Following the DoW’s suspension of CMMC Phase 2, the Department issued an RFI seeking industry input on reform. In support of small and mid-sized businesses in the defense industrial base, PreVeil submitted the response below.
PreVeil welcomes the Department’s initiative and responds from a unique vantage point: we protect CUI for more than 3,000 small and medium defense contractors — arguably the largest such footprint in the DIB — with a commercial solution that costs under $10K per company per year and deploys in hours, not months. Our offering is end-to-end encrypted file storage, file sharing, and email for CUI — what NSA and industry call the gold standard of cybersecurity — resilient against AI-era attacks and surpassing NIST 800-171 requirements. Our customers meet all 110 controls, and more than 100 have earned perfect 110 scores in CMMC assessments — as has PreVeil itself. The Department’s goal — a low-cost, high-security, compliant DIB built on commercial technology — is not aspirational: we have proven it at scale, and with a few adjustments this reform can extend it DIB-wide.
An SMB faces three compliance costs — the market has already solved two:
- IT systems to protect CUI. Real data from our 3,000+ SMB customers puts this at $8,300 per company per year on average.
- Documentation for assessments. Historically $40–70K in consultant hours; we have solved this with AIenabled compliance documentation software used by more than 2,000 SMBs, at $3.5K per company per year.
- Assessment. $30–50K per company — across ~80,000 DIB companies, billions of dollars.
Assessment is where reform must act — through properly designed self-assessment for SMBs: evidence-based, auditable, and carrying real consequences for false or misleading attestation, while larger companies continue C3PAO certification. Design is everything: self-assessment without real consequences for non-compliance is proven ineffective, as inflated SPRS scores and False Claims Act settlements attest.
We recommend evidence-backed self-assessment, beginning with a 12-month extension of CMMC Phase 1, with DFARS 252.204-7012 remaining fully in force. During this phase, every SMB implements the core controls first (e.g., the 56 controls the Department already weights 5 and 3 points), uploads specified evidence of compliance (SSP, shared-responsibility matrix, key artifacts), and a named senior executive signs a Department-created attestation specific enough that false statements carry legal consequences. Dollars go to implementing controls, not to assessments — putting the SMB DIB on a firm path to securing data.
In Phase 2, SMB self-assessments are verified — by Department-accredited AI, DIBCAC, and C3PAOs — to enforce honesty. Impossible when CMMC was designed, such verification is now practical: AI is exceptionally suited to assessing standardized compliance evidence. Adequate submissions are deemed provisionally accepted, and companies bidding on CMMC contracts must hold either a C3PAO assessment or, for SMBs, a provisionally accepted submission. The cheapest path to eligibility is genuine, well-evidenced compliance — insufficient evidence triggers a full C3PAO assessment at the company’s own expense, and false or misleading attestation carries additional penalties. The outcome: $10–15K per year instead of $80–130K, billions saved, and compliance data the Department can trust — through machinery it already runs. If the Department instead retains C3PAO assessments for every SMB — also reasonable — reducing the required team from three assessors to one dramatically lowers cost; the reforms are complementary.
Retain NIST 800-171, DFARS 7012, and FedRAMP Equivalence — simplify compliance, never lower the standard. No standard is ever perfect, but these are thoughtfully designed — and more necessary than when written: AI has made attacks on cloud infrastructure and DIB companies cheap, and FedRAMP’s cloud requirements are the Department’s only visibility into the rigor of a commercial cloud vendor’s security. Reform how equivalence is proven by updating the Department’s December 2023 FedRAMP Equivalence Memo: allow risk-based DIBCAC judgment on non-critical controls in place of absolute perfection (FedRAMP-authorized services carry POA&Ms by design; equivalence permits none), and certify services centrally through semiannual DIBCAC review of 3PAO attestations — ending the dissemination of a cloud provider’s full security dossier to thousands of customers. More high-caliber commercial vendors will then enter the DIB. Over time, strengthen CMMC by incorporating existing federal standards for end-to-end encryption (E2EE) of communication and collaboration — ITAR 120.54 already accepts E2EE for defense CUI stored, shared, or exported — delivering vastly greater cybersecurity for the DIB. The pages that follow answer the seven questions; we stand ready to pilot any element of this package with DIBCAC or the Task Force.
Response to RFI Questions
Question 1. Top five most prohibitive cost drivers, administrative burdens, or operational challenges
“Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced, or anticipates to experience, when attempting to comply with the CMMC framework and NIST SP 800-171 Rev 2.”
PreVeil provides cloud-based software that protects Controlled Unclassified Information (CUI) for more than 3,000 small and medium contractors in the Defense Industrial Base (DIB): end-to-end encrypted email and file storage and sharing, together with a complete software package that assists in generating the documentation required to demonstrate compliance. More than 100 of our customers are CMMC compliant with perfect 110/110 assessment scores; PreVeil itself is CMMC Level 2 certified, with a perfect 110 score of its own. We answer this question from that base of cost data, and our response throughout addresses the small and medium businesses that make up most of the ~80,000-company DIB — the population where the cost burden is most acute and where our data is deepest. Cost structures for large defense contractors differ materially and are not our subject. For an SMB undertaking CMMC, expense falls into three buckets — the IT systems that protect CUI, documentation preparation, and assessment — and the five most prohibitive drivers sit within and around them:
- Third-party assessment — $30–50K per SMB. The cost is structural. CMMC requires a three-assessor team for every assessment regardless of the organization’s size — overkill for an SMB whose environment may be a single commercial platform — and assessors bill by the hour for verification tasks that repeat, largely unchanged, from company to company. Limited capacity among CMMC Third-Party Assessment Organizations (C3PAOs) adds scheduling delays that stall contract eligibility. Across the DIB’s ~80,000 companies — most of them SMBs — this driver alone measures in the billions. Two straightforward fixes exist: reduce the required team to one assessor for SMBs, cutting assessment cost by roughly two-thirds; or, better, enable properly designed self-assessment — the SMB uploads specified evidence of compliance and named executive signs an itemized attestation, with AI evaluation and sampling by C3PAOs and the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) verifying submissions (our full proposal is outlined in our response to Question 5). Self-assessment done this way virtually eliminates assessment cost for SMBs while still delivering broad, real security to the DIB, because it rests on the same NIST 800-171 controls.
- Documentation preparation — $40–70K where still done by hand. Hourly-rate economics: consultants perform substantially identical work for every client. Our data conclusively proves that market forces can collapse this cost: we invested millions to build comprehensive documentation software — our Accelerator assists an SMB in creating a complete documentation package spanning all 110 controls — now serving more than 2,000 SMBs at $3.5K per SMB per year (described at www.preveil.com/compliance-package). AI is the game changer here: it assists with document preparation that, before AI, only a consultant could provide. The SMB won, the vendor won, and the market worked. No reform is required; competition gives every vendor the incentive to keep driving this cost down.
- IT systems to protect CUI — historically prohibitive for SMBs, now solved by commercial innovation.An SMB building a compliant environment in-house — or adopting legacy systems designed for sale to the government — once spent tens of thousands of dollars a year and months of effort. Innovative commercial platforms have collapsed that cost: our average SMB customer spends $8,300 per year on the IT systems that protect CUI, deployed in hours. Here too the market is working — thousands of SMBs are adopting commercial platforms for the cost and security benefits they deliver — and no policy reform is needed.
- Over-scoping. Overzealous compliance consultants routinely drive SMBs to bring the entire company into the compliance boundary, rather than only the users who handle CUI. We advocate the opposite: limit the boundary to the users who actually touch CUI, in an enclave. The market is already adopting this approach and denting the problem; clear enclave-scoping guidance from the Department would accelerate it. Over-marking of CUI by primes and by the government inflates scope further downstream and deserves attention as well.
- Inconsistent assessment scope decisions.The treatment of Security Protection Assets (SPAs) and Contractor Risk Managed Assets (CRMAs) varies from assessor to assessor, and the inconsistency compounds: fear of failing drives companies and their consultants toward maximalist positions — solutions that are not necessarily more secure, but are presumed compliant — raising cost with no security return. One company we work with failed an assessment over a cloud-connected camera that monitored the door of a room holding paper CUI in a locked cabinet — a scoping judgment, not a security gap. When scope depends on who assesses you, the rational response is to over-comply and over-pay. The fix is specific, not wholesale: standardize scoping so assets are classified by intended function and routine use rather than incidental exposure, delivered through Assessment Guide updates and C3PAO training — detailed in our response to Question 4.
Note the pattern. Where the market can compete — IT systems (driver 3) and documentation (driver 2) — costs have already collapsed without any policy intervention. Assessment cost (driver 1) cannot be competed away, because regulation fixes it in place: mandated team sizes and mandated third-party verification set a price floor no vendor can undercut. Only the Task Force can change that. Drivers 4 and 5 are likewise consistency problems only the Department can resolve. Our answers to Questions 4 through 6 address all five.
Question 2. Controls that deliver the most tangible uplift of cybersecurity and actual risk reduction
“Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction?”
