cancelled.”

“Suspended” Is the Wrong Word. So Is “Cancelled.” | Overwatch Tools Industry Update · The Deviation, Part 1 “Suspended” Is the Wrong Word. So Is “Cancelled.” The CMMC pause stopped living in a memo in July. And the September document that half the industry read as the end of the program did not change the CMMC text... Continue reading
Rev. 2 to Rev. 3: What Changes for a Small Enclave
Read more

NIST Rev. 2 to Rev. 3: What Changes for a Small Enclave

Rev. 2 to Rev. 3: What Changes for a Small Enclave | Overwatch Tools The Second Front · Part 3 of 4 Rev. 2 to Rev. 3: What Changes for a Small Enclave The Department of War enforces one revision of NIST SP 800-171. The proposed FAR CUI rule reaches for the next one. If both touch... Continue reading
Do You Actually Hold CUI on a Civilian Contract?
Read more

Do You Actually Hold CUI on a Civilian Contract?

Do You Actually Hold CUI on a Civilian Contract? | Overwatch Tools The Second Front · Part 2 of 4 Do You Actually Hold CUI on a Civilian Contract? Sensitive, proprietary, and export-controlled are three different things. None of them is automatically Controlled Unclassified Information — and the difference decides your scope. By Rob Maupin, founder of... Continue reading

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool