MFA Submits DOW’s CMMC Questionnaire

Email Update | August 18, 2026

The DOW asked how CMMC Phase 2 compliance will impact businesses, and MFA shared your insights.

Earlier this month, DOW suspended CMMC Phase 2 compliance and stood up a CMMC Reform Task Force to do a “top-to-bottom review” of the program and its impact on small to medium businesses.

Thanks to the MFA ambassadors and everyone who shared your insights for this RFI.

As a reminder — please take our CMMC survey when you have a moment. This data will help our efforts with the US Senate as they discuss including military movers in the grant program to offset CMMC II compliance costs.

We submitted the results this past Friday as part of the DOW’s CMMC RFI. The full contents of that submission are below.


REMINDER: Take the Short CMMC Survey ASAP

Movers for America is working on moving policy to support the industry, and we need your help providing key data to U.S. Senators. 

MFA is actively working with U.S. Senators and key staff to ensure military movers are eligible to apply for a grant to help offset the costs of CMMC Level 2 Compliance. The proposed grant is part of the Senate’s draft National Defense Authorization Act (NDAA) for 2027. As a reminder, the NDAA sets the annual policies and budget for DoW programs.

If you haven’t already, please take this short 6-question survey.


RECENT INDUSTRY NEWS

AUSA: Report: Military Families ‘Functioning but Vulnerable’
Though military families are faring decently, readiness across several dimensions of family life provides a more nuanced picture, according to a Military Family Advisory Network report. READ MORE

AP: Trump says US has no planned talks with Iran and other news from the Middle East
President Donald Trump on Tuesday said the U.S. has no planned talks with Iran but insisted the Strait of Hormuz remains “open and operating,” despite limited traffic and a reported strike on a ship exiting the waterway. READ MORE

USA Today: Maps capture the travel strain on USS Abraham Lincoln aircraft carrier
A change in supply bases, which resulted in 2,100 miles between U.S. Navy combat ships and their nearest resupply hub, has prompted concern over mental health of the crew and supply issues aboard the aircraft carrier USS Abraham Lincoln (CVN-72). READ MORE


MFA CMMC RFI

Subject: Reforming CMMC and Reducing Compliance Burden for the DIB

1. Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced, or anticipates experiencing, when attempting to comply with the CMMC framework and NIST SP 800-171 Rev. 2.

Across respondents, five primary challenges consistently emerged:

1. Cost of compliance and specialized cybersecurity expertise.

The financial burden of CMMC compliance is significant, particularly for small and medium-sized businesses that do not maintain dedicated internal cybersecurity teams. Organizations are increasingly dependent on third-party IT providers, consultants, managed security services, and specialized compliance expertise to interpret and implement CMMC requirements. One respondent currently spends approximately $1,600 per month in additional IT costs to maintain Phase I compliance and has received an estimate of approximately $18,000 per month for Phase II compliance. These costs can become prohibitive for smaller transportation providers, agents, and subcontractors.

2. Documentation, evidence collection, and ongoing administrative requirements.

Developing and continuously maintaining System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, risk assessments, data maps, and supporting evidence represents one of the largest administrative burdens. Organizations with multiple business lines or systems may need to document numerous in-scope environments. At Level 2, the 110 NIST SP 800-171 requirements are further evaluated through hundreds of individual assessment objectives. Without a standardized minimum evidence baseline or dedicated governance, risk, and compliance tooling, companies often maintain evidence manually across documents, spreadsheets, and repositories and may over-document defensively because assessor expectations are not always predictable.

3. FIPS-validated encryption requirements.

Implementing and continuously verifying FIPS-validated cryptography creates substantial technical and administrative costs. Companies must research individual products and vendors, obtain documentation of validation, monitor changes in certificate status, and potentially remediate legacy systems that already use strong encryption but cannot readily demonstrate FIPS validation. Respondents questioned whether applying the same requirement uniformly to all categories of CUI produces a risk reduction proportionate to the cost, particularly for transportation and logistics providers handling administrative CUI rather than sensitive defense technical information.

4. Cloud licensing, FedRAMP requirements, and regulatory uncertainty.

Respondents identified continued uncertainty regarding when commercial cloud environments, FedRAMP Moderate environments, GCC/GCC High products, or other government-specific offerings are required. Different consultants, vendors, assessors, and government representatives may provide different interpretations. Without clear, written, citable guidance, contractors may purchase significantly more expensive government-tier products simply to reduce compliance uncertainty rather than because those products materially reduce the cybersecurity risk associated with the data they handle.

5. Legacy systems, subcontractor compliance, and operational implementation.

CMMC requirements can require significant modernization of legacy infrastructure, implementation of MFA and encryption, expanded logging, device management, and other technical changes. These projects can be especially difficult for operational businesses with limited windows for major system changes. In the military household goods industry, for example, the April-through-October peak moving season makes significant production-system changes particularly disruptive. Extending requirements to small agents, suppliers, and subcontractors creates an additional challenge because many have limited IT resources and may rely entirely on outsourced technology support.

2. Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction?

Respondents consistently identified controls that directly prevent, detect, or contain cyber threats as providing the greatest measurable security benefit.

Multi-factor authentication (MFA) for user, remote, privileged, VPN, and administrative access was repeatedly identified as one of the most valuable controls because it directly reduces the risk associated with compromised credentials.

Endpoint detection and response (EDR), SIEM/SOAR, managed detection and response, and vulnerability management have also produced significant improvements by giving organizations continuous visibility into actual threats and vulnerabilities. Commercial platforms such as Rapid7 and managed SOC services allow organizations to identify suspicious activity, prioritize vulnerabilities, and respond to events more quickly.

Identity management, least-privilege access, and device hardening have reduced risk by restricting unnecessary permissions, automatically removing unauthorized administrative access, hardening browsers and endpoints, and enforcing standardized security configurations.

Respondents also identified email security, spam and phishing protection, firewalls, encryption at rest, default-deny network controls, secure cloud environments, and physical data-center protections as delivering meaningful security benefits. AI-enabled security products have further improved organizations’ ability to identify sophisticated email and behavioral threats.

Overall, respondents found the greatest value in controls that continuously prevent, identify, or respond to actual threats rather than controls primarily designed to demonstrate compliance at a single point in time.

3. Conversely, which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture?

Respondents distinguished between requirements that improve security and requirements where significant resources are spent primarily demonstrating that security exists.

Documentation and evidence production were among the most frequently cited burdens. Developing and continuously maintaining SSPs, formal governance documentation, evidence packages, meeting records, and documentation supporting individual assessment objectives can require substantial resources without necessarily changing the underlying security posture.

FIPS validation requirements were similarly cited. Respondents recognized the importance of encryption but questioned the incremental security value of repeatedly documenting that a particular implementation is FIPS-validated when strong commercial encryption is already in place. In these circumstances, significant effort may be spent obtaining and maintaining proof of compliance rather than improving encryption itself.

Cloud environment and FedRAMP/GCC licensing uncertainty can also create substantial costs. Migrating to a more expensive government-specific cloud environment may provide limited additional risk reduction where the organization handles administrative or logistics-related CUI rather than export-controlled or defense-unique technical information.

Duplicative application logging was another concern where organizations already maintain centralized SIEM and managed monitoring capabilities. Requiring additional application-specific logging that does not materially improve security visibility may create significant storage, configuration, and administrative burdens.

Finally, respondents questioned compliance approaches that emphasize point-in-time assessments and documentation snapshots rather than continuous monitoring. An organization capable of demonstrating compliance on assessment day is not necessarily more secure than one continuously monitoring, enforcing, and improving its controls throughout the year. Compliance frameworks should therefore place greater value on sustained security outcomes.

4. Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk, and how the DoW might better recognize or accept these commercial solutions within a compliance or risk framework.

Respondents rely extensively on commercially available cybersecurity technologies and managed services rather than developing bespoke government-specific solutions. These include Microsoft 365, Azure, Defender, Intune, Purview, Rapid7 InsightIDR and vulnerability management products, managed SOC services, endpoint detection and response, patch and asset management platforms, mobile device management, commercial cloud backup and disaster recovery, firewalls, MFA, email filtering, AI-enabled email security, and commercially available vulnerability-management tools. These platforms frequently address multiple CMMC requirements simultaneously while also providing meaningful day-to-day security benefits.

The Department could better recognize these investments by allowing documented commercial capabilities and vendor certifications to serve as evidence of inherited controls where appropriate. For example, a documented FedRAMP Moderate or equivalent authorization for underlying cloud infrastructure should be clearly recognized when it satisfies the applicable regulatory requirement, rather than forcing organizations to purchase a separate government-tier version of substantially the same platform.

Similarly, managed detection and response, continuous vulnerability management, automated configuration enforcement, commercial mobile application containerization, and other continuously operating controls should receive meaningful compliance recognition. The framework should encourage organizations to invest in scalable commercial capabilities that continuously reduce risk rather than requiring duplicative, government-specific implementations that produce limited incremental security benefits.

5. Regarding Phase I self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance, and how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture approach, or are they performed only for compliance purposes?

The primary challenge with Phase I self-assessments is not necessarily the initial assessment but maintaining an accurate compliance picture as systems, vendors, personnel, and business processes change.

Organizations must continuously update SSPs, POA&Ms, policies, vendor certifications, technical configurations, and supporting evidence. Without dedicated governance and compliance software, much of this information is maintained manually across separate documents and spreadsheets. As a result, an assessment can become a point-in-time snapshot that begins becoming outdated as soon as the environment changes.

Vendor certification and cloud-service requirements create additional complications. Contractors must independently verify vendor claims, track changing FIPS validation status, interpret DFARS cloud requirements, and reconcile potentially conflicting guidance from vendors, consultants, and assessors. Multiple contractors may therefore perform the same research on the same commercial products.

The process could be substantially streamlined through standardized evidence requirements, automated evidence collection, continuous monitoring, centralized vendor certification information, and standardized electronic reporting into SPRS. A clearly defined minimum evidence baseline for assessment objectives would also reduce defensive over-documentation and variability between assessors.

Experiences with self-assessment have varied. For some organizations, Phase I was primarily a compliance exercise and did not dramatically alter their cybersecurity posture because mature IT controls were already in place. For others, the assessment process identified genuine technical gaps—including encryption, legacy-system, configuration, and FIPS issues—and accelerated remediation.

Future assessments should therefore incentivize investments that create continuous and reusable security capability, such as centralized logging, automated configuration enforcement, vulnerability management, and continuous compliance monitoring, rather than placing disproportionate emphasis on manually maintained documentation that demonstrates compliance only at a particular moment.

6. What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses without degrading the protection of federal data?

Respondents strongly support maintaining meaningful cybersecurity requirements but recommend that the framework become more risk-based, scalable, and predictable.

Specific recommendations include:

●     Right-size requirements based on risk, considering the type, sensitivity, and volume of CUI handled and potentially the size and technological sophistication of the contractor. A small logistics provider handling administrative CUI should not necessarily face identical technical requirements to a defense contractor handling export-controlled weapons-system data.

●   Reevaluate whether all Level 2 requirements should apply uniformly to small and medium-sized businesses and consider whether Level 1 or an enhanced Level 1 could appropriately address lower-risk CUI environments.

●   Recognize established commercial cybersecurity frameworks and certifications, including SOC 2, ISO 27001, NIST CSF, and relevant commercial certifications, where they demonstrably satisfy equivalent CMMC objectives.

●      Clarify FIPS requirements, including where FIPS-validated encryption is required and whether requirements can be risk-tiered based on the sensitivity of the CUI involved.

●     Publish clear, written guidance regarding FedRAMP Moderate, GCC, GCC High, and other cloud requirements, eliminating the need for contractors to rely on conflicting verbal or third-party interpretations.

●   Create a centralized government repository of certifications and attestations for commonly used commercial vendors, preventing thousands of contractors from independently researching the same products.

●      Publish a standardized minimum evidence baseline for Level 2 assessment objectives so contractors know what constitutes sufficient evidence and assessors apply requirements more consistently.

●      Provide flexibility in the 180-day POA&M remediation period when major legacy-system remediation conflicts with documented operational change freezes or other mission-critical requirements.

●      Reduce duplicative documentation requirements and place greater emphasis on automated, continuously enforced controls.

●      Provide financial and technical assistance to small businesses, particularly those dependent on outsourced IT services, so compliance costs do not force otherwise capable providers out of the Defense Industrial Base.

The objective should not be to weaken cybersecurity. It should be to redirect limited contractor resources away from duplicative documentation, licensing uncertainty, and compliance administration and toward controls that demonstrably reduce cybersecurity risk.

7. What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically improve operational resilience against cyber attacks at your organization?

The Department should prioritize reforms that help organizations prevent, detect, respond to, and recover from actual cyber incidents.

First, the Department should recognize and incentivize continuous security capabilities, including endpoint detection and response, managed SOC services, SIEM/SOAR, vulnerability management, automated configuration enforcement, identity management, least-privilege access, incident response planning, and tested backup and disaster-recovery capabilities. Investments in these areas provide ongoing protection and should receive greater compliance recognition than point-in-time documentation exercises.

Second, the Department should provide shared or subsidized cybersecurity resources for small and medium-sized businesses, including access to managed detection and response services, cybersecurity consulting, training, vulnerability management, incident-response planning, and disaster-recovery exercises. Many smaller businesses do not employ full-time cybersecurity professionals and instead rely on outsourced IT providers, making advanced security services disproportionately expensive.

Third, DoW should consider creating or supporting a secure communications environment for TSPs, agents, suppliers, and transferees involved in military household goods relocations. Today, securely exchanging CUI can depend on the capabilities of numerous independent organizations and communication platforms. A standardized secure environment would reduce the risk created when small suppliers or agents lack sophisticated encryption capabilities.

Fourth, incident reporting should be streamlined so that a single report can satisfy overlapping government reporting obligations wherever possible. During an actual cyber incident, resources should be focused on containment and recovery rather than duplicative administrative reporting.

Finally, cybersecurity requirements should focus limited small-business resources on controls with demonstrated security value—including MFA, vulnerability management, advanced security awareness training, endpoint protection, identity and access management, incident-response planning, disaster recovery, backups, and continuous monitoring—while reevaluating high-cost requirements that primarily generate compliance documentation or impose technical complexity without proportionate risk reduction.

The overarching goal should be a CMMC framework that measures and rewards actual cybersecurity resilience. Small and medium-sized businesses should be encouraged to invest their limited cybersecurity resources in controls that prevent attacks, detect threats quickly, limit their impact, and enable rapid recovery, rather than disproportionately spending those resources proving compliance through documentation and administrative processes.

Movers for America has hired an independent, third-party agency to gather facts and compile information that is shared with users who access this website. Movers for America, this website, or the information contained on this website is intended to provide general, factual information and is not produced with the intent to directly or indirectly influence any decisions or behaviors of those who access the website or information. The facts and information contained on this website are made available for website users’ independent use, interpretation, and verification.

Scroll to Top