The controls that matter most are the ones that encrypt CUI itself: when the data is strongly encrypted, its protection no longer depends on every other defense holding. By that measure, the most significant development in the DIB is that thousands of SMBs are adopting advanced end-to-end encryption (E2EE) to meet CMMC — even though CMMC does not mandate it. E2EE encrypts CUI at the sender, and only the intended recipient can decrypt it — no one else, not even the provider of the service. Stored CUI is likewise encrypted by default and never decrypted on the server. That last property is the crucial difference: conventional services encrypt data in transit and at rest but decrypt it on the server, where it is visible to whoever controls — or breaches — that server. E2EE never does. The design reflects a premise PreVeil took from MIT at its founding — and one NSA advocates — that the AI era has proven correct: every system can be breached, so the data must remain protected even when the breach succeeds. A breached E2EE server yields only ciphertext; a stolen administrator credential decrypts nothing. As AI collapses the cost of phishing, credential theft, administrator impersonation, and direct attacks on servers, defenses that depend on keeping attackers out degrade — E2EE’s protection does not.
Two forces explain adoption without a mandate. First, commercial services such as PreVeil deliver E2EE at commodity prices. Second, the International Traffic in Arms Regulations (ITAR) — which apply to many of the same SMBs — explicitly accept E2EE (22 CFR 120.54, crafted by the State Department in consultation with NSA) as a means of compliance for defense CUI being stored, shared, or exported. The regulation defines E2EE in just three requirements: the data is encrypted from originator to intended recipient, never unencrypted in between; no third party — including the service provider — holds the means of decryption; and the cryptography is FIPS 140-2 compliant or of at least comparable strength. Three requirements, set against CMMC’s 110 controls — a measure of how simple, and how powerful, this protection is. One system satisfying both ITAR and CMMC is why SMBs subject to both adopt E2EE most heavily. The pattern underscores the value of what the Department has built: CMMC and DFARS drive companies to secure CUI, and adjacent federal requirements pull the most advanced protections into SMB hands — benefits now evident at scale, and an excellent foundation for future augmentation of the standard (see our Question 7 response).
Beyond E2EE, the controls that deliver the most tangible risk reduction are those that guard the endpoints and credentials around the data, and those that close the doors attackers actually use: multifactor authentication (MFA) (3.5.3), full-disk encryption on endpoints (3.13.16), endpoint protection and malware defense (3.14.2), flaw and vulnerability remediation (3.14.1, 3.11.3), control of connections to external systems (3.1.20), incident response (3.6.1–3.6.2), and protected backups (3.8.9).
This is why the core control list we recommend is practical by any of its three definitions (our Question 6 response): the 56 controls the Department already weights at 5 and 3 points — its own prior judgment, adoptable at once with no new analysis; a purpose-built list that starts from those 56 and adds the few high-impact controls identified above; or the set consistent with today’s 88-point conditional-certification threshold. Over time, a recurring, evidence-based review of point values through the normal public-comment process would keep the weighting aligned with current threat data — deliberate improvement of the frameworks, not mid-reform rework.
Question 3. Requirements with the highest administrative overhead and least measurable security improvement
“Conversely, which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture?”
We answer this question differently than most respondents will. After helping more than 3,000 SMBs implement NIST 800-171, we do not find a meaningful set of controls whose security value fails to justify keeping them — the requirements are sound, and with modern tooling the full set of 110 is achievable in four to six months. What creates the highest overhead with the least security return is not any control; it is how compliance with the controls is proven. The costs below are real and measured, and — unlike the controls — they deliver nothing.
- (a)Documentation produced for assessors rather than for operations. System Security Plan (SSP) narratives written and rewritten to match individual assessor preferences; policy documents produced for the shelf; evidence assembled by hand, then re-assembled from scratch every cycle.
- (b) Re-verification of inherited controls. Platform controls proven once are re-verified company by company, across the DIB, at hourly rates. Our own experience illustrates the waste. PreVeil is used by thousands of SMBs; the platform has been reviewed by DIBCAC and examined by dozens of C3PAOs across more than one hundred customer assessments — assessments in which our customers earned perfect 110 scores. Yet each new assessment scrutinizes the same platform again, at hourly rates, adding cost and schedule and producing no new information — not because assessors choose to, but because nothing in today’s rules lets them rely on prior verification. FedRAMP long ago solved this problem: a platform is assessed once, and every agency — including those that never sponsored it — relies on that assessment. A well-proven platform should likewise be accepted into SMB assessments without re-evaluation. The assessor’s real job should solely be to verify that the platform is properly deployed and used at this contractor. But re-assessing a platform the same assessor found compliant at a different contractor weeks earlier is unnecessary by inspection, and periodic re-review of widely used platforms — quarterly or semiannually — would preserve assurance at a fraction of the cost. Our Question 4 response formalizes this as certification plus inheritance.
- (c) Over-classification of security tools. A malware scanner or monitoring platform that incidentally touches a file containing CUI can be reclassified as a full CUI Asset, triggering the full compliance treatment with no change to its protective function. Companies lose access to the best commercial security tools — backward from the policy’s intent. The fix is in our Question 4 response.
