Comment on FR Doc # 2026-12559
Corey FurstSupportOther
Summary: The commenter argues that the CMMC framework imposes significant financial and bureaucratic burdens on small and large businesses, particularly outside the DC region. They request that federal agencies reduce CMMC Level 2 requirements for government projects and simplify the certification process to lower costs and resource investments.
In our outreach and investigations, much of the market outside of the District of Columbia/Maryland/Virginia region has not shown interest in pursuing, achieving, or retaining Cybersecurity Maturity Model Certification (CMMC) Level 2 and beyond. "SBA has also warned that the current CMMC framework imposes costly bureaucratic burdens on small contractors that are essential to growing the U.S. Defense Industrial Base (DIB), citing costs of $593,800 per CMMC certification for small firms requiring third-party assessment, and about $388,600 for firms eligible for self-assessment."
Our research has also indicated that this is a significant investment in time, resources, and capital that many large and small businesses are not able to invest in, especially given the number and size of construction opportunities outside of federal CMMC opportunities. We request that federal agencies make a considerable effort to reduce the requirements for CMMC Level 2 on government project opportunities and limit the amount of CUI and FCI required in these projects. In addition, we suggest that the requirements for meeting the CMMC Level 2 certification (both self-certified and third-party verification (C3PAO)) be reviewed and simplified to reduce the required resources and investments for both large and small businesses.
https://www.sba.gov/article/2026/07/13/sba-commends-us-department-wars-suspension-cmmc-phase-ii-small-defense-contractors