- (d) All-or-nothing assessment objectives. A single minor “not met” objective fails the entire security requirement, so a trivial, easily corrected documentation gap triggers the same Plan of Action and Milestones (POA&M) and remediation burden as a serious technical weakness — the administrative cost is identical while the risk difference is enormous.
The remedies follow from the diagnosis: keep the requirements, reform the proof. Our Question 5 and Question 6 responses replace hand-assembled, assessor-by-assessor proof with standardized evidence and AI evaluation; our Question 4 response standardizes tool classification by intended function and routine use; and a proportional remediation pathway — lighter POA&M treatment for minor gaps within otherwise-met controls — would size the burden to the risk. These are no-regret reforms: if the Department continues to require an assessment of every DIB contractor, SMBs included, they make those assessments dramatically cheaper and faster; if it adopts properly designed self-assessment for SMBs — our recommendation — they are what make the uploaded evidence trustworthy. Either future needs them; only one also eliminates the assessment bill. Together, these reforms remove the spend that buys optics without touching the controls that buy security.
Question 4. Commercial cybersecurity capabilities, and how the Department should recognize them
“Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk, and how the DoW might better recognize or accept these commercial solutions within a compliance or risk framework.”
The Department’s instinct to bring more commercial capability into the DIB is exactly right, and we offer our own history as proof. PreVeil is a commercial cloud platform created to bring the strongest available security guarantee — end-to-end encryption, regarded by national security agencies, industry, and academia alike as the gold standard, and never more needed than in the era of AI attacks — to the defense supply chain. We came from outside the traditional government-sales route, with a simple strategy: the best security, at a radically lower cost for the SMB. The headwinds were real: consultants and assessors routinely steered SMBs toward far more expensive, more complex government-authorized suites as the “safe bet” carrying an authority-to-operate (ATO) stamp — products whose cost and complexity fuel the high compliance figures widely quoted for CMMC, figures our data shows are avoidable. The market decided otherwise: more than 3,000 SMBs chose PreVeil, most of them for the cost savings — and what they received is security engineered to withstand nation-state attack, at a fraction of the price. Commercial entry made the DIB safer and cheaper at once.
Our platform shows what commercial capability does to the largest IT expense. PreVeil provides end-to-end encrypted email, file storage, and file sharing for CUI. We satisfy 100% of FedRAMP Moderate requirements while selling only commercially — our business is equipping the DIB, not the agencies. And PreVeil is itself CMMC Level 2 certified with a perfect 110 score. Deployment takes hours, not months; the platform costs under $10K per SMB per year — the collapse of the IT-systems cost bucket described in our Question 1 response — and more than 100 of our customers have earned perfect 110 assessment scores.
We then applied the same commercial strategy to documentation. Prepared the consultant way — the same work performed over and over, billed hourly — assessment documentation costs an SMB $40–70K. We invested millions to convert that repeated work into a rigorous software product, the Accelerator: more than 2,000 SMBs now use it, at $3.5K per SMB per year, to produce assessment-ready documentation across all 110 controls. AI has made it exponentially more powerful, because compliance is a use case AI is particularly well suited to — structured requirements, standardized evidence, repeatable judgments. Twice now, the Department’s instinct to promote commercial products has been validated in our own history, and the economics generalize beyond us: wherever the Department lets commercial competition operate, this cost curve follows.
How the Department should recognize commercial capability — three mechanisms, in ascending order of impact.
First, standardize scoping of commercial security tools (no rulemaking required). CMMC already provides a proportionate path: a Security Protection Asset — a tool that protects the environment but does not routinely store, process, or transmit CUI — is assessed only against the requirements relevant to its function (32 CFR § 170.19). The category is sound; its application is not. Across our customers’ assessments, similar tools are scoped differently by different assessors — the inconsistency described in our Question 1 and Question 3 responses. The fix: classify assets by intended function and routine use, not incidental exposure. A security tool that briefly touches a file containing CUI while doing its protective job should remain an SPA — with logging, containment, and remediation required — not be reclassified as a full CUI Asset; CRMAs should be held to a sound corporate baseline rather than the full 110. We note that PreVeil itself is not an SPA: our platform routinely stores, processes, and transmits CUI and is assessed accordingly, as a CUI Asset meeting FedRAMP Moderate equivalence — we advocate here for the broader ecosystem of commercial security tools, not for ourselves. Delivered through Assessment Guide updates and C3PAO training, this preserves the full control baseline for systems that routinely handle CUI. It is a faster, more consistent path to compliance — not a lower bar.
Second, certify platforms once and let companies inherit. Our Question 3 response illustrates the waste of reverifying a proven platform company by company; FedRAMP already proves the remedy. The Department certifies a widely used platform once; each company inherits the platform’s controls through the shared-responsibility matrix; and assessment effort concentrates on what is genuinely company-specific — whether the platform is properly deployed and used. Periodic re-review of certified platforms, quarterly or semiannually, keeps assurance current at a fraction of today’s cost. This is certification by the government’s own processes — inheritance, not vendor self-grading.
Third, keep FedRAMP firmly in place — and reform how equivalence is proven. We begin with advocacy: FedRAMP’s requirements are essential and must be retained. They are how the Department upholds the security of the cloud services that store and process CUI — and with AI collapsing the cost of attacks on cloud infrastructure, they are more necessary now than when they were written. Indeed, DFARS 7012’s equivalence provision is why we exist in this market: had it not wisely set the cloud standard at FedRAMP Moderate equivalence, only ATO holders could serve the DIB. We speak from experience: proving equivalence took PreVeil three years and great cost — 100% compliance with ~325 controls, a FedRAMP Third Party Assessment Organization’s (3PAO’s) annual assessment, and a multi-week DIBCAC examination. The standard is right; the perfection requirement is the barrier — and it is at odds with FedRAMP’s own design. FedRAMP-authorized services carry POA&Ms by design: the program was built to manage risk, not to demand perfection. Yet equivalence permits none, holding the commercial path to a stricter bar than the one government agencies themselves rely on. The result is predictable: extremely few commercial services have pursued equivalence, and the CMMC ecosystem is poorer for it. The Department wants more commercial entities in the DIB. That is achievable without lowering the bar, through two reforms to the December 21, 2023 Equivalency memo.
(a) Replace absolute perfection with risk-based judgment on non-critical controls. Critical controls stay nonnegotiable: fully implemented, no exceptions. For non-critical controls, let DIBCAC apply documented, risk-based judgment — restoring the risk-management approach FedRAMP itself was built on. Same rigor where it matters; an accessible journey for the strong commercial vendors the Department wants.
(b) Certify centrally; stop disseminating the Body of Evidence. Today a cloud service provider’s (CSP’s) Body of Evidence (BOE) — the complete description of its security posture: SSP, assessment plans and reports, scan results — must be furnished to every DIB customer so each can present it in its own assessment. In our case, more than 3,000 companies hold the blueprint of our defenses, and nothing prevents one of them from being an entity established precisely to probe those defenses. The fix mirrors what the Department already trusts: DIBCAC reviews the 3PAO’s attestation and continuous-monitoring reports on a semiannual cadence and certifies conforming services as meeting the FedRAMP requirement; organizations then rely on that certification for DFARS and CMMC without ever handling the BOE. Assessment engagements stop re-reviewing equivalence — cost falls — and the dissemination risk closes. Together with reforms already underway at the FedRAMP program office, these changes maintain the security of cloud services, draw more high-caliber commercial vendors into the equivalence journey, and rationally reduce the cost of compliance assessments instead of bureaucratically repeating them for no benefit.
One principle runs through everything we recommend: security first, then simplicity and cost. We have never advocated — and do not here — lower cost at the price of weaker security; the maximalist compliance postures fueling today’s costs deliver neither. None of this relaxes a standard; each mechanism preserves the full baseline while eliminating re-proof of what is already proven. Recognized this way, commercial capability means less disruption, less cost, more consistent outcomes, and faster protection of CUI — demonstrated today across thousands of DIB companies.
Question 5. Self-assessment: challenges, fundamental streamlining, and dynamic posture
“Regarding Phase I self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance, and how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture approach, or are they performed only for compliance purposes?”
We answer the second question first, candidly: today, self-assessment is performed for compliance, not security. Self-assessment without evidence and without the ability to audit does not work, and the Department’s own data proves it: DIBCAC reviews routinely find actual postures far below self-reported scores. False Claims Act enforcement has made some impact, but the cases are too few to change behavior across an 80,000-company industrial base. The clearest evidence is historical: DFARS 252.204-7012 has required NIST 800-171 compliance since 2017 on the strength of self-attestation — and the DIB moved little to protect CUI until CMMC carried the force of law. Verified requirements move markets; unverified promises do not.
The administrative burden compounds the accuracy problem. Evidence is gathered by hand each cycle. SSPs go stale between cycles. Scoring rules invite inconsistent interpretation and disputes. And there is no standard format, so the Department cannot compare one submission to another — the data it receives is neither verifiable nor comparable.
That said, we believe self-assessment can be made to work for SMBs — by giving it evidence and accountability. We recommend a 12-month extension of CMMC Phase 1 during which every SMB does three things: implements a Department-published core control list first (for example, the 56 controls the Department already weights at 5 and 3 points); uploads Department-specified evidence of compliance — SSP, shared responsibility matrix, key technical artifacts — in the everyday formats an SMB already produces (Word, PDF, spreadsheets, screenshots), which modern AI reads directly, so no special format or tooling is asked of the SMB; and has a named senior executive sign a Department-created attestation certifying specific facts — “MFA enforced for 100% of CUI accounts as of [date]” — not a general checkbox (precedents: SOX 302, and CMMC’s existing affirming-official requirement). In Phase 2, an AI evaluator — built or accredited by the Department — judges every uploaded package as adequate or requiring C3PAO assessment; DIBCAC and C3PAOs conduct statistically significant sampling, including spot-checks of packages the evaluator deemed adequate; and contract eligibility requires either a C3PAO assessment or, for SMBs, a provisionally accepted submission. The economics enforce honesty: the cheapest path to eligibility is genuine, well-evidenced compliance — insufficient evidence triggers a full C3PAO assessment at the company’s own expense, false or misleading attestation carries additional penalties, and disclosed good-faith gaps receive a safe harbor.
What makes this feasible now, when it was not in 2017, is AI. Self-attestation went unaudited for a simple reason: verifying tens of thousands of submissions by hand was impossible, so none were verified. AI changes that arithmetic radically. An AI evaluator can read every SSP, examine every uploaded artifact, judge each control against the same standard a human assessor applies, compare submissions across the entire DIB, and flag anomalies for human review — every package, not a sample, at negligible marginal cost. Compliance is a use case AI is exceptionally well suited to: structured requirements, standardized evidence, repeatable judgments. The verification gap that doomed self-assessment in 2017 no longer exists.
This design also answers the Department’s deeper question about dynamic posture. A standing evidence package converts self-assessment from an annual ritual into living compliance data — continuously refreshed, comparable across the DIB because AI evaluates every submission against the same standard, and useful to the Department in a way today’s unverifiable scores are not. Our customer experience supports this: SMBs whose documentation is generated and maintained by software keep their posture current between cycles rather than reconstructing it annually. One low-cost companion reform would help further: DoD’s full Assessment Guides include worked examples for each control, but the self-assessment materials most SMBs rely on do not — bringing that same detail into self-assessment guidance would cut scoring ambiguity for companies without in-house compliance staff.
PreVeil is already developing this evaluation tooling — an effort begun well before this RFI. Our AI Assessor, part of the Accelerator, has two goals drawn from our customers’ needs — the same goals that animate this reform. First, ensure an SMB is pre-checked, control by control, before it ever approaches a C3PAO. Second, hand the assessor a standardized, pre-verified compliance package: standardization removes variability, so the assessor streamlines the engagement instead of redoing everything at the billable hour — and the customer’s assessment cost falls. It is the same lever described throughout this response, aimed at the hardest expense bucket of the three: assessment. The tool is designed to examine the same documents and artifacts a human assessor examines and to judge whether each control is met — a readiness verdict before the real assessment. We are careful about claims: the capability is under development and not yet validated, and we expect to be in a position to pilot it — with DIBCAC or the Task Force, which we would welcome — in 2027. We share it to demonstrate direction: the evaluation tooling the Department needs is already being built by the commercial market, unprompted. As such tools mature, a natural step follows: let DIBCAC assess and accredit them against a published standard, and let assessments run by an accredited tool be admissible as evidence of compliance — standardized, reproducible, and auditable — with acceptance decisions remaining with the Department’s evaluator and DIBCAC sampling. The precedent is familiar: NIST validates a cryptographic module once, and everyone relies on its output. Accreditation should be open to any vendor’s tool; we ask only to be judged by the same standard.
Question 6. Actionable policy changes to drastically reduce SMB cost without degrading protection
“What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses without degrading the protection of federal data?”
Our recommendations share one design principle: change how compliance is proven, never what security is required. Every element reuses machinery the Department already runs — the Supplier Performance Risk System (SPRS), DIBCAC, the C3PAO ecosystem, existing memos and Assessment Guides — which is why nearly all of it is achievable within the Task Force’s 60-day window through memoranda, published forms, and class deviation, with no rulemaking. The centerpiece: adopt well-designed, enforceable self-assessment for SMBs — in six actions.
- Announce a 12-month extension of CMMC Phase 1 for SMBs, with DFARS 252.204-7012 remaining fully in force throughout — no security gap.
- Publish the core control list SMBs must implement first. Three ready definitions, all anchored in the Department’s existing practice: the 56 controls already weighted at 5 and 3 points in the 800-171 Assessment Methodology; a broader purpose-built list per our Question 2 response; or the set consistent with the 88-point score at which the Department already grants conditional CMMC certification today, with POA&Ms for the remainder. Any of these works; designation takes a memo.
- Publish the evidence specification: what the package must contain — SSP, shared-responsibility matrix, key technical artifacts — in the everyday formats SMBs already produce (Word, PDF, spreadsheets, screenshots). AI evaluation makes submissions verifiable and comparable without imposing special formats or tooling on the SMB.
- Publish the itemized executive attestation form: a named senior executive certifying specific facts, not a checkbox.
- Publish the AI-evaluator accreditation standard, start the build — and announce now that every SMB package will be evaluated. The evaluator will take time to build or accredit; the announcement should not wait. SMBs who know their submissions will be examined — by DIBCAC and C3PAO sampling from day one, and by AI evaluation as accredited tools come online — will implement and document accordingly. The deterrent begins with the announcement, not the tooling.
- Announce the Phase 2 rules now, so the DIB can plan. At the end of the extended Phase 1 — November 2027, twelve months beyond Phase 2’s current November 2026 start — only entities that are either C3PAO certified or whose executive-signed attestation and compliance evidence have been accepted through the Department’s portal are eligible to bid on contracts designated as requiring CMMC. The evaluator judges each uploaded package adequate or requiring C3PAO assessment; DIBCAC and C3PAOs conduct statistically significant sampling; SMB acceptance is refreshed annually. Insufficient evidence triggers a full C3PAO assessment at the company’s own expense; false or misleading attestation carries additional penalties; disclosed good-faith gaps receive a safe harbor. Should the Department want a longer runway, it need no designate every Phase 2 contract as requiring CMMC at once — an increasing share over time preserves competition while ensuring that companies committed to the DIB take these steps now.
Five companion reforms, each also achievable within 60 days: standardize SPA/CRMA scoping through Assessment Guide updates and C3PAO training (Question 4); publish enclave-scoping guidance so compliance boundaries are limited to the users who handle CUI (Question 1); introduce a proportional remediation pathway for minor, easily corrected gaps within otherwise-met controls (Question 3); reform the FedRAMP equivalence process by updating the December 21, 2023 Equivalency memo — risk-based judgment on non-critical controls, and central DIBCAC certification in place of Body-of-Evidence dissemination (Question 4); and commit to a stable Rev 2 baseline through the reform period, so no company pays twice for churn. One further track may require rulemaking and should begin now: acceptance of end-to-end encryption as ITAR already defines it (22 CFR 120.54) — reciprocity with an existing federal standard, not the creation of a new one — addressed in our Question 7 response.
And one pragmatic alternative deserves explicit standing. Should the Department prefer to retain C3PAO assessment for every SMB rather than adopt self-assessment, it should reduce the mandated assessment team for SMB engagements from three assessors to one — immediately cutting assessment cost by roughly two-thirds (our Question 1 response), with no loss of rigor for small, low-complexity environments. We advocate evidence-backed self-assessment as the stronger reform; this alternative delivers meaningful relief within the current model, and the two are not mutually exclusive during transition.
None of this degrades protection — the requirements never change; only the proof does, and the proof gets stronger: evidence, executive accountability, AI evaluation of every submission, and statistically significant human sampling, versus today’s unverified scores. Nor is the ask excessive. These are appropriate requirements for any entity that participates in the national security ecosystem — requiring less imposes risk on the warfighter. Our cost data shows the reformed path is comparable in effort and cost to SOC 2, a standard tens of thousands of commercial SMBs meet voluntarily because larger customers demand it as a condition of doing business. The Department’s mission is far more consequential, and these reforms let it hold that higher bar at commercial cost: maintain strong security, strengthen it over time, strip away compliance performed for its own sake, and harness commercial entities and breakthrough AI for massive savings. The outcome: total SMB compliance cost of $10–15K per year instead of $80–130K, billions saved across the DIB, and compliance data the Department can finally verify and compare. The barrier to entry falls furthest for the non-traditional businesses the Department most wants: commercial platforms, self-serve documentation, and evidence-based attestation are exactly the path a company without a compliance department can follow.
Question 7. Actionable policy changes to drastically improve operational resilience
“What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically improve operational resilience against cyber attacks at your organization?”
Resilience means staying operational after an attack — not passing an audit before one. Three reforms deliver it fastest, and all three begin within the Task Force’s window. First, core-controls-first sequencing (Question 6). The controls that stop real attacks — patching, MFA, endpoint protection, controlled external connections — get implemented and attested across the SMB DIB within months, instead of waiting on assessment schedules or arriving diluted across all 110 requirements. Current breach data shows where attackers actually enter: unpatched vulnerabilities and third-party connections. Sequencing puts the doors they use first in line.
Second, accept end-to-end encryption for communication and collaboration services, as ITAR already defines it — reciprocity with 22 CFR 120.54,1 not the creation of a new standard. The reason to act is AI. AI has collapsed the cost of mounting sophisticated attacks on servers, and nation-state actors will certainly deploy them against the DIB. Servers are where most services are weakest: conventional encryption protects data in transit and at rest, but decrypts it on the server — where it is visible to whoever breaks in. E2EE never decrypts on the server. So when a breach succeeds — and in the AI era, planning must assume some will — the attacker gets ciphertext, a stolen administrator credential decrypts nothing, and the business keeps operating because the data survives. The most lethal class of AI-era attack is defeated by architecture, not vigilance. The government’s own security authorities have reached the same conclusion: the State Department accepts E2EE as the compliance path for defense technical data that is stored, shared, or exported, and NSA — advising federal teleworkers during the pandemic — made end-to-end encryption its first criterion for selecting collaboration services.2 The field is already there: thousands of DIB companies use E2EE today to meet DFARS and CMMC. We are deliberate about scope — E2EE is not the answer for every workload. For communication and collaboration, the email and file sharing where CUI actually moves — the same scope as NSA’s guidance — it is the gold standard. We acknowledge our interest plainly: this is the market we serve. It is also where NSA’s guidance points, where ITAR already stands, and where thousands of DIB companies already are. Acceptance may require rulemaking and should begin now; encouragement need not wait. Given the AI threat, and given that E2EE is already required practice for ITAR technical data — which overlaps heavily with CMMC CUI — the Department should encourage adoption immediately. Pragmatic, rational, and proven.
Third, keep and use what already works. The 72-hour incident reporting obligation of DFARS 7012 stays — it is the Department’s early-warning system. Backups and recovery belong on the core control list, so that recovery from ransomware is provable, not aspirational. None of these three reforms adds bureaucracy; each moves real protection forward in months. And together they express the principle we would leave the Task Force with: security first, with compliance as its record — not the other way around.
Feedback on Feasibility
Everything recommended here was designed backward from feasibility. The instruments are ones the Department already uses: memoranda, published forms and specifications, Assessment Guide updates, C3PAO training, class deviation, and an update to an existing memo (the December 21, 2023 FedRAMP Moderate Equivalency memo). The institutions are ones the Department already runs: SPRS as the eligibility gate, DIBCAC for sampling and review, and the C3PAO ecosystem for certification of larger entities, streamlined reviews, and sampling support. Within the 60-day window, the Task Force can recommend — and the Department can announce — the Phase 1 extension, the core control list (three ready definitions in our Question 6 response), the evidence specification, the attestation form, the evaluator accreditation standard, and the Phase 2 eligibility rules, including the November 2027 gate.
Two elements run on longer tracks, and the design accounts for both. The AI evaluator will take time to build or accredit — which is why the announcement comes first (the deterrent begins with the announcement) and DIBCAC and C3PAO sampling carry verification from day one; commercial evaluator development is already underway across the market, ours included, with accreditation as the quality gate. Acceptance of end-to-end encryption may require rulemaking — which is why it starts now, and why the Department can encourage adoption in the interim. The dependency chain is short: publish the evidence specification and uploads begin; accredit evaluators and evaluation begins; in November 2027, eligibility attaches. The government’s costs are modest — forms, guides, a portal, an accreditation process — against billions in DIB-wide savings.
Potential Risks, Challenges, and Innovations
We flag the risks of our own proposal candidly. (a) The evidence repository is a high-value target. A central store of the DIB’s compliance evidence — SSPs, configurations, known gaps — would be among the most attractive espionage targets ever assembled. It must be protected to the highest standard, with encryption that denies access even to the repository’s operators; otherwise the fix creates a bigger version of the problem it solves. (b) AI evaluators will err in both directions. False adequacy and false referral will both occur at some rate. The design absorbs this: packages judged adequate are sampled by humans, and a company judged inadequate gets a human path — a C3PAO assessment — rather than an appeal to a machine. The human checks should be staffed primarily through the C3PAO ecosystem, with DIBCAC providing oversight and drawing on C3PAOs to augment its capacity: assessors are paid for the work and will scale to it, and neither the Department nor DIBCAC absorbs a new workload — another benefit of keeping the existing ecosystem in place. (c) The AI evaluator may take longer to build than planned. That is acceptable — by design. The system’s power is in the uploaded evidence and the detailed executive affirmation, and both are durable: they change behavior the day they are required, and they can be evaluated whenever the tooling arrives. A late evaluator delays automation, not accountability. (d) Evidence can be staged. Some companies will try to game their uploads. Executive attestation with legal consequence, statistically significant sampling, and full-cost C3PAO referral for insufficient evidence make gaming more expensive than compliance — the same economics that make the system work. (e) The C3PAO transition is real. Assessment volume shifts from routine SMB engagements toward certification of larger entities, streamlined reviews, sampling, and periodic platform re-reviews. The ecosystem remains essential, but its revenue mix changes; the Department should engage it early and phase the transition.
Two innovations deserve the Task Force’s attention beyond the core recommendations: accreditation of AI assessment tools whose outputs are admissible as evidence, with acceptance decisions remaining with the Department; and reciprocity with existing federal end-to-end encryption standards (22 CFR 120.54) for communication and collaboration services. Both extend a principle the Department already trusts — certify once, rely many times — to the technologies that can carry it furthest.